Add some reference files
This commit is contained in:
@@ -0,0 +1,32 @@
|
|||||||
|
<table class="table colsep rowsep table-striped">
|
||||||
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||||
|
|
||||||
|
<colgroup>
|
||||||
|
<col style="width: 25%" />
|
||||||
|
<col style="width: 75%" />
|
||||||
|
</colgroup>
|
||||||
|
<thead class="thead">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||||
|
</th>
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Description</b></div>
|
||||||
|
</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
|
||||||
|
<tbody class="tbody">
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-272413</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where device telemetry did not generate logs after
|
||||||
|
upgrading the firewall.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
@@ -0,0 +1,696 @@
|
|||||||
|
<table class="table colsep rowsep table-striped">
|
||||||
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||||
|
|
||||||
|
<colgroup>
|
||||||
|
<col style="width: 50%" />
|
||||||
|
<col style="width: 50%" />
|
||||||
|
</colgroup>
|
||||||
|
<thead class="thead">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<th class="entry">Issue ID</th>
|
||||||
|
<th class="entry">Description</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
|
||||||
|
<tbody class="tbody">
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-289102</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>PA-7500 Series, PA-5410, PA-5420, PA-5430, PA-5440, PA-5445,
|
||||||
|
PA-3400 Series, PA-1400 Series, PA-400 Series, VM-Series, and
|
||||||
|
CN-Series firewalls only</tt
|
||||||
|
>) Fixed a race condition issue related to predict processing, which
|
||||||
|
resulted in a dataplane restart and traffic loss.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-288930</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, when ACE was enabled, traffic from cloud
|
||||||
|
applications randomly matched an incorrect
|
||||||
|
<span class="ph uicontrol">cloud-apps</span> policy rule.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-286475</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the option to sort sequence numbers was missing
|
||||||
|
from <span class="ph uicontrol">Filters prefix list</span> in the
|
||||||
|
advanced routing filters.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-285894</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>all_task</a
|
||||||
|
>
|
||||||
|
process stopped responding, which caused the firewall to reboot
|
||||||
|
unexpectedly, and traffic failures occurred.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-284908</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where retrieving filenames from OneDrive resulted in a
|
||||||
|
cache miss.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-284116</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where mTLS decryption bypass did not work when the
|
||||||
|
decryption profile was configured with the maximum TLS version as TLS
|
||||||
|
1.3.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-284066</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after an upgrade, the SNMP polled values for
|
||||||
|
<span class="ph systemoutput">IF-MIB::ifInErrors</span> displayed a
|
||||||
|
high number of errors that did not match the values in the CLI show
|
||||||
|
interface command.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-283467</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-3400 Series firewalls only</tt>) Fixed an issue
|
||||||
|
where the firewall unexpectedly rebooted and entered maintenance mode
|
||||||
|
due to a ctd-agent out-of-memory (OOM) condition. This occurred during
|
||||||
|
advanced services load testing and a high volume of IoT EAL log
|
||||||
|
forwarding.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-283331</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where selective pushes to managed devices failed when
|
||||||
|
the <span class="ph uicontrol">User ID Master Device</span> was
|
||||||
|
configured.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-282640</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where custom reports showed incomplete data when
|
||||||
|
exported in CSV format from Panorama.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-281797</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where firewalls became unstable and stopped responding,
|
||||||
|
which resulted in an OOM condition.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-280698</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall removed the TCP timestamp from
|
||||||
|
client hello messages that did not fit in a single packet, which
|
||||||
|
resulted in connection issues.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-280505</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the web interface did not display a message to
|
||||||
|
commit prior changes before attempting a partial configuration load.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-280409</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the popup window did not appear as expected for
|
||||||
|
Clientless VPN users.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-279706</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">M-600 appliances only</tt>) Fixed an issue where
|
||||||
|
Panorama did not update all
|
||||||
|
<span class="ph systemoutput">panreplay</span> database entries after
|
||||||
|
performing a commit and full push to all devices.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-279336</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the CLI did not display a message to commit prior
|
||||||
|
changes before loading a partial configuration.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-279176</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the configuration audit displayed inaccurate
|
||||||
|
information after partially loading the configuration via the CLI,
|
||||||
|
which caused the audit to flag the configuration as deleted or
|
||||||
|
changed.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-277755</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue that caused the
|
||||||
|
<span class="ph userinput">request system private-data-reset</span>
|
||||||
|
CLI command to fail.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-277617</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where deleting the NTP server address caused a commit
|
||||||
|
validation error. This occurred when the configuration included both
|
||||||
|
primary and secondary NTP servers and the secondary server was
|
||||||
|
removed.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-273949</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall generated the following error
|
||||||
|
message in the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>snmpd</a
|
||||||
|
>
|
||||||
|
logs: <span class="ph systemoutput">pan_get_keystr_from_cryptod</span>
|
||||||
|
</div>
|
||||||
|
<div class="p">
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>(pan_snmpinterface.c:181): Key X2F1dGhfa2V5 import from cryptod
|
||||||
|
failed</span
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-271432</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall was unable to decrypt SSL traffic
|
||||||
|
when using forward proxy and HSM with an ECDSA signing certificate.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-271175</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>all_task</a
|
||||||
|
>
|
||||||
|
process stopped responding with a SIGABRT.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-270849</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed a memory leak issue related to the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>configd</a
|
||||||
|
>
|
||||||
|
process that occurred when running consecutive commits for multiple
|
||||||
|
days.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-270248</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall failed to forward logs to a SNMP
|
||||||
|
trap server if the SNMP manager IP address was unable to be resolved.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-270193</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the Panorama management server changed its
|
||||||
|
certificate authority (CA) unexpectedly, which caused managed
|
||||||
|
firewalls to disconnect.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-269700</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where commits to service connection firewalls from
|
||||||
|
Panorama failed.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-269499</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall stopped responding when receiving a
|
||||||
|
high number of logs.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-268708</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where PDF summary and email reports displayed IPv6
|
||||||
|
addresses instead of IPv4 addresses.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-268614</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on the web interface where, when all rules were
|
||||||
|
highlighted when a read-only admin user clicked the
|
||||||
|
<span class="ph uicontrol">Highlight Unused Rules</span> checkbox.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-268313</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the Priority Code Point (PCP) bits in the VLAN
|
||||||
|
header were not reset to 0 when a packet was received from one Layer 3
|
||||||
|
tagged interface and forwarded to another, which resulted in dropped
|
||||||
|
packets. To use this fix, run the CLI command
|
||||||
|
<span class="ph systemoutput">set force-vlan-pcp-reset yes</span> and
|
||||||
|
reboot the firewall.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-268017</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the IP address-to-user mapping timeout was
|
||||||
|
triggered and the Inactivity TTL was refreshed unexpectedly
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-265782</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where, after you enabled multihop in a BFD
|
||||||
|
profile, you were unable to disable it via the web interface.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-264883</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-7080 appliances with LPCs only</tt>) Fixed an
|
||||||
|
issue where syslog forwarding over TCP stopped after upgrading.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-264040</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where AAAA DNS queries went out even when
|
||||||
|
<span class="ph uicontrol">IPv6 firewalling</span> was disabled.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-262593</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where traffic to websites failed on the Google Chrome
|
||||||
|
web browser on Secure Web Gateway (SWG) nodes.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-261429</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>show auth radius-require-msg-authentic</span
|
||||||
|
>
|
||||||
|
command CLI displayed no output.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-260132</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where secondary IP addresses with a /32 prefix
|
||||||
|
configured on Layer 3 interfaces were not reachable in FRR mode.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-257117</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where CSV or PDF exports of zones did not contain all
|
||||||
|
zones.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-255914</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>VM-Series firewalls on Amazon Web Services (AWS) environments
|
||||||
|
only</tt
|
||||||
|
>) Fixed an issue where a newly bootstrapped firewall required a
|
||||||
|
management server restart, relicensing, or license push from Panorama
|
||||||
|
to invoke the device certificate.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-255759</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall was unable to match HIP data with
|
||||||
|
the correct anti-malware object for Windows Defender.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-255654</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, when QoS was enabled on aggregate interfaces,
|
||||||
|
the maximum aggregate interface throughput was capped, which limited
|
||||||
|
network traffic. This occurred even with default QoS settings and no
|
||||||
|
configured egress max-bandwidth.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-253187</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
|
||||||
|
the class of service (CoS) priority bit was not modified, causing
|
||||||
|
access points to lose connectivity to the wireless controller when
|
||||||
|
traffic was routed through the firewall.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-241230</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the SNMP get request status value for Panorama
|
||||||
|
connections was incorrect.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-224729</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where you were unable to create duplicate entries in
|
||||||
|
Advanced Routing AS path prepend in the BGP filter route map.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-224020</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where CIE validation checks on the firewall prevented
|
||||||
|
configuration pushes from Panorama, which resulted in commit failures
|
||||||
|
during new firewall deployment. This occurred when a template with an
|
||||||
|
Authentication Profile with the
|
||||||
|
<span class="ph uicontrol">Authentication Type</span> as
|
||||||
|
<span class="ph uicontrol">Cloud Authentication Service</span> was
|
||||||
|
pushed to a newly deployed firewall without internet access or without
|
||||||
|
a device certificate.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-222307</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">M-600 appliances only</tt>) Fixed an issue where
|
||||||
|
the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>reportd</a
|
||||||
|
>
|
||||||
|
process stopped responding.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-212182</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where TLS 1.3 connections failed if the server sent a
|
||||||
|
certificate request after sending its certificate.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-201298</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where unknown TCP traffic caused errors and high shared
|
||||||
|
memory usage.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
@@ -0,0 +1,740 @@
|
|||||||
|
<table class="table colsep rowsep table-striped">
|
||||||
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||||
|
|
||||||
|
<colgroup>
|
||||||
|
<col style="width: 46.728971962616825%" />
|
||||||
|
<col style="width: 53.27102803738318%" />
|
||||||
|
</colgroup>
|
||||||
|
<thead class="thead">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<th class="entry">Issue ID</th>
|
||||||
|
<th class="entry">Description</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
|
||||||
|
<tbody class="tbody">
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-298907</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on PA-VM in AWS where, in a two-arm deployment
|
||||||
|
integrated with Gateway Load Balancer (GWLB), the firewall did not
|
||||||
|
preserve the GENEVE source port for internet traffic, resulting in
|
||||||
|
increased latency. The fix ensures the firewall preserves the outer
|
||||||
|
UDP source port of GENEVE encapsulation when sending traffic back to
|
||||||
|
GWLB.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-298505</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after upgrading an HA pair of PA-7050 firewalls,
|
||||||
|
the vsys ID changed in sequence, causing autocommit failures with
|
||||||
|
validation errors. This occurred when the multi-vsys firewall had
|
||||||
|
virtual systems created and pushed from Panorama, and the vsys ID was
|
||||||
|
not in a correct sequence because the unused vsys was deleted from
|
||||||
|
Panorama and pushed to devices.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-296519</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a stream receiving a reconnect signal with an
|
||||||
|
associated error in
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>Wifclient</a
|
||||||
|
>
|
||||||
|
caused the entire pool to close, which resulted in a complete
|
||||||
|
disconnection.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-296478</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after upgrading to PAN-OS 10.2.13-h10,
|
||||||
|
GlobalProtect Clientless VPN on PA-3250 firewalls failed to execute
|
||||||
|
JavaScript links, resulting in an authorization error. This occurred
|
||||||
|
because the firewall was incorrectly injecting text into URLs when
|
||||||
|
JavaScript buttons or dropdown menus were clicked within the
|
||||||
|
Clientless VPN portal.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-296261</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where scheduled custom reports generated through
|
||||||
|
Panorama were blank (<span class="ph uicontrol"
|
||||||
|
>Monitor > Reports</span
|
||||||
|
>) due to a malformed JSON response from the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>reportd</a
|
||||||
|
>
|
||||||
|
process.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-295342</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>pan_comm</a
|
||||||
|
>
|
||||||
|
process stopped responding due to insufficient time allocated to read
|
||||||
|
file descriptors when processing long messages.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-293879</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on the firewall where the VM monitor source remained in
|
||||||
|
the <span class="ph uicontrol">Getting All</span> status, which
|
||||||
|
prevented dynamic address groups from updating IP addresses for new
|
||||||
|
EC2 instances. This issue occurred due to a race condition where two
|
||||||
|
threads that simultaneously retrieved IP address tag information from
|
||||||
|
AWS VM monitoring sources became stuck while reading the XML file.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-293673</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall stopped all tasks due to an OOM
|
||||||
|
condition caused by a scheduled log export using FTP to an external
|
||||||
|
FTP server.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-292539</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">CN-Series firewalls only</tt>) Fixed an issue where
|
||||||
|
the firewall generated incomplete or corrupted tech support files
|
||||||
|
(TSF) due to high disk usage on the management plane.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-291174</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Real Time Streaming Protocol (RTSP) video streams
|
||||||
|
did not work when connected through GlobalProtect due to the firewall
|
||||||
|
blocking 200 OK responses. This occurred because of incorrect NAT
|
||||||
|
translations for the 200 OK message from the server.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-290996</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where SNMP walks returned a value of 0 for the CPS
|
||||||
|
(Connections Per Second) per vsys on firewalls after upgrading to
|
||||||
|
PAN-OS 11.1.6-h3, even when active connections were present.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-290088</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a memory leak occurred related to the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>configd</a
|
||||||
|
>
|
||||||
|
process when pushing configurations from Panorama to a firewall. This
|
||||||
|
occurred when the configurations contained shared policy rules.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-289239</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where a new virtual system (vsys) was
|
||||||
|
automatically created with the name of a device group.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-288158</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">VM-Series firewalls</tt>) only Fixed an issue where
|
||||||
|
the firewall became inaccessible via the web interface and SSH and
|
||||||
|
remained in an initializing state.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287842</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>comm</a
|
||||||
|
>
|
||||||
|
process stopped responding due to missing heartbeats, which resulted
|
||||||
|
in a system alert and HA communication loss on slot1.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287818</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where sessions timed out sooner than expected due to
|
||||||
|
the <span class="ph systemoutput">pan_proxy_accumulation</span>
|
||||||
|
<span class="ph systemoutput">_restore_timeout</span> not initiating
|
||||||
|
when the accumulation<span class="ph systemoutput">session_init</span>
|
||||||
|
failed.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287734</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the error message
|
||||||
|
<span class="ph uicontrol">Scan ERR: Internal Err 1002</span> was
|
||||||
|
generated unexpectedly when WIF shared memory use was high.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287035</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, when an application stopped responding, a large
|
||||||
|
file was created in the /opt/panlogs directory, which caused the
|
||||||
|
partition to fill up.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287023</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a large number of logs caused the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>logrcvr</a
|
||||||
|
>
|
||||||
|
process to stop responding.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-286615</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall double-freed shared memory when the
|
||||||
|
shared memory usage reached 100% when sending large payloads. This
|
||||||
|
occurred when DLP, Advanced Advanced Threat Protection (ATP), Advanced
|
||||||
|
WildFire (AWF), or Advanced URL Filtering were enabled.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-284003</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where clients did not receive a valid response when
|
||||||
|
when searching a website due to a compression error.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-286231</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a simultaneous selective push from Panorama to
|
||||||
|
multiple firewalls with different base configurations resulted in
|
||||||
|
configuration corruption, which caused the firewall to go down.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-279901</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
An issue was fixed where the firewall dropped fragmented TLS
|
||||||
|
ClientHello packets, which blocked access to certain websites. This
|
||||||
|
occurred because the packets arrived truncated, in varying sizes and
|
||||||
|
orders, and the firewall's heuristics failed to handle them correctly.
|
||||||
|
</div>
|
||||||
|
<div class="p">
|
||||||
|
To enable this fix, run:
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>debug dataplane set ssl-decrypt accumulate-client-hello disjoined
|
||||||
|
yes</span
|
||||||
|
>
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-279500</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where TLS connections failed to establish in asymmetric
|
||||||
|
routing environments if the firewall did not see server-to-client
|
||||||
|
(s2c) packets of the TLS handshake.
|
||||||
|
</div>
|
||||||
|
<div class="p">
|
||||||
|
To use this fix, run the following CLI command:
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>debug dataplane set ssl-decrypt accumulate-client-hello
|
||||||
|
asym-disable yes</span
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-278288</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where IPv6 BGP peering established between virtual
|
||||||
|
routers even without dataplane connectivity. This occurred because the
|
||||||
|
firewall used the kernel for lookups instead of the dataplane.
|
||||||
|
</div>
|
||||||
|
<div class="p">
|
||||||
|
To use this fix, run the following CLI command:
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>set system setting loopback-workaround enable</span
|
||||||
|
>
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-276795</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the GlobalProtect client displayed an error
|
||||||
|
message when you clicked
|
||||||
|
<span class="ph uicontrol">Check Now</span> and
|
||||||
|
<span class="ph uicontrol">Preferred Releases</span> and
|
||||||
|
<span class="ph uicontrol">Base Releases</span> were unchecked (<span
|
||||||
|
class="ph menucascade"
|
||||||
|
><span class="ph uicontrol">Device > Software</span></span
|
||||||
|
>).
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-272812</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where SNMP monitoring of tunnel interfaces displayed
|
||||||
|
zero values for received bytes and packets.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-271701</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Advanced Services, App-ID Cloud Engine (ACE), and
|
||||||
|
Enhanced Application Log stopped working due to incorrect memory usage
|
||||||
|
accounting, which caused memory usage to remain at 99% after an
|
||||||
|
extended period of time.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-266653</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where unexpected path monitor failures caused the
|
||||||
|
firewall to stop responding.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-267444</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where large file downloads or uploads failed or
|
||||||
|
remained in an incomplete state when using DLP HTTP2 mirror mode.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-266279</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where the default version of IKE gateway
|
||||||
|
was not set to IKEv2 only mode, which caused VPN establishment issues
|
||||||
|
if the firewall recognized a new configuration as IKEv1.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-261825</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where traffic was dropped when Data Loss Prevention or
|
||||||
|
Advanced URL Filtering were enabled. This occurred when the payload
|
||||||
|
size was greater than 3.5 KB.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-259741</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall dropped GRE keepalive packets that
|
||||||
|
were encapsulated under another GRE tunnel.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-259076</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall displayed an OCSP/CRL check failure
|
||||||
|
when accessing websites.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-255860</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-5200 firewalls only</tt>) Fixed an issue where
|
||||||
|
the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>all_pktproc</a
|
||||||
|
>
|
||||||
|
process stopped responding when the firewall was under a heavy traffic
|
||||||
|
load.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-255619</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an intermittent issue where file downloads from websites failed
|
||||||
|
when decrypting HTTP/2 traffic.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-253485 </b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>Firewalls in active/passive HA configurations only</tt
|
||||||
|
>) Fixed an issue where dataplane packet capture filter configuration
|
||||||
|
failed on the active firewall with the error
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>op command for client dagger timed out as client is not
|
||||||
|
available</span
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-250146</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on the web interface where templates incorrectly showed
|
||||||
|
that telemetry was enabled when it was not enabled. With this fix, the
|
||||||
|
telemetry setting is not displayed in the template on the web
|
||||||
|
interface.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-247575</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the error message
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>import of failed. Please check the validity of the key pair and try
|
||||||
|
again</span
|
||||||
|
>
|
||||||
|
for unmatched keys for EC certificates.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-245064</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Multi-vsys firewalls only</tt>) Fixed an issue
|
||||||
|
where commits failed on the firewall after selecting
|
||||||
|
<span class="ph uicontrol">Export or push device config bundle</span>
|
||||||
|
on Panorama and a force push was required.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-242602</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where GlobalProtect clients experienced slow SMB-V3
|
||||||
|
download throughput when passing through a Prisma IPSec tunnel and the
|
||||||
|
firewall and the SMB-V3 session owner dataplane was the same as the
|
||||||
|
IPSec-ESP tunnel on the multi-dataplane firewall.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-241536</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where admin users with the Custom Panorama
|
||||||
|
Admin role were unable to add, edit, or delete route filters under
|
||||||
|
<span class="ph menucascade"
|
||||||
|
><span class="ph uicontrol">Routing Profiles</span></span
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-231386</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>configd</a
|
||||||
|
>
|
||||||
|
process stopped responding during certificate verification.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-220293</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall management plane could not display
|
||||||
|
BGP peer details when using the CLI command
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>show advanced-routing bgp peer detail logical-router</span
|
||||||
|
>. This was due to the
|
||||||
|
<span class="ph systemoutput">bgp_frr.py</span> script failing to
|
||||||
|
parse the IPv6 address family section of the
|
||||||
|
<span class="ph systemoutput">show ip bgp neighbors json</span>
|
||||||
|
output.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-202905</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on the firewall web interface where the
|
||||||
|
<span class="ph uicontrol">Next Hop</span> value was not displayed in
|
||||||
|
the static route configuration, the
|
||||||
|
<span class="ph uicontrol">admin-dist</span> values were empty, and
|
||||||
|
the path-monitor parameters were not listed in the management server
|
||||||
|
web interface when the firewall was configured in FRR mode.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
@@ -0,0 +1,909 @@
|
|||||||
|
<table class="table colsep rowsep table-striped">
|
||||||
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||||
|
|
||||||
|
<colgroup>
|
||||||
|
<col style="width: 25%" />
|
||||||
|
<col style="width: 75%" />
|
||||||
|
</colgroup>
|
||||||
|
<thead class="thead">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||||
|
</th>
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Description</b></div>
|
||||||
|
</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
|
||||||
|
<tbody class="tbody">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-304756</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where, after you disabled the shared
|
||||||
|
optimization feature, a full configuration push to multi-vsys devices
|
||||||
|
caused a validation error.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-299354</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Added a CLI command to adjust the local pool cache size of the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>detector_threat</a
|
||||||
|
>
|
||||||
|
process to address an issue where the local-reuse memory pool borrowed
|
||||||
|
from the global pool, which impacted performance during session
|
||||||
|
deletion.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-299228</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a session process consumed excessive CPU
|
||||||
|
resources, even when Data Loss Prevention (DLP) was not enabled. This
|
||||||
|
occurred due to the active threat list being iterated twice when
|
||||||
|
active threats were present in the session.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-298907</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on PA-VM in AWS where, in a two-arm deployment
|
||||||
|
integrated with Gateway Load Balancer (GWLB), the firewall did not
|
||||||
|
preserve the GENEVE source port for internet traffic, resulting in
|
||||||
|
increased latency. The fix ensures the firewall preserves the outer
|
||||||
|
UDP source port of GENEVE encapsulation when sending traffic back to
|
||||||
|
GWLB.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-298505</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after upgrading an HA pair of PA-7050 firewalls,
|
||||||
|
the vsys ID changed in sequence, causing autocommit failures with
|
||||||
|
validation errors. This occurred when the multi-vsys firewall had
|
||||||
|
virtual systems created and pushed from Panorama, and the vsys ID was
|
||||||
|
not in a correct sequence because the unused vsys was deleted from
|
||||||
|
Panorama and pushed to devices.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-297775</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after upgrading to an affected PAN-OS release,
|
||||||
|
the Visible Virtual System field referenced the vsys name instead of
|
||||||
|
the vsys ID, which caused inter-vsys routing to fail. This occurred
|
||||||
|
when a vsys display name matched one of the vsys IDs. If you're using
|
||||||
|
a multivsys environment, you must upgrade your firewalls to a fixed
|
||||||
|
PAN-OS version. The best practice is to upgrade both the firewalls and
|
||||||
|
Panorama to a fixed PAN-OS version.
|
||||||
|
</div>
|
||||||
|
<div class="p">
|
||||||
|
If you don't upgrade Panorama to a fixed version, you'll encounter
|
||||||
|
PAN-245064, where a commit on a multivsys firewall fails with the
|
||||||
|
message
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>vsys name should end with a number vsys is invalid</span
|
||||||
|
>
|
||||||
|
after you
|
||||||
|
<span class="ph uicontrol">Export or push device config bundle</span>
|
||||||
|
from 11.1.1 Panorama.
|
||||||
|
</div>
|
||||||
|
<div class="p">
|
||||||
|
After you upgrade Panorama to a fixed version, you'll encounter
|
||||||
|
PAN-214177, which causes an
|
||||||
|
<span class="ph uicontrol">Export or Push device config bundle</span>
|
||||||
|
from Panorama to the firewall to fail. The workaround for PAN-214177
|
||||||
|
is to first push only the template configuration and then push the
|
||||||
|
device group configurations.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-296519</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a stream receiving a reconnect signal with an
|
||||||
|
associated error in
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>Wifclient</a
|
||||||
|
>
|
||||||
|
caused the entire pool to close, which resulted in a complete
|
||||||
|
disconnection.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-296478</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after upgrading to PAN-OS 10.2.13-h10,
|
||||||
|
GlobalProtect Clientless VPN on PA-3250 firewalls failed to execute
|
||||||
|
JavaScript links, resulting in an authorization error. This occurred
|
||||||
|
because the firewall was incorrectly injecting text into URLs when
|
||||||
|
JavaScript buttons or dropdown menus were clicked within the
|
||||||
|
Clientless VPN portal.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-296261</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where scheduled custom reports generated through
|
||||||
|
Panorama were blank (<span class="ph uicontrol"
|
||||||
|
>Monitor > Reports</span
|
||||||
|
>) due to a malformed JSON response from the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>reportd</a
|
||||||
|
>
|
||||||
|
process.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-295342</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>pan_comm</a
|
||||||
|
>
|
||||||
|
process stopped responding due to insufficient time allocated to read
|
||||||
|
file descriptors when processing long messages.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-293879</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on the firewall where the VM monitor source remained in
|
||||||
|
the <span class="ph uicontrol">Getting All</span> status, which
|
||||||
|
prevented dynamic address groups from updating IP addresses for new
|
||||||
|
EC2 instances. This issue occurred due to a race condition where two
|
||||||
|
threads that simultaneously retrieved IP address tag information from
|
||||||
|
AWS VM monitoring sources became stuck while reading the XML file.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-293673</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall stopped all tasks due to an OOM
|
||||||
|
condition caused by a scheduled log export using FTP to an external
|
||||||
|
FTP server.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-292539</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">CN-Series firewalls only</tt>) Fixed an issue where
|
||||||
|
the firewall generated incomplete or corrupted tech support files
|
||||||
|
(TSF) due to high disk usage on the management plane.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-291174</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Real Time Streaming Protocol (RTSP) video streams
|
||||||
|
did not work when connected through GlobalProtect due to the firewall
|
||||||
|
blocking 200 OK responses. This occurred because of incorrect NAT
|
||||||
|
translations for the 200 OK message from the server.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-291172</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where administrators were unable to gather path
|
||||||
|
monitoring failure information when troubleshooting high dataplane CPU
|
||||||
|
utilization.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-291009</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after a web server returned a 401 or 403 error,
|
||||||
|
the firewall was unable to decrypt HTTP/2 traffic, and the firewall
|
||||||
|
rejected all subsequent streams from the client.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-290996</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where SNMP walks returned a value of 0 for the CPS
|
||||||
|
(Connections Per Second) per vsys on firewalls after upgrading to
|
||||||
|
PAN-OS 11.1.6-h3, even when active connections were present.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-290665</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue with firewalls enabled with Security profiles where
|
||||||
|
certain traffic conditions caused high dataplane CPU utilization and
|
||||||
|
packet buffer exhaustion, which caused LACP flapping conditions.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-290088</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a memory leak occurred related to the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>configd</a
|
||||||
|
>
|
||||||
|
process when pushing configurations from Panorama to a firewall. This
|
||||||
|
occurred when the configurations contained shared policy rules.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-289239</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where a new virtual system (vsys) was
|
||||||
|
automatically created with the name of a device group.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-288158</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">VM-Series firewalls</tt>) only Fixed an issue where
|
||||||
|
the firewall became inaccessible via the web interface and SSH and
|
||||||
|
remained in an initializing state.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287842</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>comm</a
|
||||||
|
>
|
||||||
|
process stopped responding due to missing heartbeats, which resulted
|
||||||
|
in a system alert and HA communication loss on slot1.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287818</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where sessions timed out sooner than expected due to
|
||||||
|
the <span class="ph systemoutput">pan_proxy_accumulation</span>
|
||||||
|
<span class="ph systemoutput">_restore_timeout</span> not initiating
|
||||||
|
when the accumulation<span class="ph systemoutput">session_init</span>
|
||||||
|
failed.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287734</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the error message
|
||||||
|
<span class="ph uicontrol">Scan ERR: Internal Err 1002</span> was
|
||||||
|
generated unexpectedly when WIF shared memory use was high.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287035</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, when an application stopped responding, a large
|
||||||
|
file was created in the /opt/panlogs directory, which caused the
|
||||||
|
partition to fill up.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287023</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a large number of logs caused the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>logrcvr</a
|
||||||
|
>
|
||||||
|
process to stop responding.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-286615</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall double-freed shared memory when the
|
||||||
|
shared memory usage reached 100% when sending large payloads. This
|
||||||
|
occurred when DLP, Advanced Advanced Threat Protection (ATP), Advanced
|
||||||
|
WildFire (AWF), or Advanced URL Filtering were enabled.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-284003</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where clients did not receive a valid response when
|
||||||
|
when searching a website due to a compression error.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-286231</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a simultaneous selective push from Panorama to
|
||||||
|
multiple firewalls with different base configurations resulted in
|
||||||
|
configuration corruption, which caused the firewall to go down.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-279901</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
An issue was fixed where the firewall dropped fragmented TLS
|
||||||
|
ClientHello packets, which blocked access to certain websites. This
|
||||||
|
occurred because the packets arrived truncated, in varying sizes and
|
||||||
|
orders, and the firewall's heuristics failed to handle them correctly.
|
||||||
|
</div>
|
||||||
|
<div class="p">
|
||||||
|
To enable this fix, run:
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>debug dataplane set ssl-decrypt accumulate-client-hello disjoined
|
||||||
|
yes</span
|
||||||
|
>
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-279500</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where TLS connections failed to establish in asymmetric
|
||||||
|
routing environments if the firewall did not see server-to-client
|
||||||
|
(s2c) packets of the TLS handshake.
|
||||||
|
</div>
|
||||||
|
<div class="p">
|
||||||
|
To use this fix, run the following CLI command:
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>debug dataplane set ssl-decrypt accumulate-client-hello
|
||||||
|
asym-disable yes</span
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-279364</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">VM-Series firewalls with multiple NICs only</tt>)
|
||||||
|
Fixed an issue were the queue count in the task dump displayed an
|
||||||
|
incorrect number of queues for SR-IOV interfaces due to the queue
|
||||||
|
mapping logic incorrectly using a non-multi-NIC function.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-279191</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a GlobalProtect gateway stopped responding when
|
||||||
|
handling HTTP/1.1 traffic with web inspection enabled.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-278288</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where IPv6 BGP peering established between virtual
|
||||||
|
routers even without dataplane connectivity. This occurred because the
|
||||||
|
firewall used the kernel for lookups instead of the dataplane.
|
||||||
|
</div>
|
||||||
|
<div class="p">
|
||||||
|
To use this fix, run the following CLI command:
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>set system setting loopback-workaround enable</span
|
||||||
|
>
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-276795</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the GlobalProtect client displayed an error
|
||||||
|
message when you clicked
|
||||||
|
<span class="ph uicontrol">Check Now</span> and
|
||||||
|
<span class="ph uicontrol">Preferred Releases</span> and
|
||||||
|
<span class="ph uicontrol">Base Releases</span> were unchecked (<span
|
||||||
|
class="ph menucascade"
|
||||||
|
><span class="ph uicontrol">Device > Software</span></span
|
||||||
|
>).
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-272812</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where SNMP monitoring of tunnel interfaces displayed
|
||||||
|
zero values for received bytes and packets.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-271701</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Advanced Services, App-ID Cloud Engine (ACE), and
|
||||||
|
Enhanced Application Log stopped working due to incorrect memory usage
|
||||||
|
accounting, which caused memory usage to remain at 99% after an
|
||||||
|
extended period of time.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-268168</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where uploading files that were 5GB or larger to Google
|
||||||
|
Drive or YouTube failed when a decryption policy rule for http2 was
|
||||||
|
enabled.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-267444</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where large file downloads or uploads failed or
|
||||||
|
remained in an incomplete state when using DLP HTTP2 mirror mode.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-266653</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where unexpected path monitor failures caused the
|
||||||
|
firewall to stop responding.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-266279</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where the default version of IKE gateway
|
||||||
|
was not set to IKEv2 only mode, which caused VPN establishment issues
|
||||||
|
if the firewall recognized a new configuration as IKEv1.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-261825</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where traffic was dropped when Data Loss Prevention or
|
||||||
|
Advanced URL Filtering were enabled. This occurred when the payload
|
||||||
|
size was greater than 3.5 KB.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-259741</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall dropped GRE keepalive packets that
|
||||||
|
were encapsulated under another GRE tunnel.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-259076</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall displayed an OCSP/CRL check failure
|
||||||
|
when accessing websites.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-255860</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-5200 firewalls only</tt>) Fixed an issue where
|
||||||
|
the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>all_pktproc</a
|
||||||
|
>
|
||||||
|
process stopped responding when the firewall was under a heavy traffic
|
||||||
|
load.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-255619</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an intermittent issue where file downloads from websites failed
|
||||||
|
when decrypting HTTP/2 traffic.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-253485 </b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>Firewalls in active/passive HA configurations only</tt
|
||||||
|
>) Fixed an issue where dataplane packet capture filter configuration
|
||||||
|
failed on the active firewall with the error
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>op command for client dagger timed out as client is not
|
||||||
|
available</span
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-250146</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on the web interface where templates incorrectly showed
|
||||||
|
that telemetry was enabled when it was not enabled. With this fix, the
|
||||||
|
telemetry setting is not displayed in the template on the web
|
||||||
|
interface.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-247575</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the error message
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>import of failed. Please check the validity of the key pair and try
|
||||||
|
again</span
|
||||||
|
>
|
||||||
|
for unmatched keys for EC certificates.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-245064</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Multi-vsys firewalls only</tt>) Fixed an issue
|
||||||
|
where commits failed on the firewall after selecting
|
||||||
|
<span class="ph uicontrol">Export or push device config bundle</span>
|
||||||
|
on Panorama and a force push was required.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-242602</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where GlobalProtect clients experienced slow SMB-V3
|
||||||
|
download throughput when passing through a Prisma IPSec tunnel and the
|
||||||
|
firewall and the SMB-V3 session owner dataplane was the same as the
|
||||||
|
IPSec-ESP tunnel on the multi-dataplane firewall.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-241536</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where admin users with the Custom Panorama
|
||||||
|
Admin role were unable to add, edit, or delete route filters under
|
||||||
|
<span class="ph menucascade"
|
||||||
|
><span class="ph uicontrol">Routing Profiles</span></span
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-231386</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>configd</a
|
||||||
|
>
|
||||||
|
process stopped responding during certificate verification.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-220293</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall management plane could not display
|
||||||
|
BGP peer details when using the CLI command
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>show advanced-routing bgp peer detail logical-router</span
|
||||||
|
>. This was due to the
|
||||||
|
<span class="ph systemoutput">bgp_frr.py</span> script failing to
|
||||||
|
parse the IPv6 address family section of the
|
||||||
|
<span class="ph systemoutput">show ip bgp neighbors json</span>
|
||||||
|
output.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-202905</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on the firewall web interface where the
|
||||||
|
<span class="ph uicontrol">Next Hop</span> value was not displayed in
|
||||||
|
the static route configuration, the
|
||||||
|
<span class="ph uicontrol">admin-dist</span> values were empty, and
|
||||||
|
the path-monitor parameters were not listed in the management server
|
||||||
|
web interface when the firewall was configured in FRR mode.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
@@ -0,0 +1,41 @@
|
|||||||
|
<table class="table colsep rowsep table-striped">
|
||||||
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||||
|
|
||||||
|
<colgroup>
|
||||||
|
<col style="width: 25%" />
|
||||||
|
<col style="width: 75%" />
|
||||||
|
</colgroup>
|
||||||
|
<thead class="thead">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||||
|
</th>
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Description</b></div>
|
||||||
|
</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
|
||||||
|
<tbody class="tbody">
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-259351</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
A fix was made to address
|
||||||
|
<a
|
||||||
|
class="xref"
|
||||||
|
href="https://security.paloaltonetworks.com/CVE-2024-3393"
|
||||||
|
title=""
|
||||||
|
data-scope="external"
|
||||||
|
data-format="html"
|
||||||
|
data-type=""
|
||||||
|
target="_blank"
|
||||||
|
>CVE-2024-3393</a
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
@@ -0,0 +1,153 @@
|
|||||||
|
<table class="table colsep rowsep table-striped">
|
||||||
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||||
|
|
||||||
|
<colgroup>
|
||||||
|
<col style="width: 25%" />
|
||||||
|
<col style="width: 75%" />
|
||||||
|
</colgroup>
|
||||||
|
<thead class="thead">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||||
|
</th>
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Description</b></div>
|
||||||
|
</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
|
||||||
|
<tbody class="tbody">
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">—</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">Fixes were made to address the following CVEs:</div>
|
||||||
|
<ul id="panos-addressed-issues-10.2.13-h18_ul-snk_4r1_gjc" class="ul">
|
||||||
|
<li class="li">
|
||||||
|
<a
|
||||||
|
class="xref"
|
||||||
|
href="https://security.paloaltonetworks.com/CVE-2026-0265"
|
||||||
|
title=""
|
||||||
|
data-scope="external"
|
||||||
|
data-format="html"
|
||||||
|
data-type=""
|
||||||
|
target="_blank"
|
||||||
|
>CVE-2026-0265</a
|
||||||
|
>
|
||||||
|
</li>
|
||||||
|
<li class="li">
|
||||||
|
<a
|
||||||
|
class="xref"
|
||||||
|
href="https://security.paloaltonetworks.com/CVE-2026-0264"
|
||||||
|
title=""
|
||||||
|
data-scope="external"
|
||||||
|
data-format="html"
|
||||||
|
data-type=""
|
||||||
|
target="_blank"
|
||||||
|
>CVE-2026-0264</a
|
||||||
|
>
|
||||||
|
</li>
|
||||||
|
<li class="li">
|
||||||
|
<a
|
||||||
|
class="xref"
|
||||||
|
href="https://security.paloaltonetworks.com/CVE-2026-0262"
|
||||||
|
title=""
|
||||||
|
data-scope="external"
|
||||||
|
data-format="html"
|
||||||
|
data-type=""
|
||||||
|
target="_blank"
|
||||||
|
>CVE-2026-0262</a
|
||||||
|
>
|
||||||
|
</li>
|
||||||
|
<li class="li">
|
||||||
|
<a
|
||||||
|
class="xref"
|
||||||
|
href="https://security.paloaltonetworks.com/CVE-2026-0261"
|
||||||
|
title=""
|
||||||
|
data-scope="external"
|
||||||
|
data-format="html"
|
||||||
|
data-type=""
|
||||||
|
target="_blank"
|
||||||
|
>CVE-2026-0261</a
|
||||||
|
>
|
||||||
|
</li>
|
||||||
|
<li class="li">
|
||||||
|
<a
|
||||||
|
class="xref"
|
||||||
|
href="https://security.paloaltonetworks.com/CVE-2026-0258"
|
||||||
|
title=""
|
||||||
|
data-scope="external"
|
||||||
|
data-format="html"
|
||||||
|
data-type=""
|
||||||
|
target="_blank"
|
||||||
|
>CVE-2026-0258</a
|
||||||
|
>
|
||||||
|
</li>
|
||||||
|
<li class="li">
|
||||||
|
<a
|
||||||
|
class="xref"
|
||||||
|
href="https://security.paloaltonetworks.com/CVE-2026-0257"
|
||||||
|
title=""
|
||||||
|
data-scope="external"
|
||||||
|
data-format="html"
|
||||||
|
data-type=""
|
||||||
|
target="_blank"
|
||||||
|
>CVE-2026-0257</a
|
||||||
|
>
|
||||||
|
</li>
|
||||||
|
<li class="li">
|
||||||
|
<a
|
||||||
|
class="xref"
|
||||||
|
href="https://security.paloaltonetworks.com/CVE-2026-0256"
|
||||||
|
title=""
|
||||||
|
data-scope="external"
|
||||||
|
data-format="html"
|
||||||
|
data-type=""
|
||||||
|
target="_blank"
|
||||||
|
>CVE-2026-0256</a
|
||||||
|
>
|
||||||
|
</li>
|
||||||
|
<li class="li">
|
||||||
|
<a
|
||||||
|
class="xref"
|
||||||
|
href="https://security.paloaltonetworks.com/CVE-2026-0259"
|
||||||
|
title=""
|
||||||
|
data-scope="external"
|
||||||
|
data-format="html"
|
||||||
|
data-type=""
|
||||||
|
target="_blank"
|
||||||
|
>CVE-2026-0259</a
|
||||||
|
>
|
||||||
|
</li>
|
||||||
|
<li class="li">
|
||||||
|
<a
|
||||||
|
class="xref"
|
||||||
|
href="https://security.paloaltonetworks.com/CVE-2026-0300"
|
||||||
|
title=""
|
||||||
|
data-scope="external"
|
||||||
|
data-format="html"
|
||||||
|
data-type=""
|
||||||
|
target="_blank"
|
||||||
|
>CVE-2026-0300</a
|
||||||
|
>
|
||||||
|
</li>
|
||||||
|
</ul>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-269254</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where high CPU utilization caused GlobalProtect VPN
|
||||||
|
tunnels to flap, users to be disconnected, and the CLI to become
|
||||||
|
unresponsive. This occurred when a large number of GlobalProtect users
|
||||||
|
were actively processing application traffic.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
@@ -0,0 +1,479 @@
|
|||||||
|
<table class="table colsep rowsep table-striped">
|
||||||
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||||
|
|
||||||
|
<colgroup>
|
||||||
|
<col style="width: 25%" />
|
||||||
|
<col style="width: 75%" />
|
||||||
|
</colgroup>
|
||||||
|
<thead class="thead">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||||
|
</th>
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Description</b></div>
|
||||||
|
</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
|
||||||
|
<tbody class="tbody">
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-274570</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>devsrvr</a
|
||||||
|
>
|
||||||
|
process restarted after a failed commit due to an invalid memory
|
||||||
|
access.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-273994</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
A fix was made to address
|
||||||
|
<a
|
||||||
|
class="xref"
|
||||||
|
href="https://security.paloaltonetworks.com/CVE-2025-0111"
|
||||||
|
title=""
|
||||||
|
data-scope="external"
|
||||||
|
data-format="html"
|
||||||
|
data-type=""
|
||||||
|
target="_blank"
|
||||||
|
>CVE-2025-0111</a
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-273971</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
A fix was made to address
|
||||||
|
<a
|
||||||
|
class="xref"
|
||||||
|
href="https://security.paloaltonetworks.com/CVE-2025-0108"
|
||||||
|
title=""
|
||||||
|
data-scope="external"
|
||||||
|
data-format="html"
|
||||||
|
data-type=""
|
||||||
|
target="_blank"
|
||||||
|
>CVE-2025-0108</a
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-273278</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
A fix was made to address
|
||||||
|
<a
|
||||||
|
class="xref"
|
||||||
|
href="https://security.paloaltonetworks.com/CVE-2025-0109"
|
||||||
|
title=""
|
||||||
|
data-scope="external"
|
||||||
|
data-format="html"
|
||||||
|
data-type=""
|
||||||
|
target="_blank"
|
||||||
|
>CVE-2025-0109</a
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-273215</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a syntax error in the index generation script
|
||||||
|
caused a high management plane CPU load after upgrading.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-273021</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where 25G port links did not come up due to a change in
|
||||||
|
the handling of 25G DAC modules.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-271926</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where TLS 1.3 decryption failed with a bad record MAC
|
||||||
|
error when the firewall was configured to decrypt and inspect TLS
|
||||||
|
traffic.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-270549</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where some TLS connections were not handled correctly,
|
||||||
|
which led to instability in the dataplane.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b"> PAN-269899</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the Panorama web interface was slower than
|
||||||
|
expected when querying for device tags.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-269731</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Panorama did not display logs from firewalls
|
||||||
|
after upgrading to PAN-OS 10.2.11 on devices due to Elasticsearch (ES)
|
||||||
|
getting restarted continuously.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-269624</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where GlobalProtect clients failed to connect with the
|
||||||
|
error message
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>The device or feature requires a GlobalProtect subscription
|
||||||
|
license</span
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-268972</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Panorama was slower than expected when using a
|
||||||
|
high number of device group tags in a non-shared context.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-268909</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where IP address tags were removed from firewalls after
|
||||||
|
a management server or
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>useridd</a
|
||||||
|
>
|
||||||
|
process restart. This occurred when a Panorama serial-number based
|
||||||
|
configuration was used for User-ID redistribution.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-268727</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where traffic was dropped when the accumulation proxy
|
||||||
|
was enabled and header insertion modified packets.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-268319</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where
|
||||||
|
<span class="ph uicontrol">Receive Time</span> and
|
||||||
|
<span class="ph uicontrol">Time Generated</span> were not visible as
|
||||||
|
attributes in the <span class="ph uicontrol">Filter Builder</span> for
|
||||||
|
system logs and URL filtering logs.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-268260</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on hardware firewalls where, when SSL decryption was
|
||||||
|
enabled and Client Hello messages spanned multiple TCP segments, some
|
||||||
|
SSL decrypted sessions failed.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-267781</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
Fixed an issue where Panorama did not display the Source Dynamic Address
|
||||||
|
Group.
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-267671</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall rebooted unexpectedly due to the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>all_task</a
|
||||||
|
>
|
||||||
|
process restarting with an OOM condition due to a memory leak on the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>reportd</a
|
||||||
|
>
|
||||||
|
process.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-267001</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where multicast streams were unstable with ECMP and
|
||||||
|
dropped every 30 seconds.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-266312</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where BFD sessions took longer than expected to
|
||||||
|
establish after an HA failover due to BGP.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-265179</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a kernel race condition caused the firewall to
|
||||||
|
reboot with a kernel panic.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-261739</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>VM-Series firewalls in Microsoft Azure environments only</tt
|
||||||
|
>) Fixed an issue where the firewall displayed 0 for the physical port
|
||||||
|
counters read from MAC.
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-259002</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where frequent external dynamic list updates caused the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>configd</a
|
||||||
|
>
|
||||||
|
process to restart.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-256051</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on the firewall where enabling flow basic caused the
|
||||||
|
firewall to stop responding due to a
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>masterd</a
|
||||||
|
>
|
||||||
|
process restart.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-249597</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the <span class="ph uicontrol">Policy</span> page
|
||||||
|
on the Panorama web interface was slower than expected when a device
|
||||||
|
group had a large number of managed devices.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-246949</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where custom admin users were not able to click
|
||||||
|
<span class="ph uicontrol">OK</span> in the push scope selection
|
||||||
|
window when device group or template were disabled under commit in the
|
||||||
|
admin roles.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-240739</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the ECMP FIB update on the dataplane didn't clear
|
||||||
|
the pending change flag, which caused the next non-ECMP FIB update to
|
||||||
|
miss the latest generation ID and age out after 5 minutes
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-225213</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where
|
||||||
|
<span class="ph uicontrol">Push All Changes</span> displayed changes
|
||||||
|
that were already committed in the push scope for another device group
|
||||||
|
after performing a selective commit and selective push to the first
|
||||||
|
device group.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-215038</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the output of the
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>request logging-service-forwarding status</span
|
||||||
|
>
|
||||||
|
CLI command did not display the correct information after successfully
|
||||||
|
onboarding a firewall to Cloud Delivered Licensing (CDL).
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
@@ -0,0 +1,272 @@
|
|||||||
|
<table class="table colsep rowsep table-striped">
|
||||||
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||||
|
|
||||||
|
<colgroup>
|
||||||
|
<col style="width: 25%" />
|
||||||
|
<col style="width: 75%" />
|
||||||
|
</colgroup>
|
||||||
|
<thead class="thead">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||||
|
</th>
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Description</b></div>
|
||||||
|
</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
|
||||||
|
<tbody class="tbody">
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-279604</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where scheduled SaaS application usage reports were
|
||||||
|
generated incorrectly, and the login page was displayed instead of the
|
||||||
|
report content.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-276822</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the packet buffer size increased significantly
|
||||||
|
when WildFire File Forwarding was continued after a threat detection
|
||||||
|
and then canceled.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-274592</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
|
||||||
|
issue where the firewall did not fail over when the active firewall
|
||||||
|
experienced data plane issues.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-273277</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
Fixed an issue where GlobalProtect clients on macOS devices were
|
||||||
|
prompted to enter their username and password for Kerberos SSO
|
||||||
|
authentication.
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-273153</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the Panorama web interface was slower than
|
||||||
|
expected due to excessive polling of the
|
||||||
|
<span class="ph systemoutput">MonitorDirect.getTasks</span> API by the
|
||||||
|
Task Manager.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-272006</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall did not trigger a kernel core dump
|
||||||
|
as a large core when the CPLD (Complex Programmable Logic Device) sent
|
||||||
|
a Non-Maskable Interrupt (NMI) to the CPU.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-271301</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>VM-Series firewalls on Amazon Web Services (AWS) environments with
|
||||||
|
GWLB integrated only</tt
|
||||||
|
>) Fixed an issue where DNS queries timed out when overlay routing was
|
||||||
|
enabled.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-268489</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">Fixed a Threat log PCAP ID overwrapping issue.</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-267704</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall did not send an ICMP error packet to
|
||||||
|
Envoy when the MSS was exceeded
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-267660</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where UserID stopped working when the
|
||||||
|
<span class="ph systemoutput">show object registered user</span> CLI
|
||||||
|
command was used with start-point and limit options.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-265399</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where DNS queries for uppercase internal domain (SRV
|
||||||
|
record) timed out when DNS Security was enabled.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-264762</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall showed the status of SFP+ interfaces
|
||||||
|
as not up, or up but not configured, when a PAN-SFP-PLUS-SR cable was
|
||||||
|
connected.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-263465</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>logrcvr</a
|
||||||
|
>
|
||||||
|
process stopped responding due to a memory leak and buffer overrun.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-261074</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall delayed video file transfers over
|
||||||
|
SMB when <span class="ph uicontrol">Exclude Video Traffic</span> from
|
||||||
|
the Tunnel feature was enabled and no applications were added to the
|
||||||
|
list.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-260827</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall consumed excessive CPU while
|
||||||
|
processing traffic for a workload running on a GKE cluster, which
|
||||||
|
caused reduced throughput.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-253921</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall displayed the following error
|
||||||
|
message:
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>critical userid register 0 fail to integrate the update of
|
||||||
|
registered ip addresses since 2 seconds ago; critical system log
|
||||||
|
alerts observed</span
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-253213</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall sent HIP notifications every time it
|
||||||
|
received a HIP report instead of every two hours.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-246304</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where commits failed due to a timeout in
|
||||||
|
the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>sysd</a
|
||||||
|
>
|
||||||
|
process during decryption.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
@@ -0,0 +1,80 @@
|
|||||||
|
<table class="table colsep rowsep table-striped">
|
||||||
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||||
|
|
||||||
|
<colgroup>
|
||||||
|
<col style="width: 25%" />
|
||||||
|
<col style="width: 75%" />
|
||||||
|
</colgroup>
|
||||||
|
<thead class="thead">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||||
|
</th>
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Description</b></div>
|
||||||
|
</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
|
||||||
|
<tbody class="tbody">
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-279746</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where SMTP packets were not sent out when the Client
|
||||||
|
Hello arrived at the firewall in multiple out-of-order segments and
|
||||||
|
the traffic was not subject to SSL decryption.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-268815</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue that caused the firewall to reboot due to the
|
||||||
|
<span class="ph systemoutput">wifclient</span> exiting multiple times
|
||||||
|
when using IoT Security.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-268800</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a large number of logs caused the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>logrcvr</a
|
||||||
|
>
|
||||||
|
process to stop responding.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-268705</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an intermittent issue where the firewall failed to process FTP
|
||||||
|
traffic after upgrading to PAN-OS 10.1.14.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
@@ -0,0 +1,801 @@
|
|||||||
|
<table class="table colsep rowsep table-striped">
|
||||||
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||||
|
|
||||||
|
<colgroup>
|
||||||
|
<col style="width: 50%" />
|
||||||
|
<col style="width: 50%" />
|
||||||
|
</colgroup>
|
||||||
|
<thead class="thead">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<th class="entry">Issue ID</th>
|
||||||
|
<th class="entry">Description</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
|
||||||
|
<tbody class="tbody">
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-286255</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, when the firewall received an unexpected
|
||||||
|
termination request for SSL sessions, the dataplane experienced a slow
|
||||||
|
buffer resource leak.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-283813</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where the web interface performance was
|
||||||
|
slower than usual when retrieving read-only configurations from
|
||||||
|
Panorama.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-282394</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a firewall was only able to display a maximum of
|
||||||
|
14 permitted IP addresses from a Panorama Template Variable.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-282236</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where large IPv6 packets were reassembled incorrectly
|
||||||
|
on the firewall when the packets arrived fragmented over an IPv4
|
||||||
|
tunnel.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-279621</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where processes stopped responding when HTTPS Forward
|
||||||
|
traffic was run.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-279400</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, when
|
||||||
|
<span class="ph uicontrol">Restrict Certificate Extension</span>s was
|
||||||
|
enabled on decryption profiles, the basic constraints extension was
|
||||||
|
overwritten incorrectly.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-278150</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall removed the Authentication Key
|
||||||
|
Identifier (AKID) from the certificate during SSL decryption, which
|
||||||
|
caused Python 3.13 to fail with a certificate verification error.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-277417</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an memory leak issue related to TLS inbound decryption.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-277234</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a device group import resulted in a Security
|
||||||
|
policy rule being created with
|
||||||
|
<span class="ph uicontrol">Application</span> set to
|
||||||
|
<span class="ph uicontrol">none</span>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-277147</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where daily scheduled reports were not generated and
|
||||||
|
emailed.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-276678</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Panorama became unresponsive while performing a
|
||||||
|
dynamic address update without a lock.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-275077</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where DNS Security intermittently logs malicious domain
|
||||||
|
URLs as Alert instead of taking a Sinkhole action, even when
|
||||||
|
configured to Sinkhole malicious DNS domains.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-274797</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a DPC on slot 3 failed intermittently due to the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>pktlog_forwarding</a
|
||||||
|
>
|
||||||
|
process restarting, which resulted in an unexpected HA failover.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-274726</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Wildfire signature generation was enabled on all
|
||||||
|
nodes in a cluster instead of only the active node.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-273964</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where SNMP scans to a firewall timed out after
|
||||||
|
upgrading to a PAN-OS 10.2 release.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-273453</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where restarting the firewall did not initiate an
|
||||||
|
autocommit job, which caused the firewall to stop responding and the
|
||||||
|
HA interface to go down.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-273141</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where GlobalProtect clients experienced slow file
|
||||||
|
transfer download throughput when passing through an IPSec tunnel.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-272959</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall generated BGP update packets larger
|
||||||
|
than 1500 bytes when the interface MTU was 1500 bytes and jumbo frames
|
||||||
|
were enabled globally.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-272395</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where informational logs caused the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>distributord</a
|
||||||
|
>
|
||||||
|
process log file to be frequently overwritten.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-272175</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where session rematch caused ACE cloud application
|
||||||
|
traffic to match the wrong policy.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-271425</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>Firewalls in active/active HA configurations only</tt
|
||||||
|
>) Fixed an issue with SSL inbound decryption on firewalls on a vwire
|
||||||
|
setup with asymmetric routing.
|
||||||
|
</div>
|
||||||
|
<div class="p">
|
||||||
|
To use this fix, enter the CLI command
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>set system setting ssl-decrypt ha-vwire-mac-learn global ye</span
|
||||||
|
>s on both firewalls in an HA pair.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-271184</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Device Telemetry failed due to an issue with the
|
||||||
|
encoding of characters in the log file path.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-269956</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>all_pktproc</a
|
||||||
|
>
|
||||||
|
process stopped responding, which caused internal path monitor
|
||||||
|
failures.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-269677</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Panorama did not check for a NULL pointer when
|
||||||
|
querying logs, which caused logs to not display on the web interface.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-269291</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the scheduled report generation script did not
|
||||||
|
return debug information.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-269106</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the wifclient stopped responding during server
|
||||||
|
certificate verification for MICA gRPC connections and caused the
|
||||||
|
dataplane to restart when using a cloud-based ML detection engine
|
||||||
|
(MICA). On certain platforms, this caused the firewall to reboot
|
||||||
|
periodically.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-269052</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where traffic was blocked by a URL filtering profile
|
||||||
|
even though the Security policy rule did not have a URL filtering
|
||||||
|
profile configured.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-269027</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue related to external dynamic lists that caused commit
|
||||||
|
times on the firewall to be higher than expected.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-268951</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed a CPS counter query issue that caused SNMP polling timeouts on
|
||||||
|
the firewall.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-268118</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on firewalls in active/passive HA configurations where,
|
||||||
|
after a failover, irrelevant routing FIB entries were seen in the
|
||||||
|
routing table on the newly active firewall.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-267707</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where BFD sessions did not come up even when BGP
|
||||||
|
peering was established.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-267097</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the replay database size increased significantly
|
||||||
|
due to local and special configurations not being purged after
|
||||||
|
commits.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-266900</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on the Panorama web interface where you were unable to
|
||||||
|
click <span class="ph uicontrol">OK</span> after selecting an install
|
||||||
|
package type and file from the dropdown and selecting a firewall.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-265791</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>all_task</a
|
||||||
|
>
|
||||||
|
process stopped responding, which caused the dataplane to go down.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-265646</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the config lock icon was not visible for a custom
|
||||||
|
role-based admin when a Superuser admin had acquired the config lock.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-264708</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a selective push was blocked when a configuration
|
||||||
|
load was done.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-264678</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where
|
||||||
|
<span class="ph uicontrol">Preview Changes</span> did not display
|
||||||
|
configuration changes in
|
||||||
|
<span class="ph uicontrol">Commit and push > Push Scope</span>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-264169</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-5400 Series firewalls only</tt>) Fixed an issue
|
||||||
|
where the firewall sent correlated event logs to the syslog server
|
||||||
|
using the management interface instead of the log interface.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-263654</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where multiple DNS responses with different CNAME
|
||||||
|
values caused evasion false positive alerts.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-263559</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the dataplane stopped responding and the firewall
|
||||||
|
unexpectedly rebooted due to multiple process restarts.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-262729</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue where
|
||||||
|
the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>configd</a
|
||||||
|
>
|
||||||
|
process experienced continuous high CPU utilization and repeatedly
|
||||||
|
restarted.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-262540</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where application traffic transactions that reused TCP
|
||||||
|
ports did not work with decryption.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-262383</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall was unable to decompress the HTTP2
|
||||||
|
header, which caused the session to be classified as unknown-tcp
|
||||||
|
instead of web-browsing.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-260300</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>PA-5410, PA-5420, PA-5430, PA-5440 and PA-5445 firewalls only</tt
|
||||||
|
>) Fixed an issue related to the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>all_pktproc</a
|
||||||
|
>
|
||||||
|
process where DPC slot 3 stopped responding.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-260131</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Wildfire content installation failed for WF-500B
|
||||||
|
clusters when deployed from Panorama using the deployment schedule.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-260015</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on the firewall where the dataplane restarted due to
|
||||||
|
insufficient allocation of memory buffers.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-254577</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a core file was created on the Log Forwarding
|
||||||
|
Card due to a third-party software issue.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-249581</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where stale BGP routes were advertised to peers even
|
||||||
|
when they were not present in the local RIB table.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-249011</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall became unresponsive when committing
|
||||||
|
a configuration change with a large number of uncommitted changes in
|
||||||
|
the replay database.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-241772</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, when TLSv1.3 was used, an incorrect error
|
||||||
|
message <span class="ph systemoutput">invalid padding</span> was
|
||||||
|
displayed instead of the expected error message
|
||||||
|
<span class="ph systemoutput">Invalid server certificate</span>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-241126</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the client IP address was incorrect in the
|
||||||
|
authentication logs for Captive Portal authentication events when the
|
||||||
|
client used IPv6.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-238594</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall rebooted when a QSFP28 cable was
|
||||||
|
removed from the port while the port was passing traffic.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-237010</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where local commits took longer than
|
||||||
|
expected after an upgrade.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-233868</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall took an incorrect action for
|
||||||
|
overlapping custom and edl-url-categories in a policy rule.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-233581</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on firewalls in active/active HA configurations where
|
||||||
|
SYN+ACK packets of asymmetric TCP sessions were dropped because of a
|
||||||
|
session synchronization issue.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-224833</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall dropped DHCPv6 relay packets if
|
||||||
|
there were duplicate link-local addresses on different sub-interfaces.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-212735</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where sessions that were previously in sw-cut-through
|
||||||
|
mode (software fast forwarding) and persisted after an HA failover
|
||||||
|
were no longer subject to software fast forwarding, which led to
|
||||||
|
increased dataplane CPU load after HA failover.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,255 @@
|
|||||||
|
<table class="table colsep rowsep table-striped">
|
||||||
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||||
|
|
||||||
|
<colgroup>
|
||||||
|
<col style="width: 46.728971962616825%" />
|
||||||
|
<col style="width: 53.27102803738318%" />
|
||||||
|
</colgroup>
|
||||||
|
<thead class="thead">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<th class="entry">Issue ID</th>
|
||||||
|
<th class="entry">Description</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
|
||||||
|
<tbody class="tbody">
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-290996</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where SNMP walks returned a value of 0 for the CPS
|
||||||
|
(Connections Per Second) per vsys on firewalls after upgrading to
|
||||||
|
PAN-OS 11.1.6-h3, even when active connections were present.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-290803</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>VM-Series firewalls on Microsoft Azure environments only</tt
|
||||||
|
>) Fixed an issue where firewall failed to bootstrap with a custom
|
||||||
|
image, and VM-Series plugin information was not displayed in the
|
||||||
|
system information.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-290088</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a memory leak occurred related to the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>configd</a
|
||||||
|
>
|
||||||
|
process when pushing configurations from Panorama to a firewall. This
|
||||||
|
occurred when the configurations contained shared policy rules.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-289763</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-5400f firewalls only</tt>) Fixed an issue where
|
||||||
|
SD-WAN SaaS monitoring did not work with URL monitoring.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-288929</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<span class="ph systemoutput">preferred_wnd</span> value provided by
|
||||||
|
CTD (Content Threat Detection) was disregarded due to TCP bandwidth
|
||||||
|
estimation, which prevented the window from closing.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-288363</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the MIB ID returned an incorrect value via SNMP.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287818</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where sessions timed out sooner than expected due to
|
||||||
|
the <span class="ph systemoutput">pan_proxy_accumulation</span>
|
||||||
|
<span class="ph systemoutput">_restore_timeout</span> not initiating
|
||||||
|
when the accumulation<span class="ph systemoutput">session_init</span>
|
||||||
|
failed.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287601</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where commits took longer than expected.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287056</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where BGP export policy rules with next-hop matching
|
||||||
|
failed to block the advertisement of static routes, and the firewall
|
||||||
|
incorrectly matched the egress interface IP address instead of the
|
||||||
|
original next-hop IP address of the static route, which caused the
|
||||||
|
deny rule to fail.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287035</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, when an application stopped responding, a large
|
||||||
|
file was created in the /opt/panlogs directory, which caused the
|
||||||
|
partition to fill up.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287023</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a large number of logs caused the logrcvr process
|
||||||
|
to stop responding.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287002</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
A fix was made to address
|
||||||
|
<a
|
||||||
|
class="xref"
|
||||||
|
href="https://security.paloaltonetworks.com/CVE-2025-0133"
|
||||||
|
title=""
|
||||||
|
data-scope="external"
|
||||||
|
data-format="html"
|
||||||
|
data-type=""
|
||||||
|
target="_blank"
|
||||||
|
>CVE-2025-0133</a
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-286306</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, when getting transceiver information from ESCC
|
||||||
|
for SFP 25G modules, the transceiver code was incorrectly updated with
|
||||||
|
<span class="ph systemoutput">Unknown</span> instead of
|
||||||
|
<span class="ph systemoutput">25GBase-SR</span>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-284744</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
A fix was made to address
|
||||||
|
<a
|
||||||
|
class="xref"
|
||||||
|
href="https://security.paloaltonetworks.com/CVE-2025-4229"
|
||||||
|
title=""
|
||||||
|
data-scope="external"
|
||||||
|
data-format="html"
|
||||||
|
data-type=""
|
||||||
|
target="_blank"
|
||||||
|
>CVE-2025-4229</a
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-278288</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where IPv6 BGP peering established between virtual
|
||||||
|
routers even without dataplane connectivity. This occurred because the
|
||||||
|
firewall used the kernel for lookups instead of the dataplane.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-268787</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where users were unable to log in to Panorama and the
|
||||||
|
following error message was displayed:
|
||||||
|
<span class="ph systemoutput">
|
||||||
|
Timed out while getting config lock. Please try again</span
|
||||||
|
>. This occurred when pushing configurations to a large number of
|
||||||
|
devices.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
@@ -0,0 +1,404 @@
|
|||||||
|
<table class="table colsep rowsep table-striped">
|
||||||
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||||
|
|
||||||
|
<colgroup>
|
||||||
|
<col style="width: 46.728971962616825%" />
|
||||||
|
<col style="width: 53.27102803738318%" />
|
||||||
|
</colgroup>
|
||||||
|
<thead class="thead">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<th class="entry">Issue ID</th>
|
||||||
|
<th class="entry">Description</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
|
||||||
|
<tbody class="tbody">
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-297349</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the MIB ID returned an incorrect value via SNMP.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-295342</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>pan_comm</a
|
||||||
|
>
|
||||||
|
process stopped responding due to insufficient time allocated to read
|
||||||
|
file descriptors when processing long messages.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-294770</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Firewalls in active/passive HA configurations</tt>)
|
||||||
|
Fixed an issue on firewalls where, after failover, certain subnets
|
||||||
|
were missing from the Link State Database, which prevented OSPF routes
|
||||||
|
from being immediately learned due to a Type-7 to Type-5 LSA
|
||||||
|
translation conflict in the ABR when the same LSA was advertised by
|
||||||
|
two peers in the NSSA area.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-293673</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall stopped all tasks due to an OOM
|
||||||
|
condition caused by a scheduled log export using FTP to an external
|
||||||
|
FTP server.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-292539</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">CN-Series firewalls only</tt>) Fixed an issue where
|
||||||
|
the firewall generated incomplete or corrupted tech support files
|
||||||
|
(TSF) due to high disk usage on the management plane.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-289239</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where a new virtual system (vsys) was
|
||||||
|
automatically created with the name of a device group.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287842</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>comm</a
|
||||||
|
>
|
||||||
|
process stopped responding due to missing heartbeats, which resulted
|
||||||
|
in a system alert and HA communication loss on slot1.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287838</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue on
|
||||||
|
the web interface where resetting the rule hit counter for multiple
|
||||||
|
policy rules failed with the error message
|
||||||
|
<span class="ph systemoutput">Failed to reset rule-hit job</span>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287734</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the error message
|
||||||
|
<span class="ph uicontrol">Scan ERR: Internal Err 1002</span> was
|
||||||
|
generated unexpectedly when WIF shared memory use was high.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-286615</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall double-freed shared memory when the
|
||||||
|
shared memory usage reached 100% when sending large payloads. This
|
||||||
|
occurred when DLP, Advanced Advanced Threat Protection (ATP), Advanced
|
||||||
|
WildFire (AWF), or Advanced URL Filtering were enabled.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-286231</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a simultaneous selective push from Panorama to
|
||||||
|
multiple firewalls with different base configurations resulted in
|
||||||
|
configuration corruption, which caused the firewall to go down.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-284003</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where clients did not receive a valid response when
|
||||||
|
searching a website due to a compression error.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-282277</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where an OOM condition on the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>logrcvr</a
|
||||||
|
>
|
||||||
|
process caused interface flapping, and the interface unexpectedly went
|
||||||
|
down and then recovered without intervention.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-280536</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where firewalls that were connected to the same Cloud
|
||||||
|
Identity Engine displayed inconsistent group membership information,
|
||||||
|
with some firewalls showing only a subset of users belonging to a
|
||||||
|
group.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-279901</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
An issue was fixed where the firewall dropped fragmented TLS
|
||||||
|
ClientHello packets, which blocked access to certain websites. This
|
||||||
|
occurred because the packets arrived truncated, in varying sizes and
|
||||||
|
orders, and the firewall's heuristics failed to handle them correctly.
|
||||||
|
</div>
|
||||||
|
<div class="p">
|
||||||
|
To enable this fix, run:
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>debug dataplane set ssl-decrypt accumulate-client-hello disjoined
|
||||||
|
yes</span
|
||||||
|
>
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-279500</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where TLS connections failed to establish in asymmetric
|
||||||
|
routing environments if the firewall did not see server-to-client
|
||||||
|
(s2c) packets of the TLS handshake.
|
||||||
|
</div>
|
||||||
|
<div class="p">
|
||||||
|
To use this fix, run the following CLI command:
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>debug dataplane set ssl-decrypt accumulate-client-hello
|
||||||
|
asym-disable yes</span
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-278288 </b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where IPv6 BGP peering established between virtual
|
||||||
|
routers even without dataplane connectivity. This occurred because the
|
||||||
|
firewall used the kernel for lookups instead of the dataplane.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-276484 </b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Panorama did not display license information for
|
||||||
|
Cloud NGFW firewalls under (<span class="ph uicontrol"
|
||||||
|
>Device Deployment > Licenses</span
|
||||||
|
>) due to the inability to perform batch-license refreshes.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-277034</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where WildFire reports were not fully displayed and
|
||||||
|
were not downloadable due to static resources not being found.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-267614</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the Panorama web interface was slower than
|
||||||
|
expected due to high CPU utilization on the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>mongodb</a
|
||||||
|
>
|
||||||
|
process.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-220293</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall management plane could not display
|
||||||
|
BGP peer details when using the CLI command
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>show advanced-routing bgp peer detail logical-router
|
||||||
|
<LR></span
|
||||||
|
>. This was due to the
|
||||||
|
<span class="ph systemoutput">bgp_frr.py</span> script failing to
|
||||||
|
parse the IPv6 address family section of the
|
||||||
|
<span class="ph systemoutput">show ip bgp neighbors json</span>
|
||||||
|
output.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-231386</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>configd</a
|
||||||
|
>
|
||||||
|
process stopped responding during certificate verification.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-202905</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on the firewall web interface where the
|
||||||
|
<span class="ph uicontrol">Next Hop</span> value was not displayed in
|
||||||
|
the static route configuration, the
|
||||||
|
<span class="ph uicontrol">admin-dist</span> values were empty, and
|
||||||
|
the path-monitor parameters were not listed in the management server
|
||||||
|
web interface when the firewall was configured in FRR mode.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-191026</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<span class="ph systemoutput">debug log receiver statistics</span> CLI
|
||||||
|
command did not display entries for hipmatch logs.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
@@ -0,0 +1,450 @@
|
|||||||
|
<table class="table colsep rowsep">
|
||||||
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||||
|
|
||||||
|
<colgroup>
|
||||||
|
<col style="width: 46.728971962616825%" />
|
||||||
|
<col style="width: 53.27102803738318%" />
|
||||||
|
</colgroup>
|
||||||
|
<thead class="thead">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<th class="entry">Issue ID</th>
|
||||||
|
<th class="entry">Description</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
|
||||||
|
<tbody class="tbody">
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-304756</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where, after you disabled the shared
|
||||||
|
optimization feature, a full configuration push to multi-vsys devices
|
||||||
|
caused a validation error.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-297775</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after upgrading to an affected PAN-OS release,
|
||||||
|
the Visible Virtual System field referenced the vsys name instead of
|
||||||
|
the vsys ID, which caused inter-vsys routing to fail. This occurred
|
||||||
|
when a vsys display name matched one of the vsys IDs. If you're using
|
||||||
|
a multivsys environment, you must upgrade your firewalls to a fixed
|
||||||
|
PAN-OS version. The best practice is to upgrade both the firewalls and
|
||||||
|
Panorama to a fixed PAN-OS version.
|
||||||
|
</div>
|
||||||
|
<div class="p">
|
||||||
|
If you don't upgrade Panorama to a fixed version, you'll encounter
|
||||||
|
PAN-245064, where a commit on a multivsys firewall fails with the
|
||||||
|
message
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>vsys name should end with a number vsys is invalid</span
|
||||||
|
>
|
||||||
|
after you
|
||||||
|
<span class="ph uicontrol">Export or push device config bundle</span>
|
||||||
|
from Panorama.
|
||||||
|
</div>
|
||||||
|
<div class="p">
|
||||||
|
After you upgrade Panorama to a fixed version, you'll encounter
|
||||||
|
PAN-214177, which causes an
|
||||||
|
<span class="ph uicontrol">Export or Push device config bundle </span
|
||||||
|
>from Panorama to the firewall to fail. The workaround for PAN-214177
|
||||||
|
is to first push only the template configuration and then push the
|
||||||
|
device group configurations.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-297349</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the MIB ID returned an incorrect value via SNMP.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-294770</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Firewalls in active/passive HA configurations</tt>)
|
||||||
|
Fixed an issue on firewalls where, after failover, certain subnets
|
||||||
|
were missing from the Link State Database, which prevented OSPF routes
|
||||||
|
from being immediately learned due to a Type-7 to Type-5 LSA
|
||||||
|
translation conflict in the ABR when the same LSA was advertised by
|
||||||
|
two peers in the NSSA area.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-293673</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall stopped all tasks due to an OOM
|
||||||
|
condition caused by a scheduled log export using FTP to an external
|
||||||
|
FTP server.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-292539</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">CN-Series firewalls only</tt>) Fixed an issue where
|
||||||
|
the firewall generated incomplete or corrupted tech support files
|
||||||
|
(TSF) due to high disk usage on the management plane.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-291716</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where during a commit, the firewall experienced an
|
||||||
|
out-of-memory (OOM) condition due to a memory leak and displayed an
|
||||||
|
error message. This issue caused the device to stop responding and
|
||||||
|
reboot unexpectedly.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-291288 </b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall rebooted unexpectedly due to a
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>pan_task</a
|
||||||
|
>
|
||||||
|
process restart related to page allocation failures.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-289239</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where a new virtual system (vsys) was
|
||||||
|
automatically created with the name of a device group.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-288097</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where on the firewall where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>routed</a
|
||||||
|
>
|
||||||
|
process stopped responding after changing the MTU or any link state
|
||||||
|
parameters when OSPF and PIM were enabled on the same interface.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287734</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the error message
|
||||||
|
<span class="ph uicontrol">Scan ERR: Internal Err 1002</span> was
|
||||||
|
generated unexpectedly when WIF shared memory use was high.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-286615</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall double-freed shared memory when the
|
||||||
|
shared memory usage reached 100% when sending large payloads. This
|
||||||
|
occurred when DLP, Advanced Advanced Threat Protection (ATP), Advanced
|
||||||
|
WildFire (AWF), or Advanced URL Filtering were enabled.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-286231</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a simultaneous selective push from Panorama to
|
||||||
|
multiple firewalls with different base configurations resulted in
|
||||||
|
configuration corruption, which caused the firewall to go down.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-285208</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall did not automatically recover after
|
||||||
|
a machine check exception (MCE) occurred.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-284067</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed a cumulative memory leak in the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>devsrvr</a
|
||||||
|
>
|
||||||
|
process that occurred whenever the CLI command
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>show running application statistics</span
|
||||||
|
>
|
||||||
|
was issued. This memory leak would gradually consume system memory and
|
||||||
|
produce an OOM condition, causing the firewall to reboot.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-284003</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where clients did not receive a valid response when
|
||||||
|
searching a website due to a compression error.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-280536</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where firewalls that were connected to the same Cloud
|
||||||
|
Identity Engine displayed inconsistent group membership information,
|
||||||
|
with some firewalls showing only a subset of users belonging to a
|
||||||
|
group.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-279901</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
An issue was fixed where the firewall dropped fragmented TLS
|
||||||
|
ClientHello packets, which blocked access to certain websites. This
|
||||||
|
occurred because the packets arrived truncated, in varying sizes and
|
||||||
|
orders, and the firewall's heuristics failed to handle them correctly.
|
||||||
|
</div>
|
||||||
|
<div class="p">
|
||||||
|
To enable this fix, run:
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>debug dataplane set ssl-decrypt accumulate-client-hello disjoined
|
||||||
|
yes</span
|
||||||
|
>
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-279500</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where TLS connections failed to establish in asymmetric
|
||||||
|
routing environments if the firewall did not see server-to-client
|
||||||
|
(s2c) packets of the TLS handshake.
|
||||||
|
</div>
|
||||||
|
<div class="p">
|
||||||
|
To use this fix, run the following CLI command:
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>debug dataplane set ssl-decrypt accumulate-client-hello
|
||||||
|
asym-disable yes</span
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-279364</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">VM-Series firewalls with multiple NICs only</tt>)
|
||||||
|
Fixed an issue were the queue count in the task dump displayed an
|
||||||
|
incorrect number of queues for SR-IOV interfaces due to the queue
|
||||||
|
mapping logic incorrectly using a non-multi-NIC function.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-278288 </b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where IPv6 BGP peering established between virtual
|
||||||
|
routers even without dataplane connectivity. This occurred because the
|
||||||
|
firewall used the kernel for lookups instead of the dataplane.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-276484 </b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Panorama did not display license information for
|
||||||
|
Cloud NGFW firewalls under (<span class="ph uicontrol"
|
||||||
|
>Device Deployment > Licenses</span
|
||||||
|
>) due to the inability to perform batch-license refreshes.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-267614</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the Panorama web interface was slower than
|
||||||
|
expected due to high CPU utilization on the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>mongodb</a
|
||||||
|
>
|
||||||
|
process.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-231386</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>configd</a
|
||||||
|
>
|
||||||
|
process stopped responding during certificate verification.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-202905</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on the firewall web interface where the
|
||||||
|
<span class="ph uicontrol">Next Hop</span> value was not displayed in
|
||||||
|
the static route configuration, the
|
||||||
|
<span class="ph uicontrol">admin-dist</span> values were empty, and
|
||||||
|
the path-monitor parameters were not listed in the management server
|
||||||
|
web interface when the firewall was configured in FRR mode.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-191026</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<span class="ph systemoutput">debug log receiver statistics</span> CLI
|
||||||
|
command did not display entries for hipmatch logs.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
@@ -0,0 +1,394 @@
|
|||||||
|
<table class="table colsep rowsep table-striped">
|
||||||
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||||
|
|
||||||
|
<colgroup>
|
||||||
|
<col style="width: 25.062656641604008%" />
|
||||||
|
<col style="width: 74.93734335839599%" />
|
||||||
|
</colgroup>
|
||||||
|
<thead class="thead">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||||
|
</th>
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Description</b></div>
|
||||||
|
</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
|
||||||
|
<tbody class="tbody">
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">—</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">Fixes were made to address the following CVEs:</div>
|
||||||
|
<ul id="pan-os-10-2-10-h31-addressed-issues_ul-snk_4r1_gjc" class="ul">
|
||||||
|
<li class="li">
|
||||||
|
<a
|
||||||
|
class="xref"
|
||||||
|
href="https://security.paloaltonetworks.com/CVE-2026-0265"
|
||||||
|
title=""
|
||||||
|
data-scope="external"
|
||||||
|
data-format="html"
|
||||||
|
data-type=""
|
||||||
|
target="_blank"
|
||||||
|
>CVE-2026-0265</a
|
||||||
|
>
|
||||||
|
</li>
|
||||||
|
<li class="li">
|
||||||
|
<a
|
||||||
|
class="xref"
|
||||||
|
href="https://security.paloaltonetworks.com/CVE-2026-0264"
|
||||||
|
title=""
|
||||||
|
data-scope="external"
|
||||||
|
data-format="html"
|
||||||
|
data-type=""
|
||||||
|
target="_blank"
|
||||||
|
>CVE-2026-0264</a
|
||||||
|
>
|
||||||
|
</li>
|
||||||
|
<li class="li">
|
||||||
|
<a
|
||||||
|
class="xref"
|
||||||
|
href="https://security.paloaltonetworks.com/CVE-2026-0262"
|
||||||
|
title=""
|
||||||
|
data-scope="external"
|
||||||
|
data-format="html"
|
||||||
|
data-type=""
|
||||||
|
target="_blank"
|
||||||
|
>CVE-2026-0262</a
|
||||||
|
>
|
||||||
|
</li>
|
||||||
|
<li class="li">
|
||||||
|
<a
|
||||||
|
class="xref"
|
||||||
|
href="https://security.paloaltonetworks.com/CVE-2026-0261"
|
||||||
|
title=""
|
||||||
|
data-scope="external"
|
||||||
|
data-format="html"
|
||||||
|
data-type=""
|
||||||
|
target="_blank"
|
||||||
|
>CVE-2026-0261</a
|
||||||
|
>
|
||||||
|
</li>
|
||||||
|
<li class="li">
|
||||||
|
<a
|
||||||
|
class="xref"
|
||||||
|
href="https://security.paloaltonetworks.com/CVE-2026-0258"
|
||||||
|
title=""
|
||||||
|
data-scope="external"
|
||||||
|
data-format="html"
|
||||||
|
data-type=""
|
||||||
|
target="_blank"
|
||||||
|
>CVE-2026-0258</a
|
||||||
|
>
|
||||||
|
</li>
|
||||||
|
<li class="li">
|
||||||
|
<a
|
||||||
|
class="xref"
|
||||||
|
href="https://security.paloaltonetworks.com/CVE-2026-0257"
|
||||||
|
title=""
|
||||||
|
data-scope="external"
|
||||||
|
data-format="html"
|
||||||
|
data-type=""
|
||||||
|
target="_blank"
|
||||||
|
>CVE-2026-0257</a
|
||||||
|
>
|
||||||
|
</li>
|
||||||
|
<li class="li">
|
||||||
|
<a
|
||||||
|
class="xref"
|
||||||
|
href="https://security.paloaltonetworks.com/CVE-2026-0256"
|
||||||
|
title=""
|
||||||
|
data-scope="external"
|
||||||
|
data-format="html"
|
||||||
|
data-type=""
|
||||||
|
target="_blank"
|
||||||
|
>CVE-2026-0256</a
|
||||||
|
>
|
||||||
|
</li>
|
||||||
|
<li class="li">
|
||||||
|
<a
|
||||||
|
class="xref"
|
||||||
|
href="https://security.paloaltonetworks.com/CVE-2026-0259"
|
||||||
|
title=""
|
||||||
|
data-scope="external"
|
||||||
|
data-format="html"
|
||||||
|
data-type=""
|
||||||
|
target="_blank"
|
||||||
|
>CVE-2026-0259</a
|
||||||
|
>
|
||||||
|
</li>
|
||||||
|
<li class="li">
|
||||||
|
<a
|
||||||
|
class="xref"
|
||||||
|
href="https://security.paloaltonetworks.com/CVE-2026-0300"
|
||||||
|
title=""
|
||||||
|
data-scope="external"
|
||||||
|
data-format="html"
|
||||||
|
data-type=""
|
||||||
|
target="_blank"
|
||||||
|
>CVE-2026-0300</a
|
||||||
|
>
|
||||||
|
</li>
|
||||||
|
</ul>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-316911</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>VM-Series firewalls on Amazon Web Services (AWS) environments
|
||||||
|
only</tt
|
||||||
|
>) Fixed an issue where a newly bootstrapped firewall required a
|
||||||
|
management server restart, relicensing, or license push from Panorama
|
||||||
|
to invoke the device certificate.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-313828</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall did not forward traffic due to
|
||||||
|
memory issues on a forwarding component.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-308507</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">Panorama managed firewalls only</tt>) Fixed an
|
||||||
|
issue where the firewall intermittently failed to maintain active log
|
||||||
|
forwarding streams to Strata Logging Service (SLS) even when duplicate
|
||||||
|
logging and enhanced application logging were enabled.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-305415</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where commits caused high dataplane CPU utilization and
|
||||||
|
briefly increased Packet Descriptors, which disrupted traffic.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-303051</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where a memory leak occurred related to the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>reportd</a
|
||||||
|
>
|
||||||
|
process due to retaining memory that was temporarily used for report
|
||||||
|
generation instead of releasing the memory for reuse, which resulted
|
||||||
|
in continuous accumulation and memory exhaustion.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-301409</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Panorama failed to perform a selective push to a
|
||||||
|
managed device when device tags were added or modified on the policy
|
||||||
|
rules. The selective push failed with the error message
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>Failed to generate selective push configuration. Schema validation
|
||||||
|
failed. Please try a full push</span
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-297610</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall became unresponsive after an upgrade
|
||||||
|
due to the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>fsck</a
|
||||||
|
>
|
||||||
|
command scanning drive partitions in parallel with the root partition,
|
||||||
|
which caused the process to take an extended amount of time.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-297295</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>VM-Series firewalls in Microsoft Azure environments only</tt
|
||||||
|
>) Fixed an issue where the firewall repeatedly restarted due to high
|
||||||
|
packet rates on the synthetic path in DPDK mode.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-295470</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on the firewall where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>useridd</a
|
||||||
|
>
|
||||||
|
process continuously increased its memory consumption, which resulted
|
||||||
|
in an OOM condition that caused the firewall to restart.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-292393</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where TFTP file transfers intermittently timed out in
|
||||||
|
active-active HA pairs when the TFTP control channel was processed by
|
||||||
|
one firewall and the data channel was processed by the other. This
|
||||||
|
occurred because the firewall receiving the data channel failed to
|
||||||
|
match the predicted session due to asynchronous processing of HA
|
||||||
|
messages.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-291067</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>devsrvr</a
|
||||||
|
>
|
||||||
|
process periodically exceeded its virtual memory limit and restarted,
|
||||||
|
which led to intermittent outages.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-289249</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a memory leak occurred on the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>reportd</a
|
||||||
|
>
|
||||||
|
process when a WildFire update was initiated while device telemetry
|
||||||
|
data collection was in progress. This resulted in an OOM condition.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-286094</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall did not forward logs to SLS when
|
||||||
|
using a proxy server configuration due to an OCSP validation failure.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-285208</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall did not automatically recover after
|
||||||
|
a machine check exception (MCE) occurred.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-242952</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where high SSL traffic depleted flex memory, which
|
||||||
|
prevented the firewall from revalidating SSLVPN client CAs during
|
||||||
|
configuration pushes.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
@@ -0,0 +1,495 @@
|
|||||||
|
<table class="table colsep rowsep">
|
||||||
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||||
|
|
||||||
|
<colgroup>
|
||||||
|
<col style="width: 25%" />
|
||||||
|
<col style="width: 75%" />
|
||||||
|
</colgroup>
|
||||||
|
<thead class="thead">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||||
|
</th>
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Description</b></div>
|
||||||
|
</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
|
||||||
|
<tbody class="tbody">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-289102</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>PA-7500 Series, PA-5410, PA-5420, PA-5430, PA-5440, PA-5445,
|
||||||
|
PA-3400 Series, PA-1400 Series, PA-400 Series, VM-Series, and
|
||||||
|
CN-Series firewalls only</tt
|
||||||
|
>) Fixed a race condition issue related to predict processing, which
|
||||||
|
resulted in a dataplane restart and traffic loss.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-287611</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after upgrading, the firewall incorrectly
|
||||||
|
calculated the UDP checksum for RTP traffic after NAT and Security
|
||||||
|
policy application, which led to dropped packets and silent calls in
|
||||||
|
applications.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-286897</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>pan_task</a
|
||||||
|
>
|
||||||
|
process stopped responding when the firewall attempted to forward
|
||||||
|
files to the WildFire public cloud, which caused the dataplane to
|
||||||
|
experience heartbeat failures.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-286475</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the option to sort sequence numbers was missing
|
||||||
|
from <span class="ph uicontrol">Filters prefix list</span> in the
|
||||||
|
advanced routing filters.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-285941</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where high memory consumption occurred on the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>logrcvr</a
|
||||||
|
>
|
||||||
|
process.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-285894</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the
|
||||||
|
<a
|
||||||
|
class="term"
|
||||||
|
href="#"
|
||||||
|
title=""
|
||||||
|
data-scope=""
|
||||||
|
data-format="dita"
|
||||||
|
data-type=""
|
||||||
|
target="_self"
|
||||||
|
>all_task</a
|
||||||
|
>
|
||||||
|
process stopped responding, which caused the firewall to reboot
|
||||||
|
unexpectedly, and traffic failures occurred.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-285590</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt"
|
||||||
|
>VM-Series firewalls on Amazon Web Services (AWS) GWLB environments
|
||||||
|
only</tt
|
||||||
|
>) Fixed an issue where the firewall CPU usage reached 100% after
|
||||||
|
upgrading to PAN-OS 11.1.6-h1.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-284908</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where retrieving filenames from OneDrive resulted in a
|
||||||
|
cache miss.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-284840</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-5220 firewalls only</tt>) Fixed an issue where
|
||||||
|
custom reports were delayed when sent via email instead of being sent
|
||||||
|
at the scheduled time.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-284069</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after an upgrade, the total number of logout
|
||||||
|
records in the HIP database incorrectly displayed as zero.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-284066</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, after an upgrade, the SNMP polled values for
|
||||||
|
<span class="ph systemoutput">IF-MIB::ifInErrors</span> displayed a
|
||||||
|
high number of errors that did not match the values in the CLI show
|
||||||
|
interface command.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-283664</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where a slow NAT leak occurred when persistent NAT was
|
||||||
|
enabled. This occurred when ICMP sessions matched the persistent
|
||||||
|
Dynamic IP and Port (DIPP) rule and no predict sessions were involved
|
||||||
|
in that rule.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-283428</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-7050 Firewalls only</tt>) Fixed an issue where,
|
||||||
|
after an upgrade, the dataplane CPU reached 100% due to packet buffer
|
||||||
|
exhaustion, which resulted in general packet processing issues.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-281797</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where firewalls became unstable and stopped responding,
|
||||||
|
which resulted in an OOM condition.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-280505</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the web interface did not display a message to
|
||||||
|
commit prior changes before attempting a partial configuration load.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-280409</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the popup window did not appear as expected for
|
||||||
|
Clientless VPN users.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-279706</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">M-600 appliances only</tt>)) Fixed an issue where
|
||||||
|
Panorama did not update all
|
||||||
|
<span class="ph systemoutput">panreplay</span> database entries after
|
||||||
|
performing a commit and full push to all devices.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-277617</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where deleting the NTP server address caused a commit
|
||||||
|
validation error. This occurred when the configuration included both
|
||||||
|
primary and secondary NTP servers and the secondary server was
|
||||||
|
removed.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-273727</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the firewall skipped the DNS policy rule of a
|
||||||
|
domain external dynamic list (EDL) during an EDL refresh.
|
||||||
|
</div>
|
||||||
|
<div class="p">
|
||||||
|
To use this fix, run the following CLI command and commit:
|
||||||
|
<span class="ph systemoutput"
|
||||||
|
>set deviceconfig setting ctd custom-edl-domains-continuous-reload
|
||||||
|
yes/no</span
|
||||||
|
>
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-271701</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where Advanced Services, App-ID Cloud Engine (ACE), and
|
||||||
|
Enhanced Application Log stopped working due to incorrect memory usage
|
||||||
|
accounting, which caused memory usage to remain at 99% after an
|
||||||
|
extended period of time.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-270379</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where socket files created in the /tmp directory were
|
||||||
|
not cleared.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-268614</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on the web interface where, when all rules were
|
||||||
|
highlighted when a read-only admin user clicked the
|
||||||
|
<span class="ph uicontrol">Highlight Unused Rules</span> checkbox.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-268313</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where the Priority Code Point (PCP) bits in the VLAN
|
||||||
|
header were not reset to 0 when a packet was received from one Layer 3
|
||||||
|
tagged interface and forwarded to another, which resulted in dropped
|
||||||
|
packets.
|
||||||
|
</div>
|
||||||
|
<div class="p">
|
||||||
|
To use this fix, run the CLI command
|
||||||
|
<span class="ph systemoutput">set force-vlan-pcp-reset yes</span> and
|
||||||
|
reboot the firewall.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-267707</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where BFD sessions did not come up even when BGP
|
||||||
|
peering was established.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-265782</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on Panorama where, after you enabled multihop in a BFD
|
||||||
|
profile, you were unable to disable it via the web interface.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-260132</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where secondary IP addresses with a /32 prefix
|
||||||
|
configured on Layer 3 interfaces were not reachable in FRR mode.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-260015</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue on the firewall where the dataplane restarted due to
|
||||||
|
insufficient allocation of memory buffers.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-255654</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where, when QoS was enabled on aggregate interfaces,
|
||||||
|
the maximum aggregate interface throughput was capped, which limited
|
||||||
|
network traffic. This occurred even with default QoS settings and no
|
||||||
|
configured egress max-bandwidth.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-253187</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
|
||||||
|
the class of service (CoS) priority bit was not modified, causing
|
||||||
|
access points to lose connectivity to the wireless controller when
|
||||||
|
traffic was routed through the firewall.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-240606</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where licenses expired a day before the expiry date.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-224729</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where you were unable to create duplicate entries in
|
||||||
|
Advanced Routing AS path prepend in the BGP filter route map.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-224020</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
Fixed an issue where CIE validation checks on the firewall prevented
|
||||||
|
configuration pushes from Panorama, which resulted in commit failures
|
||||||
|
during new firewall deployment. This occurred when a template with an
|
||||||
|
Authentication Profile with the
|
||||||
|
<span class="ph uicontrol">Authentication Type</span> as
|
||||||
|
<span class="ph uicontrol">Cloud Authentication Service</span> was
|
||||||
|
pushed to a newly deployed firewall without internet access or without
|
||||||
|
a device certificate.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">PAN-220435</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
||||||
|
the GlobalProtect client failed to install on the firewall.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
@@ -0,0 +1,41 @@
|
|||||||
|
<table class="table colsep rowsep table-striped">
|
||||||
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
||||||
|
|
||||||
|
<colgroup>
|
||||||
|
<col style="width: 25%" />
|
||||||
|
<col style="width: 75%" />
|
||||||
|
</colgroup>
|
||||||
|
<thead class="thead">
|
||||||
|
<tr class="row rowsep">
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Issue ID</b></div>
|
||||||
|
</th>
|
||||||
|
<th class="entry">
|
||||||
|
<div class="p"><b class="ph b">Description</b></div>
|
||||||
|
</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
|
||||||
|
<tbody class="tbody">
|
||||||
|
<tr class="row">
|
||||||
|
<td class="entry">
|
||||||
|
<div class="p"><b class="ph b">—</b></div>
|
||||||
|
</td>
|
||||||
|
<td class="entry relcol">
|
||||||
|
<div class="p">
|
||||||
|
A fix was made to address
|
||||||
|
<a
|
||||||
|
class="xref"
|
||||||
|
href="https://security.paloaltonetworks.com/CVE-2026-0257"
|
||||||
|
title=""
|
||||||
|
data-scope="external"
|
||||||
|
data-format="html"
|
||||||
|
data-type=""
|
||||||
|
target="_blank"
|
||||||
|
>CVE-2026-0257</a
|
||||||
|
>.
|
||||||
|
</div>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
</tbody>
|
||||||
|
</table>
|
||||||
Reference in New Issue
Block a user