Add some reference files

This commit is contained in:
2026-05-18 08:30:46 -05:00
parent e86259ffad
commit bf90a29934
17 changed files with 7430 additions and 0 deletions
+909
View File
@@ -0,0 +1,909 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-304756</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where, after you disabled the shared
optimization feature, a full configuration push to multi-vsys devices
caused a validation error.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-299354</b></div>
</td>
<td class="entry relcol">
<div class="p">
Added a CLI command to adjust the local pool cache size of the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>detector_threat</a
>
process to address an issue where the local-reuse memory pool borrowed
from the global pool, which impacted performance during session
deletion.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-299228</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a session process consumed excessive CPU
resources, even when Data Loss Prevention (DLP) was not enabled. This
occurred due to the active threat list being iterated twice when
active threats were present in the session.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-298907</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on PA-VM in AWS where, in a two-arm deployment
integrated with Gateway Load Balancer (GWLB), the firewall did not
preserve the GENEVE source port for internet traffic, resulting in
increased latency. The fix ensures the firewall preserves the outer
UDP source port of GENEVE encapsulation when sending traffic back to
GWLB.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-298505</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading an HA pair of PA-7050 firewalls,
the vsys ID changed in sequence, causing autocommit failures with
validation errors. This occurred when the multi-vsys firewall had
virtual systems created and pushed from Panorama, and the vsys ID was
not in a correct sequence because the unused vsys was deleted from
Panorama and pushed to devices.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297775</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to an affected PAN-OS release,
the Visible Virtual System field referenced the vsys name instead of
the vsys ID, which caused inter-vsys routing to fail. This occurred
when a vsys display name matched one of the vsys IDs. If you're using
a multivsys environment, you must upgrade your firewalls to a fixed
PAN-OS version. The best practice is to upgrade both the firewalls and
Panorama to a fixed PAN-OS version.
</div>
<div class="p">
If you don't upgrade Panorama to a fixed version, you'll encounter
PAN-245064, where a commit on a multivsys firewall fails with the
message
<span class="ph systemoutput"
>vsys name should end with a number vsys is invalid</span
>
after you
<span class="ph uicontrol">Export or push device config bundle</span>
from 11.1.1 Panorama.
</div>
<div class="p">
After you upgrade Panorama to a fixed version, you'll encounter
PAN-214177, which causes an
<span class="ph uicontrol">Export or Push device config bundle</span>
from Panorama to the firewall to fail. The workaround for PAN-214177
is to first push only the template configuration and then push the
device group configurations.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-296519</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a stream receiving a reconnect signal with an
associated error in
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>Wifclient</a
>
caused the entire pool to close, which resulted in a complete
disconnection.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-296478</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to PAN-OS 10.2.13-h10,
GlobalProtect Clientless VPN on PA-3250 firewalls failed to execute
JavaScript links, resulting in an authorization error. This occurred
because the firewall was incorrectly injecting text into URLs when
JavaScript buttons or dropdown menus were clicked within the
Clientless VPN portal.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-296261</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where scheduled custom reports generated through
Panorama were blank (<span class="ph uicontrol"
>Monitor &gt; Reports</span
>) due to a malformed JSON response from the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-295342</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_comm</a
>
process stopped responding due to insufficient time allocated to read
file descriptors when processing long messages.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-293879</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where the VM monitor source remained in
the <span class="ph uicontrol">Getting All</span> status, which
prevented dynamic address groups from updating IP addresses for new
EC2 instances. This issue occurred due to a race condition where two
threads that simultaneously retrieved IP address tag information from
AWS VM monitoring sources became stuck while reading the XML file.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-293673</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped all tasks due to an OOM
condition caused by a scheduled log export using FTP to an external
FTP server.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-292539</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">CN-Series firewalls only</tt>) Fixed an issue where
the firewall generated incomplete or corrupted tech support files
(TSF) due to high disk usage on the management plane.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291174</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Real Time Streaming Protocol (RTSP) video streams
did not work when connected through GlobalProtect due to the firewall
blocking 200 OK responses. This occurred because of incorrect NAT
translations for the 200 OK message from the server.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291172</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where administrators were unable to gather path
monitoring failure information when troubleshooting high dataplane CPU
utilization.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-291009</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after a web server returned a 401 or 403 error,
the firewall was unable to decrypt HTTP/2 traffic, and the firewall
rejected all subsequent streams from the client.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-290996</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SNMP walks returned a value of 0 for the CPS
(Connections Per Second) per vsys on firewalls after upgrading to
PAN-OS 11.1.6-h3, even when active connections were present.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-290665</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with firewalls enabled with Security profiles where
certain traffic conditions caused high dataplane CPU utilization and
packet buffer exhaustion, which caused LACP flapping conditions.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-290088</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory leak occurred related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process when pushing configurations from Panorama to a firewall. This
occurred when the configurations contained shared policy rules.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-289239</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a new virtual system (vsys) was
automatically created with the name of a device group.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-288158</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls</tt>) only Fixed an issue where
the firewall became inaccessible via the web interface and SSH and
remained in an initializing state.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287842</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>comm</a
>
process stopped responding due to missing heartbeats, which resulted
in a system alert and HA communication loss on slot1.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287818</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where sessions timed out sooner than expected due to
the <span class="ph systemoutput">pan_proxy_accumulation</span>
<span class="ph systemoutput">_restore_timeout</span> not initiating
when the accumulation<span class="ph systemoutput">session_init</span>
failed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287734</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the error message
<span class="ph uicontrol">Scan ERR: Internal Err 1002</span> was
generated unexpectedly when WIF shared memory use was high.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287035</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when an application stopped responding, a large
file was created in the /opt/panlogs directory, which caused the
partition to fill up.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287023</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a large number of logs caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process to stop responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286615</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall double-freed shared memory when the
shared memory usage reached 100% when sending large payloads. This
occurred when DLP, Advanced Advanced Threat Protection (ATP), Advanced
WildFire (AWF), or Advanced URL Filtering were enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-284003</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where clients did not receive a valid response when
when searching a website due to a compression error.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286231</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a simultaneous selective push from Panorama to
multiple firewalls with different base configurations resulted in
configuration corruption, which caused the firewall to go down.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279901</b></div>
</td>
<td class="entry relcol">
<div class="p">
An issue was fixed where the firewall dropped fragmented TLS
ClientHello packets, which blocked access to certain websites. This
occurred because the packets arrived truncated, in varying sizes and
orders, and the firewall's heuristics failed to handle them correctly.
</div>
<div class="p">
To enable this fix, run:
<span class="ph systemoutput"
>debug dataplane set ssl-decrypt accumulate-client-hello disjoined
yes</span
>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279500</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TLS connections failed to establish in asymmetric
routing environments if the firewall did not see server-to-client
(s2c) packets of the TLS handshake.
</div>
<div class="p">
To use this fix, run the following CLI command:
<span class="ph systemoutput"
>debug dataplane set ssl-decrypt accumulate-client-hello
asym-disable yes</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-279364</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls with multiple NICs only</tt>)
Fixed an issue were the queue count in the task dump displayed an
incorrect number of queues for SR-IOV interfaces due to the queue
mapping logic incorrectly using a non-multi-NIC function.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279191</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a GlobalProtect gateway stopped responding when
handling HTTP/1.1 traffic with web inspection enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-278288</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IPv6 BGP peering established between virtual
routers even without dataplane connectivity. This occurred because the
firewall used the kernel for lookups instead of the dataplane.
</div>
<div class="p">
To use this fix, run the following CLI command:
<span class="ph systemoutput"
>set system setting loopback-workaround enable</span
>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-276795</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect client displayed an error
message when you clicked
<span class="ph uicontrol">Check Now</span> and
<span class="ph uicontrol">Preferred Releases</span> and
<span class="ph uicontrol">Base Releases</span> were unchecked (<span
class="ph menucascade"
><span class="ph uicontrol">Device &gt; Software</span></span
>).
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272812</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SNMP monitoring of tunnel interfaces displayed
zero values for received bytes and packets.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271701</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Advanced Services, App-ID Cloud Engine (ACE), and
Enhanced Application Log stopped working due to incorrect memory usage
accounting, which caused memory usage to remain at 99% after an
extended period of time.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-268168</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where uploading files that were 5GB or larger to Google
Drive or YouTube failed when a decryption policy rule for http2 was
enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267444</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where large file downloads or uploads failed or
remained in an incomplete state when using DLP HTTP2 mirror mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-266653</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where unexpected path monitor failures caused the
firewall to stop responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-266279</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the default version of IKE gateway
was not set to IKEv2 only mode, which caused VPN establishment issues
if the firewall recognized a new configuration as IKEv1.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261825</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic was dropped when Data Loss Prevention or
Advanced URL Filtering were enabled. This occurred when the payload
size was greater than 3.5 KB.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259741</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dropped GRE keepalive packets that
were encapsulated under another GRE tunnel.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259076</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall displayed an OCSP/CRL check failure
when accessing websites.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-255860</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5200 firewalls only</tt>) Fixed an issue where
the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process stopped responding when the firewall was under a heavy traffic
load.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-255619</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an intermittent issue where file downloads from websites failed
when decrypting HTTP/2 traffic.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-253485 </b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/passive HA configurations only</tt
>) Fixed an issue where dataplane packet capture filter configuration
failed on the active firewall with the error
<span class="ph systemoutput"
>op command for client dagger timed out as client is not
available</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-250146</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where templates incorrectly showed
that telemetry was enabled when it was not enabled. With this fix, the
telemetry setting is not displayed in the template on the web
interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-247575</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the error message
<span class="ph systemoutput"
>import of failed. Please check the validity of the key pair and try
again</span
>
for unmatched keys for EC certificates.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-245064</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Multi-vsys firewalls only</tt>) Fixed an issue
where commits failed on the firewall after selecting
<span class="ph uicontrol">Export or push device config bundle</span>
on Panorama and a force push was required.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-242602</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients experienced slow SMB-V3
download throughput when passing through a Prisma IPSec tunnel and the
firewall and the SMB-V3 session owner dataplane was the same as the
IPSec-ESP tunnel on the multi-dataplane firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-241536</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where admin users with the Custom Panorama
Admin role were unable to add, edit, or delete route filters under
<span class="ph menucascade"
><span class="ph uicontrol">Routing Profiles</span></span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-231386</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding during certificate verification.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-220293</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall management plane could not display
BGP peer details when using the CLI command
<span class="ph systemoutput"
>show advanced-routing bgp peer detail logical-router</span
>. This was due to the
<span class="ph systemoutput">bgp_frr.py</span> script failing to
parse the IPv6 address family section of the
<span class="ph systemoutput">show ip bgp neighbors json</span>
output.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-202905</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall web interface where the
<span class="ph uicontrol">Next Hop</span> value was not displayed in
the static route configuration, the
<span class="ph uicontrol">admin-dist</span> values were empty, and
the path-monitor parameters were not listed in the management server
web interface when the firewall was configured in FRR mode.
</div>
</td>
</tr>
</tbody>
</table>