Add 9.0 issues data
This commit is contained in:
@@ -0,0 +1,437 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.11
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## PAN-154092
|
||||
|
||||
An enhancement was made to provide an option to increase Data Plane Development Kit (DPDK) ring size and DPDK queue number for VM-Series firewalls deployed on ESXi.
|
||||
|
||||
## PAN-153983
|
||||
|
||||
Fixed an issue where the IPSec encapsulation sequence was not properly synced to the dataplanes on a high availability (HA) active/passive cluster.
|
||||
|
||||
## PAN-153813
|
||||
|
||||
Fixed an issue where the proxy configuration did not get honored, which caused certificate revocation list (CRL) checks from the firewall to fail.
|
||||
|
||||
## PAN-153673
|
||||
|
||||
Fixed an issue where traffic logs were not shown due to a thread timeout that was causing the reading of the logs from the dataplane to slow.
|
||||
|
||||
## PAN-153436
|
||||
|
||||
Added CLI commands to increase thread limits to reduce task thread exhaustion on a process (configd).
|
||||
|
||||
## PAN-153111
|
||||
|
||||
Fixed an issue where packet buffer unavailability caused host-bound sessions to remain in an opening state in the dataplane.
|
||||
|
||||
## PAN-152706
|
||||
|
||||
Fixed an intermittent issue where Panorama did not retrieve firewall logs from Cortex Data Lake.
|
||||
|
||||
## PAN-152285
|
||||
|
||||
Fixed an issue where certain GPRS tunneling protocol (GTP-U) sessions that could not complete installation still occupied the flow table, which led to higher-than-expected session table usage.
|
||||
|
||||
## PAN-152106
|
||||
|
||||
Fixed an issue where a process (genindex.sh) caused the management plane CPU usage to remain high for a longer period of time than expected.
|
||||
|
||||
## PAN-152027
|
||||
|
||||
Fixed an issue with URL Filtering where websites that were previously in the malicious category but have since been cleared remained in the malicious category in the dataplane cache. These websites were moved to the benign category only after you manually cleared the cache.
|
||||
|
||||
## PAN-151203
|
||||
|
||||
Fixed an issue where the firewall dropped certain GTPv1 Update PDP Context packets.
|
||||
|
||||
## PAN-151057
|
||||
|
||||
Fixed an issue where upgrading the capacity license on a VM-Series HA pair resulted in both firewalls going into a non-functional state instead of only the higher capacity license firewall.
|
||||
|
||||
## PAN-150750
|
||||
|
||||
```caveat
|
||||
PA-5200 Series and PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an intermittent issue where the firewall dropped packets when two or more GTP packets on the same GTP tunnel were very close to each other.
|
||||
|
||||
## PAN-150748
|
||||
|
||||
Fixed an issue where the firewall silently dropped GTPv2-C Delete Session Response packets.
|
||||
|
||||
## PAN-150746
|
||||
|
||||
Fixed an issue where the firewall dropped GTP packets with Delete Bearer messages for EBI 6 if they were received within two seconds of receiving the Delete Bearer messages for EBI 5.
|
||||
|
||||
## PAN-150613
|
||||
|
||||
Fixed an issue that caused a process (mprelay) to stop responding when committing changes in the Netflow Server Profile configuration (**Device > Server Profiles > Netflow**).
|
||||
|
||||
## PAN-150243
|
||||
|
||||
Fixed an issue where the candidate configuration was not updated to the running configuration after a successful commit when the commit was initiated by an API-privileges-only custom role-based administrator.
|
||||
|
||||
## PAN-149912
|
||||
|
||||
Fixed an issue where FIB entries were unexpectedly removed due to miscommunication between internal processes.
|
||||
|
||||
## PAN-149480
|
||||
|
||||
Fixed an issue where a custom report query from Panorama, which includes new fields not supported in prior releases, triggered a restart of a process (reportd) when Panorama was connected to log collectors running an earlier PAN-OS release.
|
||||
|
||||
## PAN-149426
|
||||
|
||||
Fixed an issue where non-superuser administrators with all rights enabled were unable to **Review Policies** or **Review Apps** for downloaded or installed content versions.
|
||||
|
||||
## PAN-149296
|
||||
|
||||
Fixed an issue on Panorama where system and configuration logs from dedicated Log Collectors did not display on Panorama appliances in Management Only mode.
|
||||
|
||||
## PAN-148564
|
||||
|
||||
Fixed an issue where Panorama stopped showing new logs when url_category_list was in the URL payload format of the HTTP(S) server profile used to forward URL logs from the Panorama Log Collector.
|
||||
|
||||
## PAN-147741
|
||||
|
||||
Fixed an issue where an API call for correlated events did not return any events .
|
||||
|
||||
## PAN-147595
|
||||
|
||||
Fixed an issue where stream control transmission protocol (SCTP) logs for an existing SCTP session still showed old rule information after a policy commit and session rematch.
|
||||
|
||||
## PAN-147285
|
||||
|
||||
Fixed an issue where host information profile (HIP) details were not available on Panorama even with a valid and active HIP redistribution configuration.
|
||||
|
||||
## PAN-146878
|
||||
|
||||
Fixed an issue where TCP traffic dropped due to TCP sequence checking in an HA active/active configuration where traffic was asymmetric.
|
||||
|
||||
## PAN-146650
|
||||
|
||||
A fix was made to address an authentication bypass vulnerability in the GlobalProtect SSL VPN component of PAN-OS that allowed an attacker to bypass all client certificate checks with an invalid certificate. As a result, the attacker was able to authenticate as any user and gain access to restricted VPN network resources when the gateway or portal was configured to rely only on certificate-based authentication ([CVE-2020-2050](https://security.paloaltonetworks.com/CVE-2020-2050)).
|
||||
|
||||
## PAN-146531
|
||||
|
||||
Fixed an issue where conversion from Panorama mode to logger mode was enabled even when an administrative user named admin did not exist in the configuration, which prevented access to the appliance after conversion.
|
||||
|
||||
## PAN-146506
|
||||
|
||||
Fixed an issue where memory usage on a process (useridd) was high, which caused the process to restart on the firewall that was acting as the User-ID redistribution agent. This issue occurred when multiple clients requested IP address-to-user mappings at the same time.
|
||||
|
||||
## PAN-146284
|
||||
|
||||
Fixed an issue where Applications and Threats content installation failed on the firewall with the following error message: Error: Threat database handler failed.
|
||||
|
||||
## PAN-146117
|
||||
|
||||
Fixed an issue on the firewall where memory usage on a process (devsrvr) increased after running the show object dynamic-address-group all CLI command.
|
||||
|
||||
## PAN-146115
|
||||
|
||||
Fixed an issue where GlobalProtect™ IPSec connections flapped when the peer address to the gateway changed due to NAT.
|
||||
|
||||
## PAN-145823
|
||||
|
||||
Fixed an issue where BGP-learned routes were incorrectly populated with a VR error as a next hop.
|
||||
|
||||
## PAN-145757
|
||||
|
||||
Fixed an issue where a firewall process (all_pktproc) restarted while processing Session Traversal Utilities for NAT (STUN) over TCP.
|
||||
|
||||
## PAN-145752
|
||||
|
||||
Fixed an issue where exporting policies to PDF or CSV files did not include all policies and contained duplicates.
|
||||
|
||||
## PAN-145188
|
||||
|
||||
Fixed an issue on Panorama in PAN-DB mode where content updates did not successfully install, which caused the cloud state to degrade.
|
||||
|
||||
## PAN-145133
|
||||
|
||||
A fix was made to address a vulnerability in the PAN-OS signature-based threat detection engine that allowed an attacker to evade threat prevention signatures using specifically crafted TCP packets ([CVE-2020-1999](https://security.paloaltonetworks.com/CVE-2020-1999)).
|
||||
|
||||
## PAN-144919
|
||||
|
||||
Fixed an issue on an M-600 appliance where the Panorama management server stopped receiving new logs from firewalls because delayed log purging caused log storage on the Log Collectors to reach maximum capacity.
|
||||
|
||||
## PAN-144448
|
||||
|
||||
Fixed an issue with the automated correlation engine that caused firewalls to stop generating correlated event logs for the beacon-heuristics object (ID 6005).
|
||||
|
||||
## PAN-143959
|
||||
|
||||
Fixed an issue on Panorama where a custom administrator with all rights enabled was not able to display the content of the external dynamic list (EDL) on the Panorama web interface.
|
||||
|
||||
## PAN-143809
|
||||
|
||||
Fixed an issue where Log Collectors had problems ingesting older logs for previous days received at a high rate.
|
||||
|
||||
## PAN-143796
|
||||
|
||||
Fixed an issue where commits failed on the firewall due to memory allocation failure. You can check configuration memory using the debug dataplane show cfg-memstat statistics CLI command.
|
||||
|
||||
## PAN-141980
|
||||
|
||||
Fixed an issue where random member ports in a link aggregate group failed to join the aggregate group due to the following error: Link speed mismatch.
|
||||
|
||||
## PAN-141923
|
||||
|
||||
Fixed an issue where authentication stopped working after a commit and a process (authd) exited, which caused other processes to exit.
|
||||
|
||||
## PAN-141793
|
||||
|
||||
Fixed an issue where Panorama did not show correct logs filtered with not, leq, and geq.
|
||||
|
||||
## PAN-141717
|
||||
|
||||
Fixed an issue where an administrative user using custom admin roles and without access to the **Device** tab was unable to expand the detailed views of **Monitor > Logs**.
|
||||
|
||||
## PAN-141551
|
||||
|
||||
Fixed an issue where SSH service restart management did not take effect in the SSH management server profile.
|
||||
|
||||
## PAN-141262
|
||||
|
||||
Fixed an issue where the resolution of FQDN for a policy on the web interface did not work as expected if the FQDN contained CAPITAL letters.
|
||||
|
||||
## PAN-140900
|
||||
|
||||
Fixed an issue where IP address-to-tag mapping entries had negative time-to-live (TTL) values instead of being removed after expiry.
|
||||
|
||||
## PAN-140883
|
||||
|
||||
Fixed an issue where, after rebooting the firewall, the SNMP object identifier (OID) for TCP connections per second (panVsysActiveTcpCps / .1.3.6.1.4.1.25461.2.1.2.3.9.1.6.1) returned 0 until another OID was pulled. Additionally, after a restart of a process (snmpd), if the above OID was called before other OIDs, there was an approximate 10-second delay in populating the data pulled by each OID.
|
||||
|
||||
## PAN-140628
|
||||
|
||||
Fixed an issue where a memory leak on a process (useridd) caused multiple processes to restart during device serial number checks.
|
||||
|
||||
## PAN-140382
|
||||
|
||||
Fixed an issue where the Host Evasion Threat ID signature did not trigger for the initial session even when the DNS response was received before the session expired.
|
||||
|
||||
## PAN-140227
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed a rare issue where the firewall rebooted due to a path monitoring failure on the Log Processing Card (LPC).
|
||||
|
||||
## PAN-140173
|
||||
|
||||
Fixed an issue where a large number of groups in group mapping caused a process (useridd) to stop responding.
|
||||
|
||||
## PAN-140157
|
||||
|
||||
A fix was made to address a vulnerability where the password for a configured system proxy server for a PAN-OS appliance was displayed in cleartext when using the CLI in PAN-OS ([CVE-2020-2048](https://security.paloaltonetworks.com/CVE-2020-2048)).
|
||||
|
||||
## PAN-140121
|
||||
|
||||
Fixed an issue where a process (authid) used a large amount of memory due to many incomplete authentication requests, which caused an out-of-memory (OOM) condition.
|
||||
|
||||
## PAN-140084
|
||||
|
||||
```caveat
|
||||
PA-3200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the default Dynamic IP and Port (DIPP) NAT oversubscription rate was set to 2.
|
||||
|
||||
## PAN-139991
|
||||
|
||||
Fixed an issue where the web interface and the CLI were inaccessible, which caused the following error message to display on the web interface: Timed out while getting config lock.
|
||||
|
||||
## PAN-139680
|
||||
|
||||
Fixed an issue where dynamic route updates triggered an unintentional refresh of the DHCP client interface IP address, which led to the removal and re-addition of the default route associated with the DHCP client IP address and caused traffic disruption.
|
||||
|
||||
## PAN-139233
|
||||
|
||||
Fixed an issue where HIP reports failed to display on either the web interface or the CLI.
|
||||
|
||||
## PAN-139136
|
||||
|
||||
Fixed an issue where a large number of groups in group mappings caused a process (useridd) to stop responding.
|
||||
|
||||
## PAN-138938
|
||||
|
||||
An enhancement was made to reduce the memory usage of a process (logrcvr) to avoid out-of-memory (OOM) conditions on lower-end platforms.
|
||||
|
||||
## PAN-138674
|
||||
|
||||
Fixed an issue where custom role-based admins were able to reset the rule hit counter for disabled device groups.
|
||||
|
||||
## PAN-138427
|
||||
|
||||
Fixed an issue where pushing a configuration from a Panorama management server running PAN-OS 9.0 to a firewall running PAN-OS 8.1 produced a HTTP/2 warning. To leverage this fix, update both Panorama and the firewall to PAN-OS 9.0.11 or a later PAN-OS 9.0 release.
|
||||
|
||||
## PAN-137770
|
||||
|
||||
Fixed an issue where the dataplane restarted due to a loop in DoS protection source-destination IP address classification.
|
||||
|
||||
## PAN-137716
|
||||
|
||||
Fixed an issue where, for users with admin roles, logs for only one device group were displayed due to a query string with multiple device groups.
|
||||
|
||||
## PAN-137663
|
||||
|
||||
Fixed a cosmetic issue where misleading App-ID and rule shadowing warnings populated after a commit.
|
||||
|
||||
## PAN-136791
|
||||
|
||||
Fixed an intermittent issue where the first response to a SIP INVITE message created incorrect appinfo2ip entries and caused Via header translation failure.
|
||||
|
||||
## PAN-136716
|
||||
|
||||
```caveat
|
||||
Panorama virtual appliances only
|
||||
```
|
||||
|
||||
Fixed an issue where SNMP monitoring of ifSpeed reported the interface speed as 0 for interfaces other than eth0.
|
||||
|
||||
## PAN-136650
|
||||
|
||||
Fixed an issue where a Log Collector remained in an out-of-sync state after configuring an IP address (local or public) on an additional Ethernet interface.
|
||||
|
||||
## PAN-135887
|
||||
|
||||
Fixed an issue where the inner GTP-U flows were installed using incorrect zones, which led to traffic issues when the firewall was in line for the S1-U interface.
|
||||
|
||||
## PAN-135071
|
||||
|
||||
Fixed an issue in Panorama where the template stack drop-down was missing templates when using access domain.
|
||||
|
||||
This issue is fixed only for existing template stacks.
|
||||
|
||||
## PAN-134907
|
||||
|
||||
Fixed an issue where IP tags were not evaluated in the filter evaluation criteria when Dynamic Address Groups were configured.
|
||||
|
||||
## PAN-134745
|
||||
|
||||
Fixed an issue where Panorama commits failed due to a process (useridd) exceeding the maximum number of file descriptors while a large number of firewalls were connecting to Panorama for User-ID redistribution.
|
||||
|
||||
## PAN-134226
|
||||
|
||||
Fixed an issue where **AdminStatus** for HA1 and High Speed Chassis Interconnect (HSCI) interfaces were incorrectly reported.
|
||||
|
||||
## PAN-134029
|
||||
|
||||
Fixed an intermittent issue on the firewall where H.225 VOIP signaling packets dropped.
|
||||
|
||||
## PAN-133934
|
||||
|
||||
Fixed an intermittent issue where user-to-IP address mappings were not redistributed to client firewalls.
|
||||
|
||||
## PAN-133388
|
||||
|
||||
Fixed an issue where an HA configuration went out of sync when the HA sync job was queued and processed during an ongoing content installation job on the passive firewall.
|
||||
|
||||
## PAN-133179
|
||||
|
||||
Fixed a rare issue where the show ntp CLI command showed the status as rejected even when the NTP was synced with at least one NTP server.
|
||||
|
||||
## PAN-132285
|
||||
|
||||
Fixed an intermittent issue where a Security policy with **Send ICMP Unreachable** enabled for certain drop or reset sessions caused a process (all-pktproc) to restart.
|
||||
|
||||
## PAN-132053
|
||||
|
||||
Added an enhancement to improve handling for firewall management web interface sessions that timeout so that the message Your session has expired does not display. Now, the web interface will present a timeout page that presents a button to redirect back to the login page.
|
||||
|
||||
## PAN-131750
|
||||
|
||||
Fixed an issue where a configuration push from Panorama to the firewall showed the **Commit All** status as complete even though the job was still in process.
|
||||
|
||||
## PAN-130955
|
||||
|
||||
Fixed an issue where templates on the secondary Panorama appliance were out of sync with the primary Panorama appliance due to an empty content-preview node.
|
||||
|
||||
## PAN-130357
|
||||
|
||||
Fixed a memory leak issue where virtual memory used by the SNMP process started to slowly increase when the request was sent with a request-id of 0.
|
||||
|
||||
## PAN-129376
|
||||
|
||||
```caveat
|
||||
PA-800 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue that prevented ports 9-12 from being powered down by hardware after being requested to do so.
|
||||
|
||||
## PAN-128172
|
||||
|
||||
Fixed an issue on Panorama where the show system logdb-quota CLI command took more time than expected, which caused the configuration lock to time out.
|
||||
|
||||
## PAN-128048
|
||||
|
||||
Fixed an issue where certificate-based authentication with IKEv2 IPSec tunnels failed to establish with some third-party vendors.
|
||||
|
||||
## PAN-125218
|
||||
|
||||
A fix was made to address an information exposure vulnerability in Panorama that disclosed the token for the Panorama web interface administrator's session to a managed device when the Panorama administrator performed a context switch ([CVE-2020-2022](https://security.paloaltonetworks.com/CVE-2020-2022)).
|
||||
|
||||
## PAN-124819
|
||||
|
||||
Fixed an issue where only the current day's logs were visible on Panorama.
|
||||
|
||||
## PAN-124331
|
||||
|
||||
Fixed an issue where the LDAP query took longer than expected to populate in the web interface.
|
||||
|
||||
## PAN-122672
|
||||
|
||||
Fixed an issue where the firewall returned incorrect information about the logging service status when the information was requested through the web interface.
|
||||
|
||||
## PAN-122115
|
||||
|
||||
Fixed an issue with the session browser search where using more than 32 characters caused an error.
|
||||
|
||||
## PAN-121944
|
||||
|
||||
Fixed an issue where the **Device Connectivity** status was grey on the firewall web interface even when the SSL session with the logging service was successful.
|
||||
|
||||
## PAN-121035
|
||||
|
||||
Added support for high powered module PAN-QSFP28-100GBASE-ER4.
|
||||
|
||||
## PAN-120245
|
||||
|
||||
Fixed an issue on Panorama where WildFire® cloud content download failed for content deployment to the WF-500 appliance.
|
||||
|
||||
## PAN-119982
|
||||
|
||||
Fixed an issue where template variable view failed to display some template variables when the **Device Priority** type variable was configured.
|
||||
|
||||
## PAN-119329
|
||||
|
||||
Fixed an issue where a process (devsrvr) stopped responding when the firewall received corrupted data from the PAN-DB cloud.
|
||||
|
||||
## PAN-118667
|
||||
|
||||
Fixed an issue where firewall policy configurations displayed **[object Object]** instead of the object names.
|
||||
|
||||
## PAN-115896
|
||||
|
||||
Fixed an issue where the static route path monitoring status was not viewable from the CLI or web interface and failed with the following error message: failed to execute op command.
|
||||
|
||||
## PAN-115541
|
||||
|
||||
Fixed an issue where removing a cipher from an SSL/TLS profile did not take effect if it was attached to the management interface.
|
||||
|
||||
## PAN-112449
|
||||
|
||||
Fixed an issue that caused a process (snmpd) to stop responding when sending a Simple Network Management Protocol (SNMP) GET request for LcLogUsageTable on a Panorama appliance in Management Only mode.
|
||||
|
||||
## PAN-110511
|
||||
|
||||
Fixed an issue where a passive Panorama appliance reported that device groups were out of sync despite a successful HA sync from the active Panorama appliance. This issue occurred when the address objects defined in the device group were in use under the corresponding template.
|
||||
@@ -0,0 +1,35 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.14-h3
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## PAN-176661
|
||||
|
||||
Fixed an issue in Simple Certificate Enrollment Protocol (SCEP) ([CVE-2021-3060](https://security.paloaltonetworks.com/CVE-2021-3060)).
|
||||
|
||||
## PAN-176655
|
||||
|
||||
A fix was made to address an OS command injection vulnerability in the PAN-OS CLI that enabled an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges ([CVE-2021-3061](https://security.paloaltonetworks.com/CVE-2021-3061)).
|
||||
|
||||
## PAN-158334
|
||||
|
||||
A fix was made to address an OS command injection vulnerability in the PAN-OS CLI that enabled an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges ([CVE-2021-3061](https://security.paloaltonetworks.com/CVE-2021-3061)).
|
||||
|
||||
## PAN-176653
|
||||
|
||||
A fix was made to address an OS command injection vulnerability in the PAN-OS web interface that enabled an authenticated administrator with permissions to use XML API to execute arbitrary OS commands to escalate privileges ([CVE-2021-3058](https://security.paloaltonetworks.com/CVE-2021-3058)).
|
||||
|
||||
## PAN-176618
|
||||
|
||||
A fix was made to address an OS command injection vulnerability in PAN-OS that existed when performing dynamic updates ([CVE-2021-3059](https://security.paloaltonetworks.com/CVE-2021-3059)).
|
||||
|
||||
## PAN-171203
|
||||
|
||||
Fixed an issue in a high availability (HA) configuration where, when one firewall was active and its peer was in a suspended state, the suspended firewall continued to send traffic, which triggered the detection of duplicate MAC addresses.
|
||||
|
||||
## PAN-160708
|
||||
|
||||
Fixed an issue where the dataplane restarted after configuring a **deny_all** policy.
|
||||
@@ -0,0 +1,123 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.15
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## PAN-184592
|
||||
|
||||
A fix was made to address a remote code execution vulnerability in Elasticsearch included with Panorama management servers known as Log4Shell ([CVE-2021-44228](https://security.paloaltonetworks.com/CVE-2021-44228)).
|
||||
|
||||
## PAN-183767
|
||||
|
||||
Fixed an issue where downloading Dynamic Updates files failed when connected to the static update server at us-static.updates.paloaltonetworks.com.
|
||||
|
||||
## PAN-179581
|
||||
|
||||
Fixed an issue on firewalls in high availability (HA) configurations where a process (brdagent) stopped responding on a suspended active peer, which caused the suspended firewall to continue sending traffic.
|
||||
|
||||
## PAN-174055
|
||||
|
||||
Fixed an issue where SNMP readings reported as 0 for dataplane interface packet statistics for Amazon Web Services (AWS) m5n.4xlarge instance types. This issue occurred because the physical port counters read from MAC addresses were reported as 0.
|
||||
|
||||
## PAN-173978
|
||||
|
||||
Fixed an issue where the Elasticsearch process continuously restarted if zero-length files were present.
|
||||
|
||||
## PAN-172783
|
||||
|
||||
Fixed an issue on an HA active/passive configuration where old (GPRS tunneling protocol) GTP-U tunnel sessions did not sync to the passive firewall during some upgrades, such as upgrading from a PAN-OS 8.1 release version to a 9.0 release version or upgrading from a 9.0 release version to a 9.1 release version.
|
||||
|
||||
## PAN-172490
|
||||
|
||||
Fixed an issue on firewalls in HA configuration where HA-2 links continuously flapped on HSCI interfaces after upgrading to PAN-OS 8.1.19.
|
||||
|
||||
## PAN-172243
|
||||
|
||||
Fixed an issue where NetFlow traffic triggered a packet buffer leak.
|
||||
|
||||
## PAN-171203
|
||||
|
||||
Fixed an issue in an HA configuration where, when one firewall was active and its peer was in a suspended state, the suspended firewall continued to send traffic, which triggered the detection of duplicate MAC addresses.
|
||||
|
||||
## PAN-170825
|
||||
|
||||
Fixed an issue where, when a partial **Preview Change** job failed, a process (configd) stopped responding.
|
||||
|
||||
## PAN-170595
|
||||
|
||||
Fixed an issue with Content and Threat Detection where traffic patterns created a bus error, which caused the all_pktproc process to stop responding and the dataplane to restart.
|
||||
|
||||
## PAN-166299
|
||||
|
||||
```caveat
|
||||
PA-3000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where Server Message Block (SMB) sessions failed due to resource unavailability.
|
||||
|
||||
## PAN-166180
|
||||
|
||||
Fixed an issue where SNMPV3 traps were not processed by the snmptrap receiver after a firewall reboot.
|
||||
|
||||
## PAN-161496
|
||||
|
||||
Fixed an issue when calculating the incremental checksum after a post-NAT translation where the arguments to pan_in_cksm32_diff overflowed the 32-bit integer.
|
||||
|
||||
## PAN-160708
|
||||
|
||||
Fixed an issue where the dataplane restarted after configuring a **deny_all** policy.
|
||||
|
||||
## PAN-160238
|
||||
|
||||
Fixed an issue where intermittent VXLAN packet drops occurred if the TCI was not configured for inspecting VXLAN traffic. This issue occurred when traffic was migrated from a firewall running a PAN-OS version earlier than PAN-OS 9.0 to a firewall running PAN-OS 9.0 or later.
|
||||
|
||||
## PAN-158280
|
||||
|
||||
Fixed an issue where SMB session were discarded with the following error message: ctd out of resource.
|
||||
|
||||
## PAN-157730
|
||||
|
||||
Fixed an issue where, after a firewall reboot, a commit or auto-commit operation failed with the following error message: ID population failed. This issue occurred because the Phase1 ID assignment failure did not trigger an idmgr reset.
|
||||
|
||||
## PAN-157725
|
||||
|
||||
Fixed an issue on firewalls where URL category responses were not processed by the dataplane in a timely fashion, which adversely affected web-browsing traffic.
|
||||
|
||||
## PAN-157632
|
||||
|
||||
Fixed an intermittent issue where the firewall dropped GTP-U traffic with the message TEID=0x00000000.
|
||||
|
||||
## PAN-154526
|
||||
|
||||
Fixed an issue where a process (genindex.sh) caused high memory usage on the management plane. Due to the resulting out-of-memory (OOM) condition, multiple processes stopped responding.
|
||||
|
||||
## PAN-154433
|
||||
|
||||
Fixed an issue where the firewall was unable to detect end-user IP address spoofing on the GTP-U for a user data session when using an IPv6 address.
|
||||
|
||||
## PAN-150097
|
||||
|
||||
Fixed an issue where hourly URL summary log generation failed.
|
||||
|
||||
## PAN-147256
|
||||
|
||||
```caveat
|
||||
Firewalls in HA configurations only
|
||||
```
|
||||
|
||||
Fixed an issue where connections to the SafeNet hardware security module (HSM) were lost after upgrading to a new major PAN-OS release.
|
||||
|
||||
## PAN-141454
|
||||
|
||||
Fixed an issue where the output of the CLI command show running resource-monitor ingress-backlogs displayed an incorrect total utilization value.
|
||||
|
||||
## PAN-128634
|
||||
|
||||
A debug command was added to provide more verbose output when troubleshooting packet processing on the firewall.
|
||||
|
||||
## PAN-113093
|
||||
|
||||
Fixed an intermittent issue where, when the DNS Security cloud was not reachable, DNS responses had bad UDP checksums.
|
||||
@@ -0,0 +1,15 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.16-h5
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## PAN-202450
|
||||
|
||||
Fixed an issue where the device-client-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
|
||||
|
||||
## PAN-198372
|
||||
|
||||
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
|
||||
@@ -0,0 +1,71 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.16
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## PAN-179581
|
||||
|
||||
Fixed an issue on firewalls in high availability (HA) configurations where a process (brdagent) stopped responding on a suspended active peer, which caused the suspended firewall to continue sending traffic.
|
||||
|
||||
## PAN-177551
|
||||
|
||||
A fix was made to address a vulnerability that enabled an authenticated network-based administrator to upload a specifically created configuration that disrupted system processes and was able to execute arbitrary code with root privileges when the configuration was committed ([CVE-2022-0024](https://security.paloaltonetworks.com/CVE-2022-0024)).
|
||||
|
||||
## PAN-176703
|
||||
|
||||
Fixed an issue that occurred after upgrading to a PAN-OS 9.0 or later release where commits to the firewall configuration failed with the following error message: statistics-service is invalid.
|
||||
|
||||
## PAN-175716
|
||||
|
||||
Fixed an issue where sorting address groups by name, address, or location did not work on a device group that was part of a nested device group.
|
||||
|
||||
## PAN-175211
|
||||
|
||||
Fixed a memory leak issue in the mgmtsrvr process.
|
||||
|
||||
## PAN-174998
|
||||
|
||||
```caveat
|
||||
M-200 and M-500 appliances only
|
||||
```
|
||||
|
||||
Fixed a capacity issue that was caused by high operational activity and large configurations. This fix increases the virtual memory limit on the configd process to 32GB.
|
||||
|
||||
## PAN-174709
|
||||
|
||||
Fixed an out-of-memory (OOM) condition that occurred due to multiple parallel jobs being created by the scheduled log export feature.
|
||||
|
||||
## PAN-170997
|
||||
|
||||
Fixed an issue where FQDN service routes were not installed after a system reboot.
|
||||
|
||||
## PAN-170952
|
||||
|
||||
Fixed an issue where the dataplane failed due to path monitor failure.
|
||||
|
||||
## PAN-163245
|
||||
|
||||
Fixed an issue where a commit-all or push to the firewall from Panorama failed with the following error message: client routed requesting last config in the middle of a commit/validate. Aborting current commit/validate.
|
||||
|
||||
## PAN-161940
|
||||
|
||||
Fixed an issue where the firewall did not honor the peer RX interval timeout in a Bidirectional Forwarding Detection (BFD) INIT state.
|
||||
|
||||
## PAN-161297
|
||||
|
||||
Fixed an interoperability issue with other vendors when IKEv2 used SHA2-based certificate authentication.
|
||||
|
||||
## PAN-159936
|
||||
|
||||
Fixed an issue where BGP routing stopped advertising a redistributed route when a similar new redistributed route was configured.
|
||||
|
||||
## PAN-155532
|
||||
|
||||
Fixed an issue where the mgmtsrv process restarted due to a missing protective check around access to potentially NULL pointers.
|
||||
|
||||
## PAN-149911
|
||||
|
||||
Fixed an issue where URL filtering logs for credential phishing displayed a slash character ( / ) in the URL field.
|
||||
@@ -0,0 +1,79 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.17-h4
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## PAN-237871
|
||||
|
||||
```caveat
|
||||
WF-500 appliances and PAN-DB private cloud deployments only
|
||||
```
|
||||
|
||||
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
|
||||
|
||||
## PAN-221224
|
||||
|
||||
```caveat
|
||||
and PAN-216858
|
||||
```
|
||||
|
||||
A fix was made to address customer and internal bugs.
|
||||
|
||||
## PAN-227523
|
||||
|
||||
```caveat
|
||||
and PAN-216858
|
||||
```
|
||||
|
||||
A fix was made to address customer and internal bugs.
|
||||
|
||||
## PAN-218663
|
||||
|
||||
```caveat
|
||||
and PAN-216858
|
||||
```
|
||||
|
||||
A fix was made to address customer and internal bugs.
|
||||
|
||||
## PAN-216216
|
||||
|
||||
```caveat
|
||||
and PAN-216858
|
||||
```
|
||||
|
||||
A fix was made to address customer and internal bugs.
|
||||
|
||||
## PAN-224964
|
||||
|
||||
```caveat
|
||||
and PAN-216858
|
||||
```
|
||||
|
||||
A fix was made to address customer and internal bugs.
|
||||
|
||||
## PAN-221352
|
||||
|
||||
```caveat
|
||||
and PAN-216858
|
||||
```
|
||||
|
||||
A fix was made to address customer and internal bugs.
|
||||
|
||||
## PAN-220267
|
||||
|
||||
```caveat
|
||||
and PAN-216858
|
||||
```
|
||||
|
||||
A fix was made to address customer and internal bugs.
|
||||
|
||||
## PAN-202450
|
||||
|
||||
Fixed an issue where the device-client-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
|
||||
|
||||
## PAN-198372
|
||||
|
||||
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
|
||||
@@ -0,0 +1,19 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.2-h4
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## PAN-119745
|
||||
|
||||
A security-related fix was made to address the Netflix Linux kernel TCP SACK vulnerability ([PAN-SA-2019-0013](https://securityadvisories.paloaltonetworks.com/Home/Detail/151) / CVE-2019-11477,CVE-2019-11478,CVE-2019-11479, and CVE-2019-5599).
|
||||
|
||||
## PAN-118869
|
||||
|
||||
A security-related fix was made to address an issue where the php-debug log incorrectly displayed non-sanitized data ([PAN-SA-2019-0019](https://securityadvisories.paloaltonetworks.com/Home/Detail/157) / CVE-2019-1575).
|
||||
|
||||
## PAN-107239
|
||||
|
||||
A security-related fix was made to address cleartext passwords and keys that were visible in the logs for XML API calls ([PAN-SA-2019-0019](https://securityadvisories.paloaltonetworks.com/Home/Detail/157) / CVE-2019-1575).
|
||||
@@ -0,0 +1,193 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.2
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## WF500-5023
|
||||
|
||||
Fixed an issue on WF-500 appliances where the cluster service took longer than expected to start due to a large number of queued sample data.
|
||||
|
||||
## WF500-5022
|
||||
|
||||
Fixed an issue where a non-functioning CLI command was removed from WF-500 appliances.
|
||||
|
||||
## WF500-4974
|
||||
|
||||
Fixed an issue on a WF-500 appliance where the static analysis results displayed in the PDF report but did not display in the WildFire® analysis summary of the web interface.
|
||||
|
||||
## WF500-4844
|
||||
|
||||
Fixed an issue on WildFire appliance clusters where the passive-controller responded with the incorrect Common Name (CN) in the certificate, which caused the registration to fail.
|
||||
|
||||
## WF500-4838
|
||||
|
||||
Fixed an intermittent issue on a WF-500 appliance where WildFire reports took longer than expected to generate, which caused the task to automatically timeout.
|
||||
|
||||
## WF500-4784
|
||||
|
||||
Fixed an issue on a WF-500 appliance where during a reboot, the following error message displayed: FATAL: module nbd not found.
|
||||
|
||||
## WF500-4743
|
||||
|
||||
Fixed an intermittent issue on a WF-500 appliance where the CLI command debug wildfire reset global-database fix became unresponsive.
|
||||
|
||||
## PAN-118065
|
||||
|
||||
```caveat
|
||||
M-Series Panorama™ management servers in Management Only mode
|
||||
```
|
||||
|
||||
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the show interface all command in the CLI after you commit.
|
||||
|
||||
**Workaround:**Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
|
||||
|
||||
## PAN-116919
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall dropped packets passing through IPSec tunnels if you enabled jumbo frames (**Device** > **Setup** > **Session** > **Session Settings**).
|
||||
|
||||
## PAN-116658
|
||||
|
||||
Fixed a rare issue where the firewall sent HTTP/2 DATA frames with incorrect padding byte lengths, which caused software buffer corruption and a process (all_pktproc) to stop responding.
|
||||
|
||||
## PAN-116316
|
||||
|
||||
Fixed an issue where RTP and RTCP predict sessions failed, which caused the firewall to stop processing RTSP-based video streaming.
|
||||
|
||||
## PAN-116084
|
||||
|
||||
Fixed an issue where a VM-Series firewall on Microsoft Azure deployed using MMAP dropped traffic when the firewall was experiencing heavy traffic.
|
||||
|
||||
## PAN-115592
|
||||
|
||||
Fixed an issue where the firewall rebooted due to a plugin memory leak.
|
||||
|
||||
## PAN-115591
|
||||
|
||||
Fixed an issue where the snmpd process was leaking memory when polling for global counters.
|
||||
|
||||
## PAN-114984
|
||||
|
||||
Fixed OpenSSL vulnerability CVE-2019-1559, see [PAN-SA-2019-0039](https://securityadvisories.paloaltonetworks.com/Home/Detail/202) for details.
|
||||
|
||||
## PAN-114893
|
||||
|
||||
Fixed an issue where a context switch from Panorama to a firewall did not respond as expected when a web browser was used.
|
||||
|
||||
## PAN-114804
|
||||
|
||||
Fixed an issue where a configuration change resets to "default" when you conducted a search in the Categories (**Objects** > **URL Filtering** > **Categories**) web interface.
|
||||
|
||||
## PAN-114601
|
||||
|
||||
Fixed an issue where the Allow List (**Device** > **Setup** > **Authentication Setting** > **<authentication profile - name>** > **Authentication**) did not update after you added new users to a group in the Active Directory.
|
||||
|
||||
## PAN-114255
|
||||
|
||||
Fixed an issue where Bidirectional Forwarding Detection (BFD) went down temporarily during a commit or EDL refresh if you configured a large value for the BFD Hold Time.
|
||||
|
||||
## PAN-114003
|
||||
|
||||
Fixed an issue on a Panorama management server running PAN-OS 9.0 where a context switch to firewalls did not respond.
|
||||
|
||||
## PAN-113829
|
||||
|
||||
Fixed an issue where, after you upgraded the firewall to PAN-OS® 9.0, a firewall configured from "none" to "allow" in the custom URL category reverted to "none" after a commit.
|
||||
|
||||
## PAN-113692
|
||||
|
||||
Fixed an intermittent issue on a firewall in a high availability (HA) active/passive configuration where five minutes after a failover test IP routes disappeared, which caused traffic interruptions.
|
||||
|
||||
## PAN-113608
|
||||
|
||||
Fixed an issue on a firewall with packet capture (pcap) enabled where the log receiver stopped responding when larger than expected packets were received.
|
||||
|
||||
## PAN-113414
|
||||
|
||||
Fixed an issue where the User-ID™ (useridd) process stopped responding.
|
||||
|
||||
## PAN-112815
|
||||
|
||||
Fixed an issue on a firewall in an HA active/passive configuration where a process (useridd) did not respond to the alternate user attribute (**Device** > **User Identification** > **Group Mapping Settings** > **<group mapping-name>** > **User and Group Attributes**) on the passive firewall during a restart.
|
||||
|
||||
## PAN-112814
|
||||
|
||||
Fixed an issue where H.323-based calls lost audio because the predicted H.245 session was not converted to Active status, which caused the firewall to drop the H.245 traffic.
|
||||
|
||||
## PAN-112729
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where Decrypted Sessions Info (**Panorama** > **Managed Devices** > **Health** > **All Devices** > **<device-name>** > **Sessions**) did not display as expected for VM-Series firewalls.
|
||||
|
||||
## PAN-112699
|
||||
|
||||
```caveat
|
||||
VM-Series firewall on AWS running on a C5 or M5 instance only
|
||||
```
|
||||
|
||||
Fixed an issue where you were unable use the mgmt-interface-swap command to [swap the interfaces](https://docs.paloaltonetworks.com/vm-series/9-0/vm-series-deployment/set-up-the-vm-series-firewall-on-aws/about-the-vm-series-firewall-on-aws/management-interface-mapping-for-use-with-amazon-elb.html) for deploying a VM-Series firewall behind a web load balancer (such as AWS ALB or Classic ELB).
|
||||
|
||||
## PAN-112626
|
||||
|
||||
Fixed an issue where a new DNS Security subscription was not available on your VM-Series firewall after you upgraded to a PAN-OS 9.0® release with a PAYG Bundle 2 license.
|
||||
|
||||
## PAN-112445
|
||||
|
||||
Fixed an issue on a firewall in an HA active/passive configuration where a race condition caused the firewall to stop responding after an HA1 link flap.
|
||||
|
||||
## PAN-112340
|
||||
|
||||
Fixed an issue with performance, including high CPU usage, that occurred when you enabled URL Filtering without enabling Threat Prevention in an environment that processes a large number (thousands) of URL look-ups per second per dataplane.
|
||||
|
||||
## PAN-112194
|
||||
|
||||
Fixed an issue where packet buffers did not release GlobalProtect™ clientless VPN packets, which caused the firewall to stop responding.
|
||||
|
||||
## PAN-111679
|
||||
|
||||
Fixed an issue where URL filtering profiles were being incorrectly applied to security policies during a commit.
|
||||
|
||||
## PAN-111553
|
||||
|
||||
Fixed an issue on the Panorama management server where the **Include Device and Network Templates** setting (**Commit** > **Push to Devices** > **Edit Selections** or **Commit** > **Commit and Push** > **Edit Selections**) was disabled by default and caused your push attempts to fail. With this fix, your push will **Include Device and Network Templates** by default.
|
||||
|
||||
## PAN-111540
|
||||
|
||||
Fixed an issue on PA-5200 Series firewalls where the dataplane stopped responding when the session table was full.
|
||||
|
||||
## PAN-111251
|
||||
|
||||
Fixed an issue where administrators were unable to use the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule (they were able to execute the command but the firewall did not implement the change).
|
||||
|
||||
## PAN-110390
|
||||
|
||||
Fixed an issue on PA-7000 Series firewalls where invalid filters caused the device management server to stop responding when you generated a database (DB) report from a remote firewall.
|
||||
|
||||
## PAN-110273
|
||||
|
||||
Fixed an issue where you were unable to establish OSPF neighborship when an OSPF routing protocol was configured with MD5 authentication and one of the firewalls was restarted.
|
||||
|
||||
## PAN-109672
|
||||
|
||||
Fixed an issue on a VM-Series firewall in an HA active/passive configuration where the passive firewall received buffered packets while in an idle state when the data plane development kit (DPDK) is enabled.
|
||||
|
||||
## PAN-109344
|
||||
|
||||
Fixed an issue where service objects did not import into Panorama when you configured them identically but with different names.
|
||||
|
||||
## PAN-108374
|
||||
|
||||
Fixed an issue on GlobalProtect where you were unable to authenticate when the domain name included the ampersand ( "&" ) character.
|
||||
|
||||
## PAN-106518
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where predefined DHCP options did not accept template variables when you configured a DHCP server for a template.
|
||||
|
||||
## PAN-101341
|
||||
|
||||
Fixed an issue where administrators configured with Device Group and Template Admin type were unable to perform a global search and returned the following message: Unauthorized request.
|
||||
@@ -0,0 +1,23 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.3-h3
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## PAN-123700
|
||||
|
||||
A security-related fix was made to prevent a memory corruption vulnerability in PAN-OS® software ([PAN-SA-2019-0023](https://securityadvisories.paloaltonetworks.com/Home/Detail/161) / CVE-2019-1582).
|
||||
|
||||
## PAN-123603
|
||||
|
||||
A security-related fix was made to prevent a memory corruption vulnerability in PAN-OS software ([PAN-SA-2019-0021](https://securityadvisories.paloaltonetworks.com/Home/Detail/159) / CVE-2019-1580).
|
||||
|
||||
## PAN-123564
|
||||
|
||||
Fixed CVE-2019-1581, see [PAN-SA-2019-0022](https://securityadvisories.paloaltonetworks.com/Home/Detail/160) for details.
|
||||
|
||||
## PAN-121814
|
||||
|
||||
Fixed an issue where the threat log incorrectly displayed informational severity-level threats with high severity level.
|
||||
@@ -0,0 +1,521 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.3
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## WF500-4995
|
||||
|
||||
Fixed an issue on Panorama™ M-Series and WF-500 appliances where administrators were unable to run the debugsoftware disk-usage aggressive-cleaning enable CLI command and resulted in the following error message: Server error:Failed to execute op command.
|
||||
|
||||
## PAN-118949
|
||||
|
||||
Fixed an issue where after you changed the filter configuration in the user.src notin 'cns\proxy full profile, the firewall displayed the following error message: Unknown user group cns\Proxy Full.
|
||||
|
||||
## PAN-118640
|
||||
|
||||
Fixed an issue where the GTP-U session did not match the correct policy, which caused the IMSI and IMEI not to display in the inner session traffic and threat logs.
|
||||
|
||||
## PAN-118525
|
||||
|
||||
```caveat
|
||||
PA-5250, PA-5260, PA-5280, and PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the QSFP28 port did not come up with the TR-FC13L-N00 version of the PAN-QSFP28-100GBASE-LR4 optical transceiver on firewalls running a PAN-OS 9.0 release.
|
||||
|
||||
## PAN-118008
|
||||
|
||||
```caveat
|
||||
PA-3000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an intermittent issue where a low memory condition prevented decoders from loading, which led to traffic inspection issues related to the impacted decoder(s).
|
||||
|
||||
## PAN-117424
|
||||
|
||||
[Cortex Data Lake without Panorama](https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-new-features/management-features/cortex-data-lake-without-panorama.html)—where we removed Panorama as a requirement to send logs to Cortex Data Lake—was introduced in PAN-OS® 9.0.2, and was not initially supported for PA-220 and PA-800 Series firewalls. This issue details a change we've made in PAN-OS 9.0.3 to support this feature across all firewall platforms. [Here’s](https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-new-features/management-features/cortex-data-lake-without-panorama.html) how you can get started with Cortex Data Lake now.
|
||||
|
||||
## PAN-117359
|
||||
|
||||
```caveat
|
||||
Firewalls with an AutoFocus license only
|
||||
```
|
||||
|
||||
Fixed an issue where AutoFocus™ threat intelligence did not display when hovering over source and destination addresses in the logs when you configure a service route or proxy.
|
||||
|
||||
## PAN-117249
|
||||
|
||||
Fixed an issue where end users who don't have REST API authentication roles were able to list and edit configuration rules.
|
||||
|
||||
## PAN-117149
|
||||
|
||||
Fixed an issue on firewalls configured with authentication policies where sessions matching an authentication policy did not generate traffic logs as defined in the security policy when sessions were redirected or denied.
|
||||
|
||||
## PAN-116969
|
||||
|
||||
Fixed an issue where authentication failed when you configured a User Principal Name (UPN) and included a group in the profile.
|
||||
|
||||
## PAN-116848
|
||||
|
||||
Fixed an issue where multiple device group administrators simultaneously enabled configuration locks caused a race condition.
|
||||
|
||||
## PAN-116828
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where the management server and a process (configd) used higher than expected CPU and memory.
|
||||
|
||||
## PAN-116069
|
||||
|
||||
```caveat
|
||||
PA-200 firewalls only
|
||||
```
|
||||
|
||||
Fixed a rare out-of-memory (OOM) condition.
|
||||
|
||||
## PAN-116579
|
||||
|
||||
Fixed an issue where the firewall sent truncated URLs to the Captive Portal Redirect message when HTTPS traffic sent through a proxy server was subjected to decryption.
|
||||
|
||||
## PAN-116188
|
||||
|
||||
Fixed an issue where communication between tunnel interfaces did not respond when you configured a generic routing encapsulation (GRE) tunnel.
|
||||
|
||||
## PAN-116022
|
||||
|
||||
Fixed an issue where the NSX Manager passed a blank string to Panorama, which added a null entry into the configuration and caused commits to fail.
|
||||
|
||||
## PAN-115930
|
||||
|
||||
Fixed an intermittent issue where after a configuration change, a commit caused the dataplane to stop responding.
|
||||
|
||||
## PAN-115526
|
||||
|
||||
Fixed an issue where a dataplane process (all_pktproc) stopped responding due to a packet buffer protection feature.
|
||||
|
||||
## PAN-115494
|
||||
|
||||
Fixed an issue where the /opt/pancfg/ partition became full due to a configuration preview operation not responding.
|
||||
|
||||
## PAN-115415
|
||||
|
||||
Fixed an issue where a session created from a predict session went into DISCARD state.
|
||||
|
||||
## PAN-115379
|
||||
|
||||
Fixed an issue where you were unable to create a custom log forwarding profile when you configured a filter with the "in" and "not in" configurations (**Objects** > **Log Forwarding** > **Add** > **Add** > **Filter** > **Filter Builder**) and resulted in the following error message: Invalid filter policy-logging-cf-ent -> match-list -> ITS_url_logs -> filteris invalid.
|
||||
|
||||
## PAN-115339
|
||||
|
||||
Fixed a rare issue where a commit caused the firewall to stop responding when you enabled flow debug and configured a NAT policy.
|
||||
|
||||
## PAN-115035
|
||||
|
||||
Fixed a rare issue where **Traffic** logs, **Threat** logs and **URL filtering** logs stopped generating.
|
||||
|
||||
## PAN-115012
|
||||
|
||||
Fixed an issue where a process (appweb) stopped responding, which caused the web interface to stop responding.
|
||||
|
||||
## PAN-114867
|
||||
|
||||
Fixed an issue where GlobalProtect™ gateway client configuration generation failed when a matching rule existed.
|
||||
|
||||
## PAN-114743
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where, after you upgraded the firewall to PAN-OS 8.1, commits failed when Panorama was configured to manage shared gateway objects for managed firewalls.
|
||||
|
||||
## PAN-114695
|
||||
|
||||
Fixed an issue where a daemon (authd) stopped responding when you configured a GlobalProtect portal and gateway with Security Assertion Markup Language (SAML) authentication.
|
||||
|
||||
## PAN-114642
|
||||
|
||||
Fixed an issue where firewall logs incorrectly included the end-user IP address in GTP message logs when you configured PAA IE with IPv4 and IPv6 dual stack in the Create Session Response message.
|
||||
|
||||
## PAN-114607
|
||||
|
||||
Fixed an issue where all the log collectors did not get queued when you configured more than 32 collector groups.
|
||||
|
||||
## PAN-114593
|
||||
|
||||
Fixed an issue where the setsystem setting layer4-checksum disable CLI command did not disable the Layer 4 checksum check as expected.
|
||||
|
||||
## PAN-114577
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where you were unable to authenticate when the authentication profile contained a server profile that used the FQDN of the server.
|
||||
|
||||
## PAN-114437
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where, after you upgraded the firewall from PAN-OS 8.0.8 to PAN-OS 8.1.4, commits took longer than expected when you configured the Device Group with large group hierarchies.
|
||||
|
||||
## PAN-114435
|
||||
|
||||
Fixed an issue where multiple dataplanes stopped responding and caused traffic outages after you enabled IPSec tunnels.
|
||||
|
||||
## PAN-114434
|
||||
|
||||
Fixed an issue where the firewall created incorrect predict sessions, which caused flow sessions to fail for applications.
|
||||
|
||||
## PAN-114403
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where serial numbers for deployed firewalls did not display in the web interface with the exception of GlobalProtect cloud service firewalls.
|
||||
|
||||
## PAN-114395
|
||||
|
||||
Fixed an issue on a VM-Series firewall where a process (all_task) stopped responding, which caused the firewall to reboot.
|
||||
|
||||
## PAN-114275
|
||||
|
||||
Fixed an issue where the firewall dropped GTPv1 DELETE PDP response packets that had a termination endpoint ID (TEID) value of 0.
|
||||
|
||||
## PAN-114181
|
||||
|
||||
Fixed an issue where the firewall incorrectly triggered Reverse Path Forwarding (RPF), which caused packet leaks.
|
||||
|
||||
## PAN-113795
|
||||
|
||||
Fixed an issue on a firewall configured with GlobalProtect Clientless VPN where a process (all_pkts) stopped responding, which caused the dataplane to restart.
|
||||
|
||||
## PAN-113775
|
||||
|
||||
Fixed an issue where the firewall dropped UpdatePDPContext reponse packets and displayed the following GTP log event: 122113.
|
||||
|
||||
## PAN-113631
|
||||
|
||||
A security-related fix was made to address a use-after-free (UAF) vulnerability in the Linux kernel ([PAN-SA-2019-0017](https://securityadvisories.paloaltonetworks.com/Home/Detail/155) / CVE-2019-8912)
|
||||
|
||||
## PAN-113614
|
||||
|
||||
Fixed an issue with a memory leak on Panorama appliances associated with commits that eventually caused an unexpected restart of the configuration (configd) process.
|
||||
|
||||
## PAN-113340
|
||||
|
||||
```caveat
|
||||
PA-200 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the management plane (MP) memory was lower than expected, which caused the MP to restart.
|
||||
|
||||
## PAN-113189
|
||||
|
||||
A security-related fix was made to correct log file string-conversion errors that caused parsing issues, which caused the User-ID™ (useridd) process to stop running.
|
||||
|
||||
## PAN-113117
|
||||
|
||||
Fixed an issue on Panorama VM-Series firewalls where you were logged out of the web interface and had to log back in to push a device group and template configuration from a newly launched bootstrapped firewall.
|
||||
|
||||
## PAN-113046
|
||||
|
||||
```caveat
|
||||
PA-5200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where a process (brdagent) stopped responding, which caused the management plane to stop responding.
|
||||
|
||||
## PAN-112674
|
||||
|
||||
Fixed an issue where an escape ( “\” ) character was added to HTTP log s when a log contained a comma.
|
||||
|
||||
## PAN-112577
|
||||
|
||||
Fixed an issue on a VM-Series firewall in an HA active/passive configuration where the HA1 port flapped and caused a split-brain condition.
|
||||
|
||||
## PAN-112446
|
||||
|
||||
Fixed an issue where a predefined report (blocked credential post) generated reports using the incorrect query builder (flags has credential-builder), which caused the report to incorrectly display logs for alerts.
|
||||
|
||||
## PAN-112293
|
||||
|
||||
Fixed an issue where the connection between the firewall and Log Collector flapped.
|
||||
|
||||
## PAN-112167
|
||||
|
||||
Fixed an issue where IPv4 BGP routes were missing from the routing table and FIB after a failover event.
|
||||
|
||||
## PAN-112106
|
||||
|
||||
Fixed an issue where the firewall was unable to add IPv6 loopback IP address ::1 to the external dynamic list and displayed the following error message: Invalid ips: ::1.
|
||||
|
||||
## PAN-111976
|
||||
|
||||
Fixed an issue where you were unable to generate user activity reports when the username included a colon ( : ), ampersand ( & ), single parenthesis ( ' ) character.
|
||||
|
||||
## PAN-111872
|
||||
|
||||
A security-related fix was made to address a command injection vulnerability ([PAN-SA-2019-0018](https://securityadvisories.paloaltonetworks.com/Home/Detail/156) / CVE-2019-1576).
|
||||
|
||||
## PAN-111708
|
||||
|
||||
```caveat
|
||||
PA-3200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed a rare software issue that caused the dataplane to restart unexpectedly. To leverage this fix, you must run the debug dataplane set pow no-desched yes CLI command.
|
||||
|
||||
## PAN-111380
|
||||
|
||||
```caveat
|
||||
PA-5200, PA-3200, and PA-7000 Series firewalls with 100Gbps cards only
|
||||
```
|
||||
|
||||
Fixed an issue where the show qos interface ae1 throughput 0 CLI command incorrectly displayed the active data stream only and QoS was not working as expected on the first subinterface.
|
||||
|
||||
## PAN-111286
|
||||
|
||||
Fixed an issue where you were unable to generate a custom report (**Monitor** > **Manage Custom Report** > **<device-name>** > **Report Setting**).
|
||||
|
||||
## PAN-110996
|
||||
|
||||
Fixed an issue where the dataplane stopped responding due to an incorrectly calculated offset when you configured **Exclude video traffic from the tunnel** (**Network** > **GlobalProtect** > **Gateways** > **<gateway-name>** > **Agent** > **Video Traffic**).
|
||||
|
||||
## PAN-110962
|
||||
|
||||
Fixed an issue where a process (all_pktproc) stopped responding when SSH decryption was enabled, which caused the dataplane to restart.
|
||||
|
||||
## PAN-110883
|
||||
|
||||
Fixed an issue on a VM-Series firewall where all jobs did not execute and returned the following error message: Error- time out sending/receiving message.
|
||||
|
||||
## PAN-110873
|
||||
|
||||
Fixed an issue where member interfaces of the aggregate interface did not display on web interface (**Panorama** > **Managed Devices** > **Health** > **All Devices** > **<device-name>** > **Interfaces**).
|
||||
|
||||
## PAN-110758
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where you were unable to configure the firewall to disable the portal log in page.
|
||||
|
||||
## PAN-110638
|
||||
|
||||
Fixed an issue where you were unable to establish a GlobalProtect connection on IPv6 and displayed the following error message: Packet too big due to the firewall MTU value set lower than normal on the neighboring firewall.
|
||||
|
||||
## PAN-110548
|
||||
|
||||
Fixed an intermittent issue where heartbeats failed on the management plane (MP), which caused the dataplane to stop responding and displayed the following error message: Dataplaneis down: controlplane exit failure.
|
||||
|
||||
## PAN-110526
|
||||
|
||||
Fixed an issue where Captive Portal authentication required two log-in attempts when the authentication sequence was configured as an authentication profile.
|
||||
|
||||
## PAN-110293
|
||||
|
||||
Fixed an issue where GTP-U traffic dropped when the GTP tunnel endpoint ID (TEID) was not updated correctly during a GTP-C update.
|
||||
|
||||
## PAN-109966
|
||||
|
||||
Fixed an issue where the content update threshold downloaded and installed an older content version after you manually installed a newer content version.
|
||||
|
||||
## PAN-109954
|
||||
|
||||
Fixed an issue where a commit failed with an error message: cluster is missing 'encryption' when HA Traffic Encryption (**Panorama** > **Managed WildFire Clusters** > **<appliance-name>** > **Communication**) was not configured and after upgrading from PAN-OS 8.0.12 to PAN-OS 8.1.4.
|
||||
|
||||
## PAN-109944
|
||||
|
||||
Fixed an intermittent issue where a process (configd) restarted due to a race condition when generating custom reports.
|
||||
|
||||
## PAN-109663
|
||||
|
||||
Fixed an intermittent issue where the firewall dropped packets when the policy rule was set to allow but denied the packets during a commit or high availability (HA) sync.
|
||||
|
||||
## PAN-109837
|
||||
|
||||
Fixed an issue where a race condition occurred when a configuration push and NetFlow update occurred simultaneously, which caused the dataplane to restart.
|
||||
|
||||
## PAN-109575
|
||||
|
||||
Fixed an issue where you were unable to configure more than one device certificate (**Device** > **Certificate Management** > **Certificates** > **<device certificate-name>**) with **Trusted Root CA**.
|
||||
|
||||
## PAN-109336
|
||||
|
||||
```caveat
|
||||
PA-500 and PA-800 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where commits failed after you imported a device state from Panorama the template configuration referenced Bidirectional Forwarding Detection (BFD).
|
||||
|
||||
## PAN-109186
|
||||
|
||||
Fixed an issue where the dataplane stopped responding and caused a failover event.
|
||||
|
||||
## PAN-109101
|
||||
|
||||
Fixed an issue where you were unable to override IKE Gateway configurations (**Network** > **IKE Gateways** > **<template-name>**) in the template stack. However, with this fix, you still cannot override template stacks when you configure any value with **none**. Additionally, to override the Local Identification, select **Authentication** in the pop-up dialogue.
|
||||
|
||||
## PAN-109024
|
||||
|
||||
Fixed an issue where, after you upgrade the firewall from PAN-OS 8.0 to PAN-OS 8.1, firewalls configured with the User-ID agent and group mapping incorrectly mapped users to groups.
|
||||
|
||||
## PAN-108990
|
||||
|
||||
Fixed an intermittent issue on a firewall where configuring **Force Template Values** (**Network** > **Interfaces** > **Commit** > **Push to Devices** > **Templates**) deleted the zone assigned to an interface.
|
||||
|
||||
## PAN-108878
|
||||
|
||||
Fixed an issue where host traffic ICMP packets larger than 9,180 bytes dropped when you configured a jumbo frame with a maximum MTU value of 9,216 bytes and with the DF option enabled.
|
||||
|
||||
## PAN-108846
|
||||
|
||||
Fixed an issue where a higher than expected rate of tunnel resolution packets occurred due to an internal loop, which caused a spike in dataplane CPU usage for firewalls that support distributed tunnel ownership.
|
||||
|
||||
## PAN-108785
|
||||
|
||||
Fixed an intermittent issue on a firewall in an HA active/passive configuration where a ping test stopped responding on Ethernet 1/1, 1/2, and 1/4 due to input errors on the corresponding switch port after a HA failover.
|
||||
|
||||
## PAN-108715
|
||||
|
||||
Fixed an issue where the firewall did not update the dataplane DNS cache after the management plane (MP) DNS entries expired, which caused evasion signatures to erroneously trigger a Suspicious TLS/HTTP(S)Evasion Found event.
|
||||
|
||||
## PAN-108164
|
||||
|
||||
Fixed an issue where a process (tund) caused the dataplane to restart during a commit.
|
||||
|
||||
## PAN-107989
|
||||
|
||||
Fixed an issue where the Strict IP Address Check incorrectly triggered when you enabled ECMP (**Network** > **Virtual Routers** > **Add** > **Router settings** > **ECMP**).
|
||||
|
||||
## PAN-107662
|
||||
|
||||
Fixed an issue on a firewall in an HA active/active configuration where client-bound DHCPv6 packets dropped when you configured the firewall as a DHCPv6 relay agent.
|
||||
|
||||
## PAN-107370
|
||||
|
||||
Fixed an issue where IPv6 traffic throughput reduced more than expected after you updated a static ND entry (**Network** > **Interfaces** > **<interface-name>** > **Advanced** > **ND Entries**) by moving the interface to a different virtual router.
|
||||
|
||||
## PAN-107126
|
||||
|
||||
Fixed an issue where an SSL inbound session cache corruption caused a process (all_pktproc) to stop responding.
|
||||
|
||||
## PAN-106861
|
||||
|
||||
Fixed an issue where stale route entries remained in the FIB after the routes were removed from the routing table when you used a redistribution rule without a profile.
|
||||
|
||||
## PAN-106857
|
||||
|
||||
Fixed an issue where the dataplane restarted due to an internal path monitoring failure Caused by large SSL decrypted file transfer sessions.
|
||||
|
||||
## PAN-106543
|
||||
|
||||
Fixed an issue on a firewall in an HA active/active configuration where the show vpn ipsec-sa CLI command incorrectly returned an error message: Server error: An error occurred. See dagger.log for information when you ran the command on the active secondary firewall.
|
||||
|
||||
## PAN-106344
|
||||
|
||||
Fixed an issue where the log collector within a collector group retained varying numbers of detailed firewall logs when you enabled log redundancy.
|
||||
|
||||
## PAN-106274
|
||||
|
||||
Fixed an issue on a firewall where a Layer 2 interface that contained a VLAN sub-interface in conjunction with policy based forwarding (PBF) caused the firewall to forward the return traffic to the incorrect web interface.
|
||||
|
||||
## PAN-106259
|
||||
|
||||
Fixed an issue on a firewall in an HA active/passive configuration where the passive firewall reported a higher number of GlobalProtect user accounts than the active firewall.
|
||||
|
||||
## PAN-105925
|
||||
|
||||
Fixed an issue where the GlobalProtect Gateway web interface did not display the list of previous users.
|
||||
|
||||
## PAN-105412
|
||||
|
||||
Fixed an issue where forward error correction (FEC) was disabled by default for AOC modules, which caused QSFP ports to flap or remain in the DOWN state. With this fix, FEC is enabled by default for AOC modules.
|
||||
|
||||
## PAN-105397
|
||||
|
||||
Fixed an issue where a firewall incorrectly processed path monitoring, which originated from a NAT firewall on the same network segment.
|
||||
|
||||
## PAN-105091
|
||||
|
||||
Fixed an issue on a firewall where stateful inspection failed, which caused the firewall to drop GTPv2-C Modify Bearer Request packets.
|
||||
|
||||
## PAN-104568
|
||||
|
||||
Fixed an issue where the firewall did not send emails when you configured the email gateway with an FQDN.
|
||||
|
||||
## PAN-104274
|
||||
|
||||
Addressed an issue where in a slow network environment the firewall displayed an error message: error online 1 at column 1: document is empty when you used an API call to fetch a license even when the auth code was successfully applied. Extremely slow networks may still see this issue.
|
||||
|
||||
## PAN-103285
|
||||
|
||||
Fixed an issue where an API call (show system disk details), responded with the following error message: An error occurred. See dagger.log for information.
|
||||
|
||||
## PAN-103225
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where the Task Manager did not display progress after you pushed a configuration to a firewall.
|
||||
|
||||
## PAN-102979
|
||||
|
||||
Fixed an issue where Dynamic Updates did not display expired threat prevention licenses when you tried to install an application from Panorama.
|
||||
|
||||
## PAN-102745
|
||||
|
||||
Fixed an intermittent issue on a firewall where a commit and FQDN refresh took longer than expected.
|
||||
|
||||
## PAN-101970
|
||||
|
||||
Fixed an issue where the decode filter was unable to detect the end characters of a file name, which caused the firewall to bypass the file blocking profile.
|
||||
|
||||
## PAN-101764
|
||||
|
||||
Fixed an issue where a process (slmgr) stopped responding during an auto-commit.
|
||||
|
||||
## PAN-101379
|
||||
|
||||
Fixed an issue where an invalid Captive Portal authentication policy was successfully pushed to managed firewalls, which caused auto-commits to fail.
|
||||
|
||||
## PAN-101052
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where Panorama unnecessarily checked and updated licenses for VM-Series firewalls on AWS after every commit, which resulted in new log entries. With this fix, Panorama no longer checks licenses after every commit.
|
||||
|
||||
## PAN-100773
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the Quad Small Form-factor Pluggable (QSFP) port on a 20GQ NPC card took longer than expected to respond.
|
||||
|
||||
## PAN-100742
|
||||
|
||||
Fixed an issue Panorama M-Series and virtual appliances where scheduled reports generated more than one DNS lookups, which caused inconsistent name resolutions for DNS deployments.
|
||||
|
||||
## PAN-100693
|
||||
|
||||
Fixed an issue where you were unable to process Address Group match criteria when the match name included the double quotation ( " ) character.
|
||||
|
||||
## PAN-99483
|
||||
|
||||
```caveat
|
||||
PA-5250, PA-5260, and PA-5280
|
||||
```
|
||||
|
||||
Fixed an issue where, when you deployed the firewall in a network that uses Dynamic IP and Port (DIPP) NAT translation with PPTP, client systems were limited to using a translated IP address-and-port pair for only one connection.
|
||||
|
||||
See [Limitations](/content/techdocs/en_US/pan-os/9-0/pan-os-release-notes/pan-os-9-0-release-information/limitations.html#id1787F0E08SZ) for PA-7000 Series firewalls that do not use second-generation PA-7050-SMC-B or PA-7080-SMC-B Switch Management Cards.
|
||||
|
||||
## PAN-99354
|
||||
|
||||
Fixed an issue where the firewall incorrectly denied URL access when the URL filtering profile was configured to alert.
|
||||
|
||||
## PAN-99134
|
||||
|
||||
Fixed an issue where temporary files generated during preview changes did not get cleared, which caused disk space issues.
|
||||
|
||||
## PAN-98746
|
||||
|
||||
Fixed an issue where GlobalProtect clientless VPN did not get redirected to the application URL when you used Internet Explorer as a web browser.
|
||||
|
||||
## PAN-97288
|
||||
|
||||
Fixed an issue on GlobalProtect Clientless VPN where the URL gets truncated when you exclude the domain from the Rewrite Exclude Domain List (**Network** > **GlobalProtect** > **Portals** > **<portal-name>** > **Clientless VPN** > **Advanced Settings**).
|
||||
|
||||
## PAN-92872
|
||||
|
||||
Fixed an intermittent issue where the firewall sent packets incorrectly to an outgoing interface.
|
||||
|
||||
## PAN-89820
|
||||
|
||||
Fixed an intermittent issue where the Data Filtering (**Monitor** > **Data Filtering**) and Threat Log (**Monitor** > **Threat**) did not display file names when you transferred multiple files into a single session.
|
||||
|
||||
## PAN-81778
|
||||
|
||||
Fixed an issue where scheduled reports did not generate as expected due to a race condition.
|
||||
@@ -0,0 +1,555 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.5
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## WF500-5137
|
||||
|
||||
Fixed an issue where the show wildfire global last-device-registration all CLI command incorrectly returned an error message: Failed, even when you registered the firewall correctly.
|
||||
|
||||
## PAN-128561
|
||||
|
||||
Fixed an issue where a process (all_pktproc) stopped responding after you upgraded the firewall to PAN-OS® 9.0.4.
|
||||
|
||||
## PAN-128324
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where internal path monitoring failures occurred due to either a buffer leak or buffer corruption.
|
||||
|
||||
## PAN-127932
|
||||
|
||||
Fixed an issue where the REST API reference did not display the web browser documentation, which resulted in an error when running a PAN-OS 9.0.4 release.
|
||||
|
||||
## PAN-127807
|
||||
|
||||
Fixed an issue on Panorama™ M-Series and virtual appliances where a process (configd) stopped responding when you performed a commit to a large number of firewalls.
|
||||
|
||||
## PAN-127189
|
||||
|
||||
Fixed an issue where images displayed through the Clientless VPN were corrupted.
|
||||
|
||||
## PAN-126921
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where internal path monitoring failed when the firewall processed corrupt packets.
|
||||
|
||||
## PAN-126697
|
||||
|
||||
Fixed an HTTPD issue with PHP where it leaked memory.
|
||||
|
||||
## PAN-126547
|
||||
|
||||
Fixed an issue where a process (configd) stopped responding when an XML API call with type=config&action=get triggered during a commit.
|
||||
|
||||
## PAN-126534
|
||||
|
||||
```caveat
|
||||
PAN-OS 8.1.10 and later releases only
|
||||
```
|
||||
|
||||
Fixed an issue where the data from Security policies did not export as expected.
|
||||
|
||||
## PAN-126354
|
||||
|
||||
Fixed an issue where log in and commits took longer than expected when you used XML API calls to create new address objects.
|
||||
|
||||
## PAN-125933
|
||||
|
||||
Fixed an issue where the receiving firewall deleted the host information profile (HIP) report due to the report containing the same IPv4 address in the IP and IP2 fields and caused a process (useridd) to stop responding.
|
||||
|
||||
## PAN-125833
|
||||
|
||||
Fixed an issue on a firewall in a high availability (HA) active/passive configuration where a daemon (routed) did not receive the updated interface status after an HA failover, which caused routes to remain in the routing and FIB tables.
|
||||
|
||||
## PAN-125775
|
||||
|
||||
Fixed an issue where Panorama management servers deployed using the C5 or M5 instance types on Amazon Web Services (AWS) caused the Panorama instance to stop responding in regions that supported these instance types.
|
||||
|
||||
## PAN-125517
|
||||
|
||||
An enhancement was made to improve firewall performance for stream control transmission protocol (SCTP) flows. To enable this enhancement, run the set sctp fast-sack yes CLI command.
|
||||
|
||||
## PAN-125515
|
||||
|
||||
Fixed an issue on VM-Series firewalls where the firewall dropped all traffic traversing from the dataplane to the management plane.
|
||||
|
||||
## PAN-125478
|
||||
|
||||
Fixed an issue on a firewall in an HA active/passive configuration where the route to the passive firewall dropped during a failover.
|
||||
|
||||
## PAN-125452
|
||||
|
||||
Fixed an issue where the firewall did not list registered addresses from the Dynamic Address Group when the same IP-tag information was received from two sources, which caused the traffic flow to stop responding as expected.
|
||||
|
||||
## PAN-125346
|
||||
|
||||
An enhancement was made to enable you to configure IPv6 in the web interface and through a CLI command when you added IPv6 virtual addresses to a firewall in an HA active/active configuration.
|
||||
|
||||
## PAN-125121
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where custom images did not function as expected for PAN-OS 9.0.
|
||||
|
||||
## PAN-125069
|
||||
|
||||
An enhancement was made to enable you to delete the GTP-C tunnel with all GTP-U tunnel sessions after the firewall received a Delete Bearer Response message where default bearer ID=5. To enable this enhancement, run the set gtp ebi5-del-gtpc [yes/no] CLI command.
|
||||
|
||||
## PAN-124996
|
||||
|
||||
Fixed an issue where a GlobalProtect™ daemon (rasmgr) stopped responding when you connected with an overlapping IPv6 address, which caused subsequent GlobalProtect connections to fail.
|
||||
|
||||
## PAN-124890
|
||||
|
||||
Fixed a configuration lock issue where you were unable to log in after you upgraded from PAN-OS 8.1.6 to PAN-OS 8.1.9.
|
||||
|
||||
## PAN-124630
|
||||
|
||||
Fixed an issue where new logs were not ingested due to a buffer exhaustion condition caused by invalid messages incorrectly handled by elastic search.
|
||||
|
||||
## PAN-124481
|
||||
|
||||
Fixed an issue where the dataplane stopped responding when SMTP sessions were used.
|
||||
|
||||
## PAN-124299
|
||||
|
||||
Fixed an issue on VM-Series firewalls in an HA active/passive configuration where the active firewall leaked packet buffers when links were disconnected from the hypervisor.
|
||||
|
||||
## PAN-123850
|
||||
|
||||
```caveat
|
||||
PA-5200 and PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where conflicting GTP sessions were installed in short interval, which caused the firewall to queue GTP packets and deplete packet buffers.
|
||||
|
||||
## PAN-123600
|
||||
|
||||
Fixed an issue where the firewall was unable to establish a connection to the DNS Security feature domain (dns.service.paloaltonetworks.com) when the firewall could not connect with the primary DNS server but could connect with the secondary DNS server.
|
||||
|
||||
## PAN-123446
|
||||
|
||||
Fixed an issue where an administrator with a Superuser role could not reset administrator credentials.
|
||||
|
||||
## PAN-123362
|
||||
|
||||
Fixed an issue where the firewall used more than expected virtual memory when you decreased the maximum elastic search heap size.
|
||||
|
||||
## PAN-123190
|
||||
|
||||
Fixed an issue on a firewall in an HA active/passive configuration where a process (useridd) restarted multiple times and caused the firewall to reboot.
|
||||
|
||||
## PAN-123030
|
||||
|
||||
Fixed an issue with a memory leak associated with a process (mgmtsrvr) when you pushed a commit.
|
||||
|
||||
## PAN-122662
|
||||
|
||||
```caveat
|
||||
PA-5260 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where a process (mpreplay) stopped responding after a commit when you configured the firewall with more than 200 virtual systems (vsys) running on PAN-OS 8.1.9.
|
||||
|
||||
## PAN-122601
|
||||
|
||||
Fixed a memory leak issue with a process (configd) when you performed device group related operations.
|
||||
|
||||
## PAN-122550
|
||||
|
||||
Fixed an issue where VM-Series firewalls on Microsoft Azure experienced traffic latency due to an incompatible driver.
|
||||
|
||||
## PAN-121945
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where after you deployed the firewall in Google Cloud the Panorama serial console stopped responding.
|
||||
|
||||
## PAN-121911
|
||||
|
||||
Fixed an issue where a process (logrcvr) restarted during commits.
|
||||
|
||||
## PAN-121667
|
||||
|
||||
Fixed an issue where traffic incorrectly matched Security policies when configured static address groups and FQDN IP addresses on Security policies overlapped.
|
||||
|
||||
## PAN-121523
|
||||
|
||||
Fixed an issue where an API call triggered memory errors, which caused a process (configd) to stop responding and triggered SIGABRT logs.
|
||||
|
||||
## PAN-121447
|
||||
|
||||
Fixed an issue where the BGP did not remove the IPv6 default route from the forwarding table after the route was withdrawn.
|
||||
|
||||
## PAN-121133
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where a validation job triggered a memory leak in a process (configd), which caused context switching between Panorama and the web interface to respond slower than expected.
|
||||
|
||||
## PAN-121001
|
||||
|
||||
Fixed an issue where the firewall only reported a maximum of two logs when you configured more than two hardware security modules (HSM).
|
||||
|
||||
## PAN-120901
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where partial commits did not apply configuration changes as expected.
|
||||
|
||||
## PAN-120361
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where objects were not compressed, which caused higher than expected CPU and memory usage.
|
||||
|
||||
## PAN-120287
|
||||
|
||||
Fixed a JavaScript error due to an incorrect HTTP response, which prevented GlobalProtect Clientless VPN applications to load.
|
||||
|
||||
## PAN-120151
|
||||
|
||||
Fixed an issue where the DNS packet parser incorrectly processed DNS packet headers when the QD count is 0. With this fix, the DNS packet parser aborts further processing when QD != 1.
|
||||
|
||||
## PAN-119765
|
||||
|
||||
Fixed an intermittent issue where the firewall dropped sessions that used a large number of predict sessions.
|
||||
|
||||
## PAN-119680
|
||||
|
||||
Fixed a rare issue where the show running CLI commands for policy addresses caused file descriptor leaks.
|
||||
|
||||
## PAN-119289
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where you were unable to query Cortex™ Data Lake by the serial number filter.
|
||||
|
||||
## PAN-119225
|
||||
|
||||
Fixed an issue where an inaccurate sequence number check for an RST packet caused the packet to drop.
|
||||
|
||||
## PAN-119185
|
||||
|
||||
Fixed an issue where a process (panio) caused more than expected CPU consumption.
|
||||
|
||||
## PAN-119172
|
||||
|
||||
Fixed an issue where the firewall incorrectly enforced URL category policies and erroneously triggered alert instead of block.
|
||||
|
||||
## PAN-118985
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where a process (configd) experienced high memory utilization and a memory leak condition, which caused slower than expected performance.
|
||||
|
||||
## PAN-118881
|
||||
|
||||
Fixed an issue where the user domain information was missing from the user IP mapping entry when you configured **Allow Authentication with User Credentials or Client Certificate** to **Yes** while using a client certificate for GlobalProtect authentication.
|
||||
|
||||
## PAN-118783
|
||||
|
||||
Fixed an intermittent issue where a daemon (dnsproxy) stopped responding when you configured an HTTP proxy on the firewall.
|
||||
|
||||
## PAN-118762
|
||||
|
||||
Fixed an issue where the GlobalProtect portal used an outdated jQuery library.
|
||||
|
||||
## PAN-118720
|
||||
|
||||
Fixed an issue on a firewall in an HA active/active configuration where Oracle traffic SYN packets dropped intermittently with the flow_fpp_owner_err_no_predict counter.
|
||||
|
||||
## PAN-118628
|
||||
|
||||
Fixed an issue where after you deployed Panorama in Azure, you were unable to log in to Panorama with the username and password that was provided during the deployment process.
|
||||
|
||||
## PAN-118583
|
||||
|
||||
Fixed a memory allocation issue that prevented URL filtering logs from displaying the full URL.
|
||||
|
||||
## PAN-118430
|
||||
|
||||
Fixed an issue where pushed template configurations were overridden when you made a configuration change in the Master Key **Lifetime** (**Device** > **Master Key and Diagnostic** > **Edit**) field.
|
||||
|
||||
## PAN-118370
|
||||
|
||||
Fixed an issue where the firewall displayed incorrect application dependency warnings during commits when a Security policy used a wildcard address.
|
||||
|
||||
## PAN-118277
|
||||
|
||||
Fixed an issue where the firewall stopped responding due to a race condition.
|
||||
|
||||
## PAN-118256
|
||||
|
||||
Fixed an issue where a DNS Security signature response from a cloud service caused a daemon (dnsproxyd) to stop responding.
|
||||
|
||||
## PAN-118183
|
||||
|
||||
Fixed an issue where a process (dnsproxyd) stopped responding due to higher than expected CPU usage.
|
||||
|
||||
## PAN-118180
|
||||
|
||||
Fixed an issue on firewalls configured with authentication policies where UDP and ICMP packets matching an authentication policy did not generate traffic logs as defined in the Security policy when sessions were redirected or denied.
|
||||
|
||||
## PAN-118057
|
||||
|
||||
Fixed an issue on a firewall in an HA active/passive configuration where a process (all_pktproc) stopped responding and the dataplane restarted, which caused an internal path monitoring failure and an HA failover event.
|
||||
|
||||
## PAN-118055
|
||||
|
||||
Fixed an issue where administrators were unable to export Security Assertion Markup Language (SAML) metadata files from virtual system (vsys) specific authentication profiles.
|
||||
|
||||
## PAN-117959
|
||||
|
||||
Fixed an issue where LDAP authentication failed when you configured the authentication server with an FQDN.
|
||||
|
||||
## PAN-117907
|
||||
|
||||
Fixed an issue where the date and time provided for a request license information output did not match the show clock output provided by the NTP server.
|
||||
|
||||
## PAN-117900
|
||||
|
||||
Fixed an issue where commits failed when you moved an object referenced in a policy to a shared group.
|
||||
|
||||
## PAN-117888
|
||||
|
||||
Fixed an issue where the firewall was unable to detect the hardware security module (HSM), which caused the firewall to drop SSL traffic.
|
||||
|
||||
## PAN-117878
|
||||
|
||||
Fixed an issue where you were unable to add a service definition to the NSX manager and the following error message displayed: Failed to create object service-definition. Ret code is 400.
|
||||
|
||||
## PAN-117835
|
||||
|
||||
Fixed an intermittent issue where a process (all_pktproc) stopped responding, which caused a heartbeat failure and the firewall to drop LACP and OSPF connections.
|
||||
|
||||
## PAN-117738
|
||||
|
||||
```caveat
|
||||
PA-3050 and PA-3060 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where a higher than expected number of flow_fpga_flow_update messages occurred when you configured QoS.
|
||||
|
||||
## PAN-117727
|
||||
|
||||
Fixed an issue where job threads were deadlocked, which prevented log in attempts and displayed the following error message: CONFIG_LOCK: write lock TIMEDOUT for cmd.
|
||||
|
||||
## PAN-117384
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where the connection between Panorama and managed firewalls timed out when you upgraded PAN-OS 9.0.0 to PAN-OS 9.0.1 and displayed the following error message: Error - time out sending/receiving message.
|
||||
|
||||
## PAN-117303
|
||||
|
||||
Fixed an issue where the BGP aggregate prefix, which is advertised to multiple BGP peers was removed from RIB OUT when you disabled one of the BGP peers.
|
||||
|
||||
## PAN-117120
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where a process (configd) restarted due to virtual memory issues.
|
||||
|
||||
## PAN-117086
|
||||
|
||||
Fixed an issue where community attributes to BGP routes had a character limit of 31 characters, which caused expressions to take longer than expected to process.
|
||||
|
||||
## PAN-117068
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where memory utilization increased more than expected when you deleted several rules with an XML API delete command.
|
||||
|
||||
## PAN-116977
|
||||
|
||||
Fixed an issue on VM-Series firewalls where you could not upgrade to PAN-OS 9.0.1 or a later release with a pre-licensed firewall.
|
||||
|
||||
## PAN-116949
|
||||
|
||||
Fixed a memory leak issue with a process (mprelay), which caused the dataplane to restart.
|
||||
|
||||
## PAN-116903
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where you were unable to configure **Enable X-Auth Support** (**Network** > **GlobalProtect** > **Gateways** > **Template** > **<Template-stack>** > **Agent** > **Tunnel Settings**) at the Template-stack level.
|
||||
|
||||
## PAN-116772
|
||||
|
||||
Fixed an issue where the firewall sent empty attributes in the LDAP query when you did not configure **Alternate Username 1 - 3** (**Device** > **User Identification** > **Group Mapping Settings** > **<group-name>** > **User and Group Attributes**) in the User Attributes web interface.
|
||||
|
||||
## PAN-116708
|
||||
|
||||
Fixed an issue where administrators were unable to export policies and objects in PDF format.
|
||||
|
||||
## PAN-116611
|
||||
|
||||
Fixed an issue where an API call for correlated events did not return any events.
|
||||
|
||||
## PAN-116473
|
||||
|
||||
Fixed an issue where the firewall logged URL categories configured for Allow in the URL filtering logs.
|
||||
|
||||
## PAN-116334
|
||||
|
||||
Fixed an issue where a process (mgmtsrvr) leaked memory caused by SNMP traps.
|
||||
|
||||
## PAN-116286
|
||||
|
||||
Fixed an issue where commits failed after you upgraded from PAN-OS 8.0.16 to PAN-OS 8.1.6 due to an invalid encryption state for a host information profile (HIP) object.
|
||||
|
||||
## PAN-116274
|
||||
|
||||
Fixed an issue where the firewall was unable to authenticate when you pushed a public key from Panorama.
|
||||
|
||||
## PAN-116189
|
||||
|
||||
Fixed an issue where Session Initiation Protocol (SIP) calls failed and displayed the following error message: end-reason: resources-unavailable.
|
||||
|
||||
## PAN-115990
|
||||
|
||||
Fixed an issue where the FQDN address object (**Policy** > **Security** > **<address-object>** > **Value**) displayed the following unrelated error: <FQDN-name> Not used.
|
||||
|
||||
## PAN-115959
|
||||
|
||||
Fixed an issue where DNS names with more than 63 characters did not resolve FQDN address objects during an FQDN refresh.
|
||||
|
||||
## PAN-115890
|
||||
|
||||
Fixed an issue where the show system info CLI command incorrectly displayed VMware ESXi as VMWare ESXi.
|
||||
|
||||
## PAN-115879
|
||||
|
||||
Fixed an issue on a firewall where a bypass switch sent heartbeat messages to the firewall, which triggered non-stop link status change interrupts through a Marvell switch.
|
||||
|
||||
## PAN-115697
|
||||
|
||||
Fixed CVE-2019-17437, see [PAN-SA-2019-0038](https://securityadvisories.paloaltonetworks.com/Home/Detail/201) for details.
|
||||
|
||||
## PAN-115549
|
||||
|
||||
Fixed an issue where predict sessions were incorrectly created with a captive-portal zone, which caused the firewall to drop RTP traffic.
|
||||
|
||||
## PAN-115349
|
||||
|
||||
Fixed an issue where an incorrect predict session was created when a policy-based forwarding (PBF) policy was used without a NAT in the parent session, which caused the firewall to drop RTP and RTCP packets.
|
||||
|
||||
## PAN-115344
|
||||
|
||||
Fixed an issue where the Username Modifier%USERDOMAIN%\%USERINPUT% enabled you to log in to a locked out user account.
|
||||
|
||||
## PAN-115340
|
||||
|
||||
Fixed an issue on a firewall in an HA active/passive configuration where the passive firewall experienced higher than expected dataplane CPU usage caused by HA IPSec messages bouncing between dataplanes.
|
||||
|
||||
## PAN-115282
|
||||
|
||||
Fixed an issue where temporary download files were deleted before a download job was completed, which caused the progress bar to remain at 0% and prevented a timeout when downloads fail.
|
||||
|
||||
## PAN-115281
|
||||
|
||||
Fixed an issue where the firewall did not resolve an external dynamic list server address when the DNS proxy configured it as a static entry.
|
||||
|
||||
## PAN-115110
|
||||
|
||||
An enhancement was made to enable you to configure syslog parameters through the CLI debug command. To view the available parameters and change the configurations, run the debug syslogng-params settings CLI command and perform a commit force to apply the edits.
|
||||
|
||||
## PAN-115108
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where scheduled uploading and installation of WildFire® content meta files to WF-500 appliances failed and displayed the following error message: device not supported.
|
||||
|
||||
## PAN-114880
|
||||
|
||||
Fixed an issue where the debug management-server summary-logs flush-options max-keys CLI command did not persist through a system reboot.
|
||||
|
||||
## PAN-114856
|
||||
|
||||
A change was made to limit debug log visibility to superusers only.
|
||||
|
||||
## PAN-114771
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where **Decrypt Mirror** (**Objects** > **Decryption** > **Decryption Profile** > **<Device Group-name>**) did not appear in the **Interface** drop-down menu when you tried to configure a Decryption Profile.
|
||||
|
||||
## PAN-114667
|
||||
|
||||
Fixed an issue on a firewall in an HA active/passive configuration where a split-brain condition occurred after you upgraded from PAN-OS 8.1.3 to PAN-OS 8.1.6.
|
||||
|
||||
## PAN-114628
|
||||
|
||||
Fixed an issue where Panorama was unable to query logs forwarded from the firewall to the log collector.
|
||||
|
||||
## PAN-114540
|
||||
|
||||
Fixed an issue where renaming a template stack did not change the value and reset to the original value after you commit the change.
|
||||
|
||||
## PAN-114456
|
||||
|
||||
Fixed an issue where extended packet capture (pcap) for threat logs caused a process (mgmtsrvr) to stop responding.
|
||||
|
||||
## PAN-114270
|
||||
|
||||
Fixed an issue where the firewall dropped TCP trace route traffic after you upgraded to PAN-OS 8.1.5. To leverage this fix, run the set session tcp-reject-diff-syn no CLI command.
|
||||
|
||||
## PAN-114247
|
||||
|
||||
Fixed an issue where a larger than expected number of Could not find entry for interface ethernet1/<interface>.<subinterface> in CPS table filled the snmpd.log, which caused the log file to rotate more frequently than expected.
|
||||
|
||||
## PAN-113610
|
||||
|
||||
Fixed an issue where Panorama incorrectly deleted valid device group directories and was unable to generate reports.
|
||||
|
||||
## PAN-113606
|
||||
|
||||
Fixed an issue where the Throughput column (**Panorama** > **Managed Devices** > **Health**) was incorrectly labeled.
|
||||
|
||||
## PAN-113261
|
||||
|
||||
```caveat
|
||||
PA-5200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the total entries for the URL filtering allow list, block list, and custom categories were incorrectly set to an entry limit value other than 100,000.
|
||||
|
||||
## PAN-113162
|
||||
|
||||
Fixed an issue where you were unable to create shared URL filtering profiles from the Panorama web interface.
|
||||
|
||||
## PAN-112661
|
||||
|
||||
Fixed an issue where you were unable to access a firewall due to a defective small form-factor pluggable (SFP)/SFP+ module inserted into the firewall.
|
||||
|
||||
## PAN-111544
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances configured as log collectors where SSH did not respond after you enabled SSH on ethernet1/1.
|
||||
|
||||
## PAN-110685
|
||||
|
||||
Fixed a rare issue where an incorrect User-ID™ match to the respective LDAP group caused a security policy mismatch.
|
||||
|
||||
## PAN-110098
|
||||
|
||||
Fixed an issue on a firewall in an HA active/passive configuration where you were unable to synchronize configurations or dynamic updates between HA pairs.
|
||||
|
||||
## PAN-109874
|
||||
|
||||
Fixed a memory leak issue on a firewall during a commit, which prevented the firewall from generating GlobalProtect client configurations.
|
||||
|
||||
## PAN-108876
|
||||
|
||||
Fixed an issue where the firewall dropped Session Initiation Protocol (SIP) registration packets, which caused SIP sessions to fail.
|
||||
|
||||
## PAN-108373
|
||||
|
||||
Fixed an issue where an application dependency warning incorrectly displayed when you configured negate-source yes on a security rule to deny an application.
|
||||
|
||||
## PAN-108012
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where you could not add and generate a certificate as expected.
|
||||
|
||||
## PAN-106434
|
||||
|
||||
Fixed an issue where a process (keymgr) stopped responding due to missed heartbeats, which caused IPSec tunnels to stop responding.
|
||||
|
||||
## PAN-102195
|
||||
|
||||
Fixed an issue where the firewall did not detect all threat sessions while the App and Threat content installation was processed.
|
||||
|
||||
## PAN-100977
|
||||
|
||||
```caveat
|
||||
VM-Series NSX edition firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the existing logs for dynamic address updates had insufficient information to debug the root cause of an issue and where the dynamic address update logs were larger than expected, which caused the file to roll over every five minutes and did not provide a sufficient log history to debug issues.
|
||||
@@ -0,0 +1,622 @@
|
||||
---
|
||||
type: Known
|
||||
product: PAN-OS
|
||||
version: 9.0.10
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||
|
||||
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
A Panorama management server running PAN-OS 9.0 does not currently support management of appliances running WildFire 7.1 or earlier releases. Even though these management options are visible on the Panorama 9.0 web interface (**Panorama** > **Managed WildFire Clusters** and **Panorama** > **Managed WildFire Appliances**), making changes to these settings for appliances running WildFire 7.1 or an earlier release has no effect.
|
||||
|
||||
## WF500-4200
|
||||
|
||||
The Create Date shown when using the `show wildfire global sample-status sha256 equal<hash>` or `show wildfire global sample-analysis` CLI command is two hours behind the actual time for WF-500 appliance samples.
|
||||
|
||||
## PLUG-1854
|
||||
|
||||
```caveat
|
||||
PAN-OS 9.0.2 and later releases on AWS and GCP only
|
||||
```
|
||||
|
||||
You cannot swap the management interface.
|
||||
|
||||
## PLUG-1827
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
The firewall drops packets due to larger than expected packet sizes when Accelerated networking is enabled on the firewall (**Settings** > **Networking**).
|
||||
|
||||
## PLUG-1709
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
There is an intermittent issue where the secondary IP address becomes associated with the passive firewall after multiple failovers.
|
||||
|
||||
**Workaround:** Reassign IP addresses to the active and passive firewalls in Azure as needed.
|
||||
|
||||
## PLUG-1694
|
||||
|
||||
```caveat
|
||||
PAYG licenses only
|
||||
```
|
||||
|
||||
Your pay-as-you-go (PAYG) license is not retained when you upgrade from a PAN-OS 8.1 release to a PAN-OS 9.0 release.
|
||||
|
||||
**Workaround:** Upgrade to VM-Series plugin 1.0.2 (or later) after you upgrade to a PAN-OS 9.0 release and then reboot the firewall to recover your PAYG license.
|
||||
|
||||
## PLUG-1681
|
||||
|
||||
If you bootstrap a PAN-OS 9.0.1 image while using VM-Series plugin 1.0.0, the firewall will not apply the capacity license. To downgrade the VM-Series plugin from version 1.0.2 to 1.0.0, first bootstrap the PAN-OS 9.0.1 image and then downgrade the plugin.
|
||||
|
||||
## PLUG-1642
|
||||
|
||||
```caveat
|
||||
This issue is resolved with VM-Series plugin 1.0.2.
|
||||
```
|
||||
|
||||
After a high availability (HA) failover, the dataplane interface on a VM-Series firewall on Azure with Accelerated Networking (SR-IOV) becomes disabled when, as a result of the failover, the secondary IP address is detached from or attached to the firewall and moved to its HA peer.
|
||||
|
||||
## PLUG-1503
|
||||
|
||||
```caveat
|
||||
This issue is resolved with VM-Series plugin 1.0.3.
|
||||
```
|
||||
|
||||
When a VM-Series firewall on AWS running on a C5 or M5 instance experiences a high availability (HA) failover, the dataplane interfaces from the previously active firewall are not moved to the newly active (previously passive) peer.
|
||||
|
||||
**Workaround:** Check for the latest VM-Series plugin version and install the VM-Series plugin 9.0.0 version; the built-in version is 9.0.0-c29.
|
||||
|
||||
## PLUG-1074
|
||||
|
||||
On the VM-Series firewall on AWS, when you change the instance type, the firewall no longer has a serial number or a license. Additionally, if you manage this firewall using Panorama, it is no longer connected to Panorama.
|
||||
|
||||
## PLUG-380
|
||||
|
||||
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||
|
||||
## PAN-178194
|
||||
|
||||
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
|
||||
|
||||
## PAN-154247
|
||||
|
||||
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
|
||||
|
||||
**Workaround:** Log out and back in to the Panorama web interface.
|
||||
|
||||
## PAN-151909
|
||||
|
||||
On the Panorama management server, Preview Changes (**Commit** > **Commit to Panorama**) incorrectly displays an existing route as Added and the new route as an existing route in the Candidate Configuration when you configure a new virtual router route (**Network** > **Virtual Router**).
|
||||
|
||||
## PAN-150998
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. See PAN-OS 9.0.13 Addressed Issues.
|
||||
```
|
||||
|
||||
If you deploy a VM-Series firewall on VMware NSX that has been assigned a serial number that was used by a previously deactivated firewall, the new firewall might be deployed in a deactivated or partially deactivated state.
|
||||
|
||||
## PAN-150172
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. See PAN-OS 9.0.9-h1 Addressed Issues.
|
||||
```
|
||||
|
||||
Dataplane processes restart when attempting to access websites that have the `NotBefore` attribute less than or equal to Unix Epoch Time in the server certificate with forward proxy enabled.
|
||||
|
||||
## PAN-146573
|
||||
|
||||
PA-7000 Series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||
|
||||
## PAN-140084
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. See PAN-OS 9.0.11 Addressed Issues.
|
||||
```
|
||||
|
||||
There is an issue where the default Dynamic IP and Port (DIPP) NAT oversubscription rate is set to 2.
|
||||
|
||||
## PAN-136701
|
||||
|
||||
```caveat
|
||||
PA-7000b Series firewalls only
|
||||
```
|
||||
|
||||
Packets for new sessions drop when handling predict sessions.
|
||||
|
||||
**Workaround:** Use the following CLI command to bypass this issue:
|
||||
|
||||
- `set session hwpredict disable yes`
|
||||
|
||||
To enable hwpredict again `set session hwpredict disable no`.
|
||||
|
||||
To verify the current settings, `show session hwpredict status`.
|
||||
|
||||
## PAN-131915
|
||||
|
||||
There is an issue when you implement a new firewall bootstrap with a USB drive where the bootstrap fails and displays the following error message: `no USB device found`.
|
||||
|
||||
**Workaround:** Perform a factory reset or run the `request system private-data-reset` CLI command and then proceed with bootstrapping.
|
||||
|
||||
## PAN-124956
|
||||
|
||||
There is an issue where VM-Series firewalls do not support packet buffer protection.
|
||||
|
||||
## PAN-120440
|
||||
|
||||
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||
|
||||
## PAN-120303
|
||||
|
||||
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||
|
||||
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||
|
||||
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||
2. **Commit** your changes.
|
||||
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||
4. **Commit** your changes.
|
||||
- Restart the firewall (devsrvr) process.
|
||||
1. Log in to the firewall CLI.
|
||||
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||
|
||||
## PAN-118414
|
||||
|
||||
```caveat
|
||||
PAN-OS 9.0.2 and later releases only
|
||||
```
|
||||
|
||||
There is an intermittent issue where a Panorama management server and managing Prisma™ Access or Cortex™ Data Lake fails to authorize one-time-password (OTP) submissions during the onboarding process.
|
||||
|
||||
**Workaround:** Downgrade to PAN-OS 9.0.1.
|
||||
|
||||
## PAN-117043
|
||||
|
||||
There is an issue on the Panorama management server and all supported firewalls where special characters contained in the tag names of the Security policy rules returns the following error message: `group-tag is invalid` when you commit or push a configuration.
|
||||
|
||||
**Workaround:** Modify the tags and group tags (**Objects** > **Tags**) to exclude special characters.
|
||||
|
||||
## PAN-116017
|
||||
|
||||
```caveat
|
||||
Google Cloud Platform (GCP) only
|
||||
```
|
||||
|
||||
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||
|
||||
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||
|
||||
## PAN-115816
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||
|
||||
**Workaround:** Reboot the firewall.
|
||||
|
||||
## PAN-115733
|
||||
|
||||
```caveat
|
||||
PAN-OS firewalls in an HA configuration only
|
||||
```
|
||||
|
||||
There is a rare issue where data interfaces do not come up after you reboot the firewall when running a C5 or M5 instance type in AWS.
|
||||
|
||||
**Workaround:** Reboot the firewall.
|
||||
|
||||
## PAN-114495
|
||||
|
||||
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||
|
||||
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||
|
||||
## PAN-113117
|
||||
|
||||
A newly launched firewall does not get its configuration from Panorama when it first connects if you installed the VM-Series plugin on Panorama. When a newly launched firewall that is bootstrapped connects to Panorama, a process restart occurs on Panorama. Upon restart, you are logged out of the user interface and you need to log in and push the device group and template configuration to the newly connected firewall.
|
||||
|
||||
## PAN-113098
|
||||
|
||||
In the firewall web interface, you can temporarily submit change requests for the following URL categories: insufficient-content, high-risk, medium-risk, low-risk, and newly-registered-domains. However, Palo Alto Networks does not support or process change requests for these categories.
|
||||
|
||||
## PAN-112983
|
||||
|
||||
```caveat
|
||||
Firewalls with multiple virtual systems only; no impact to Panorama
|
||||
```
|
||||
|
||||
If you select any Location other than Shared when you generate or import a new CA Certificate in a Certificate Profile (**Device** > **Certificate Management** > **Certificate Profile**), the firewall adds the newly generated or imported certificate to vsys1. For example, if you specify vsys3 as the **Location**, **Add** a CA Certificate, and then **Generate** a new certificate, the firewall adds the certificate to vsys1 instead of vsys3. When you click **OK** to configure the Certificate Profile, the firewall returns an `Operation Failed` error message because it sees a certificate for vsys1 added to vsys3.
|
||||
|
||||
**Workaround 1:**
|
||||
|
||||
1. Generate or import the new certificate in a Certificate Profile (**Device** > **Certificate Management** > **Certificates** > **Device Certificates**) and select the appropriate vsys **Location** when you generate or import the certificate.
|
||||
2. When you create or edit the Certificate Profile, specify the vsys **Location** and **Add** the certificate that you generated (or imported) from the list of existing certificates.
|
||||
|
||||
**Workaround 2:** When you generate or import a new certificate when you configure a Certificate Profile for a vsys other than vsys1, specify the **Location** as Shared.
|
||||
|
||||
## PAN-112694
|
||||
|
||||
```caveat
|
||||
Firewalls with multiple virtual systems only
|
||||
```
|
||||
|
||||
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||
|
||||
## PAN-112626
|
||||
|
||||
When you upgrade to PAN-OS 9.0 with a PAYG Bundle 2 license, the new DNS Security subscription is not available on your VM-Series firewall.
|
||||
|
||||
This subscription is included with the BYOL and VM-Series ELA when you upgrade.
|
||||
|
||||
## PAN-112562
|
||||
|
||||
The **Log Forwarding Card** (LFC) subinterface incorrectly uses the interface IP address instead of the subinterface IP address for all services that forward logs (such as syslog, email, and SNMP) for selected virtual systems.
|
||||
|
||||
## PAN-112456
|
||||
|
||||
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
|
||||
|
||||
## PAN-111928
|
||||
|
||||
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||
|
||||
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||
|
||||
## PAN-111866
|
||||
|
||||
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||
|
||||
**Workaround:** Perform one of the following tasks.
|
||||
|
||||
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||
- Manually select the devices that belong to the modified device group and template configurations.
|
||||
|
||||
## PAN-111729
|
||||
|
||||
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||
|
||||
## PAN-111670
|
||||
|
||||
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||
|
||||
## PAN-110794
|
||||
|
||||
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||
|
||||
## PAN-110603
|
||||
|
||||
In some cases, when a port on an PA-7000 Series 100Gbps Network Processor Card (NPC) has an SFP+ transceiver inserted but no cable is connected, the system detects a signal and attempts to tune and link with that port. As a result, if the device at the other end of the connection is rebooted or has an HA failover event, the link is sometimes held down for an extended period of time while the interface attempts to tune itself.
|
||||
|
||||
**Workaround:** Connect a cable to the installed SFP+ transceiver to allow the system to tune and link. Then, when you disconnect the cable, the system will correctly detect that the link is down. Alternatively, remove the SFP+ transceiver from the port.
|
||||
|
||||
## PAN-109526
|
||||
|
||||
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||
|
||||
## PAN-106989
|
||||
|
||||
There is a display-only issue on Panorama that results in a `commit failed` status for Template Last Commit State (**Panorama** > **Managed Devices** > **Summary**).
|
||||
|
||||
**Workaround:** Push templates to managed devices.
|
||||
|
||||
## PAN-106675
|
||||
|
||||
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||
|
||||
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||
|
||||
## PAN-105210
|
||||
|
||||
```caveat
|
||||
Panorama in FIPS mode only when managing non-FIPS firewalls
|
||||
```
|
||||
|
||||
You cannot configure a GlobalProtect portal on Panorama in FIPS mode when managing a non-FIPS firewall. If you attempt to do so, you will receive the following error message: `agent-user-override-key unexpected here Portal_fips.`
|
||||
|
||||
## PAN-104780
|
||||
|
||||
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||
|
||||
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||
|
||||
## PAN-103336
|
||||
|
||||
```caveat
|
||||
HA configurations only
|
||||
```
|
||||
|
||||
When you downgrade a VM-Series firewall on Azure from PAN-OS 9.0 to an earlier release, you do not receive warnings. Do not downgrade your firewall without saving and exporting your current configuration.
|
||||
|
||||
**Workaround:** Because HA is not supported in earlier versions of VM-Series firewalls on Azure, to prevent the loss of your configuration:
|
||||
|
||||
- Save and export the configuration before you downgrade.
|
||||
- After you downgrade, load the saved configuration and commit your changes. The firewall will resume operation without the HA configuration.
|
||||
|
||||
## PAN-103276
|
||||
|
||||
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||
|
||||
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||
|
||||
## PAN-103018
|
||||
|
||||
```caveat
|
||||
Panorama plugins
|
||||
```
|
||||
|
||||
When you use the AND/OR boolean operators to define the match criteria for Dynamic Address Groups on Panorama, the boolean operators do not function properly. The member IP addresses are not included in the address group as expected.
|
||||
|
||||
## PAN-101688
|
||||
|
||||
```caveat
|
||||
Panorama plugins
|
||||
```
|
||||
|
||||
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||
|
||||
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||
|
||||
## PAN-101537
|
||||
|
||||
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||
|
||||
**Workaround:** Specify the vsys in the query string:
|
||||
|
||||
`admin>` `set system target-vsys <vsys-name>`
|
||||
|
||||
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||
|
||||
## PAN-98803
|
||||
|
||||
If you configure the Panorama plugin to monitor virtual machines or endpoints in your AWS, Azure, or Cisco ACI environment without installing the NSX plugin, the IP-address-to-tag mappings for Dynamic Address Groups are not displayed on Panorama.
|
||||
|
||||
**Workaround:** Install the NSX plugin (you do not need to use the NSX plugin for the installation to resolve this display issue).
|
||||
|
||||
## PAN-98520
|
||||
|
||||
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||
|
||||
## PAN-97757
|
||||
|
||||
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||
|
||||
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||
|
||||
## PAN-97524
|
||||
|
||||
```caveat
|
||||
Panorama management server only
|
||||
```
|
||||
|
||||
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||
|
||||
## PAN-96985
|
||||
|
||||
The `request shutdown system` command does not shut down the Panorama management server.
|
||||
|
||||
## PAN-96960
|
||||
|
||||
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
|
||||
|
||||
## PAN-96446
|
||||
|
||||
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||
|
||||
## PAN-95773
|
||||
|
||||
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||
|
||||
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||
|
||||
## PAN-95717
|
||||
|
||||
After 30,000 or more end users log in to the GlobalProtect gateway within a two- to three-hour period, the firewall web interface responds slowly, commits take longer than expected or intermittently fail, and Tech Support File generation times out and fails.
|
||||
|
||||
## PAN-95602
|
||||
|
||||
In a deployment where a Log Collector connects to Panorama management servers in a high availability (HA) configuration, after you switch the Log Collector appliance to Panorama mode, commit operations fail on the appliance.
|
||||
|
||||
**Workaround:** Remove the following node from the running-config.xml file on the Log Collector before switching it to Panorama mode: `devices/entry[@name='localhost.localdomain']/deviceconfig/system/panorama-server-2`
|
||||
|
||||
## PAN-95511
|
||||
|
||||
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||
|
||||
## PAN-95028
|
||||
|
||||
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||
|
||||
## PAN-94966
|
||||
|
||||
After you delete disconnected and connected Terminal Server (TS) agents in the same operation, the firewall still displays the IP address-to-port-user mappings (`show user ip-port-user-mapping` CLI command) for the disconnected TS agents you deleted (**Device** > **User Identification** > **Terminal Services Agents**).
|
||||
|
||||
**Workaround:** Do not delete both disconnected and connected TS agents in the same operation.
|
||||
|
||||
## PAN-94846
|
||||
|
||||
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||
|
||||
## PAN-94093
|
||||
|
||||
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||
|
||||
## PAN-93968
|
||||
|
||||
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||
|
||||
## PAN-93842
|
||||
|
||||
The logging status of a Panorama Log Collector deployed on AWS or Azure displays as disconnected when you configure the ethernet1/1 to ethernet1/5 interfaces for log collection (**Panorama** > **Managed Collectors** > **Interfaces**). This results in firewalls not sending logs to the Log Collector.
|
||||
|
||||
**Workaround:** Configure the management (MGT) interface for log collection.
|
||||
|
||||
## PAN-93607
|
||||
|
||||
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||
|
||||
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||
|
||||
## PAN-93532
|
||||
|
||||
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||
|
||||
## PAN-93193
|
||||
|
||||
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||
|
||||
- Switch to the firewall **Context** on the Panorama management server.
|
||||
- Commit changes when a dynamic update is being installed.
|
||||
- Generate a custom report when a dynamic update is being installed.
|
||||
- Generate custom reports during a commit.
|
||||
|
||||
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||
|
||||
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||
|
||||
## PAN-91802
|
||||
|
||||
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||
|
||||
## PAN-86903
|
||||
|
||||
In rare cases, PA-800 Series firewalls shut themselves down due to a false over-current measurement.
|
||||
|
||||
## PAN-83610
|
||||
|
||||
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||
|
||||
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session off load for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||
|
||||
## PAN-83598
|
||||
|
||||
VM-Series firewalls cannot monitor more than 500 virtual machine (VM) information sources (**Device** > **VM Information Sources**).
|
||||
|
||||
## PAN-83236
|
||||
|
||||
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||
|
||||
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||
|
||||
## PAN-83215
|
||||
|
||||
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||
|
||||
## PAN-81521
|
||||
|
||||
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||
|
||||
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||
|
||||
## PAN-79423
|
||||
|
||||
Panorama cannot push address group objects from device groups to managed firewalls when zones specify the objects in the User Identification ACL include or exclude lists (**Network** > **Zones**) and the **Share Unused Address and Service Objects with Devices** option is disabled (**Panorama** > **Setup** > **Management** > **Panorama Settings**).
|
||||
|
||||
## PAN-77125
|
||||
|
||||
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||
|
||||
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||
|
||||
## PAN-75457
|
||||
|
||||
```caveat
|
||||
PAN-OS 8.0.1 and later releases
|
||||
```
|
||||
|
||||
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||
|
||||
## PAN-73530
|
||||
|
||||
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||
|
||||
## PAN-73401
|
||||
|
||||
```caveat
|
||||
PAN-OS 8.0.1 and later releases
|
||||
```
|
||||
|
||||
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||
|
||||
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||
|
||||
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||
|
||||
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||
- Configure a worker list on the cluster controller:
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||
or
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||
|
||||
## PAN-71329
|
||||
|
||||
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
|
||||
|
||||
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
|
||||
|
||||
## PAN-70906
|
||||
|
||||
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||
|
||||
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||
|
||||
## PAN-69505
|
||||
|
||||
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||
|
||||
## PAN-41558
|
||||
|
||||
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||
|
||||
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||
|
||||
## PAN-40079
|
||||
|
||||
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||
|
||||
## PAN-39636
|
||||
|
||||
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||
|
||||
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||
|
||||
## PAN-38255
|
||||
|
||||
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||
|
||||
## PAN-31832
|
||||
|
||||
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||
|
||||
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||
|
||||
## PAN-25046
|
||||
|
||||
Firewalls store SSH host keys used for SCP log exports in the known hosts file. In an HA deployment, PAN-OS synchronizes the SCP log export configuration between the firewall HA peers (**Device** > **Scheduled Log Export**), but not the known host file. When a failover occurs, the SCP log export fails.
|
||||
|
||||
**Workaround:** Log in to each peer in HA, select **Device** > **Scheduled Log Export** > **<log_export_configuration>**, and **Test SCP server connection** to confirm the host key so that SCP log forwarding continues to work after a failover.
|
||||
@@ -0,0 +1,614 @@
|
||||
---
|
||||
type: Known
|
||||
product: PAN-OS
|
||||
version: 9.0.11
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||
|
||||
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
A Panorama management server running PAN-OS 9.0 does not currently support management of appliances running WildFire 7.1 or earlier releases. Even though these management options are visible on the Panorama 9.0 web interface (**Panorama** > **Managed WildFire Clusters** and **Panorama** > **Managed WildFire Appliances**), making changes to these settings for appliances running WildFire 7.1 or an earlier release has no effect.
|
||||
|
||||
## WF500-4200
|
||||
|
||||
The Create Date shown when using the `show wildfire global sample-status sha256 equal<hash>` or `show wildfire global sample-analysis` CLI command is two hours behind the actual time for WF-500 appliance samples.
|
||||
|
||||
## PLUG-1854
|
||||
|
||||
```caveat
|
||||
PAN-OS 9.0.2 and later releases on AWS and GCP only
|
||||
```
|
||||
|
||||
You cannot swap the management interface.
|
||||
|
||||
## PLUG-1827
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
The firewall drops packets due to larger than expected packet sizes when Accelerated networking is enabled on the firewall (**Settings** > **Networking**).
|
||||
|
||||
## PLUG-1709
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
There is an intermittent issue where the secondary IP address becomes associated with the passive firewall after multiple failovers.
|
||||
|
||||
**Workaround:** Reassign IP addresses to the active and passive firewalls in Azure as needed.
|
||||
|
||||
## PLUG-1694
|
||||
|
||||
```caveat
|
||||
PAYG licenses only
|
||||
```
|
||||
|
||||
Your pay-as-you-go (PAYG) license is not retained when you upgrade from a PAN-OS 8.1 release to a PAN-OS 9.0 release.
|
||||
|
||||
**Workaround:** Upgrade to VM-Series plugin 1.0.2 (or later) after you upgrade to a PAN-OS 9.0 release and then reboot the firewall to recover your PAYG license.
|
||||
|
||||
## PLUG-1681
|
||||
|
||||
If you bootstrap a PAN-OS 9.0.1 image while using VM-Series plugin 1.0.0, the firewall will not apply the capacity license. To downgrade the VM-Series plugin from version 1.0.2 to 1.0.0, first bootstrap the PAN-OS 9.0.1 image and then downgrade the plugin.
|
||||
|
||||
## PLUG-1642
|
||||
|
||||
```caveat
|
||||
This issue is resolved with VM-Series plugin 1.0.2.
|
||||
```
|
||||
|
||||
After a high availability (HA) failover, the dataplane interface on a VM-Series firewall on Azure with Accelerated Networking (SR-IOV) becomes disabled when, as a result of the failover, the secondary IP address is detached from or attached to the firewall and moved to its HA peer.
|
||||
|
||||
## PLUG-1503
|
||||
|
||||
```caveat
|
||||
This issue is resolved with VM-Series plugin 1.0.3.
|
||||
```
|
||||
|
||||
When a VM-Series firewall on AWS running on a C5 or M5 instance experiences a high availability (HA) failover, the dataplane interfaces from the previously active firewall are not moved to the newly active (previously passive) peer.
|
||||
|
||||
**Workaround:** Check for the latest VM-Series plugin version and install the VM-Series plugin 9.0.0 version; the built-in version is 9.0.0-c29.
|
||||
|
||||
## PLUG-1074
|
||||
|
||||
On the VM-Series firewall on AWS, when you change the instance type, the firewall no longer has a serial number or a license. Additionally, if you manage this firewall using Panorama, it is no longer connected to Panorama.
|
||||
|
||||
## PLUG-380
|
||||
|
||||
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||
|
||||
## PAN-178194
|
||||
|
||||
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
|
||||
|
||||
## PAN-154247
|
||||
|
||||
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
|
||||
|
||||
**Workaround:** Log out and back in to the Panorama web interface.
|
||||
|
||||
## PAN-151909
|
||||
|
||||
On the Panorama management server, Preview Changes (**Commit** > **Commit to Panorama**) incorrectly displays an existing route as Added and the new route as an existing route in the Candidate Configuration when you configure a new virtual router route (**Network** > **Virtual Router**).
|
||||
|
||||
## PAN-150998
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. See PAN-OS 9.0.13 Addressed Issues.
|
||||
```
|
||||
|
||||
If you deploy a VM-Series firewall on VMware NSX that has been assigned a serial number that was used by a previously deactivated firewall, the new firewall might be deployed in a deactivated or partially deactivated state.
|
||||
|
||||
## PAN-150172
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. See PAN-OS 9.0.9-h1 Addressed Issues.
|
||||
```
|
||||
|
||||
Dataplane processes restart when attempting to access websites that have the `NotBefore` attribute less than or equal to Unix Epoch Time in the server certificate with forward proxy enabled.
|
||||
|
||||
## PAN-146573
|
||||
|
||||
PA-7000 Series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||
|
||||
## PAN-136701
|
||||
|
||||
```caveat
|
||||
PA-7000b Series firewalls only
|
||||
```
|
||||
|
||||
Packets for new sessions drop when handling predict sessions.
|
||||
|
||||
**Workaround:** Use the following CLI command to bypass this issue:
|
||||
|
||||
- `set session hwpredict disable yes`
|
||||
|
||||
To enable hwpredict again `set session hwpredict disable no`.
|
||||
|
||||
To verify the current settings, `show session hwpredict status`.
|
||||
|
||||
## PAN-131915
|
||||
|
||||
There is an issue when you implement a new firewall bootstrap with a USB drive where the bootstrap fails and displays the following error message: `no USB device found`.
|
||||
|
||||
**Workaround:** Perform a factory reset or run the `request system private-data-reset` CLI command and then proceed with bootstrapping.
|
||||
|
||||
## PAN-124956
|
||||
|
||||
There is an issue where VM-Series firewalls do not support packet buffer protection.
|
||||
|
||||
## PAN-120440
|
||||
|
||||
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||
|
||||
## PAN-120303
|
||||
|
||||
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||
|
||||
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||
|
||||
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||
2. **Commit** your changes.
|
||||
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||
4. **Commit** your changes.
|
||||
- Restart the firewall (devsrvr) process.
|
||||
1. Log in to the firewall CLI.
|
||||
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||
|
||||
## PAN-118414
|
||||
|
||||
```caveat
|
||||
PAN-OS 9.0.2 and later releases only
|
||||
```
|
||||
|
||||
There is an intermittent issue where a Panorama management server and managing Prisma™ Access or Cortex™ Data Lake fails to authorize one-time-password (OTP) submissions during the onboarding process.
|
||||
|
||||
**Workaround:** Downgrade to PAN-OS 9.0.1.
|
||||
|
||||
## PAN-117043
|
||||
|
||||
There is an issue on the Panorama management server and all supported firewalls where special characters contained in the tag names of the Security policy rules returns the following error message: `group-tag is invalid` when you commit or push a configuration.
|
||||
|
||||
**Workaround:** Modify the tags and group tags (**Objects** > **Tags**) to exclude special characters.
|
||||
|
||||
## PAN-116017
|
||||
|
||||
```caveat
|
||||
Google Cloud Platform (GCP) only
|
||||
```
|
||||
|
||||
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||
|
||||
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||
|
||||
## PAN-115816
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||
|
||||
**Workaround:** Reboot the firewall.
|
||||
|
||||
## PAN-115733
|
||||
|
||||
```caveat
|
||||
PAN-OS firewalls in an HA configuration only
|
||||
```
|
||||
|
||||
There is a rare issue where data interfaces do not come up after you reboot the firewall when running a C5 or M5 instance type in AWS.
|
||||
|
||||
**Workaround:** Reboot the firewall.
|
||||
|
||||
## PAN-114495
|
||||
|
||||
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||
|
||||
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||
|
||||
## PAN-113117
|
||||
|
||||
A newly launched firewall does not get its configuration from Panorama when it first connects if you installed the VM-Series plugin on Panorama. When a newly launched firewall that is bootstrapped connects to Panorama, a process restart occurs on Panorama. Upon restart, you are logged out of the user interface and you need to log in and push the device group and template configuration to the newly connected firewall.
|
||||
|
||||
## PAN-113098
|
||||
|
||||
In the firewall web interface, you can temporarily submit change requests for the following URL categories: insufficient-content, high-risk, medium-risk, low-risk, and newly-registered-domains. However, Palo Alto Networks does not support or process change requests for these categories.
|
||||
|
||||
## PAN-112983
|
||||
|
||||
```caveat
|
||||
Firewalls with multiple virtual systems only; no impact to Panorama
|
||||
```
|
||||
|
||||
If you select any Location other than Shared when you generate or import a new CA Certificate in a Certificate Profile (**Device** > **Certificate Management** > **Certificate Profile**), the firewall adds the newly generated or imported certificate to vsys1. For example, if you specify vsys3 as the **Location**, **Add** a CA Certificate, and then **Generate** a new certificate, the firewall adds the certificate to vsys1 instead of vsys3. When you click **OK** to configure the Certificate Profile, the firewall returns an `Operation Failed` error message because it sees a certificate for vsys1 added to vsys3.
|
||||
|
||||
**Workaround 1:**
|
||||
|
||||
1. Generate or import the new certificate in a Certificate Profile (**Device** > **Certificate Management** > **Certificates** > **Device Certificates**) and select the appropriate vsys **Location** when you generate or import the certificate.
|
||||
2. When you create or edit the Certificate Profile, specify the vsys **Location** and **Add** the certificate that you generated (or imported) from the list of existing certificates.
|
||||
|
||||
**Workaround 2:** When you generate or import a new certificate when you configure a Certificate Profile for a vsys other than vsys1, specify the **Location** as Shared.
|
||||
|
||||
## PAN-112694
|
||||
|
||||
```caveat
|
||||
Firewalls with multiple virtual systems only
|
||||
```
|
||||
|
||||
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||
|
||||
## PAN-112626
|
||||
|
||||
When you upgrade to PAN-OS 9.0 with a PAYG Bundle 2 license, the new DNS Security subscription is not available on your VM-Series firewall.
|
||||
|
||||
This subscription is included with the BYOL and VM-Series ELA when you upgrade.
|
||||
|
||||
## PAN-112562
|
||||
|
||||
The **Log Forwarding Card** (LFC) subinterface incorrectly uses the interface IP address instead of the subinterface IP address for all services that forward logs (such as syslog, email, and SNMP) for selected virtual systems.
|
||||
|
||||
## PAN-112456
|
||||
|
||||
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
|
||||
|
||||
## PAN-111928
|
||||
|
||||
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||
|
||||
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||
|
||||
## PAN-111866
|
||||
|
||||
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||
|
||||
**Workaround:** Perform one of the following tasks.
|
||||
|
||||
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||
- Manually select the devices that belong to the modified device group and template configurations.
|
||||
|
||||
## PAN-111729
|
||||
|
||||
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||
|
||||
## PAN-111670
|
||||
|
||||
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||
|
||||
## PAN-110794
|
||||
|
||||
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||
|
||||
## PAN-110603
|
||||
|
||||
In some cases, when a port on an PA-7000 Series 100Gbps Network Processor Card (NPC) has an SFP+ transceiver inserted but no cable is connected, the system detects a signal and attempts to tune and link with that port. As a result, if the device at the other end of the connection is rebooted or has an HA failover event, the link is sometimes held down for an extended period of time while the interface attempts to tune itself.
|
||||
|
||||
**Workaround:** Connect a cable to the installed SFP+ transceiver to allow the system to tune and link. Then, when you disconnect the cable, the system will correctly detect that the link is down. Alternatively, remove the SFP+ transceiver from the port.
|
||||
|
||||
## PAN-109526
|
||||
|
||||
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||
|
||||
## PAN-106989
|
||||
|
||||
There is a display-only issue on Panorama that results in a `commit failed` status for Template Last Commit State (**Panorama** > **Managed Devices** > **Summary**).
|
||||
|
||||
**Workaround:** Push templates to managed devices.
|
||||
|
||||
## PAN-106675
|
||||
|
||||
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||
|
||||
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||
|
||||
## PAN-105210
|
||||
|
||||
```caveat
|
||||
Panorama in FIPS mode only when managing non-FIPS firewalls
|
||||
```
|
||||
|
||||
You cannot configure a GlobalProtect portal on Panorama in FIPS mode when managing a non-FIPS firewall. If you attempt to do so, you will receive the following error message: `agent-user-override-key unexpected here Portal_fips.`
|
||||
|
||||
## PAN-104780
|
||||
|
||||
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||
|
||||
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||
|
||||
## PAN-103336
|
||||
|
||||
```caveat
|
||||
HA configurations only
|
||||
```
|
||||
|
||||
When you downgrade a VM-Series firewall on Azure from PAN-OS 9.0 to an earlier release, you do not receive warnings. Do not downgrade your firewall without saving and exporting your current configuration.
|
||||
|
||||
**Workaround:** Because HA is not supported in earlier versions of VM-Series firewalls on Azure, to prevent the loss of your configuration:
|
||||
|
||||
- Save and export the configuration before you downgrade.
|
||||
- After you downgrade, load the saved configuration and commit your changes. The firewall will resume operation without the HA configuration.
|
||||
|
||||
## PAN-103276
|
||||
|
||||
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||
|
||||
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||
|
||||
## PAN-103018
|
||||
|
||||
```caveat
|
||||
Panorama plugins
|
||||
```
|
||||
|
||||
When you use the AND/OR boolean operators to define the match criteria for Dynamic Address Groups on Panorama, the boolean operators do not function properly. The member IP addresses are not included in the address group as expected.
|
||||
|
||||
## PAN-101688
|
||||
|
||||
```caveat
|
||||
Panorama plugins
|
||||
```
|
||||
|
||||
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||
|
||||
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||
|
||||
## PAN-101537
|
||||
|
||||
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||
|
||||
**Workaround:** Specify the vsys in the query string:
|
||||
|
||||
`admin>` `set system target-vsys <vsys-name>`
|
||||
|
||||
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||
|
||||
## PAN-98803
|
||||
|
||||
If you configure the Panorama plugin to monitor virtual machines or endpoints in your AWS, Azure, or Cisco ACI environment without installing the NSX plugin, the IP-address-to-tag mappings for Dynamic Address Groups are not displayed on Panorama.
|
||||
|
||||
**Workaround:** Install the NSX plugin (you do not need to use the NSX plugin for the installation to resolve this display issue).
|
||||
|
||||
## PAN-98520
|
||||
|
||||
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||
|
||||
## PAN-97757
|
||||
|
||||
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||
|
||||
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||
|
||||
## PAN-97524
|
||||
|
||||
```caveat
|
||||
Panorama management server only
|
||||
```
|
||||
|
||||
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||
|
||||
## PAN-96985
|
||||
|
||||
The `request shutdown system` command does not shut down the Panorama management server.
|
||||
|
||||
## PAN-96960
|
||||
|
||||
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
|
||||
|
||||
## PAN-96446
|
||||
|
||||
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||
|
||||
## PAN-95773
|
||||
|
||||
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||
|
||||
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||
|
||||
## PAN-95717
|
||||
|
||||
After 30,000 or more end users log in to the GlobalProtect gateway within a two- to three-hour period, the firewall web interface responds slowly, commits take longer than expected or intermittently fail, and Tech Support File generation times out and fails.
|
||||
|
||||
## PAN-95602
|
||||
|
||||
In a deployment where a Log Collector connects to Panorama management servers in a high availability (HA) configuration, after you switch the Log Collector appliance to Panorama mode, commit operations fail on the appliance.
|
||||
|
||||
**Workaround:** Remove the following node from the running-config.xml file on the Log Collector before switching it to Panorama mode: `devices/entry[@name='localhost.localdomain']/deviceconfig/system/panorama-server-2`
|
||||
|
||||
## PAN-95511
|
||||
|
||||
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||
|
||||
## PAN-95028
|
||||
|
||||
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||
|
||||
## PAN-94966
|
||||
|
||||
After you delete disconnected and connected Terminal Server (TS) agents in the same operation, the firewall still displays the IP address-to-port-user mappings (`show user ip-port-user-mapping` CLI command) for the disconnected TS agents you deleted (**Device** > **User Identification** > **Terminal Services Agents**).
|
||||
|
||||
**Workaround:** Do not delete both disconnected and connected TS agents in the same operation.
|
||||
|
||||
## PAN-94846
|
||||
|
||||
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||
|
||||
## PAN-94093
|
||||
|
||||
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||
|
||||
## PAN-93968
|
||||
|
||||
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||
|
||||
## PAN-93842
|
||||
|
||||
The logging status of a Panorama Log Collector deployed on AWS or Azure displays as disconnected when you configure the ethernet1/1 to ethernet1/5 interfaces for log collection (**Panorama** > **Managed Collectors** > **Interfaces**). This results in firewalls not sending logs to the Log Collector.
|
||||
|
||||
**Workaround:** Configure the management (MGT) interface for log collection.
|
||||
|
||||
## PAN-93607
|
||||
|
||||
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||
|
||||
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||
|
||||
## PAN-93532
|
||||
|
||||
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||
|
||||
## PAN-93193
|
||||
|
||||
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||
|
||||
- Switch to the firewall **Context** on the Panorama management server.
|
||||
- Commit changes when a dynamic update is being installed.
|
||||
- Generate a custom report when a dynamic update is being installed.
|
||||
- Generate custom reports during a commit.
|
||||
|
||||
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||
|
||||
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||
|
||||
## PAN-91802
|
||||
|
||||
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||
|
||||
## PAN-86903
|
||||
|
||||
In rare cases, PA-800 Series firewalls shut themselves down due to a false over-current measurement.
|
||||
|
||||
## PAN-83610
|
||||
|
||||
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||
|
||||
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session off load for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||
|
||||
## PAN-83598
|
||||
|
||||
VM-Series firewalls cannot monitor more than 500 virtual machine (VM) information sources (**Device** > **VM Information Sources**).
|
||||
|
||||
## PAN-83236
|
||||
|
||||
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||
|
||||
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||
|
||||
## PAN-83215
|
||||
|
||||
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||
|
||||
## PAN-81521
|
||||
|
||||
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||
|
||||
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||
|
||||
## PAN-79423
|
||||
|
||||
Panorama cannot push address group objects from device groups to managed firewalls when zones specify the objects in the User Identification ACL include or exclude lists (**Network** > **Zones**) and the **Share Unused Address and Service Objects with Devices** option is disabled (**Panorama** > **Setup** > **Management** > **Panorama Settings**).
|
||||
|
||||
## PAN-77125
|
||||
|
||||
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||
|
||||
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||
|
||||
## PAN-75457
|
||||
|
||||
```caveat
|
||||
PAN-OS 8.0.1 and later releases
|
||||
```
|
||||
|
||||
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||
|
||||
## PAN-73530
|
||||
|
||||
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||
|
||||
## PAN-73401
|
||||
|
||||
```caveat
|
||||
PAN-OS 8.0.1 and later releases
|
||||
```
|
||||
|
||||
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||
|
||||
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||
|
||||
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||
|
||||
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||
- Configure a worker list on the cluster controller:
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||
or
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||
|
||||
## PAN-71329
|
||||
|
||||
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
|
||||
|
||||
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
|
||||
|
||||
## PAN-70906
|
||||
|
||||
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||
|
||||
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||
|
||||
## PAN-69505
|
||||
|
||||
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||
|
||||
## PAN-41558
|
||||
|
||||
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||
|
||||
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||
|
||||
## PAN-40079
|
||||
|
||||
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||
|
||||
## PAN-39636
|
||||
|
||||
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||
|
||||
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||
|
||||
## PAN-38255
|
||||
|
||||
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||
|
||||
## PAN-31832
|
||||
|
||||
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||
|
||||
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||
|
||||
## PAN-25046
|
||||
|
||||
Firewalls store SSH host keys used for SCP log exports in the known hosts file. In an HA deployment, PAN-OS synchronizes the SCP log export configuration between the firewall HA peers (**Device** > **Scheduled Log Export**), but not the known host file. When a failover occurs, the SCP log export fails.
|
||||
|
||||
**Workaround:** Log in to each peer in HA, select **Device** > **Scheduled Log Export** > **<log_export_configuration>**, and **Test SCP server connection** to confirm the host key so that SCP log forwarding continues to work after a failover.
|
||||
@@ -0,0 +1,622 @@
|
||||
---
|
||||
type: Known
|
||||
product: PAN-OS
|
||||
version: 9.0.12
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||
|
||||
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
A Panorama management server running PAN-OS 9.0 does not currently support management of appliances running WildFire 7.1 or earlier releases. Even though these management options are visible on the Panorama 9.0 web interface (**Panorama** > **Managed WildFire Clusters** and **Panorama** > **Managed WildFire Appliances**), making changes to these settings for appliances running WildFire 7.1 or an earlier release has no effect.
|
||||
|
||||
## WF500-4200
|
||||
|
||||
The Create Date shown when using the `show wildfire global sample-status sha256 equal<hash>` or `show wildfire global sample-analysis` CLI command is two hours behind the actual time for WF-500 appliance samples.
|
||||
|
||||
## PLUG-1854
|
||||
|
||||
```caveat
|
||||
PAN-OS 9.0.2 and later releases on AWS and GCP only
|
||||
```
|
||||
|
||||
You cannot swap the management interface.
|
||||
|
||||
## PLUG-1827
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
The firewall drops packets due to larger than expected packet sizes when Accelerated networking is enabled on the firewall (**Settings** > **Networking**).
|
||||
|
||||
## PLUG-1709
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
There is an intermittent issue where the secondary IP address becomes associated with the passive firewall after multiple failovers.
|
||||
|
||||
**Workaround:** Reassign IP addresses to the active and passive firewalls in Azure as needed.
|
||||
|
||||
## PLUG-1694
|
||||
|
||||
```caveat
|
||||
PAYG licenses only
|
||||
```
|
||||
|
||||
Your pay-as-you-go (PAYG) license is not retained when you upgrade from a PAN-OS 8.1 release to a PAN-OS 9.0 release.
|
||||
|
||||
**Workaround:** Upgrade to VM-Series plugin 1.0.2 (or later) after you upgrade to a PAN-OS 9.0 release and then reboot the firewall to recover your PAYG license.
|
||||
|
||||
## PLUG-1681
|
||||
|
||||
If you bootstrap a PAN-OS 9.0.1 image while using VM-Series plugin 1.0.0, the firewall will not apply the capacity license. To downgrade the VM-Series plugin from version 1.0.2 to 1.0.0, first bootstrap the PAN-OS 9.0.1 image and then downgrade the plugin.
|
||||
|
||||
## PLUG-1642
|
||||
|
||||
```caveat
|
||||
This issue is resolved with VM-Series plugin 1.0.2.
|
||||
```
|
||||
|
||||
After a high availability (HA) failover, the dataplane interface on a VM-Series firewall on Azure with Accelerated Networking (SR-IOV) becomes disabled when, as a result of the failover, the secondary IP address is detached from or attached to the firewall and moved to its HA peer.
|
||||
|
||||
## PLUG-1503
|
||||
|
||||
```caveat
|
||||
This issue is resolved with VM-Series plugin 1.0.3.
|
||||
```
|
||||
|
||||
When a VM-Series firewall on AWS running on a C5 or M5 instance experiences a high availability (HA) failover, the dataplane interfaces from the previously active firewall are not moved to the newly active (previously passive) peer.
|
||||
|
||||
**Workaround:** Check for the latest VM-Series plugin version and install the VM-Series plugin 9.0.0 version; the built-in version is 9.0.0-c29.
|
||||
|
||||
## PLUG-1074
|
||||
|
||||
On the VM-Series firewall on AWS, when you change the instance type, the firewall no longer has a serial number or a license. Additionally, if you manage this firewall using Panorama, it is no longer connected to Panorama.
|
||||
|
||||
## PLUG-380
|
||||
|
||||
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||
|
||||
## PAN-178194
|
||||
|
||||
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
|
||||
|
||||
## PAN-161121
|
||||
|
||||
On the Panorama management server, invalid reference errors occur when attempting to delete an address object (**Objects** > **Addresses**) after removing the address object reference from an address group (**Objects** > **Address Groups**) resulting in you being unable commit and push the configuration to managed firewalls.
|
||||
|
||||
**Workaround:** Log in to the [Panorama CLI](https://docs.paloaltonetworks.com/panorama/9-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli.html) and restart `configd`.
|
||||
|
||||
`admin>``debug software restart process configd`
|
||||
|
||||
## PAN-154247
|
||||
|
||||
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
|
||||
|
||||
**Workaround:** Log out and back in to the Panorama web interface.
|
||||
|
||||
## PAN-151909
|
||||
|
||||
On the Panorama management server, Preview Changes (**Commit** > **Commit to Panorama**) incorrectly displays an existing route as Added and the new route as an existing route in the Candidate Configuration when you configure a new virtual router route (**Network** > **Virtual Router**).
|
||||
|
||||
## PAN-150998
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. See PAN-OS 9.0.13 Addressed Issues.
|
||||
```
|
||||
|
||||
If you deploy a VM-Series firewall on VMware NSX that has been assigned a serial number that was used by a previously deactivated firewall, the new firewall might be deployed in a deactivated or partially deactivated state.
|
||||
|
||||
## PAN-150172
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. See PAN-OS 9.0.9-h1 Addressed Issues.
|
||||
```
|
||||
|
||||
Dataplane processes restart when attempting to access websites that have the `NotBefore` attribute less than or equal to Unix Epoch Time in the server certificate with forward proxy enabled.
|
||||
|
||||
## PAN-146573
|
||||
|
||||
PA-7000 Series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||
|
||||
## PAN-136701
|
||||
|
||||
```caveat
|
||||
PA-7000b Series firewalls only
|
||||
```
|
||||
|
||||
Packets for new sessions drop when handling predict sessions.
|
||||
|
||||
**Workaround:** Use the following CLI command to bypass this issue:
|
||||
|
||||
- `set session hwpredict disable yes`
|
||||
|
||||
To enable hwpredict again `set session hwpredict disable no`.
|
||||
|
||||
To verify the current settings, `show session hwpredict status`.
|
||||
|
||||
## PAN-131915
|
||||
|
||||
There is an issue when you implement a new firewall bootstrap with a USB drive where the bootstrap fails and displays the following error message: `no USB device found`.
|
||||
|
||||
**Workaround:** Perform a factory reset or run the `request system private-data-reset` CLI command and then proceed with bootstrapping.
|
||||
|
||||
## PAN-124956
|
||||
|
||||
There is an issue where VM-Series firewalls do not support packet buffer protection.
|
||||
|
||||
## PAN-120440
|
||||
|
||||
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||
|
||||
## PAN-120303
|
||||
|
||||
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||
|
||||
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||
|
||||
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||
2. **Commit** your changes.
|
||||
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||
4. **Commit** your changes.
|
||||
- Restart the firewall (devsrvr) process.
|
||||
1. Log in to the firewall CLI.
|
||||
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||
|
||||
## PAN-118414
|
||||
|
||||
```caveat
|
||||
PAN-OS 9.0.2 and later releases only
|
||||
```
|
||||
|
||||
There is an intermittent issue where a Panorama management server and managing Prisma™ Access or Cortex™ Data Lake fails to authorize one-time-password (OTP) submissions during the onboarding process.
|
||||
|
||||
**Workaround:** Downgrade to PAN-OS 9.0.1.
|
||||
|
||||
## PAN-117043
|
||||
|
||||
There is an issue on the Panorama management server and all supported firewalls where special characters contained in the tag names of the Security policy rules returns the following error message: `group-tag is invalid` when you commit or push a configuration.
|
||||
|
||||
**Workaround:** Modify the tags and group tags (**Objects** > **Tags**) to exclude special characters.
|
||||
|
||||
## PAN-116017
|
||||
|
||||
```caveat
|
||||
Google Cloud Platform (GCP) only
|
||||
```
|
||||
|
||||
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||
|
||||
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||
|
||||
## PAN-115816
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||
|
||||
**Workaround:** Reboot the firewall.
|
||||
|
||||
## PAN-115733
|
||||
|
||||
```caveat
|
||||
PAN-OS firewalls in an HA configuration only
|
||||
```
|
||||
|
||||
There is a rare issue where data interfaces do not come up after you reboot the firewall when running a C5 or M5 instance type in AWS.
|
||||
|
||||
**Workaround:** Reboot the firewall.
|
||||
|
||||
## PAN-114495
|
||||
|
||||
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||
|
||||
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||
|
||||
## PAN-113117
|
||||
|
||||
A newly launched firewall does not get its configuration from Panorama when it first connects if you installed the VM-Series plugin on Panorama. When a newly launched firewall that is bootstrapped connects to Panorama, a process restart occurs on Panorama. Upon restart, you are logged out of the user interface and you need to log in and push the device group and template configuration to the newly connected firewall.
|
||||
|
||||
## PAN-113098
|
||||
|
||||
In the firewall web interface, you can temporarily submit change requests for the following URL categories: insufficient-content, high-risk, medium-risk, low-risk, and newly-registered-domains. However, Palo Alto Networks does not support or process change requests for these categories.
|
||||
|
||||
## PAN-112983
|
||||
|
||||
```caveat
|
||||
Firewalls with multiple virtual systems only; no impact to Panorama
|
||||
```
|
||||
|
||||
If you select any Location other than Shared when you generate or import a new CA Certificate in a Certificate Profile (**Device** > **Certificate Management** > **Certificate Profile**), the firewall adds the newly generated or imported certificate to vsys1. For example, if you specify vsys3 as the **Location**, **Add** a CA Certificate, and then **Generate** a new certificate, the firewall adds the certificate to vsys1 instead of vsys3. When you click **OK** to configure the Certificate Profile, the firewall returns an `Operation Failed` error message because it sees a certificate for vsys1 added to vsys3.
|
||||
|
||||
**Workaround 1:**
|
||||
|
||||
1. Generate or import the new certificate in a Certificate Profile (**Device** > **Certificate Management** > **Certificates** > **Device Certificates**) and select the appropriate vsys **Location** when you generate or import the certificate.
|
||||
2. When you create or edit the Certificate Profile, specify the vsys **Location** and **Add** the certificate that you generated (or imported) from the list of existing certificates.
|
||||
|
||||
**Workaround 2:** When you generate or import a new certificate when you configure a Certificate Profile for a vsys other than vsys1, specify the **Location** as Shared.
|
||||
|
||||
## PAN-112694
|
||||
|
||||
```caveat
|
||||
Firewalls with multiple virtual systems only
|
||||
```
|
||||
|
||||
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||
|
||||
## PAN-112626
|
||||
|
||||
When you upgrade to PAN-OS 9.0 with a PAYG Bundle 2 license, the new DNS Security subscription is not available on your VM-Series firewall.
|
||||
|
||||
This subscription is included with the BYOL and VM-Series ELA when you upgrade.
|
||||
|
||||
## PAN-112562
|
||||
|
||||
The **Log Forwarding Card** (LFC) subinterface incorrectly uses the interface IP address instead of the subinterface IP address for all services that forward logs (such as syslog, email, and SNMP) for selected virtual systems.
|
||||
|
||||
## PAN-112456
|
||||
|
||||
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
|
||||
|
||||
## PAN-111928
|
||||
|
||||
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||
|
||||
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||
|
||||
## PAN-111866
|
||||
|
||||
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||
|
||||
**Workaround:** Perform one of the following tasks.
|
||||
|
||||
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||
- Manually select the devices that belong to the modified device group and template configurations.
|
||||
|
||||
## PAN-111729
|
||||
|
||||
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||
|
||||
## PAN-111670
|
||||
|
||||
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||
|
||||
## PAN-110794
|
||||
|
||||
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||
|
||||
## PAN-110603
|
||||
|
||||
In some cases, when a port on an PA-7000 Series 100Gbps Network Processor Card (NPC) has an SFP+ transceiver inserted but no cable is connected, the system detects a signal and attempts to tune and link with that port. As a result, if the device at the other end of the connection is rebooted or has an HA failover event, the link is sometimes held down for an extended period of time while the interface attempts to tune itself.
|
||||
|
||||
**Workaround:** Connect a cable to the installed SFP+ transceiver to allow the system to tune and link. Then, when you disconnect the cable, the system will correctly detect that the link is down. Alternatively, remove the SFP+ transceiver from the port.
|
||||
|
||||
## PAN-109526
|
||||
|
||||
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||
|
||||
## PAN-106989
|
||||
|
||||
There is a display-only issue on Panorama that results in a `commit failed` status for Template Last Commit State (**Panorama** > **Managed Devices** > **Summary**).
|
||||
|
||||
**Workaround:** Push templates to managed devices.
|
||||
|
||||
## PAN-106675
|
||||
|
||||
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||
|
||||
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||
|
||||
## PAN-105210
|
||||
|
||||
```caveat
|
||||
Panorama in FIPS mode only when managing non-FIPS firewalls
|
||||
```
|
||||
|
||||
You cannot configure a GlobalProtect portal on Panorama in FIPS mode when managing a non-FIPS firewall. If you attempt to do so, you will receive the following error message: `agent-user-override-key unexpected here Portal_fips.`
|
||||
|
||||
## PAN-104780
|
||||
|
||||
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||
|
||||
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||
|
||||
## PAN-103336
|
||||
|
||||
```caveat
|
||||
HA configurations only
|
||||
```
|
||||
|
||||
When you downgrade a VM-Series firewall on Azure from PAN-OS 9.0 to an earlier release, you do not receive warnings. Do not downgrade your firewall without saving and exporting your current configuration.
|
||||
|
||||
**Workaround:** Because HA is not supported in earlier versions of VM-Series firewalls on Azure, to prevent the loss of your configuration:
|
||||
|
||||
- Save and export the configuration before you downgrade.
|
||||
- After you downgrade, load the saved configuration and commit your changes. The firewall will resume operation without the HA configuration.
|
||||
|
||||
## PAN-103276
|
||||
|
||||
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||
|
||||
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||
|
||||
## PAN-103018
|
||||
|
||||
```caveat
|
||||
Panorama plugins
|
||||
```
|
||||
|
||||
When you use the AND/OR boolean operators to define the match criteria for Dynamic Address Groups on Panorama, the boolean operators do not function properly. The member IP addresses are not included in the address group as expected.
|
||||
|
||||
## PAN-101688
|
||||
|
||||
```caveat
|
||||
Panorama plugins
|
||||
```
|
||||
|
||||
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||
|
||||
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||
|
||||
## PAN-101537
|
||||
|
||||
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||
|
||||
**Workaround:** Specify the vsys in the query string:
|
||||
|
||||
`admin>` `set system target-vsys <vsys-name>`
|
||||
|
||||
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||
|
||||
## PAN-98803
|
||||
|
||||
If you configure the Panorama plugin to monitor virtual machines or endpoints in your AWS, Azure, or Cisco ACI environment without installing the NSX plugin, the IP-address-to-tag mappings for Dynamic Address Groups are not displayed on Panorama.
|
||||
|
||||
**Workaround:** Install the NSX plugin (you do not need to use the NSX plugin for the installation to resolve this display issue).
|
||||
|
||||
## PAN-98520
|
||||
|
||||
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||
|
||||
## PAN-97757
|
||||
|
||||
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||
|
||||
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||
|
||||
## PAN-97524
|
||||
|
||||
```caveat
|
||||
Panorama management server only
|
||||
```
|
||||
|
||||
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||
|
||||
## PAN-96985
|
||||
|
||||
The `request shutdown system` command does not shut down the Panorama management server.
|
||||
|
||||
## PAN-96960
|
||||
|
||||
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
|
||||
|
||||
## PAN-96446
|
||||
|
||||
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||
|
||||
## PAN-95773
|
||||
|
||||
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||
|
||||
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||
|
||||
## PAN-95717
|
||||
|
||||
After 30,000 or more end users log in to the GlobalProtect gateway within a two- to three-hour period, the firewall web interface responds slowly, commits take longer than expected or intermittently fail, and Tech Support File generation times out and fails.
|
||||
|
||||
## PAN-95602
|
||||
|
||||
In a deployment where a Log Collector connects to Panorama management servers in a high availability (HA) configuration, after you switch the Log Collector appliance to Panorama mode, commit operations fail on the appliance.
|
||||
|
||||
**Workaround:** Remove the following node from the running-config.xml file on the Log Collector before switching it to Panorama mode: `devices/entry[@name='localhost.localdomain']/deviceconfig/system/panorama-server-2`
|
||||
|
||||
## PAN-95511
|
||||
|
||||
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||
|
||||
## PAN-95028
|
||||
|
||||
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||
|
||||
## PAN-94966
|
||||
|
||||
After you delete disconnected and connected Terminal Server (TS) agents in the same operation, the firewall still displays the IP address-to-port-user mappings (`show user ip-port-user-mapping` CLI command) for the disconnected TS agents you deleted (**Device** > **User Identification** > **Terminal Services Agents**).
|
||||
|
||||
**Workaround:** Do not delete both disconnected and connected TS agents in the same operation.
|
||||
|
||||
## PAN-94846
|
||||
|
||||
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||
|
||||
## PAN-94093
|
||||
|
||||
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||
|
||||
## PAN-93968
|
||||
|
||||
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||
|
||||
## PAN-93842
|
||||
|
||||
The logging status of a Panorama Log Collector deployed on AWS or Azure displays as disconnected when you configure the ethernet1/1 to ethernet1/5 interfaces for log collection (**Panorama** > **Managed Collectors** > **Interfaces**). This results in firewalls not sending logs to the Log Collector.
|
||||
|
||||
**Workaround:** Configure the management (MGT) interface for log collection.
|
||||
|
||||
## PAN-93607
|
||||
|
||||
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||
|
||||
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||
|
||||
## PAN-93532
|
||||
|
||||
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||
|
||||
## PAN-93193
|
||||
|
||||
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||
|
||||
- Switch to the firewall **Context** on the Panorama management server.
|
||||
- Commit changes when a dynamic update is being installed.
|
||||
- Generate a custom report when a dynamic update is being installed.
|
||||
- Generate custom reports during a commit.
|
||||
|
||||
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||
|
||||
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||
|
||||
## PAN-91802
|
||||
|
||||
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||
|
||||
## PAN-86903
|
||||
|
||||
In rare cases, PA-800 Series firewalls shut themselves down due to a false over-current measurement.
|
||||
|
||||
## PAN-83610
|
||||
|
||||
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||
|
||||
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session off load for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||
|
||||
## PAN-83598
|
||||
|
||||
VM-Series firewalls cannot monitor more than 500 virtual machine (VM) information sources (**Device** > **VM Information Sources**).
|
||||
|
||||
## PAN-83236
|
||||
|
||||
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||
|
||||
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||
|
||||
## PAN-83215
|
||||
|
||||
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||
|
||||
## PAN-81521
|
||||
|
||||
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||
|
||||
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||
|
||||
## PAN-79423
|
||||
|
||||
Panorama cannot push address group objects from device groups to managed firewalls when zones specify the objects in the User Identification ACL include or exclude lists (**Network** > **Zones**) and the **Share Unused Address and Service Objects with Devices** option is disabled (**Panorama** > **Setup** > **Management** > **Panorama Settings**).
|
||||
|
||||
## PAN-77125
|
||||
|
||||
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||
|
||||
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||
|
||||
## PAN-75457
|
||||
|
||||
```caveat
|
||||
PAN-OS 8.0.1 and later releases
|
||||
```
|
||||
|
||||
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||
|
||||
## PAN-73530
|
||||
|
||||
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||
|
||||
## PAN-73401
|
||||
|
||||
```caveat
|
||||
PAN-OS 8.0.1 and later releases
|
||||
```
|
||||
|
||||
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||
|
||||
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||
|
||||
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||
|
||||
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||
- Configure a worker list on the cluster controller:
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||
or
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||
|
||||
## PAN-71329
|
||||
|
||||
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
|
||||
|
||||
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
|
||||
|
||||
## PAN-70906
|
||||
|
||||
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||
|
||||
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||
|
||||
## PAN-69505
|
||||
|
||||
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||
|
||||
## PAN-41558
|
||||
|
||||
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||
|
||||
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||
|
||||
## PAN-40079
|
||||
|
||||
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||
|
||||
## PAN-39636
|
||||
|
||||
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||
|
||||
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||
|
||||
## PAN-38255
|
||||
|
||||
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||
|
||||
## PAN-31832
|
||||
|
||||
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||
|
||||
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||
|
||||
## PAN-25046
|
||||
|
||||
Firewalls store SSH host keys used for SCP log exports in the known hosts file. In an HA deployment, PAN-OS synchronizes the SCP log export configuration between the firewall HA peers (**Device** > **Scheduled Log Export**), but not the known host file. When a failover occurs, the SCP log export fails.
|
||||
|
||||
**Workaround:** Log in to each peer in HA, select **Device** > **Scheduled Log Export** > **<log_export_configuration>**, and **Test SCP server connection** to confirm the host key so that SCP log forwarding continues to work after a failover.
|
||||
@@ -0,0 +1,614 @@
|
||||
---
|
||||
type: Known
|
||||
product: PAN-OS
|
||||
version: 9.0.13
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||
|
||||
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
A Panorama management server running PAN-OS 9.0 does not currently support management of appliances running WildFire 7.1 or earlier releases. Even though these management options are visible on the Panorama 9.0 web interface (**Panorama** > **Managed WildFire Clusters** and **Panorama** > **Managed WildFire Appliances**), making changes to these settings for appliances running WildFire 7.1 or an earlier release has no effect.
|
||||
|
||||
## WF500-4200
|
||||
|
||||
The Create Date shown when using the `show wildfire global sample-status sha256 equal<hash>` or `show wildfire global sample-analysis` CLI command is two hours behind the actual time for WF-500 appliance samples.
|
||||
|
||||
## PLUG-1854
|
||||
|
||||
```caveat
|
||||
PAN-OS 9.0.2 and later releases on AWS and GCP only
|
||||
```
|
||||
|
||||
You cannot swap the management interface.
|
||||
|
||||
## PLUG-1827
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
The firewall drops packets due to larger than expected packet sizes when Accelerated networking is enabled on the firewall (**Settings** > **Networking**).
|
||||
|
||||
## PLUG-1709
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
There is an intermittent issue where the secondary IP address becomes associated with the passive firewall after multiple failovers.
|
||||
|
||||
**Workaround:** Reassign IP addresses to the active and passive firewalls in Azure as needed.
|
||||
|
||||
## PLUG-1694
|
||||
|
||||
```caveat
|
||||
PAYG licenses only
|
||||
```
|
||||
|
||||
Your pay-as-you-go (PAYG) license is not retained when you upgrade from a PAN-OS 8.1 release to a PAN-OS 9.0 release.
|
||||
|
||||
**Workaround:** Upgrade to VM-Series plugin 1.0.2 (or later) after you upgrade to a PAN-OS 9.0 release and then reboot the firewall to recover your PAYG license.
|
||||
|
||||
## PLUG-1681
|
||||
|
||||
If you bootstrap a PAN-OS 9.0.1 image while using VM-Series plugin 1.0.0, the firewall will not apply the capacity license. To downgrade the VM-Series plugin from version 1.0.2 to 1.0.0, first bootstrap the PAN-OS 9.0.1 image and then downgrade the plugin.
|
||||
|
||||
## PLUG-1642
|
||||
|
||||
```caveat
|
||||
This issue is resolved with VM-Series plugin 1.0.2.
|
||||
```
|
||||
|
||||
After a high availability (HA) failover, the dataplane interface on a VM-Series firewall on Azure with Accelerated Networking (SR-IOV) becomes disabled when, as a result of the failover, the secondary IP address is detached from or attached to the firewall and moved to its HA peer.
|
||||
|
||||
## PLUG-1503
|
||||
|
||||
```caveat
|
||||
This issue is resolved with VM-Series plugin 1.0.3.
|
||||
```
|
||||
|
||||
When a VM-Series firewall on AWS running on a C5 or M5 instance experiences a high availability (HA) failover, the dataplane interfaces from the previously active firewall are not moved to the newly active (previously passive) peer.
|
||||
|
||||
**Workaround:** Check for the latest VM-Series plugin version and install the VM-Series plugin 9.0.0 version; the built-in version is 9.0.0-c29.
|
||||
|
||||
## PLUG-1074
|
||||
|
||||
On the VM-Series firewall on AWS, when you change the instance type, the firewall no longer has a serial number or a license. Additionally, if you manage this firewall using Panorama, it is no longer connected to Panorama.
|
||||
|
||||
## PLUG-380
|
||||
|
||||
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||
|
||||
## PAN-178194
|
||||
|
||||
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
|
||||
|
||||
## PAN-161121
|
||||
|
||||
On the Panorama management server, invalid reference errors occur when attempting to delete an address object (**Objects** > **Addresses**) after removing the address object reference from an address group (**Objects** > **Address Groups**) resulting in you being unable commit and push the configuration to managed firewalls.
|
||||
|
||||
**Workaround:** Log in to the [Panorama CLI](https://docs.paloaltonetworks.com/panorama/9-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli.html) and restart `configd`.
|
||||
|
||||
`admin>``debug software restart process configd`
|
||||
|
||||
## PAN-154247
|
||||
|
||||
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
|
||||
|
||||
**Workaround:** Log out and back in to the Panorama web interface.
|
||||
|
||||
## PAN-151909
|
||||
|
||||
On the Panorama management server, Preview Changes (**Commit** > **Commit to Panorama**) incorrectly displays an existing route as Added and the new route as an existing route in the Candidate Configuration when you configure a new virtual router route (**Network** > **Virtual Router**).
|
||||
|
||||
## PAN-150172
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. See PAN-OS 9.0.9-h1 Addressed Issues.
|
||||
```
|
||||
|
||||
Dataplane processes restart when attempting to access websites that have the `NotBefore` attribute less than or equal to Unix Epoch Time in the server certificate with forward proxy enabled.
|
||||
|
||||
## PAN-146573
|
||||
|
||||
PA-7000 Series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||
|
||||
## PAN-136701
|
||||
|
||||
```caveat
|
||||
PA-7000b Series firewalls only
|
||||
```
|
||||
|
||||
Packets for new sessions drop when handling predict sessions.
|
||||
|
||||
**Workaround:** Use the following CLI command to bypass this issue:
|
||||
|
||||
- `set session hwpredict disable yes`
|
||||
|
||||
To enable hwpredict again `set session hwpredict disable no`.
|
||||
|
||||
To verify the current settings, `show session hwpredict status`.
|
||||
|
||||
## PAN-131915
|
||||
|
||||
There is an issue when you implement a new firewall bootstrap with a USB drive where the bootstrap fails and displays the following error message: `no USB device found`.
|
||||
|
||||
**Workaround:** Perform a factory reset or run the `request system private-data-reset` CLI command and then proceed with bootstrapping.
|
||||
|
||||
## PAN-124956
|
||||
|
||||
There is an issue where VM-Series firewalls do not support packet buffer protection.
|
||||
|
||||
## PAN-120440
|
||||
|
||||
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||
|
||||
## PAN-120303
|
||||
|
||||
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||
|
||||
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||
|
||||
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||
2. **Commit** your changes.
|
||||
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||
4. **Commit** your changes.
|
||||
- Restart the firewall (devsrvr) process.
|
||||
1. Log in to the firewall CLI.
|
||||
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||
|
||||
## PAN-118414
|
||||
|
||||
```caveat
|
||||
PAN-OS 9.0.2 and later releases only
|
||||
```
|
||||
|
||||
There is an intermittent issue where a Panorama management server and managing Prisma™ Access or Cortex™ Data Lake fails to authorize one-time-password (OTP) submissions during the onboarding process.
|
||||
|
||||
**Workaround:** Downgrade to PAN-OS 9.0.1.
|
||||
|
||||
## PAN-117043
|
||||
|
||||
There is an issue on the Panorama management server and all supported firewalls where special characters contained in the tag names of the Security policy rules returns the following error message: `group-tag is invalid` when you commit or push a configuration.
|
||||
|
||||
**Workaround:** Modify the tags and group tags (**Objects** > **Tags**) to exclude special characters.
|
||||
|
||||
## PAN-116017
|
||||
|
||||
```caveat
|
||||
Google Cloud Platform (GCP) only
|
||||
```
|
||||
|
||||
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||
|
||||
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||
|
||||
## PAN-115816
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||
|
||||
**Workaround:** Reboot the firewall.
|
||||
|
||||
## PAN-115733
|
||||
|
||||
```caveat
|
||||
PAN-OS firewalls in an HA configuration only
|
||||
```
|
||||
|
||||
There is a rare issue where data interfaces do not come up after you reboot the firewall when running a C5 or M5 instance type in AWS.
|
||||
|
||||
**Workaround:** Reboot the firewall.
|
||||
|
||||
## PAN-114495
|
||||
|
||||
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||
|
||||
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||
|
||||
## PAN-113117
|
||||
|
||||
A newly launched firewall does not get its configuration from Panorama when it first connects if you installed the VM-Series plugin on Panorama. When a newly launched firewall that is bootstrapped connects to Panorama, a process restart occurs on Panorama. Upon restart, you are logged out of the user interface and you need to log in and push the device group and template configuration to the newly connected firewall.
|
||||
|
||||
## PAN-113098
|
||||
|
||||
In the firewall web interface, you can temporarily submit change requests for the following URL categories: insufficient-content, high-risk, medium-risk, low-risk, and newly-registered-domains. However, Palo Alto Networks does not support or process change requests for these categories.
|
||||
|
||||
## PAN-112983
|
||||
|
||||
```caveat
|
||||
Firewalls with multiple virtual systems only; no impact to Panorama
|
||||
```
|
||||
|
||||
If you select any Location other than Shared when you generate or import a new CA Certificate in a Certificate Profile (**Device** > **Certificate Management** > **Certificate Profile**), the firewall adds the newly generated or imported certificate to vsys1. For example, if you specify vsys3 as the **Location**, **Add** a CA Certificate, and then **Generate** a new certificate, the firewall adds the certificate to vsys1 instead of vsys3. When you click **OK** to configure the Certificate Profile, the firewall returns an `Operation Failed` error message because it sees a certificate for vsys1 added to vsys3.
|
||||
|
||||
**Workaround 1:**
|
||||
|
||||
1. Generate or import the new certificate in a Certificate Profile (**Device** > **Certificate Management** > **Certificates** > **Device Certificates**) and select the appropriate vsys **Location** when you generate or import the certificate.
|
||||
2. When you create or edit the Certificate Profile, specify the vsys **Location** and **Add** the certificate that you generated (or imported) from the list of existing certificates.
|
||||
|
||||
**Workaround 2:** When you generate or import a new certificate when you configure a Certificate Profile for a vsys other than vsys1, specify the **Location** as Shared.
|
||||
|
||||
## PAN-112694
|
||||
|
||||
```caveat
|
||||
Firewalls with multiple virtual systems only
|
||||
```
|
||||
|
||||
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||
|
||||
## PAN-112626
|
||||
|
||||
When you upgrade to PAN-OS 9.0 with a PAYG Bundle 2 license, the new DNS Security subscription is not available on your VM-Series firewall.
|
||||
|
||||
This subscription is included with the BYOL and VM-Series ELA when you upgrade.
|
||||
|
||||
## PAN-112562
|
||||
|
||||
The **Log Forwarding Card** (LFC) subinterface incorrectly uses the interface IP address instead of the subinterface IP address for all services that forward logs (such as syslog, email, and SNMP) for selected virtual systems.
|
||||
|
||||
## PAN-112456
|
||||
|
||||
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
|
||||
|
||||
## PAN-111928
|
||||
|
||||
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||
|
||||
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||
|
||||
## PAN-111866
|
||||
|
||||
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||
|
||||
**Workaround:** Perform one of the following tasks.
|
||||
|
||||
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||
- Manually select the devices that belong to the modified device group and template configurations.
|
||||
|
||||
## PAN-111729
|
||||
|
||||
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||
|
||||
## PAN-111670
|
||||
|
||||
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||
|
||||
## PAN-110794
|
||||
|
||||
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||
|
||||
## PAN-110603
|
||||
|
||||
In some cases, when a port on an PA-7000 Series 100Gbps Network Processor Card (NPC) has an SFP+ transceiver inserted but no cable is connected, the system detects a signal and attempts to tune and link with that port. As a result, if the device at the other end of the connection is rebooted or has an HA failover event, the link is sometimes held down for an extended period of time while the interface attempts to tune itself.
|
||||
|
||||
**Workaround:** Connect a cable to the installed SFP+ transceiver to allow the system to tune and link. Then, when you disconnect the cable, the system will correctly detect that the link is down. Alternatively, remove the SFP+ transceiver from the port.
|
||||
|
||||
## PAN-109526
|
||||
|
||||
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||
|
||||
## PAN-106989
|
||||
|
||||
There is a display-only issue on Panorama that results in a `commit failed` status for Template Last Commit State (**Panorama** > **Managed Devices** > **Summary**).
|
||||
|
||||
**Workaround:** Push templates to managed devices.
|
||||
|
||||
## PAN-106675
|
||||
|
||||
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||
|
||||
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||
|
||||
## PAN-105210
|
||||
|
||||
```caveat
|
||||
Panorama in FIPS mode only when managing non-FIPS firewalls
|
||||
```
|
||||
|
||||
You cannot configure a GlobalProtect portal on Panorama in FIPS mode when managing a non-FIPS firewall. If you attempt to do so, you will receive the following error message: `agent-user-override-key unexpected here Portal_fips.`
|
||||
|
||||
## PAN-104780
|
||||
|
||||
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||
|
||||
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||
|
||||
## PAN-103336
|
||||
|
||||
```caveat
|
||||
HA configurations only
|
||||
```
|
||||
|
||||
When you downgrade a VM-Series firewall on Azure from PAN-OS 9.0 to an earlier release, you do not receive warnings. Do not downgrade your firewall without saving and exporting your current configuration.
|
||||
|
||||
**Workaround:** Because HA is not supported in earlier versions of VM-Series firewalls on Azure, to prevent the loss of your configuration:
|
||||
|
||||
- Save and export the configuration before you downgrade.
|
||||
- After you downgrade, load the saved configuration and commit your changes. The firewall will resume operation without the HA configuration.
|
||||
|
||||
## PAN-103276
|
||||
|
||||
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||
|
||||
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||
|
||||
## PAN-103018
|
||||
|
||||
```caveat
|
||||
Panorama plugins
|
||||
```
|
||||
|
||||
When you use the AND/OR boolean operators to define the match criteria for Dynamic Address Groups on Panorama, the boolean operators do not function properly. The member IP addresses are not included in the address group as expected.
|
||||
|
||||
## PAN-101688
|
||||
|
||||
```caveat
|
||||
Panorama plugins
|
||||
```
|
||||
|
||||
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||
|
||||
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||
|
||||
## PAN-101537
|
||||
|
||||
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||
|
||||
**Workaround:** Specify the vsys in the query string:
|
||||
|
||||
`admin>` `set system target-vsys <vsys-name>`
|
||||
|
||||
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||
|
||||
## PAN-98803
|
||||
|
||||
If you configure the Panorama plugin to monitor virtual machines or endpoints in your AWS, Azure, or Cisco ACI environment without installing the NSX plugin, the IP-address-to-tag mappings for Dynamic Address Groups are not displayed on Panorama.
|
||||
|
||||
**Workaround:** Install the NSX plugin (you do not need to use the NSX plugin for the installation to resolve this display issue).
|
||||
|
||||
## PAN-98520
|
||||
|
||||
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||
|
||||
## PAN-97757
|
||||
|
||||
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||
|
||||
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||
|
||||
## PAN-97524
|
||||
|
||||
```caveat
|
||||
Panorama management server only
|
||||
```
|
||||
|
||||
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||
|
||||
## PAN-96985
|
||||
|
||||
The `request shutdown system` command does not shut down the Panorama management server.
|
||||
|
||||
## PAN-96960
|
||||
|
||||
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
|
||||
|
||||
## PAN-96446
|
||||
|
||||
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||
|
||||
## PAN-95773
|
||||
|
||||
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||
|
||||
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||
|
||||
## PAN-95717
|
||||
|
||||
After 30,000 or more end users log in to the GlobalProtect gateway within a two- to three-hour period, the firewall web interface responds slowly, commits take longer than expected or intermittently fail, and Tech Support File generation times out and fails.
|
||||
|
||||
## PAN-95602
|
||||
|
||||
In a deployment where a Log Collector connects to Panorama management servers in a high availability (HA) configuration, after you switch the Log Collector appliance to Panorama mode, commit operations fail on the appliance.
|
||||
|
||||
**Workaround:** Remove the following node from the running-config.xml file on the Log Collector before switching it to Panorama mode: `devices/entry[@name='localhost.localdomain']/deviceconfig/system/panorama-server-2`
|
||||
|
||||
## PAN-95511
|
||||
|
||||
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||
|
||||
## PAN-95028
|
||||
|
||||
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||
|
||||
## PAN-94966
|
||||
|
||||
After you delete disconnected and connected Terminal Server (TS) agents in the same operation, the firewall still displays the IP address-to-port-user mappings (`show user ip-port-user-mapping` CLI command) for the disconnected TS agents you deleted (**Device** > **User Identification** > **Terminal Services Agents**).
|
||||
|
||||
**Workaround:** Do not delete both disconnected and connected TS agents in the same operation.
|
||||
|
||||
## PAN-94846
|
||||
|
||||
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||
|
||||
## PAN-94093
|
||||
|
||||
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||
|
||||
## PAN-93968
|
||||
|
||||
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||
|
||||
## PAN-93842
|
||||
|
||||
The logging status of a Panorama Log Collector deployed on AWS or Azure displays as disconnected when you configure the ethernet1/1 to ethernet1/5 interfaces for log collection (**Panorama** > **Managed Collectors** > **Interfaces**). This results in firewalls not sending logs to the Log Collector.
|
||||
|
||||
**Workaround:** Configure the management (MGT) interface for log collection.
|
||||
|
||||
## PAN-93607
|
||||
|
||||
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||
|
||||
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||
|
||||
## PAN-93532
|
||||
|
||||
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||
|
||||
## PAN-93193
|
||||
|
||||
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||
|
||||
- Switch to the firewall **Context** on the Panorama management server.
|
||||
- Commit changes when a dynamic update is being installed.
|
||||
- Generate a custom report when a dynamic update is being installed.
|
||||
- Generate custom reports during a commit.
|
||||
|
||||
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||
|
||||
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||
|
||||
## PAN-91802
|
||||
|
||||
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||
|
||||
## PAN-86903
|
||||
|
||||
In rare cases, PA-800 Series firewalls shut themselves down due to a false over-current measurement.
|
||||
|
||||
## PAN-83610
|
||||
|
||||
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||
|
||||
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session off load for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||
|
||||
## PAN-83598
|
||||
|
||||
VM-Series firewalls cannot monitor more than 500 virtual machine (VM) information sources (**Device** > **VM Information Sources**).
|
||||
|
||||
## PAN-83236
|
||||
|
||||
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||
|
||||
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||
|
||||
## PAN-83215
|
||||
|
||||
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||
|
||||
## PAN-81521
|
||||
|
||||
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||
|
||||
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||
|
||||
## PAN-79423
|
||||
|
||||
Panorama cannot push address group objects from device groups to managed firewalls when zones specify the objects in the User Identification ACL include or exclude lists (**Network** > **Zones**) and the **Share Unused Address and Service Objects with Devices** option is disabled (**Panorama** > **Setup** > **Management** > **Panorama Settings**).
|
||||
|
||||
## PAN-77125
|
||||
|
||||
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||
|
||||
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||
|
||||
## PAN-75457
|
||||
|
||||
```caveat
|
||||
PAN-OS 8.0.1 and later releases
|
||||
```
|
||||
|
||||
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||
|
||||
## PAN-73530
|
||||
|
||||
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||
|
||||
## PAN-73401
|
||||
|
||||
```caveat
|
||||
PAN-OS 8.0.1 and later releases
|
||||
```
|
||||
|
||||
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||
|
||||
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||
|
||||
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||
|
||||
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||
- Configure a worker list on the cluster controller:
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||
or
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||
|
||||
## PAN-71329
|
||||
|
||||
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
|
||||
|
||||
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
|
||||
|
||||
## PAN-70906
|
||||
|
||||
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||
|
||||
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||
|
||||
## PAN-69505
|
||||
|
||||
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||
|
||||
## PAN-41558
|
||||
|
||||
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||
|
||||
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||
|
||||
## PAN-40079
|
||||
|
||||
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||
|
||||
## PAN-39636
|
||||
|
||||
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||
|
||||
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||
|
||||
## PAN-38255
|
||||
|
||||
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||
|
||||
## PAN-31832
|
||||
|
||||
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||
|
||||
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||
|
||||
## PAN-25046
|
||||
|
||||
Firewalls store SSH host keys used for SCP log exports in the known hosts file. In an HA deployment, PAN-OS synchronizes the SCP log export configuration between the firewall HA peers (**Device** > **Scheduled Log Export**), but not the known host file. When a failover occurs, the SCP log export fails.
|
||||
|
||||
**Workaround:** Log in to each peer in HA, select **Device** > **Scheduled Log Export** > **<log_export_configuration>**, and **Test SCP server connection** to confirm the host key so that SCP log forwarding continues to work after a failover.
|
||||
@@ -0,0 +1,614 @@
|
||||
---
|
||||
type: Known
|
||||
product: PAN-OS
|
||||
version: 9.0.14
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||
|
||||
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
A Panorama management server running PAN-OS 9.0 does not currently support management of appliances running WildFire 7.1 or earlier releases. Even though these management options are visible on the Panorama 9.0 web interface (**Panorama** > **Managed WildFire Clusters** and **Panorama** > **Managed WildFire Appliances**), making changes to these settings for appliances running WildFire 7.1 or an earlier release has no effect.
|
||||
|
||||
## WF500-4200
|
||||
|
||||
The Create Date shown when using the `show wildfire global sample-status sha256 equal<hash>` or `show wildfire global sample-analysis` CLI command is two hours behind the actual time for WF-500 appliance samples.
|
||||
|
||||
## PLUG-1854
|
||||
|
||||
```caveat
|
||||
PAN-OS 9.0.2 and later releases on AWS and GCP only
|
||||
```
|
||||
|
||||
You cannot swap the management interface.
|
||||
|
||||
## PLUG-1827
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
The firewall drops packets due to larger than expected packet sizes when Accelerated networking is enabled on the firewall (**Settings** > **Networking**).
|
||||
|
||||
## PLUG-1709
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
There is an intermittent issue where the secondary IP address becomes associated with the passive firewall after multiple failovers.
|
||||
|
||||
**Workaround:** Reassign IP addresses to the active and passive firewalls in Azure as needed.
|
||||
|
||||
## PLUG-1694
|
||||
|
||||
```caveat
|
||||
PAYG licenses only
|
||||
```
|
||||
|
||||
Your pay-as-you-go (PAYG) license is not retained when you upgrade from a PAN-OS 8.1 release to a PAN-OS 9.0 release.
|
||||
|
||||
**Workaround:** Upgrade to VM-Series plugin 1.0.2 (or later) after you upgrade to a PAN-OS 9.0 release and then reboot the firewall to recover your PAYG license.
|
||||
|
||||
## PLUG-1681
|
||||
|
||||
If you bootstrap a PAN-OS 9.0.1 image while using VM-Series plugin 1.0.0, the firewall will not apply the capacity license. To downgrade the VM-Series plugin from version 1.0.2 to 1.0.0, first bootstrap the PAN-OS 9.0.1 image and then downgrade the plugin.
|
||||
|
||||
## PLUG-1642
|
||||
|
||||
```caveat
|
||||
This issue is resolved with VM-Series plugin 1.0.2.
|
||||
```
|
||||
|
||||
After a high availability (HA) failover, the dataplane interface on a VM-Series firewall on Azure with Accelerated Networking (SR-IOV) becomes disabled when, as a result of the failover, the secondary IP address is detached from or attached to the firewall and moved to its HA peer.
|
||||
|
||||
## PLUG-1503
|
||||
|
||||
```caveat
|
||||
This issue is resolved with VM-Series plugin 1.0.3.
|
||||
```
|
||||
|
||||
When a VM-Series firewall on AWS running on a C5 or M5 instance experiences a high availability (HA) failover, the dataplane interfaces from the previously active firewall are not moved to the newly active (previously passive) peer.
|
||||
|
||||
**Workaround:** Check for the latest VM-Series plugin version and install the VM-Series plugin 9.0.0 version; the built-in version is 9.0.0-c29.
|
||||
|
||||
## PLUG-1074
|
||||
|
||||
On the VM-Series firewall on AWS, when you change the instance type, the firewall no longer has a serial number or a license. Additionally, if you manage this firewall using Panorama, it is no longer connected to Panorama.
|
||||
|
||||
## PLUG-380
|
||||
|
||||
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||
|
||||
## PAN-178194
|
||||
|
||||
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
|
||||
|
||||
## PAN-161121
|
||||
|
||||
On the Panorama management server, invalid reference errors occur when attempting to delete an address object (**Objects** > **Addresses**) after removing the address object reference from an address group (**Objects** > **Address Groups**) resulting in you being unable commit and push the configuration to managed firewalls.
|
||||
|
||||
**Workaround:** Log in to the [Panorama CLI](https://docs.paloaltonetworks.com/panorama/9-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli.html) and restart `configd`.
|
||||
|
||||
`admin>``debug software restart process configd`
|
||||
|
||||
## PAN-154247
|
||||
|
||||
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
|
||||
|
||||
**Workaround:** Log out and back in to the Panorama web interface.
|
||||
|
||||
## PAN-151909
|
||||
|
||||
On the Panorama management server, Preview Changes (**Commit** > **Commit to Panorama**) incorrectly displays an existing route as Added and the new route as an existing route in the Candidate Configuration when you configure a new virtual router route (**Network** > **Virtual Router**).
|
||||
|
||||
## PAN-150172
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. See PAN-OS 9.0.9-h1 Addressed Issues.
|
||||
```
|
||||
|
||||
Dataplane processes restart when attempting to access websites that have the `NotBefore` attribute less than or equal to Unix Epoch Time in the server certificate with forward proxy enabled.
|
||||
|
||||
## PAN-146573
|
||||
|
||||
PA-7000 Series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||
|
||||
## PAN-136701
|
||||
|
||||
```caveat
|
||||
PA-7000b Series firewalls only
|
||||
```
|
||||
|
||||
Packets for new sessions drop when handling predict sessions.
|
||||
|
||||
**Workaround:** Use the following CLI command to bypass this issue:
|
||||
|
||||
- `set session hwpredict disable yes`
|
||||
|
||||
To enable hwpredict again `set session hwpredict disable no`.
|
||||
|
||||
To verify the current settings, `show session hwpredict status`.
|
||||
|
||||
## PAN-131915
|
||||
|
||||
There is an issue when you implement a new firewall bootstrap with a USB drive where the bootstrap fails and displays the following error message: `no USB device found`.
|
||||
|
||||
**Workaround:** Perform a factory reset or run the `request system private-data-reset` CLI command and then proceed with bootstrapping.
|
||||
|
||||
## PAN-124956
|
||||
|
||||
There is an issue where VM-Series firewalls do not support packet buffer protection.
|
||||
|
||||
## PAN-120440
|
||||
|
||||
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||
|
||||
## PAN-120303
|
||||
|
||||
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||
|
||||
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||
|
||||
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||
2. **Commit** your changes.
|
||||
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||
4. **Commit** your changes.
|
||||
- Restart the firewall (devsrvr) process.
|
||||
1. Log in to the firewall CLI.
|
||||
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||
|
||||
## PAN-118414
|
||||
|
||||
```caveat
|
||||
PAN-OS 9.0.2 and later releases only
|
||||
```
|
||||
|
||||
There is an intermittent issue where a Panorama management server and managing Prisma™ Access or Cortex™ Data Lake fails to authorize one-time-password (OTP) submissions during the onboarding process.
|
||||
|
||||
**Workaround:** Downgrade to PAN-OS 9.0.1.
|
||||
|
||||
## PAN-117043
|
||||
|
||||
There is an issue on the Panorama management server and all supported firewalls where special characters contained in the tag names of the Security policy rules returns the following error message: `group-tag is invalid` when you commit or push a configuration.
|
||||
|
||||
**Workaround:** Modify the tags and group tags (**Objects** > **Tags**) to exclude special characters.
|
||||
|
||||
## PAN-116017
|
||||
|
||||
```caveat
|
||||
Google Cloud Platform (GCP) only
|
||||
```
|
||||
|
||||
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||
|
||||
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||
|
||||
## PAN-115816
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||
|
||||
**Workaround:** Reboot the firewall.
|
||||
|
||||
## PAN-115733
|
||||
|
||||
```caveat
|
||||
PAN-OS firewalls in an HA configuration only
|
||||
```
|
||||
|
||||
There is a rare issue where data interfaces do not come up after you reboot the firewall when running a C5 or M5 instance type in AWS.
|
||||
|
||||
**Workaround:** Reboot the firewall.
|
||||
|
||||
## PAN-114495
|
||||
|
||||
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||
|
||||
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||
|
||||
## PAN-113117
|
||||
|
||||
A newly launched firewall does not get its configuration from Panorama when it first connects if you installed the VM-Series plugin on Panorama. When a newly launched firewall that is bootstrapped connects to Panorama, a process restart occurs on Panorama. Upon restart, you are logged out of the user interface and you need to log in and push the device group and template configuration to the newly connected firewall.
|
||||
|
||||
## PAN-113098
|
||||
|
||||
In the firewall web interface, you can temporarily submit change requests for the following URL categories: insufficient-content, high-risk, medium-risk, low-risk, and newly-registered-domains. However, Palo Alto Networks does not support or process change requests for these categories.
|
||||
|
||||
## PAN-112983
|
||||
|
||||
```caveat
|
||||
Firewalls with multiple virtual systems only; no impact to Panorama
|
||||
```
|
||||
|
||||
If you select any Location other than Shared when you generate or import a new CA Certificate in a Certificate Profile (**Device** > **Certificate Management** > **Certificate Profile**), the firewall adds the newly generated or imported certificate to vsys1. For example, if you specify vsys3 as the **Location**, **Add** a CA Certificate, and then **Generate** a new certificate, the firewall adds the certificate to vsys1 instead of vsys3. When you click **OK** to configure the Certificate Profile, the firewall returns an `Operation Failed` error message because it sees a certificate for vsys1 added to vsys3.
|
||||
|
||||
**Workaround 1:**
|
||||
|
||||
1. Generate or import the new certificate in a Certificate Profile (**Device** > **Certificate Management** > **Certificates** > **Device Certificates**) and select the appropriate vsys **Location** when you generate or import the certificate.
|
||||
2. When you create or edit the Certificate Profile, specify the vsys **Location** and **Add** the certificate that you generated (or imported) from the list of existing certificates.
|
||||
|
||||
**Workaround 2:** When you generate or import a new certificate when you configure a Certificate Profile for a vsys other than vsys1, specify the **Location** as Shared.
|
||||
|
||||
## PAN-112694
|
||||
|
||||
```caveat
|
||||
Firewalls with multiple virtual systems only
|
||||
```
|
||||
|
||||
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||
|
||||
## PAN-112626
|
||||
|
||||
When you upgrade to PAN-OS 9.0 with a PAYG Bundle 2 license, the new DNS Security subscription is not available on your VM-Series firewall.
|
||||
|
||||
This subscription is included with the BYOL and VM-Series ELA when you upgrade.
|
||||
|
||||
## PAN-112562
|
||||
|
||||
The **Log Forwarding Card** (LFC) subinterface incorrectly uses the interface IP address instead of the subinterface IP address for all services that forward logs (such as syslog, email, and SNMP) for selected virtual systems.
|
||||
|
||||
## PAN-112456
|
||||
|
||||
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
|
||||
|
||||
## PAN-111928
|
||||
|
||||
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||
|
||||
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||
|
||||
## PAN-111866
|
||||
|
||||
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||
|
||||
**Workaround:** Perform one of the following tasks.
|
||||
|
||||
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||
- Manually select the devices that belong to the modified device group and template configurations.
|
||||
|
||||
## PAN-111729
|
||||
|
||||
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||
|
||||
## PAN-111670
|
||||
|
||||
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||
|
||||
## PAN-110794
|
||||
|
||||
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||
|
||||
## PAN-110603
|
||||
|
||||
In some cases, when a port on an PA-7000 Series 100Gbps Network Processor Card (NPC) has an SFP+ transceiver inserted but no cable is connected, the system detects a signal and attempts to tune and link with that port. As a result, if the device at the other end of the connection is rebooted or has an HA failover event, the link is sometimes held down for an extended period of time while the interface attempts to tune itself.
|
||||
|
||||
**Workaround:** Connect a cable to the installed SFP+ transceiver to allow the system to tune and link. Then, when you disconnect the cable, the system will correctly detect that the link is down. Alternatively, remove the SFP+ transceiver from the port.
|
||||
|
||||
## PAN-109526
|
||||
|
||||
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||
|
||||
## PAN-106989
|
||||
|
||||
There is a display-only issue on Panorama that results in a `commit failed` status for Template Last Commit State (**Panorama** > **Managed Devices** > **Summary**).
|
||||
|
||||
**Workaround:** Push templates to managed devices.
|
||||
|
||||
## PAN-106675
|
||||
|
||||
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||
|
||||
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||
|
||||
## PAN-105210
|
||||
|
||||
```caveat
|
||||
Panorama in FIPS mode only when managing non-FIPS firewalls
|
||||
```
|
||||
|
||||
You cannot configure a GlobalProtect portal on Panorama in FIPS mode when managing a non-FIPS firewall. If you attempt to do so, you will receive the following error message: `agent-user-override-key unexpected here Portal_fips.`
|
||||
|
||||
## PAN-104780
|
||||
|
||||
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||
|
||||
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||
|
||||
## PAN-103336
|
||||
|
||||
```caveat
|
||||
HA configurations only
|
||||
```
|
||||
|
||||
When you downgrade a VM-Series firewall on Azure from PAN-OS 9.0 to an earlier release, you do not receive warnings. Do not downgrade your firewall without saving and exporting your current configuration.
|
||||
|
||||
**Workaround:** Because HA is not supported in earlier versions of VM-Series firewalls on Azure, to prevent the loss of your configuration:
|
||||
|
||||
- Save and export the configuration before you downgrade.
|
||||
- After you downgrade, load the saved configuration and commit your changes. The firewall will resume operation without the HA configuration.
|
||||
|
||||
## PAN-103276
|
||||
|
||||
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||
|
||||
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||
|
||||
## PAN-103018
|
||||
|
||||
```caveat
|
||||
Panorama plugins
|
||||
```
|
||||
|
||||
When you use the AND/OR boolean operators to define the match criteria for Dynamic Address Groups on Panorama, the boolean operators do not function properly. The member IP addresses are not included in the address group as expected.
|
||||
|
||||
## PAN-101688
|
||||
|
||||
```caveat
|
||||
Panorama plugins
|
||||
```
|
||||
|
||||
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||
|
||||
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||
|
||||
## PAN-101537
|
||||
|
||||
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||
|
||||
**Workaround:** Specify the vsys in the query string:
|
||||
|
||||
`admin>` `set system target-vsys <vsys-name>`
|
||||
|
||||
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||
|
||||
## PAN-98803
|
||||
|
||||
If you configure the Panorama plugin to monitor virtual machines or endpoints in your AWS, Azure, or Cisco ACI environment without installing the NSX plugin, the IP-address-to-tag mappings for Dynamic Address Groups are not displayed on Panorama.
|
||||
|
||||
**Workaround:** Install the NSX plugin (you do not need to use the NSX plugin for the installation to resolve this display issue).
|
||||
|
||||
## PAN-98520
|
||||
|
||||
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||
|
||||
## PAN-97757
|
||||
|
||||
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||
|
||||
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||
|
||||
## PAN-97524
|
||||
|
||||
```caveat
|
||||
Panorama management server only
|
||||
```
|
||||
|
||||
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||
|
||||
## PAN-96985
|
||||
|
||||
The `request shutdown system` command does not shut down the Panorama management server.
|
||||
|
||||
## PAN-96960
|
||||
|
||||
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
|
||||
|
||||
## PAN-96446
|
||||
|
||||
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||
|
||||
## PAN-95773
|
||||
|
||||
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||
|
||||
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||
|
||||
## PAN-95717
|
||||
|
||||
After 30,000 or more end users log in to the GlobalProtect gateway within a two- to three-hour period, the firewall web interface responds slowly, commits take longer than expected or intermittently fail, and Tech Support File generation times out and fails.
|
||||
|
||||
## PAN-95602
|
||||
|
||||
In a deployment where a Log Collector connects to Panorama management servers in a high availability (HA) configuration, after you switch the Log Collector appliance to Panorama mode, commit operations fail on the appliance.
|
||||
|
||||
**Workaround:** Remove the following node from the running-config.xml file on the Log Collector before switching it to Panorama mode: `devices/entry[@name='localhost.localdomain']/deviceconfig/system/panorama-server-2`
|
||||
|
||||
## PAN-95511
|
||||
|
||||
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||
|
||||
## PAN-95028
|
||||
|
||||
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||
|
||||
## PAN-94966
|
||||
|
||||
After you delete disconnected and connected Terminal Server (TS) agents in the same operation, the firewall still displays the IP address-to-port-user mappings (`show user ip-port-user-mapping` CLI command) for the disconnected TS agents you deleted (**Device** > **User Identification** > **Terminal Services Agents**).
|
||||
|
||||
**Workaround:** Do not delete both disconnected and connected TS agents in the same operation.
|
||||
|
||||
## PAN-94846
|
||||
|
||||
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||
|
||||
## PAN-94093
|
||||
|
||||
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||
|
||||
## PAN-93968
|
||||
|
||||
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||
|
||||
## PAN-93842
|
||||
|
||||
The logging status of a Panorama Log Collector deployed on AWS or Azure displays as disconnected when you configure the ethernet1/1 to ethernet1/5 interfaces for log collection (**Panorama** > **Managed Collectors** > **Interfaces**). This results in firewalls not sending logs to the Log Collector.
|
||||
|
||||
**Workaround:** Configure the management (MGT) interface for log collection.
|
||||
|
||||
## PAN-93607
|
||||
|
||||
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||
|
||||
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||
|
||||
## PAN-93532
|
||||
|
||||
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||
|
||||
## PAN-93193
|
||||
|
||||
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||
|
||||
- Switch to the firewall **Context** on the Panorama management server.
|
||||
- Commit changes when a dynamic update is being installed.
|
||||
- Generate a custom report when a dynamic update is being installed.
|
||||
- Generate custom reports during a commit.
|
||||
|
||||
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||
|
||||
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||
|
||||
## PAN-91802
|
||||
|
||||
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||
|
||||
## PAN-86903
|
||||
|
||||
In rare cases, PA-800 Series firewalls shut themselves down due to a false over-current measurement.
|
||||
|
||||
## PAN-83610
|
||||
|
||||
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||
|
||||
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session off load for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||
|
||||
## PAN-83598
|
||||
|
||||
VM-Series firewalls cannot monitor more than 500 virtual machine (VM) information sources (**Device** > **VM Information Sources**).
|
||||
|
||||
## PAN-83236
|
||||
|
||||
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||
|
||||
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||
|
||||
## PAN-83215
|
||||
|
||||
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||
|
||||
## PAN-81521
|
||||
|
||||
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||
|
||||
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||
|
||||
## PAN-79423
|
||||
|
||||
Panorama cannot push address group objects from device groups to managed firewalls when zones specify the objects in the User Identification ACL include or exclude lists (**Network** > **Zones**) and the **Share Unused Address and Service Objects with Devices** option is disabled (**Panorama** > **Setup** > **Management** > **Panorama Settings**).
|
||||
|
||||
## PAN-77125
|
||||
|
||||
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||
|
||||
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||
|
||||
## PAN-75457
|
||||
|
||||
```caveat
|
||||
PAN-OS 8.0.1 and later releases
|
||||
```
|
||||
|
||||
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||
|
||||
## PAN-73530
|
||||
|
||||
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||
|
||||
## PAN-73401
|
||||
|
||||
```caveat
|
||||
PAN-OS 8.0.1 and later releases
|
||||
```
|
||||
|
||||
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||
|
||||
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||
|
||||
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||
|
||||
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||
- Configure a worker list on the cluster controller:
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||
or
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||
|
||||
## PAN-71329
|
||||
|
||||
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
|
||||
|
||||
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
|
||||
|
||||
## PAN-70906
|
||||
|
||||
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||
|
||||
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||
|
||||
## PAN-69505
|
||||
|
||||
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||
|
||||
## PAN-41558
|
||||
|
||||
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||
|
||||
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||
|
||||
## PAN-40079
|
||||
|
||||
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||
|
||||
## PAN-39636
|
||||
|
||||
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||
|
||||
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||
|
||||
## PAN-38255
|
||||
|
||||
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||
|
||||
## PAN-31832
|
||||
|
||||
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||
|
||||
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||
|
||||
## PAN-25046
|
||||
|
||||
Firewalls store SSH host keys used for SCP log exports in the known hosts file. In an HA deployment, PAN-OS synchronizes the SCP log export configuration between the firewall HA peers (**Device** > **Scheduled Log Export**), but not the known host file. When a failover occurs, the SCP log export fails.
|
||||
|
||||
**Workaround:** Log in to each peer in HA, select **Device** > **Scheduled Log Export** > **<log_export_configuration>**, and **Test SCP server connection** to confirm the host key so that SCP log forwarding continues to work after a failover.
|
||||
@@ -0,0 +1,618 @@
|
||||
---
|
||||
type: Known
|
||||
product: PAN-OS
|
||||
version: 9.0.15
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||
|
||||
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
A Panorama management server running PAN-OS 9.0 does not currently support management of appliances running WildFire 7.1 or earlier releases. Even though these management options are visible on the Panorama 9.0 web interface (**Panorama** > **Managed WildFire Clusters** and **Panorama** > **Managed WildFire Appliances**), making changes to these settings for appliances running WildFire 7.1 or an earlier release has no effect.
|
||||
|
||||
## WF500-4200
|
||||
|
||||
The Create Date shown when using the `show wildfire global sample-status sha256 equal<hash>` or `show wildfire global sample-analysis` CLI command is two hours behind the actual time for WF-500 appliance samples.
|
||||
|
||||
## PLUG-1854
|
||||
|
||||
```caveat
|
||||
PAN-OS 9.0.2 and later releases on AWS and GCP only
|
||||
```
|
||||
|
||||
You cannot swap the management interface.
|
||||
|
||||
## PLUG-1827
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
The firewall drops packets due to larger than expected packet sizes when Accelerated networking is enabled on the firewall (**Settings** > **Networking**).
|
||||
|
||||
## PLUG-1709
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
There is an intermittent issue where the secondary IP address becomes associated with the passive firewall after multiple failovers.
|
||||
|
||||
**Workaround:** Reassign IP addresses to the active and passive firewalls in Azure as needed.
|
||||
|
||||
## PLUG-1694
|
||||
|
||||
```caveat
|
||||
PAYG licenses only
|
||||
```
|
||||
|
||||
Your pay-as-you-go (PAYG) license is not retained when you upgrade from a PAN-OS 8.1 release to a PAN-OS 9.0 release.
|
||||
|
||||
**Workaround:** Upgrade to VM-Series plugin 1.0.2 (or later) after you upgrade to a PAN-OS 9.0 release and then reboot the firewall to recover your PAYG license.
|
||||
|
||||
## PLUG-1681
|
||||
|
||||
If you bootstrap a PAN-OS 9.0.1 image while using VM-Series plugin 1.0.0, the firewall will not apply the capacity license. To downgrade the VM-Series plugin from version 1.0.2 to 1.0.0, first bootstrap the PAN-OS 9.0.1 image and then downgrade the plugin.
|
||||
|
||||
## PLUG-1642
|
||||
|
||||
```caveat
|
||||
This issue is resolved with VM-Series plugin 1.0.2.
|
||||
```
|
||||
|
||||
After a high availability (HA) failover, the dataplane interface on a VM-Series firewall on Azure with Accelerated Networking (SR-IOV) becomes disabled when, as a result of the failover, the secondary IP address is detached from or attached to the firewall and moved to its HA peer.
|
||||
|
||||
## PLUG-1503
|
||||
|
||||
```caveat
|
||||
This issue is resolved with VM-Series plugin 1.0.3.
|
||||
```
|
||||
|
||||
When a VM-Series firewall on AWS running on a C5 or M5 instance experiences a high availability (HA) failover, the dataplane interfaces from the previously active firewall are not moved to the newly active (previously passive) peer.
|
||||
|
||||
**Workaround:** Check for the latest VM-Series plugin version and install the VM-Series plugin 9.0.0 version; the built-in version is 9.0.0-c29.
|
||||
|
||||
## PLUG-1074
|
||||
|
||||
On the VM-Series firewall on AWS, when you change the instance type, the firewall no longer has a serial number or a license. Additionally, if you manage this firewall using Panorama, it is no longer connected to Panorama.
|
||||
|
||||
## PLUG-380
|
||||
|
||||
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||
|
||||
## PAN-184850
|
||||
|
||||
On Panorama, the function `pan_check_and_restart_tunnels` is incorrectly called, which results in invalid inputs, and `esmonitor.log` displays an error message even though Elasticsearch remains functional.
|
||||
|
||||
## PAN-178194
|
||||
|
||||
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
|
||||
|
||||
## PAN-161121
|
||||
|
||||
On the Panorama management server, invalid reference errors occur when attempting to delete an address object (**Objects** > **Addresses**) after removing the address object reference from an address group (**Objects** > **Address Groups**) resulting in you being unable commit and push the configuration to managed firewalls.
|
||||
|
||||
**Workaround:** Log in to the [Panorama CLI](https://docs.paloaltonetworks.com/panorama/9-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli.html) and restart `configd`.
|
||||
|
||||
`admin>``debug software restart process configd`
|
||||
|
||||
## PAN-154247
|
||||
|
||||
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
|
||||
|
||||
**Workaround:** Log out and back in to the Panorama web interface.
|
||||
|
||||
## PAN-151909
|
||||
|
||||
On the Panorama management server, Preview Changes (**Commit** > **Commit to Panorama**) incorrectly displays an existing route as Added and the new route as an existing route in the Candidate Configuration when you configure a new virtual router route (**Network** > **Virtual Router**).
|
||||
|
||||
## PAN-150172
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. See PAN-OS 9.0.9-h1 Addressed Issues.
|
||||
```
|
||||
|
||||
Dataplane processes restart when attempting to access websites that have the `NotBefore` attribute less than or equal to Unix Epoch Time in the server certificate with forward proxy enabled.
|
||||
|
||||
## PAN-146573
|
||||
|
||||
PA-7000 Series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||
|
||||
## PAN-136701
|
||||
|
||||
```caveat
|
||||
PA-7000b Series firewalls only
|
||||
```
|
||||
|
||||
Packets for new sessions drop when handling predict sessions.
|
||||
|
||||
**Workaround:** Use the following CLI command to bypass this issue:
|
||||
|
||||
- `set session hwpredict disable yes`
|
||||
|
||||
To enable hwpredict again `set session hwpredict disable no`.
|
||||
|
||||
To verify the current settings, `show session hwpredict status`.
|
||||
|
||||
## PAN-131915
|
||||
|
||||
There is an issue when you implement a new firewall bootstrap with a USB drive where the bootstrap fails and displays the following error message: `no USB device found`.
|
||||
|
||||
**Workaround:** Perform a factory reset or run the `request system private-data-reset` CLI command and then proceed with bootstrapping.
|
||||
|
||||
## PAN-124956
|
||||
|
||||
There is an issue where VM-Series firewalls do not support packet buffer protection.
|
||||
|
||||
## PAN-120440
|
||||
|
||||
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||
|
||||
## PAN-120303
|
||||
|
||||
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||
|
||||
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||
|
||||
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||
2. **Commit** your changes.
|
||||
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||
4. **Commit** your changes.
|
||||
- Restart the firewall (devsrvr) process.
|
||||
1. Log in to the firewall CLI.
|
||||
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||
|
||||
## PAN-118414
|
||||
|
||||
```caveat
|
||||
PAN-OS 9.0.2 and later releases only
|
||||
```
|
||||
|
||||
There is an intermittent issue where a Panorama management server and managing Prisma™ Access or Cortex™ Data Lake fails to authorize one-time-password (OTP) submissions during the onboarding process.
|
||||
|
||||
**Workaround:** Downgrade to PAN-OS 9.0.1.
|
||||
|
||||
## PAN-117043
|
||||
|
||||
There is an issue on the Panorama management server and all supported firewalls where special characters contained in the tag names of the Security policy rules returns the following error message: `group-tag is invalid` when you commit or push a configuration.
|
||||
|
||||
**Workaround:** Modify the tags and group tags (**Objects** > **Tags**) to exclude special characters.
|
||||
|
||||
## PAN-116017
|
||||
|
||||
```caveat
|
||||
Google Cloud Platform (GCP) only
|
||||
```
|
||||
|
||||
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||
|
||||
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||
|
||||
## PAN-115816
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||
|
||||
**Workaround:** Reboot the firewall.
|
||||
|
||||
## PAN-115733
|
||||
|
||||
```caveat
|
||||
PAN-OS firewalls in an HA configuration only
|
||||
```
|
||||
|
||||
There is a rare issue where data interfaces do not come up after you reboot the firewall when running a C5 or M5 instance type in AWS.
|
||||
|
||||
**Workaround:** Reboot the firewall.
|
||||
|
||||
## PAN-114495
|
||||
|
||||
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||
|
||||
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||
|
||||
## PAN-113117
|
||||
|
||||
A newly launched firewall does not get its configuration from Panorama when it first connects if you installed the VM-Series plugin on Panorama. When a newly launched firewall that is bootstrapped connects to Panorama, a process restart occurs on Panorama. Upon restart, you are logged out of the user interface and you need to log in and push the device group and template configuration to the newly connected firewall.
|
||||
|
||||
## PAN-113098
|
||||
|
||||
In the firewall web interface, you can temporarily submit change requests for the following URL categories: insufficient-content, high-risk, medium-risk, low-risk, and newly-registered-domains. However, Palo Alto Networks does not support or process change requests for these categories.
|
||||
|
||||
## PAN-112983
|
||||
|
||||
```caveat
|
||||
Firewalls with multiple virtual systems only; no impact to Panorama
|
||||
```
|
||||
|
||||
If you select any Location other than Shared when you generate or import a new CA Certificate in a Certificate Profile (**Device** > **Certificate Management** > **Certificate Profile**), the firewall adds the newly generated or imported certificate to vsys1. For example, if you specify vsys3 as the **Location**, **Add** a CA Certificate, and then **Generate** a new certificate, the firewall adds the certificate to vsys1 instead of vsys3. When you click **OK** to configure the Certificate Profile, the firewall returns an `Operation Failed` error message because it sees a certificate for vsys1 added to vsys3.
|
||||
|
||||
**Workaround 1:**
|
||||
|
||||
1. Generate or import the new certificate in a Certificate Profile (**Device** > **Certificate Management** > **Certificates** > **Device Certificates**) and select the appropriate vsys **Location** when you generate or import the certificate.
|
||||
2. When you create or edit the Certificate Profile, specify the vsys **Location** and **Add** the certificate that you generated (or imported) from the list of existing certificates.
|
||||
|
||||
**Workaround 2:** When you generate or import a new certificate when you configure a Certificate Profile for a vsys other than vsys1, specify the **Location** as Shared.
|
||||
|
||||
## PAN-112694
|
||||
|
||||
```caveat
|
||||
Firewalls with multiple virtual systems only
|
||||
```
|
||||
|
||||
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||
|
||||
## PAN-112626
|
||||
|
||||
When you upgrade to PAN-OS 9.0 with a PAYG Bundle 2 license, the new DNS Security subscription is not available on your VM-Series firewall.
|
||||
|
||||
This subscription is included with the BYOL and VM-Series ELA when you upgrade.
|
||||
|
||||
## PAN-112562
|
||||
|
||||
The **Log Forwarding Card** (LFC) subinterface incorrectly uses the interface IP address instead of the subinterface IP address for all services that forward logs (such as syslog, email, and SNMP) for selected virtual systems.
|
||||
|
||||
## PAN-112456
|
||||
|
||||
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
|
||||
|
||||
## PAN-111928
|
||||
|
||||
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||
|
||||
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||
|
||||
## PAN-111866
|
||||
|
||||
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||
|
||||
**Workaround:** Perform one of the following tasks.
|
||||
|
||||
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||
- Manually select the devices that belong to the modified device group and template configurations.
|
||||
|
||||
## PAN-111729
|
||||
|
||||
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||
|
||||
## PAN-111670
|
||||
|
||||
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||
|
||||
## PAN-110794
|
||||
|
||||
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||
|
||||
## PAN-110603
|
||||
|
||||
In some cases, when a port on an PA-7000 Series 100Gbps Network Processor Card (NPC) has an SFP+ transceiver inserted but no cable is connected, the system detects a signal and attempts to tune and link with that port. As a result, if the device at the other end of the connection is rebooted or has an HA failover event, the link is sometimes held down for an extended period of time while the interface attempts to tune itself.
|
||||
|
||||
**Workaround:** Connect a cable to the installed SFP+ transceiver to allow the system to tune and link. Then, when you disconnect the cable, the system will correctly detect that the link is down. Alternatively, remove the SFP+ transceiver from the port.
|
||||
|
||||
## PAN-109526
|
||||
|
||||
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||
|
||||
## PAN-106989
|
||||
|
||||
There is a display-only issue on Panorama that results in a `commit failed` status for Template Last Commit State (**Panorama** > **Managed Devices** > **Summary**).
|
||||
|
||||
**Workaround:** Push templates to managed devices.
|
||||
|
||||
## PAN-106675
|
||||
|
||||
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||
|
||||
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||
|
||||
## PAN-105210
|
||||
|
||||
```caveat
|
||||
Panorama in FIPS mode only when managing non-FIPS firewalls
|
||||
```
|
||||
|
||||
You cannot configure a GlobalProtect portal on Panorama in FIPS mode when managing a non-FIPS firewall. If you attempt to do so, you will receive the following error message: `agent-user-override-key unexpected here Portal_fips.`
|
||||
|
||||
## PAN-104780
|
||||
|
||||
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||
|
||||
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||
|
||||
## PAN-103336
|
||||
|
||||
```caveat
|
||||
HA configurations only
|
||||
```
|
||||
|
||||
When you downgrade a VM-Series firewall on Azure from PAN-OS 9.0 to an earlier release, you do not receive warnings. Do not downgrade your firewall without saving and exporting your current configuration.
|
||||
|
||||
**Workaround:** Because HA is not supported in earlier versions of VM-Series firewalls on Azure, to prevent the loss of your configuration:
|
||||
|
||||
- Save and export the configuration before you downgrade.
|
||||
- After you downgrade, load the saved configuration and commit your changes. The firewall will resume operation without the HA configuration.
|
||||
|
||||
## PAN-103276
|
||||
|
||||
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||
|
||||
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||
|
||||
## PAN-103018
|
||||
|
||||
```caveat
|
||||
Panorama plugins
|
||||
```
|
||||
|
||||
When you use the AND/OR boolean operators to define the match criteria for Dynamic Address Groups on Panorama, the boolean operators do not function properly. The member IP addresses are not included in the address group as expected.
|
||||
|
||||
## PAN-101688
|
||||
|
||||
```caveat
|
||||
Panorama plugins
|
||||
```
|
||||
|
||||
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||
|
||||
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||
|
||||
## PAN-101537
|
||||
|
||||
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||
|
||||
**Workaround:** Specify the vsys in the query string:
|
||||
|
||||
`admin>` `set system target-vsys <vsys-name>`
|
||||
|
||||
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||
|
||||
## PAN-98803
|
||||
|
||||
If you configure the Panorama plugin to monitor virtual machines or endpoints in your AWS, Azure, or Cisco ACI environment without installing the NSX plugin, the IP-address-to-tag mappings for Dynamic Address Groups are not displayed on Panorama.
|
||||
|
||||
**Workaround:** Install the NSX plugin (you do not need to use the NSX plugin for the installation to resolve this display issue).
|
||||
|
||||
## PAN-98520
|
||||
|
||||
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||
|
||||
## PAN-97757
|
||||
|
||||
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||
|
||||
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||
|
||||
## PAN-97524
|
||||
|
||||
```caveat
|
||||
Panorama management server only
|
||||
```
|
||||
|
||||
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||
|
||||
## PAN-96985
|
||||
|
||||
The `request shutdown system` command does not shut down the Panorama management server.
|
||||
|
||||
## PAN-96960
|
||||
|
||||
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
|
||||
|
||||
## PAN-96446
|
||||
|
||||
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||
|
||||
## PAN-95773
|
||||
|
||||
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||
|
||||
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||
|
||||
## PAN-95717
|
||||
|
||||
After 30,000 or more end users log in to the GlobalProtect gateway within a two- to three-hour period, the firewall web interface responds slowly, commits take longer than expected or intermittently fail, and Tech Support File generation times out and fails.
|
||||
|
||||
## PAN-95602
|
||||
|
||||
In a deployment where a Log Collector connects to Panorama management servers in a high availability (HA) configuration, after you switch the Log Collector appliance to Panorama mode, commit operations fail on the appliance.
|
||||
|
||||
**Workaround:** Remove the following node from the running-config.xml file on the Log Collector before switching it to Panorama mode: `devices/entry[@name='localhost.localdomain']/deviceconfig/system/panorama-server-2`
|
||||
|
||||
## PAN-95511
|
||||
|
||||
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||
|
||||
## PAN-95028
|
||||
|
||||
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||
|
||||
## PAN-94966
|
||||
|
||||
After you delete disconnected and connected Terminal Server (TS) agents in the same operation, the firewall still displays the IP address-to-port-user mappings (`show user ip-port-user-mapping` CLI command) for the disconnected TS agents you deleted (**Device** > **User Identification** > **Terminal Services Agents**).
|
||||
|
||||
**Workaround:** Do not delete both disconnected and connected TS agents in the same operation.
|
||||
|
||||
## PAN-94846
|
||||
|
||||
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||
|
||||
## PAN-94093
|
||||
|
||||
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||
|
||||
## PAN-93968
|
||||
|
||||
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||
|
||||
## PAN-93842
|
||||
|
||||
The logging status of a Panorama Log Collector deployed on AWS or Azure displays as disconnected when you configure the ethernet1/1 to ethernet1/5 interfaces for log collection (**Panorama** > **Managed Collectors** > **Interfaces**). This results in firewalls not sending logs to the Log Collector.
|
||||
|
||||
**Workaround:** Configure the management (MGT) interface for log collection.
|
||||
|
||||
## PAN-93607
|
||||
|
||||
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||
|
||||
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||
|
||||
## PAN-93532
|
||||
|
||||
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||
|
||||
## PAN-93193
|
||||
|
||||
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||
|
||||
- Switch to the firewall **Context** on the Panorama management server.
|
||||
- Commit changes when a dynamic update is being installed.
|
||||
- Generate a custom report when a dynamic update is being installed.
|
||||
- Generate custom reports during a commit.
|
||||
|
||||
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||
|
||||
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||
|
||||
## PAN-91802
|
||||
|
||||
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||
|
||||
## PAN-86903
|
||||
|
||||
In rare cases, PA-800 Series firewalls shut themselves down due to a false over-current measurement.
|
||||
|
||||
## PAN-83610
|
||||
|
||||
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||
|
||||
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session off load for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||
|
||||
## PAN-83598
|
||||
|
||||
VM-Series firewalls cannot monitor more than 500 virtual machine (VM) information sources (**Device** > **VM Information Sources**).
|
||||
|
||||
## PAN-83236
|
||||
|
||||
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||
|
||||
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||
|
||||
## PAN-83215
|
||||
|
||||
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||
|
||||
## PAN-81521
|
||||
|
||||
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||
|
||||
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||
|
||||
## PAN-79423
|
||||
|
||||
Panorama cannot push address group objects from device groups to managed firewalls when zones specify the objects in the User Identification ACL include or exclude lists (**Network** > **Zones**) and the **Share Unused Address and Service Objects with Devices** option is disabled (**Panorama** > **Setup** > **Management** > **Panorama Settings**).
|
||||
|
||||
## PAN-77125
|
||||
|
||||
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||
|
||||
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||
|
||||
## PAN-75457
|
||||
|
||||
```caveat
|
||||
PAN-OS 8.0.1 and later releases
|
||||
```
|
||||
|
||||
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||
|
||||
## PAN-73530
|
||||
|
||||
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||
|
||||
## PAN-73401
|
||||
|
||||
```caveat
|
||||
PAN-OS 8.0.1 and later releases
|
||||
```
|
||||
|
||||
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||
|
||||
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||
|
||||
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||
|
||||
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||
- Configure a worker list on the cluster controller:
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||
or
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||
|
||||
## PAN-71329
|
||||
|
||||
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
|
||||
|
||||
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
|
||||
|
||||
## PAN-70906
|
||||
|
||||
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||
|
||||
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||
|
||||
## PAN-69505
|
||||
|
||||
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||
|
||||
## PAN-41558
|
||||
|
||||
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||
|
||||
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||
|
||||
## PAN-40079
|
||||
|
||||
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||
|
||||
## PAN-39636
|
||||
|
||||
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||
|
||||
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||
|
||||
## PAN-38255
|
||||
|
||||
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||
|
||||
## PAN-31832
|
||||
|
||||
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||
|
||||
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||
|
||||
## PAN-25046
|
||||
|
||||
Firewalls store SSH host keys used for SCP log exports in the known hosts file. In an HA deployment, PAN-OS synchronizes the SCP log export configuration between the firewall HA peers (**Device** > **Scheduled Log Export**), but not the known host file. When a failover occurs, the SCP log export fails.
|
||||
|
||||
**Workaround:** Log in to each peer in HA, select **Device** > **Scheduled Log Export** > **<log_export_configuration>**, and **Test SCP server connection** to confirm the host key so that SCP log forwarding continues to work after a failover.
|
||||
@@ -0,0 +1,618 @@
|
||||
---
|
||||
type: Known
|
||||
product: PAN-OS
|
||||
version: 9.0.16
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||
|
||||
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
A Panorama management server running PAN-OS 9.0 does not currently support management of appliances running WildFire 7.1 or earlier releases. Even though these management options are visible on the Panorama 9.0 web interface (**Panorama** > **Managed WildFire Clusters** and **Panorama** > **Managed WildFire Appliances**), making changes to these settings for appliances running WildFire 7.1 or an earlier release has no effect.
|
||||
|
||||
## WF500-4200
|
||||
|
||||
The Create Date shown when using the `show wildfire global sample-status sha256 equal<hash>` or `show wildfire global sample-analysis` CLI command is two hours behind the actual time for WF-500 appliance samples.
|
||||
|
||||
## PLUG-1854
|
||||
|
||||
```caveat
|
||||
PAN-OS 9.0.2 and later releases on AWS and GCP only
|
||||
```
|
||||
|
||||
You cannot swap the management interface.
|
||||
|
||||
## PLUG-1827
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
The firewall drops packets due to larger than expected packet sizes when Accelerated networking is enabled on the firewall (**Settings** > **Networking**).
|
||||
|
||||
## PLUG-1709
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
There is an intermittent issue where the secondary IP address becomes associated with the passive firewall after multiple failovers.
|
||||
|
||||
**Workaround:** Reassign IP addresses to the active and passive firewalls in Azure as needed.
|
||||
|
||||
## PLUG-1694
|
||||
|
||||
```caveat
|
||||
PAYG licenses only
|
||||
```
|
||||
|
||||
Your pay-as-you-go (PAYG) license is not retained when you upgrade from a PAN-OS 8.1 release to a PAN-OS 9.0 release.
|
||||
|
||||
**Workaround:** Upgrade to VM-Series plugin 1.0.2 (or later) after you upgrade to a PAN-OS 9.0 release and then reboot the firewall to recover your PAYG license.
|
||||
|
||||
## PLUG-1681
|
||||
|
||||
If you bootstrap a PAN-OS 9.0.1 image while using VM-Series plugin 1.0.0, the firewall will not apply the capacity license. To downgrade the VM-Series plugin from version 1.0.2 to 1.0.0, first bootstrap the PAN-OS 9.0.1 image and then downgrade the plugin.
|
||||
|
||||
## PLUG-1642
|
||||
|
||||
```caveat
|
||||
This issue is resolved with VM-Series plugin 1.0.2.
|
||||
```
|
||||
|
||||
After a high availability (HA) failover, the dataplane interface on a VM-Series firewall on Azure with Accelerated Networking (SR-IOV) becomes disabled when, as a result of the failover, the secondary IP address is detached from or attached to the firewall and moved to its HA peer.
|
||||
|
||||
## PLUG-1503
|
||||
|
||||
```caveat
|
||||
This issue is resolved with VM-Series plugin 1.0.3.
|
||||
```
|
||||
|
||||
When a VM-Series firewall on AWS running on a C5 or M5 instance experiences a high availability (HA) failover, the dataplane interfaces from the previously active firewall are not moved to the newly active (previously passive) peer.
|
||||
|
||||
**Workaround:** Check for the latest VM-Series plugin version and install the VM-Series plugin 9.0.0 version; the built-in version is 9.0.0-c29.
|
||||
|
||||
## PLUG-1074
|
||||
|
||||
On the VM-Series firewall on AWS, when you change the instance type, the firewall no longer has a serial number or a license. Additionally, if you manage this firewall using Panorama, it is no longer connected to Panorama.
|
||||
|
||||
## PLUG-380
|
||||
|
||||
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||
|
||||
## PAN-184850
|
||||
|
||||
On Panorama, the function `pan_check_and_restart_tunnels` is incorrectly called, which results in invalid inputs, and `esmonitor.log` displays an error message even though Elasticsearch remains functional.
|
||||
|
||||
## PAN-178194
|
||||
|
||||
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
|
||||
|
||||
## PAN-161121
|
||||
|
||||
On the Panorama management server, invalid reference errors occur when attempting to delete an address object (**Objects** > **Addresses**) after removing the address object reference from an address group (**Objects** > **Address Groups**) resulting in you being unable commit and push the configuration to managed firewalls.
|
||||
|
||||
**Workaround:** Log in to the [Panorama CLI](https://docs.paloaltonetworks.com/panorama/9-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli.html) and restart `configd`.
|
||||
|
||||
`admin>``debug software restart process configd`
|
||||
|
||||
## PAN-154247
|
||||
|
||||
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
|
||||
|
||||
**Workaround:** Log out and back in to the Panorama web interface.
|
||||
|
||||
## PAN-151909
|
||||
|
||||
On the Panorama management server, Preview Changes (**Commit** > **Commit to Panorama**) incorrectly displays an existing route as Added and the new route as an existing route in the Candidate Configuration when you configure a new virtual router route (**Network** > **Virtual Router**).
|
||||
|
||||
## PAN-150172
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. See PAN-OS 9.0.9-h1 Addressed Issues.
|
||||
```
|
||||
|
||||
Dataplane processes restart when attempting to access websites that have the `NotBefore` attribute less than or equal to Unix Epoch Time in the server certificate with forward proxy enabled.
|
||||
|
||||
## PAN-146573
|
||||
|
||||
PA-7000 Series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||
|
||||
## PAN-136701
|
||||
|
||||
```caveat
|
||||
PA-7000b Series firewalls only
|
||||
```
|
||||
|
||||
Packets for new sessions drop when handling predict sessions.
|
||||
|
||||
**Workaround:** Use the following CLI command to bypass this issue:
|
||||
|
||||
- `set session hwpredict disable yes`
|
||||
|
||||
To enable hwpredict again `set session hwpredict disable no`.
|
||||
|
||||
To verify the current settings, `show session hwpredict status`.
|
||||
|
||||
## PAN-131915
|
||||
|
||||
There is an issue when you implement a new firewall bootstrap with a USB drive where the bootstrap fails and displays the following error message: `no USB device found`.
|
||||
|
||||
**Workaround:** Perform a factory reset or run the `request system private-data-reset` CLI command and then proceed with bootstrapping.
|
||||
|
||||
## PAN-124956
|
||||
|
||||
There is an issue where VM-Series firewalls do not support packet buffer protection.
|
||||
|
||||
## PAN-120440
|
||||
|
||||
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||
|
||||
## PAN-120303
|
||||
|
||||
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||
|
||||
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||
|
||||
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||
2. **Commit** your changes.
|
||||
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||
4. **Commit** your changes.
|
||||
- Restart the firewall (devsrvr) process.
|
||||
1. Log in to the firewall CLI.
|
||||
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||
|
||||
## PAN-118414
|
||||
|
||||
```caveat
|
||||
PAN-OS 9.0.2 and later releases only
|
||||
```
|
||||
|
||||
There is an intermittent issue where a Panorama management server and managing Prisma™ Access or Cortex™ Data Lake fails to authorize one-time-password (OTP) submissions during the onboarding process.
|
||||
|
||||
**Workaround:** Downgrade to PAN-OS 9.0.1.
|
||||
|
||||
## PAN-117043
|
||||
|
||||
There is an issue on the Panorama management server and all supported firewalls where special characters contained in the tag names of the Security policy rules returns the following error message: `group-tag is invalid` when you commit or push a configuration.
|
||||
|
||||
**Workaround:** Modify the tags and group tags (**Objects** > **Tags**) to exclude special characters.
|
||||
|
||||
## PAN-116017
|
||||
|
||||
```caveat
|
||||
Google Cloud Platform (GCP) only
|
||||
```
|
||||
|
||||
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||
|
||||
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||
|
||||
## PAN-115816
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||
|
||||
**Workaround:** Reboot the firewall.
|
||||
|
||||
## PAN-115733
|
||||
|
||||
```caveat
|
||||
PAN-OS firewalls in an HA configuration only
|
||||
```
|
||||
|
||||
There is a rare issue where data interfaces do not come up after you reboot the firewall when running a C5 or M5 instance type in AWS.
|
||||
|
||||
**Workaround:** Reboot the firewall.
|
||||
|
||||
## PAN-114495
|
||||
|
||||
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||
|
||||
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||
|
||||
## PAN-113117
|
||||
|
||||
A newly launched firewall does not get its configuration from Panorama when it first connects if you installed the VM-Series plugin on Panorama. When a newly launched firewall that is bootstrapped connects to Panorama, a process restart occurs on Panorama. Upon restart, you are logged out of the user interface and you need to log in and push the device group and template configuration to the newly connected firewall.
|
||||
|
||||
## PAN-113098
|
||||
|
||||
In the firewall web interface, you can temporarily submit change requests for the following URL categories: insufficient-content, high-risk, medium-risk, low-risk, and newly-registered-domains. However, Palo Alto Networks does not support or process change requests for these categories.
|
||||
|
||||
## PAN-112983
|
||||
|
||||
```caveat
|
||||
Firewalls with multiple virtual systems only; no impact to Panorama
|
||||
```
|
||||
|
||||
If you select any Location other than Shared when you generate or import a new CA Certificate in a Certificate Profile (**Device** > **Certificate Management** > **Certificate Profile**), the firewall adds the newly generated or imported certificate to vsys1. For example, if you specify vsys3 as the **Location**, **Add** a CA Certificate, and then **Generate** a new certificate, the firewall adds the certificate to vsys1 instead of vsys3. When you click **OK** to configure the Certificate Profile, the firewall returns an `Operation Failed` error message because it sees a certificate for vsys1 added to vsys3.
|
||||
|
||||
**Workaround 1:**
|
||||
|
||||
1. Generate or import the new certificate in a Certificate Profile (**Device** > **Certificate Management** > **Certificates** > **Device Certificates**) and select the appropriate vsys **Location** when you generate or import the certificate.
|
||||
2. When you create or edit the Certificate Profile, specify the vsys **Location** and **Add** the certificate that you generated (or imported) from the list of existing certificates.
|
||||
|
||||
**Workaround 2:** When you generate or import a new certificate when you configure a Certificate Profile for a vsys other than vsys1, specify the **Location** as Shared.
|
||||
|
||||
## PAN-112694
|
||||
|
||||
```caveat
|
||||
Firewalls with multiple virtual systems only
|
||||
```
|
||||
|
||||
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||
|
||||
## PAN-112626
|
||||
|
||||
When you upgrade to PAN-OS 9.0 with a PAYG Bundle 2 license, the new DNS Security subscription is not available on your VM-Series firewall.
|
||||
|
||||
This subscription is included with the BYOL and VM-Series ELA when you upgrade.
|
||||
|
||||
## PAN-112562
|
||||
|
||||
The **Log Forwarding Card** (LFC) subinterface incorrectly uses the interface IP address instead of the subinterface IP address for all services that forward logs (such as syslog, email, and SNMP) for selected virtual systems.
|
||||
|
||||
## PAN-112456
|
||||
|
||||
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
|
||||
|
||||
## PAN-111928
|
||||
|
||||
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||
|
||||
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||
|
||||
## PAN-111866
|
||||
|
||||
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||
|
||||
**Workaround:** Perform one of the following tasks.
|
||||
|
||||
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||
- Manually select the devices that belong to the modified device group and template configurations.
|
||||
|
||||
## PAN-111729
|
||||
|
||||
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||
|
||||
## PAN-111670
|
||||
|
||||
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||
|
||||
## PAN-110794
|
||||
|
||||
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||
|
||||
## PAN-110603
|
||||
|
||||
In some cases, when a port on an PA-7000 Series 100Gbps Network Processor Card (NPC) has an SFP+ transceiver inserted but no cable is connected, the system detects a signal and attempts to tune and link with that port. As a result, if the device at the other end of the connection is rebooted or has an HA failover event, the link is sometimes held down for an extended period of time while the interface attempts to tune itself.
|
||||
|
||||
**Workaround:** Connect a cable to the installed SFP+ transceiver to allow the system to tune and link. Then, when you disconnect the cable, the system will correctly detect that the link is down. Alternatively, remove the SFP+ transceiver from the port.
|
||||
|
||||
## PAN-109526
|
||||
|
||||
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||
|
||||
## PAN-106989
|
||||
|
||||
There is a display-only issue on Panorama that results in a `commit failed` status for Template Last Commit State (**Panorama** > **Managed Devices** > **Summary**).
|
||||
|
||||
**Workaround:** Push templates to managed devices.
|
||||
|
||||
## PAN-106675
|
||||
|
||||
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||
|
||||
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||
|
||||
## PAN-105210
|
||||
|
||||
```caveat
|
||||
Panorama in FIPS mode only when managing non-FIPS firewalls
|
||||
```
|
||||
|
||||
You cannot configure a GlobalProtect portal on Panorama in FIPS mode when managing a non-FIPS firewall. If you attempt to do so, you will receive the following error message: `agent-user-override-key unexpected here Portal_fips.`
|
||||
|
||||
## PAN-104780
|
||||
|
||||
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||
|
||||
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||
|
||||
## PAN-103336
|
||||
|
||||
```caveat
|
||||
HA configurations only
|
||||
```
|
||||
|
||||
When you downgrade a VM-Series firewall on Azure from PAN-OS 9.0 to an earlier release, you do not receive warnings. Do not downgrade your firewall without saving and exporting your current configuration.
|
||||
|
||||
**Workaround:** Because HA is not supported in earlier versions of VM-Series firewalls on Azure, to prevent the loss of your configuration:
|
||||
|
||||
- Save and export the configuration before you downgrade.
|
||||
- After you downgrade, load the saved configuration and commit your changes. The firewall will resume operation without the HA configuration.
|
||||
|
||||
## PAN-103276
|
||||
|
||||
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||
|
||||
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||
|
||||
## PAN-103018
|
||||
|
||||
```caveat
|
||||
Panorama plugins
|
||||
```
|
||||
|
||||
When you use the AND/OR boolean operators to define the match criteria for Dynamic Address Groups on Panorama, the boolean operators do not function properly. The member IP addresses are not included in the address group as expected.
|
||||
|
||||
## PAN-101688
|
||||
|
||||
```caveat
|
||||
Panorama plugins
|
||||
```
|
||||
|
||||
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||
|
||||
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||
|
||||
## PAN-101537
|
||||
|
||||
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||
|
||||
**Workaround:** Specify the vsys in the query string:
|
||||
|
||||
`admin>` `set system target-vsys <vsys-name>`
|
||||
|
||||
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||
|
||||
## PAN-98803
|
||||
|
||||
If you configure the Panorama plugin to monitor virtual machines or endpoints in your AWS, Azure, or Cisco ACI environment without installing the NSX plugin, the IP-address-to-tag mappings for Dynamic Address Groups are not displayed on Panorama.
|
||||
|
||||
**Workaround:** Install the NSX plugin (you do not need to use the NSX plugin for the installation to resolve this display issue).
|
||||
|
||||
## PAN-98520
|
||||
|
||||
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||
|
||||
## PAN-97757
|
||||
|
||||
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||
|
||||
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||
|
||||
## PAN-97524
|
||||
|
||||
```caveat
|
||||
Panorama management server only
|
||||
```
|
||||
|
||||
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||
|
||||
## PAN-96985
|
||||
|
||||
The `request shutdown system` command does not shut down the Panorama management server.
|
||||
|
||||
## PAN-96960
|
||||
|
||||
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
|
||||
|
||||
## PAN-96446
|
||||
|
||||
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||
|
||||
## PAN-95773
|
||||
|
||||
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||
|
||||
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||
|
||||
## PAN-95717
|
||||
|
||||
After 30,000 or more end users log in to the GlobalProtect gateway within a two- to three-hour period, the firewall web interface responds slowly, commits take longer than expected or intermittently fail, and Tech Support File generation times out and fails.
|
||||
|
||||
## PAN-95602
|
||||
|
||||
In a deployment where a Log Collector connects to Panorama management servers in a high availability (HA) configuration, after you switch the Log Collector appliance to Panorama mode, commit operations fail on the appliance.
|
||||
|
||||
**Workaround:** Remove the following node from the running-config.xml file on the Log Collector before switching it to Panorama mode: `devices/entry[@name='localhost.localdomain']/deviceconfig/system/panorama-server-2`
|
||||
|
||||
## PAN-95511
|
||||
|
||||
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||
|
||||
## PAN-95028
|
||||
|
||||
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||
|
||||
## PAN-94966
|
||||
|
||||
After you delete disconnected and connected Terminal Server (TS) agents in the same operation, the firewall still displays the IP address-to-port-user mappings (`show user ip-port-user-mapping` CLI command) for the disconnected TS agents you deleted (**Device** > **User Identification** > **Terminal Services Agents**).
|
||||
|
||||
**Workaround:** Do not delete both disconnected and connected TS agents in the same operation.
|
||||
|
||||
## PAN-94846
|
||||
|
||||
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||
|
||||
## PAN-94093
|
||||
|
||||
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||
|
||||
## PAN-93968
|
||||
|
||||
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||
|
||||
## PAN-93842
|
||||
|
||||
The logging status of a Panorama Log Collector deployed on AWS or Azure displays as disconnected when you configure the ethernet1/1 to ethernet1/5 interfaces for log collection (**Panorama** > **Managed Collectors** > **Interfaces**). This results in firewalls not sending logs to the Log Collector.
|
||||
|
||||
**Workaround:** Configure the management (MGT) interface for log collection.
|
||||
|
||||
## PAN-93607
|
||||
|
||||
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||
|
||||
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||
|
||||
## PAN-93532
|
||||
|
||||
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||
|
||||
## PAN-93193
|
||||
|
||||
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||
|
||||
- Switch to the firewall **Context** on the Panorama management server.
|
||||
- Commit changes when a dynamic update is being installed.
|
||||
- Generate a custom report when a dynamic update is being installed.
|
||||
- Generate custom reports during a commit.
|
||||
|
||||
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||
|
||||
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||
|
||||
## PAN-91802
|
||||
|
||||
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||
|
||||
## PAN-86903
|
||||
|
||||
In rare cases, PA-800 Series firewalls shut themselves down due to a false over-current measurement.
|
||||
|
||||
## PAN-83610
|
||||
|
||||
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||
|
||||
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session off load for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||
|
||||
## PAN-83598
|
||||
|
||||
VM-Series firewalls cannot monitor more than 500 virtual machine (VM) information sources (**Device** > **VM Information Sources**).
|
||||
|
||||
## PAN-83236
|
||||
|
||||
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||
|
||||
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||
|
||||
## PAN-83215
|
||||
|
||||
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||
|
||||
## PAN-81521
|
||||
|
||||
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||
|
||||
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||
|
||||
## PAN-79423
|
||||
|
||||
Panorama cannot push address group objects from device groups to managed firewalls when zones specify the objects in the User Identification ACL include or exclude lists (**Network** > **Zones**) and the **Share Unused Address and Service Objects with Devices** option is disabled (**Panorama** > **Setup** > **Management** > **Panorama Settings**).
|
||||
|
||||
## PAN-77125
|
||||
|
||||
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||
|
||||
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||
|
||||
## PAN-75457
|
||||
|
||||
```caveat
|
||||
PAN-OS 8.0.1 and later releases
|
||||
```
|
||||
|
||||
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||
|
||||
## PAN-73530
|
||||
|
||||
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||
|
||||
## PAN-73401
|
||||
|
||||
```caveat
|
||||
PAN-OS 8.0.1 and later releases
|
||||
```
|
||||
|
||||
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||
|
||||
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||
|
||||
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||
|
||||
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||
- Configure a worker list on the cluster controller:
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||
or
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||
|
||||
## PAN-71329
|
||||
|
||||
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
|
||||
|
||||
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
|
||||
|
||||
## PAN-70906
|
||||
|
||||
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||
|
||||
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||
|
||||
## PAN-69505
|
||||
|
||||
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||
|
||||
## PAN-41558
|
||||
|
||||
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||
|
||||
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||
|
||||
## PAN-40079
|
||||
|
||||
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||
|
||||
## PAN-39636
|
||||
|
||||
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||
|
||||
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||
|
||||
## PAN-38255
|
||||
|
||||
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||
|
||||
## PAN-31832
|
||||
|
||||
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||
|
||||
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||
|
||||
## PAN-25046
|
||||
|
||||
Firewalls store SSH host keys used for SCP log exports in the known hosts file. In an HA deployment, PAN-OS synchronizes the SCP log export configuration between the firewall HA peers (**Device** > **Scheduled Log Export**), but not the known host file. When a failover occurs, the SCP log export fails.
|
||||
|
||||
**Workaround:** Log in to each peer in HA, select **Device** > **Scheduled Log Export** > **<log_export_configuration>**, and **Test SCP server connection** to confirm the host key so that SCP log forwarding continues to work after a failover.
|
||||
@@ -0,0 +1,718 @@
|
||||
---
|
||||
type: Known
|
||||
product: PAN-OS
|
||||
version: 9.0.1
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||
|
||||
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
A Panorama management server running PAN-OS 9.0 does not currently support management of appliances running WildFire 7.1 or earlier releases. Even though these management options are visible on the Panorama 9.0 web interface (**Panorama** > **Managed WildFire Clusters** and **Panorama** > **Managed WildFire Appliances**), making changes to these settings for appliances running WildFire 7.1 or an earlier release has no effect.
|
||||
|
||||
## WF500-4200
|
||||
|
||||
The Create Date shown when using the `show wildfire global sample-status sha256 equal<hash>` or `show wildfire global sample-analysis` CLI command is two hours behind the actual time for WF-500 appliance samples.
|
||||
|
||||
## PLUG-1827
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
The firewall drops packets due to larger than expected packet sizes when Accelerated networking is enabled on the firewall (**Settings** > **Networking**).
|
||||
|
||||
## PLUG-1709
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
There is an intermittent issue where the secondary IP address becomes associated with the passive firewall after multiple failovers.
|
||||
|
||||
**Workaround:** Reassign IP addresses to the active and passive firewalls in Azure as needed.
|
||||
|
||||
## PLUG-1694
|
||||
|
||||
```caveat
|
||||
PAYG licenses only
|
||||
```
|
||||
|
||||
Your pay-as-you-go (PAYG) license is not retained when you upgrade from a PAN-OS 8.1 release to a PAN-OS 9.0 release.
|
||||
|
||||
**Workaround:** Upgrade to VM-Series plugin 1.0.2 (or later) after you upgrade to a PAN-OS 9.0 release and then reboot the firewall to recover your PAYG license.
|
||||
|
||||
## PLUG-1681
|
||||
|
||||
If you bootstrap a PAN-OS 9.0.1 image while using VM-Series plugin 1.0.0, the firewall will not apply the capacity license. To downgrade the VM-Series plugin from version 1.0.2 to 1.0.0, first bootstrap the PAN-OS 9.0.1 image and then downgrade the plugin.
|
||||
|
||||
## PLUG-1642
|
||||
|
||||
```caveat
|
||||
This issue is resolved with VM-Series plugin 1.0.2.
|
||||
```
|
||||
|
||||
After a high availability (HA) failover, the dataplane interface on a VM-Series firewall on Azure with Accelerated Networking (SR-IOV) becomes disabled when, as a result of the failover, the secondary IP address is detached from or attached to the firewall and moved to its HA peer.
|
||||
|
||||
## PLUG-1503
|
||||
|
||||
```caveat
|
||||
This issue is resolved with VM-Series plugin 1.0.3.
|
||||
```
|
||||
|
||||
When a VM-Series firewall on AWS running on a C5 or M5 instance experiences a high availability (HA) failover, the dataplane interfaces from the previously active firewall are not moved to the newly active (previously passive) peer.
|
||||
|
||||
**Workaround:** Check for the latest VM-Series plugin version and install the VM-Series plugin 9.0.0 version; the built-in version is 9.0.0-c29.
|
||||
|
||||
## PLUG-1074
|
||||
|
||||
On the VM-Series firewall on AWS, when you change the instance type, the firewall no longer has a serial number or a license. Additionally, if you manage this firewall using Panorama, it is no longer connected to Panorama.
|
||||
|
||||
## PLUG-380
|
||||
|
||||
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||
|
||||
## PAN-178194
|
||||
|
||||
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
|
||||
|
||||
## PAN-157240
|
||||
|
||||
When a firewall has hardware offloading turned on and OSPF enabled, if ECMP is enabled or disabled for a virtual router during a configuration commit, OSPF sessions may get stuck in Exchange Start state.
|
||||
|
||||
**Workaround:** Disable OSPF when enabling or disabling ECMP, and then re-enable OSPF in the next commit.
|
||||
|
||||
## PAN-154247
|
||||
|
||||
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
|
||||
|
||||
**Workaround:** Log out and back in to the Panorama web interface.
|
||||
|
||||
## PAN-151198
|
||||
|
||||
On the Panorama management server, read-only Panorama administrators (**Panorama** > **Administrators**) can load managed firewall configuration Backups (**Panorama** > **Managed Devices** > **Summary**).
|
||||
|
||||
## PAN-131915
|
||||
|
||||
There is an issue when you implement a new firewall bootstrap with a USB drive where the bootstrap fails and displays the following error message: `no USB device found`.
|
||||
|
||||
**Workaround:** Perform a factory reset or run the `request system private-data-reset` CLI command and then proceed with bootstrapping.
|
||||
|
||||
## PAN-131792
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. SeePAN-OS 9.0.9 Addressed Issues.
|
||||
```
|
||||
|
||||
The Name log filter (**Monitor** > **Logs** > **Traffic**) is not maintained when viewing the Log Viewer for a Security policy rule (**Policies** > **Security**) from the drop-down menu.
|
||||
|
||||
## PAN-130069
|
||||
|
||||
There is an issue where the firewall incorrectly interprets an external dynamic list MineMeld instability error code as an empty external dynamic list.
|
||||
|
||||
## PAN-126921
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
There is an issue where internal path monitoring fails when the firewall processes corrupt packets.
|
||||
|
||||
## PAN-125775
|
||||
|
||||
There is an issue where Panorama management servers deployed using the C5 or M5 instance types on Amazon Web Services (AWS) cause the Panorama instance to stop responding in regions that support these instance types.
|
||||
|
||||
## PAN-125121
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
There is an issue where custom images do not function as expected for PAN-OS 9.0.
|
||||
|
||||
**Workaround:** Use PAN-OS 8.1 for creating custom images.
|
||||
|
||||
## PAN-124956
|
||||
|
||||
There is an issue where VM-Series firewalls do not support packet buffer protection.
|
||||
|
||||
## PAN-120662
|
||||
|
||||
```caveat
|
||||
PA-7000 series firewalls using PA-7000-20G-NPC cards only
|
||||
```
|
||||
|
||||
There is an intermittent issue where an out-of-memory (OOM) condition causes dataplane or internal path monitoring to stop responding.
|
||||
|
||||
## PAN-120440
|
||||
|
||||
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||
|
||||
## PAN-120303
|
||||
|
||||
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||
|
||||
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||
|
||||
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||
2. **Commit** your changes.
|
||||
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||
4. **Commit** your changes.
|
||||
- Restart the firewall (devsrvr) process.
|
||||
1. Log in to the firewall CLI.
|
||||
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||
|
||||
## PAN-118628
|
||||
|
||||
There is an issue where after you deploy Panorama in Azure, you cannot log in to Panorama with the username and password that was provided during the deployment process.
|
||||
|
||||
## PAN-118525
|
||||
|
||||
```caveat
|
||||
PA-5250, PA-5260, PA-5280, and PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
There is an issue where the QSFP28 port does not come up with the TR-FC13L-N00 version of the PAN-QSFP28-100GBASE-LR4 optical transceiver on firewalls running a PAN-OS 9.0 release. For assistance, please contact Support.
|
||||
|
||||
## PAN-118108
|
||||
|
||||
There is an issue where an API call against a Panorama management server, which triggers the `request analyze-shared-policy` command causes Panorama to reboot after you execute the command.
|
||||
|
||||
## PAN-118065
|
||||
|
||||
```caveat
|
||||
M-Series Panorama management servers in Management Only mode
|
||||
```
|
||||
|
||||
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
|
||||
|
||||
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
|
||||
|
||||
## PAN-118008
|
||||
|
||||
```caveat
|
||||
Affects PA-3000 series appliances only
|
||||
```
|
||||
|
||||
There is an infrequently encountered issue where a low memory condition intermittently prevents decoders from loading, leading to traffic inspection issues related to the impacted decoder(s).
|
||||
|
||||
## PAN-117043
|
||||
|
||||
There is an issue on the Panorama management server and all supported firewalls where special characters contained in the tag names of the Security policy rules returns the following error message: `group-tag is invalid` when you commit or push a configuration.
|
||||
|
||||
**Workaround:** Modify the tags and group tags (**Objects** > **Tags**) to exclude special characters.
|
||||
|
||||
## PAN-116436
|
||||
|
||||
```caveat
|
||||
Panorama virtual appliances only
|
||||
```
|
||||
|
||||
There is a disk space calculation error that eventually leads to an erroneous opt/panlogs/ partition full condition and causes a process (CDB) to stop responding.
|
||||
|
||||
## PAN-116084
|
||||
|
||||
VM-Series firewalls on Microsoft Azure deployed using MMAP drops traffic when the firewall experiences heavy traffic.
|
||||
|
||||
## PAN-116069
|
||||
|
||||
```caveat
|
||||
PA-200 firewalls only
|
||||
```
|
||||
|
||||
There is a rare out-of-memory (OOM) condition.
|
||||
|
||||
## PAN-116017
|
||||
|
||||
```caveat
|
||||
Google Cloud Platform (GCP) only
|
||||
```
|
||||
|
||||
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||
|
||||
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||
|
||||
## PAN-115816
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||
|
||||
**Workaround:** Reboot the firewall.
|
||||
|
||||
## PAN-115733
|
||||
|
||||
```caveat
|
||||
PAN-OS firewalls in an HA configuration only
|
||||
```
|
||||
|
||||
There is a rare issue where data interfaces do not come up after you reboot the firewall when running a C5 or M5 instance type in AWS.
|
||||
|
||||
**Workaround:** Reboot the firewall.
|
||||
|
||||
## PAN-114495
|
||||
|
||||
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||
|
||||
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||
|
||||
## PAN-113501
|
||||
|
||||
The Panorama management server returns a Secure Copy (SCP) server connection error after you create an SCP Scheduled Config Export profile (**Panorama** > **Scheduled Config Export**) due to the SCP server password exceeding 15 characters in length.
|
||||
|
||||
## PAN-113117
|
||||
|
||||
A newly launched firewall does not get its configuration from Panorama when it first connects if you installed the VM-Series plugin on Panorama. When a newly launched firewall that is bootstrapped connects to Panorama, a process restart occurs on Panorama. Upon restart, you are logged out of the user interface and you need to log in and push the device group and template configuration to the newly connected firewall.
|
||||
|
||||
## PAN-113098
|
||||
|
||||
In the firewall web interface, you can temporarily submit change requests for the following URL categories: insufficient-content, high-risk, medium-risk, low-risk, and newly-registered-domains. However, Palo Alto Networks does not support or process change requests for these categories.
|
||||
|
||||
## PAN-112983
|
||||
|
||||
```caveat
|
||||
Firewalls with multiple virtual systems only; no impact to Panorama
|
||||
```
|
||||
|
||||
If you select any Location other than Shared when you generate or import a new CA Certificate in a Certificate Profile (**Device** > **Certificate Management** > **Certificate Profile**), the firewall adds the newly generated or imported certificate to vsys1. For example, if you specify vsys3 as the **Location**, **Add** a CA Certificate, and then **Generate** a new certificate, the firewall adds the certificate to vsys1 instead of vsys3. When you click **OK** to configure the Certificate Profile, the firewall returns an `Operation Failed` error message because it sees a certificate for vsys1 added to vsys3.
|
||||
|
||||
**Workaround 1:**
|
||||
|
||||
1. Generate or import the new certificate in a Certificate Profile (**Device** > **Certificate Management** > **Certificates** > **Device Certificates**) and select the appropriate vsys **Location** when you generate or import the certificate.
|
||||
2. When you create or edit the Certificate Profile, specify the vsys **Location** and **Add** the certificate that you generated (or imported) from the list of existing certificates.
|
||||
|
||||
**Workaround 2:** When you generate or import a new certificate when you configure a Certificate Profile for a vsys other than vsys1, specify the **Location** as Shared.
|
||||
|
||||
## PAN-112814
|
||||
|
||||
H.323-based calls lose audio when the predicted H.245 session cannot convert to Active status, which causes the firewall to incorrectly drop H.245 traffic.
|
||||
|
||||
## PAN-112699
|
||||
|
||||
```caveat
|
||||
VM-Series firewall on AWS running on a C5 or M5 instance only
|
||||
```
|
||||
|
||||
You cannot use the `mgmt-interface-swap` command to [swap the interfaces](https://docs.paloaltonetworks.com/vm-series/9-0/vm-series-deployment/set-up-the-vm-series-firewall-on-aws/about-the-vm-series-firewall-on-aws/management-interface-mapping-for-use-with-amazon-elb.html) for deploying a VM-Series firewall behind a web load balancer (such as AWS ALB or Classic ELB).
|
||||
|
||||
**Workaround:** Check for the latest VM-Series plugin version and install the VM-Series plugin 9.0.0 version; the built-in version is 9.0.0-c29.
|
||||
|
||||
## PAN-112694
|
||||
|
||||
```caveat
|
||||
Firewalls with multiple virtual systems only
|
||||
```
|
||||
|
||||
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||
|
||||
## PAN-112626
|
||||
|
||||
When you upgrade to PAN-OS 9.0 with a PAYG Bundle 2 license, the new DNS Security subscription is not available on your VM-Series firewall.
|
||||
|
||||
This subscription is included with the BYOL and VM-Series ELA when you upgrade.
|
||||
|
||||
## PAN-112562
|
||||
|
||||
The **Log Forwarding Card** (LFC) subinterface incorrectly uses the interface IP address instead of the subinterface IP address for all services that forward logs (such as syslog, email, and SNMP) for selected virtual systems.
|
||||
|
||||
## PAN-112456
|
||||
|
||||
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
|
||||
|
||||
## PAN-112340
|
||||
|
||||
If you enable URL Filtering without enabling Threat Prevention and your environment processes a large number (thousands) of URL look-ups per second per dataplane, you are likely to experience performance issues, including high CPU usage.
|
||||
|
||||
## PAN-111928
|
||||
|
||||
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||
|
||||
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||
|
||||
## PAN-111866
|
||||
|
||||
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||
|
||||
**Workaround:** Perform one of the following tasks.
|
||||
|
||||
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||
- Manually select the devices that belong to the modified device group and template configurations.
|
||||
|
||||
## PAN-111729
|
||||
|
||||
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||
|
||||
## PAN-111670
|
||||
|
||||
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||
|
||||
## PAN-111553
|
||||
|
||||
On the Panorama management server, the **Include Device and Network Templates** setting is disabled by default when you attempt to push changes to managed devices, which causes your push to fail.
|
||||
|
||||
**Workaround:** Before you commit and push the configuration changes from Panorama to your managed devices, edit the push scope (**Commit** > **Push to Devices** > **Edit Selections** or **Commit** > **Commit and Push** > **Edit Selections**) to **Include Device and Network Templates**.
|
||||
|
||||
## PAN-111251
|
||||
|
||||
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
|
||||
|
||||
## PAN-110794
|
||||
|
||||
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||
|
||||
## PAN-110603
|
||||
|
||||
In some cases, when a port on an PA-7000 Series 100Gbps Network Processor Card (NPC) has an SFP+ transceiver inserted but no cable is connected, the system detects a signal and attempts to tune and link with that port. As a result, if the device at the other end of the connection is rebooted or has an HA failover event, the link is sometimes held down for an extended period of time while the interface attempts to tune itself.
|
||||
|
||||
**Workaround:** Connect a cable to the installed SFP+ transceiver to allow the system to tune and link. Then, when you disconnect the cable, the system will correctly detect that the link is down. Alternatively, remove the SFP+ transceiver from the port.
|
||||
|
||||
## PAN-109526
|
||||
|
||||
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||
|
||||
## PAN-106989
|
||||
|
||||
There is a display-only issue on Panorama that results in a `commit failed` status for Template Last Commit State (**Panorama** > **Managed Devices** > **Summary**).
|
||||
|
||||
**Workaround:** Push templates to managed devices.
|
||||
|
||||
## PAN-106675
|
||||
|
||||
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||
|
||||
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||
|
||||
## PAN-105210
|
||||
|
||||
```caveat
|
||||
Panorama in FIPS mode only when managing non-FIPS firewalls
|
||||
```
|
||||
|
||||
You cannot configure a GlobalProtect portal on Panorama in FIPS mode when managing a non-FIPS firewall. If you attempt to do so, you will receive the following error message: `agent-user-override-key unexpected here Portal_fips.`
|
||||
|
||||
## PAN-104808
|
||||
|
||||
There is an issue where scheduled SaaS reports generate and email empty PDF reports.
|
||||
|
||||
**Workaround:** Manually generate the report from the Panorama web interface.
|
||||
|
||||
## PAN-104780
|
||||
|
||||
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||
|
||||
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||
|
||||
## PAN-103336
|
||||
|
||||
```caveat
|
||||
HA configurations only
|
||||
```
|
||||
|
||||
When you downgrade a VM-Series firewall on Azure from PAN-OS 9.0 to an earlier release, you do not receive warnings. Do not downgrade your firewall without saving and exporting your current configuration.
|
||||
|
||||
**Workaround:** Because HA is not supported in earlier versions of VM-Series firewalls on Azure, to prevent the loss of your configuration:
|
||||
|
||||
- Save and export the configuration before you downgrade.
|
||||
- After you downgrade, load the saved configuration and commit your changes. The firewall will resume operation without the HA configuration.
|
||||
|
||||
## PAN-103276
|
||||
|
||||
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||
|
||||
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||
|
||||
## PAN-103018
|
||||
|
||||
```caveat
|
||||
Panorama plugins
|
||||
```
|
||||
|
||||
When you use the AND/OR boolean operators to define the match criteria for Dynamic Address Groups on Panorama, the boolean operators do not function properly. The member IP addresses are not included in the address group as expected.
|
||||
|
||||
## PAN-101688
|
||||
|
||||
```caveat
|
||||
Panorama plugins
|
||||
```
|
||||
|
||||
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||
|
||||
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||
|
||||
## PAN-101537
|
||||
|
||||
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||
|
||||
**Workaround:** Specify the vsys in the query string:
|
||||
|
||||
`admin>` `set system target-vsys <vsys-name>`
|
||||
|
||||
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||
|
||||
## PAN-99483
|
||||
|
||||
```caveat
|
||||
PA-5250, PA-5260, and PA-5280 firewalls only
|
||||
```
|
||||
|
||||
When you deploy the firewall in a network that uses Dynamic IP and Port (DIPP) NAT translation with PPTP, client systems are limited to using a translated IP address-and-port pair for only one connection. This issue occurs because the PPTP protocol uses a TCP signaling (control) protocol that exchanges data using Generic Routing Encapsulation (GRE) version 1 and the hardware cannot correlate the call-id in the GRE version 1 header with the correct dataplane (the one that owns the predict session of GRE).
|
||||
|
||||
## PAN-98803
|
||||
|
||||
If you configure the Panorama plugin to monitor virtual machines or endpoints in your AWS, Azure, or Cisco ACI environment without installing the NSX plugin, the IP-address-to-tag mappings for Dynamic Address Groups are not displayed on Panorama.
|
||||
|
||||
**Workaround:** Install the NSX plugin (you do not need to use the NSX plugin for the installation to resolve this display issue).
|
||||
|
||||
## PAN-98520
|
||||
|
||||
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||
|
||||
## PAN-97757
|
||||
|
||||
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||
|
||||
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||
|
||||
## PAN-97524
|
||||
|
||||
```caveat
|
||||
Panorama management server only
|
||||
```
|
||||
|
||||
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||
|
||||
## PAN-96985
|
||||
|
||||
The `request shutdown system` command does not shut down the Panorama management server.
|
||||
|
||||
## PAN-96960
|
||||
|
||||
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
|
||||
|
||||
## PAN-96446
|
||||
|
||||
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||
|
||||
## PAN-95773
|
||||
|
||||
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||
|
||||
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||
|
||||
## PAN-95717
|
||||
|
||||
After 30,000 or more end users log in to the GlobalProtect gateway within a two- to three-hour period, the firewall web interface responds slowly, commits take longer than expected or intermittently fail, and Tech Support File generation times out and fails.
|
||||
|
||||
## PAN-95602
|
||||
|
||||
In a deployment where a Log Collector connects to Panorama management servers in a high availability (HA) configuration, after you switch the Log Collector appliance to Panorama mode, commit operations fail on the appliance.
|
||||
|
||||
**Workaround:** Remove the following node from the running-config.xml file on the Log Collector before switching it to Panorama mode: `devices/entry[@name='localhost.localdomain']/deviceconfig/system/panorama-server-2`
|
||||
|
||||
## PAN-95511
|
||||
|
||||
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||
|
||||
## PAN-95028
|
||||
|
||||
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||
|
||||
## PAN-94966
|
||||
|
||||
After you delete disconnected and connected Terminal Server (TS) agents in the same operation, the firewall still displays the IP address-to-port-user mappings (`show user ip-port-user-mapping` CLI command) for the disconnected TS agents you deleted (**Device** > **User Identification** > **Terminal Services Agents**).
|
||||
|
||||
**Workaround:** Do not delete both disconnected and connected TS agents in the same operation.
|
||||
|
||||
## PAN-94846
|
||||
|
||||
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||
|
||||
## PAN-94093
|
||||
|
||||
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||
|
||||
## PAN-93968
|
||||
|
||||
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||
|
||||
## PAN-93842
|
||||
|
||||
The logging status of a Panorama Log Collector deployed on AWS or Azure displays as disconnected when you configure the ethernet1/1 to ethernet1/5 interfaces for log collection (**Panorama** > **Managed Collectors** > **Interfaces**). This results in firewalls not sending logs to the Log Collector.
|
||||
|
||||
**Workaround:** Configure the management (MGT) interface for log collection.
|
||||
|
||||
## PAN-93607
|
||||
|
||||
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||
|
||||
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||
|
||||
## PAN-93532
|
||||
|
||||
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||
|
||||
## PAN-93193
|
||||
|
||||
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||
|
||||
- Switch to the firewall **Context** on the Panorama management server.
|
||||
- Commit changes when a dynamic update is being installed.
|
||||
- Generate a custom report when a dynamic update is being installed.
|
||||
- Generate custom reports during a commit.
|
||||
|
||||
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||
|
||||
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||
|
||||
## PAN-91802
|
||||
|
||||
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||
|
||||
## PAN-86903
|
||||
|
||||
In rare cases, PA-800 Series firewalls shut themselves down due to a false over-current measurement.
|
||||
|
||||
## PAN-84670
|
||||
|
||||
When you disable decryption for HTTPS traffic, end users who don't have valid authentication timestamps can access HTTPS services and applications regardless of Authentication policy.
|
||||
|
||||
**Workaround:** Create a Security policy rule that blocks HTTPS traffic that is not decrypted.
|
||||
|
||||
## PAN-99483
|
||||
|
||||
On PA-7000 Series and PA-5200 Series firewalls, client systems can use a translated IP address-and-port pair for only one connection even if you configure the Dynamic IP and Port (DIPP) **NAT Oversubscription Rate** to allow multiple connections (**Device** > **Setup** > **Session** > **Session Settings** > **NAT Oversubscription**).
|
||||
|
||||
## PAN-83610
|
||||
|
||||
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||
|
||||
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||
|
||||
## PAN-83598
|
||||
|
||||
VM-Series firewalls cannot monitor more than 500 virtual machine (VM) information sources (**Device** > **VM Information Sources**).
|
||||
|
||||
## PAN-83236
|
||||
|
||||
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||
|
||||
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||
|
||||
## PAN-83215
|
||||
|
||||
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||
|
||||
## PAN-81521
|
||||
|
||||
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||
|
||||
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||
|
||||
## PAN-79423
|
||||
|
||||
Panorama cannot push address group objects from device groups to managed firewalls when zones specify the objects in the User Identification ACL include or exclude lists (**Network** > **Zones**) and the **Share Unused Address and Service Objects with Devices** option is disabled (**Panorama** > **Setup** > **Management** > **Panorama Settings**).
|
||||
|
||||
## PAN-77125
|
||||
|
||||
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||
|
||||
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||
|
||||
## PAN-75457
|
||||
|
||||
```caveat
|
||||
PAN-OS 8.0.1 and later releases
|
||||
```
|
||||
|
||||
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||
|
||||
## PAN-73530
|
||||
|
||||
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||
|
||||
## PAN-73401
|
||||
|
||||
```caveat
|
||||
PAN-OS 8.0.1 and later releases
|
||||
```
|
||||
|
||||
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||
|
||||
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||
|
||||
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||
|
||||
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||
- Configure a worker list on the cluster controller:
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||
or
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||
|
||||
## PAN-71329
|
||||
|
||||
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
|
||||
|
||||
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
|
||||
|
||||
## PAN-70906
|
||||
|
||||
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||
|
||||
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||
|
||||
## PAN-69505
|
||||
|
||||
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||
|
||||
## PAN-41558
|
||||
|
||||
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||
|
||||
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||
|
||||
## PAN-40079
|
||||
|
||||
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||
|
||||
## PAN-39636
|
||||
|
||||
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||
|
||||
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||
|
||||
## PAN-38255
|
||||
|
||||
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||
|
||||
## PAN-31832
|
||||
|
||||
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||
|
||||
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||
|
||||
## PAN-25046
|
||||
|
||||
Firewalls store SSH host keys used for SCP log exports in the known hosts file. In an HA deployment, PAN-OS synchronizes the SCP log export configuration between the firewall HA peers (**Device** > **Scheduled Log Export**), but not the known host file. When a failover occurs, the SCP log export fails.
|
||||
|
||||
**Workaround:** Log in to each peer in HA, select **Device** > **Scheduled Log Export** > **<log_export_configuration>**, and **Test SCP server connection** to confirm the host key so that SCP log forwarding continues to work after a failover.
|
||||
@@ -0,0 +1,642 @@
|
||||
---
|
||||
type: Known
|
||||
product: PAN-OS
|
||||
version: 9.0.4
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||
|
||||
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
A Panorama management server running PAN-OS 9.0 does not currently support management of appliances running WildFire 7.1 or earlier releases. Even though these management options are visible on the Panorama 9.0 web interface (**Panorama** > **Managed WildFire Clusters** and **Panorama** > **Managed WildFire Appliances**), making changes to these settings for appliances running WildFire 7.1 or an earlier release has no effect.
|
||||
|
||||
## WF500-4200
|
||||
|
||||
The Create Date shown when using the `show wildfire global sample-status sha256 equal<hash>` or `show wildfire global sample-analysis` CLI command is two hours behind the actual time for WF-500 appliance samples.
|
||||
|
||||
## PLUG-1854
|
||||
|
||||
```caveat
|
||||
PAN-OS 9.0.2 and later releases on AWS and GCP only
|
||||
```
|
||||
|
||||
You cannot swap the management interface.
|
||||
|
||||
## PLUG-1827
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
The firewall drops packets due to larger than expected packet sizes when Accelerated networking is enabled on the firewall (**Settings** > **Networking**).
|
||||
|
||||
## PLUG-1709
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
There is an intermittent issue where the secondary IP address becomes associated with the passive firewall after multiple failovers.
|
||||
|
||||
**Workaround:** Reassign IP addresses to the active and passive firewalls in Azure as needed.
|
||||
|
||||
## PLUG-1694
|
||||
|
||||
```caveat
|
||||
PAYG licenses only
|
||||
```
|
||||
|
||||
Your pay-as-you-go (PAYG) license is not retained when you upgrade from a PAN-OS 8.1 release to a PAN-OS 9.0 release.
|
||||
|
||||
**Workaround:** Upgrade to VM-Series plugin 1.0.2 (or later) after you upgrade to a PAN-OS 9.0 release and then reboot the firewall to recover your PAYG license.
|
||||
|
||||
## PLUG-1681
|
||||
|
||||
If you bootstrap a PAN-OS 9.0.1 image while using VM-Series plugin 1.0.0, the firewall will not apply the capacity license. To downgrade the VM-Series plugin from version 1.0.2 to 1.0.0, first bootstrap the PAN-OS 9.0.1 image and then downgrade the plugin.
|
||||
|
||||
## PLUG-1642
|
||||
|
||||
```caveat
|
||||
This issue is resolved with VM-Series plugin 1.0.2.
|
||||
```
|
||||
|
||||
After a high availability (HA) failover, the dataplane interface on a VM-Series firewall on Azure with Accelerated Networking (SR-IOV) becomes disabled when, as a result of the failover, the secondary IP address is detached from or attached to the firewall and moved to its HA peer.
|
||||
|
||||
## PLUG-1503
|
||||
|
||||
```caveat
|
||||
This issue is resolved with VM-Series plugin 1.0.3.
|
||||
```
|
||||
|
||||
When a VM-Series firewall on AWS running on a C5 or M5 instance experiences a high availability (HA) failover, the dataplane interfaces from the previously active firewall are not moved to the newly active (previously passive) peer.
|
||||
|
||||
**Workaround:** Check for the latest VM-Series plugin version and install the VM-Series plugin 9.0.0 version; the built-in version is 9.0.0-c29.
|
||||
|
||||
## PLUG-1074
|
||||
|
||||
On the VM-Series firewall on AWS, when you change the instance type, the firewall no longer has a serial number or a license. Additionally, if you manage this firewall using Panorama, it is no longer connected to Panorama.
|
||||
|
||||
## PLUG-380
|
||||
|
||||
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||
|
||||
## PAN-178194
|
||||
|
||||
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
|
||||
|
||||
## PAN-154247
|
||||
|
||||
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
|
||||
|
||||
**Workaround:** Log out and back in to the Panorama web interface.
|
||||
|
||||
## PAN-140084
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. See PAN-OS 9.0.11 Addressed Issues.
|
||||
```
|
||||
|
||||
There is an issue where the default Dynamic IP and Port (DIPP) NAT oversubscription rate is set to 2.
|
||||
|
||||
## PAN-131915
|
||||
|
||||
There is an issue when you implement a new firewall bootstrap with a USB drive where the bootstrap fails and displays the following error message: `no USB device found`.
|
||||
|
||||
**Workaround:** Perform a factory reset or run the `request system private-data-reset` CLI command and then proceed with bootstrapping.
|
||||
|
||||
## PAN-131792
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. SeePAN-OS 9.0.9 Addressed Issues.
|
||||
```
|
||||
|
||||
The Name log filter (**Monitor** > **Logs** > **Traffic**) is not maintained when viewing the Log Viewer for a Security policy rule (**Policies** > **Security**) from the drop-down menu.
|
||||
|
||||
## PAN-130069
|
||||
|
||||
There is an issue where the firewall incorrectly interprets an external dynamic list MineMeld instability error code as an empty external dynamic list.
|
||||
|
||||
## PAN-128269
|
||||
|
||||
```caveat
|
||||
PA-5250, PA-5260, and PA-5280 firewalls with 100GB AOC cables only
|
||||
```
|
||||
|
||||
When you upgrade the first peer in a high availability (HA) configuration to PAN-OS 9.0.3 or a later PAN-OS 9.0 release, the High Speed Chassis Interconnect (HSCI) port did not come up due to an FEC mismatch until after you finished upgrading the second peer.
|
||||
|
||||
## PAN-127189
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
The non-blocking pattern match setting is enabled by default, which results in CTD performance degradation.
|
||||
|
||||
**Workaround:** Manually disable the feature and improve performance by using the following CLI command: `set system setting ctd nonblocking-pattern-match disable`.
|
||||
|
||||
## PAN-126921
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
There is an issue where internal path monitoring fails when the firewall processes corrupt packets.
|
||||
|
||||
## PAN-125775
|
||||
|
||||
There is an issue where Panorama management servers deployed using the C5 or M5 instance types on Amazon Web Services (AWS) cause the Panorama instance to stop responding in regions that support these instance types.
|
||||
|
||||
## PAN-125121
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
There is an issue where custom images do not function as expected for PAN-OS 9.0.
|
||||
|
||||
**Workaround:** Use PAN-OS 8.1 for creating custom images.
|
||||
|
||||
## PAN-124956
|
||||
|
||||
There is an issue where VM-Series firewalls do not support packet buffer protection.
|
||||
|
||||
## PAN-120440
|
||||
|
||||
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||
|
||||
## PAN-120303
|
||||
|
||||
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||
|
||||
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||
|
||||
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||
2. **Commit** your changes.
|
||||
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||
4. **Commit** your changes.
|
||||
- Restart the firewall (devsrvr) process.
|
||||
1. Log in to the firewall CLI.
|
||||
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||
|
||||
## PAN-118628
|
||||
|
||||
There is an issue where after you deploy Panorama in Azure, you cannot log in to Panorama with the username and password that was provided during the deployment process.
|
||||
|
||||
## PAN-118414
|
||||
|
||||
```caveat
|
||||
PAN-OS 9.0.2 and later releases only
|
||||
```
|
||||
|
||||
There is an intermittent issue where a Panorama management server and managing Prisma™ Access or Cortex™ Data Lake fails to authorize one-time-password (OTP) submissions during the onboarding process.
|
||||
|
||||
**Workaround:** Downgrade to PAN-OS 9.0.1.
|
||||
|
||||
## PAN-118108
|
||||
|
||||
There is an issue where an API call against a Panorama management server, which triggers the `request analyze-shared-policy` command causes Panorama to reboot after you execute the command.
|
||||
|
||||
## PAN-117043
|
||||
|
||||
There is an issue on the Panorama management server and all supported firewalls where special characters contained in the tag names of the Security policy rules returns the following error message: `group-tag is invalid` when you commit or push a configuration.
|
||||
|
||||
**Workaround:** Modify the tags and group tags (**Objects** > **Tags**) to exclude special characters.
|
||||
|
||||
## PAN-116017
|
||||
|
||||
```caveat
|
||||
Google Cloud Platform (GCP) only
|
||||
```
|
||||
|
||||
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||
|
||||
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||
|
||||
## PAN-115816
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||
|
||||
**Workaround:** Reboot the firewall.
|
||||
|
||||
## PAN-115733
|
||||
|
||||
```caveat
|
||||
PAN-OS firewalls in an HA configuration only
|
||||
```
|
||||
|
||||
There is a rare issue where data interfaces do not come up after you reboot the firewall when running a C5 or M5 instance type in AWS.
|
||||
|
||||
**Workaround:** Reboot the firewall.
|
||||
|
||||
## PAN-114495
|
||||
|
||||
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||
|
||||
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||
|
||||
## PAN-113117
|
||||
|
||||
A newly launched firewall does not get its configuration from Panorama when it first connects if you installed the VM-Series plugin on Panorama. When a newly launched firewall that is bootstrapped connects to Panorama, a process restart occurs on Panorama. Upon restart, you are logged out of the user interface and you need to log in and push the device group and template configuration to the newly connected firewall.
|
||||
|
||||
## PAN-113098
|
||||
|
||||
In the firewall web interface, you can temporarily submit change requests for the following URL categories: insufficient-content, high-risk, medium-risk, low-risk, and newly-registered-domains. However, Palo Alto Networks does not support or process change requests for these categories.
|
||||
|
||||
## PAN-112983
|
||||
|
||||
```caveat
|
||||
Firewalls with multiple virtual systems only; no impact to Panorama
|
||||
```
|
||||
|
||||
If you select any Location other than Shared when you generate or import a new CA Certificate in a Certificate Profile (**Device** > **Certificate Management** > **Certificate Profile**), the firewall adds the newly generated or imported certificate to vsys1. For example, if you specify vsys3 as the **Location**, **Add** a CA Certificate, and then **Generate** a new certificate, the firewall adds the certificate to vsys1 instead of vsys3. When you click **OK** to configure the Certificate Profile, the firewall returns an `Operation Failed` error message because it sees a certificate for vsys1 added to vsys3.
|
||||
|
||||
**Workaround 1:**
|
||||
|
||||
1. Generate or import the new certificate in a Certificate Profile (**Device** > **Certificate Management** > **Certificates** > **Device Certificates**) and select the appropriate vsys **Location** when you generate or import the certificate.
|
||||
2. When you create or edit the Certificate Profile, specify the vsys **Location** and **Add** the certificate that you generated (or imported) from the list of existing certificates.
|
||||
|
||||
**Workaround 2:** When you generate or import a new certificate when you configure a Certificate Profile for a vsys other than vsys1, specify the **Location** as Shared.
|
||||
|
||||
## PAN-112694
|
||||
|
||||
```caveat
|
||||
Firewalls with multiple virtual systems only
|
||||
```
|
||||
|
||||
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||
|
||||
## PAN-112626
|
||||
|
||||
When you upgrade to PAN-OS 9.0 with a PAYG Bundle 2 license, the new DNS Security subscription is not available on your VM-Series firewall.
|
||||
|
||||
This subscription is included with the BYOL and VM-Series ELA when you upgrade.
|
||||
|
||||
## PAN-112562
|
||||
|
||||
The **Log Forwarding Card** (LFC) subinterface incorrectly uses the interface IP address instead of the subinterface IP address for all services that forward logs (such as syslog, email, and SNMP) for selected virtual systems.
|
||||
|
||||
## PAN-112456
|
||||
|
||||
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
|
||||
|
||||
## PAN-111928
|
||||
|
||||
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||
|
||||
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||
|
||||
## PAN-111866
|
||||
|
||||
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||
|
||||
**Workaround:** Perform one of the following tasks.
|
||||
|
||||
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||
- Manually select the devices that belong to the modified device group and template configurations.
|
||||
|
||||
## PAN-111729
|
||||
|
||||
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||
|
||||
## PAN-111670
|
||||
|
||||
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||
|
||||
## PAN-110794
|
||||
|
||||
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||
|
||||
## PAN-110603
|
||||
|
||||
In some cases, when a port on an PA-7000 Series 100Gbps Network Processor Card (NPC) has an SFP+ transceiver inserted but no cable is connected, the system detects a signal and attempts to tune and link with that port. As a result, if the device at the other end of the connection is rebooted or has an HA failover event, the link is sometimes held down for an extended period of time while the interface attempts to tune itself.
|
||||
|
||||
**Workaround:** Connect a cable to the installed SFP+ transceiver to allow the system to tune and link. Then, when you disconnect the cable, the system will correctly detect that the link is down. Alternatively, remove the SFP+ transceiver from the port.
|
||||
|
||||
## PAN-109526
|
||||
|
||||
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||
|
||||
## PAN-106989
|
||||
|
||||
There is a display-only issue on Panorama that results in a `commit failed` status for Template Last Commit State (**Panorama** > **Managed Devices** > **Summary**).
|
||||
|
||||
**Workaround:** Push templates to managed devices.
|
||||
|
||||
## PAN-106675
|
||||
|
||||
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||
|
||||
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||
|
||||
## PAN-105210
|
||||
|
||||
```caveat
|
||||
Panorama in FIPS mode only when managing non-FIPS firewalls
|
||||
```
|
||||
|
||||
You cannot configure a GlobalProtect portal on Panorama in FIPS mode when managing a non-FIPS firewall. If you attempt to do so, you will receive the following error message: `agent-user-override-key unexpected here Portal_fips.`
|
||||
|
||||
## PAN-104780
|
||||
|
||||
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||
|
||||
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||
|
||||
## PAN-103336
|
||||
|
||||
```caveat
|
||||
HA configurations only
|
||||
```
|
||||
|
||||
When you downgrade a VM-Series firewall on Azure from PAN-OS 9.0 to an earlier release, you do not receive warnings. Do not downgrade your firewall without saving and exporting your current configuration.
|
||||
|
||||
**Workaround:** Because HA is not supported in earlier versions of VM-Series firewalls on Azure, to prevent the loss of your configuration:
|
||||
|
||||
- Save and export the configuration before you downgrade.
|
||||
- After you downgrade, load the saved configuration and commit your changes. The firewall will resume operation without the HA configuration.
|
||||
|
||||
## PAN-103276
|
||||
|
||||
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||
|
||||
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||
|
||||
## PAN-103018
|
||||
|
||||
```caveat
|
||||
Panorama plugins
|
||||
```
|
||||
|
||||
When you use the AND/OR boolean operators to define the match criteria for Dynamic Address Groups on Panorama, the boolean operators do not function properly. The member IP addresses are not included in the address group as expected.
|
||||
|
||||
## PAN-101688
|
||||
|
||||
```caveat
|
||||
Panorama plugins
|
||||
```
|
||||
|
||||
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||
|
||||
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||
|
||||
## PAN-101537
|
||||
|
||||
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||
|
||||
**Workaround:** Specify the vsys in the query string:
|
||||
|
||||
`admin>` `set system target-vsys <vsys-name>`
|
||||
|
||||
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||
|
||||
## PAN-98803
|
||||
|
||||
If you configure the Panorama plugin to monitor virtual machines or endpoints in your AWS, Azure, or Cisco ACI environment without installing the NSX plugin, the IP-address-to-tag mappings for Dynamic Address Groups are not displayed on Panorama.
|
||||
|
||||
**Workaround:** Install the NSX plugin (you do not need to use the NSX plugin for the installation to resolve this display issue).
|
||||
|
||||
## PAN-98520
|
||||
|
||||
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||
|
||||
## PAN-97757
|
||||
|
||||
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||
|
||||
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||
|
||||
## PAN-97524
|
||||
|
||||
```caveat
|
||||
Panorama management server only
|
||||
```
|
||||
|
||||
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||
|
||||
## PAN-96985
|
||||
|
||||
The `request shutdown system` command does not shut down the Panorama management server.
|
||||
|
||||
## PAN-96960
|
||||
|
||||
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
|
||||
|
||||
## PAN-96446
|
||||
|
||||
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||
|
||||
## PAN-95773
|
||||
|
||||
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||
|
||||
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||
|
||||
## PAN-95717
|
||||
|
||||
After 30,000 or more end users log in to the GlobalProtect gateway within a two- to three-hour period, the firewall web interface responds slowly, commits take longer than expected or intermittently fail, and Tech Support File generation times out and fails.
|
||||
|
||||
## PAN-95602
|
||||
|
||||
In a deployment where a Log Collector connects to Panorama management servers in a high availability (HA) configuration, after you switch the Log Collector appliance to Panorama mode, commit operations fail on the appliance.
|
||||
|
||||
**Workaround:** Remove the following node from the running-config.xml file on the Log Collector before switching it to Panorama mode: `devices/entry[@name='localhost.localdomain']/deviceconfig/system/panorama-server-2`
|
||||
|
||||
## PAN-95511
|
||||
|
||||
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||
|
||||
## PAN-95028
|
||||
|
||||
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||
|
||||
## PAN-94966
|
||||
|
||||
After you delete disconnected and connected Terminal Server (TS) agents in the same operation, the firewall still displays the IP address-to-port-user mappings (`show user ip-port-user-mapping` CLI command) for the disconnected TS agents you deleted (**Device** > **User Identification** > **Terminal Services Agents**).
|
||||
|
||||
**Workaround:** Do not delete both disconnected and connected TS agents in the same operation.
|
||||
|
||||
## PAN-94846
|
||||
|
||||
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||
|
||||
## PAN-94093
|
||||
|
||||
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||
|
||||
## PAN-93968
|
||||
|
||||
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||
|
||||
## PAN-93842
|
||||
|
||||
The logging status of a Panorama Log Collector deployed on AWS or Azure displays as disconnected when you configure the ethernet1/1 to ethernet1/5 interfaces for log collection (**Panorama** > **Managed Collectors** > **Interfaces**). This results in firewalls not sending logs to the Log Collector.
|
||||
|
||||
**Workaround:** Configure the management (MGT) interface for log collection.
|
||||
|
||||
## PAN-93607
|
||||
|
||||
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||
|
||||
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||
|
||||
## PAN-93532
|
||||
|
||||
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||
|
||||
## PAN-93193
|
||||
|
||||
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||
|
||||
- Switch to the firewall **Context** on the Panorama management server.
|
||||
- Commit changes when a dynamic update is being installed.
|
||||
- Generate a custom report when a dynamic update is being installed.
|
||||
- Generate custom reports during a commit.
|
||||
|
||||
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||
|
||||
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||
|
||||
## PAN-91802
|
||||
|
||||
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||
|
||||
## PAN-86903
|
||||
|
||||
In rare cases, PA-800 Series firewalls shut themselves down due to a false over-current measurement.
|
||||
|
||||
## PAN-83610
|
||||
|
||||
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||
|
||||
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||
|
||||
## PAN-83598
|
||||
|
||||
VM-Series firewalls cannot monitor more than 500 virtual machine (VM) information sources (**Device** > **VM Information Sources**).
|
||||
|
||||
## PAN-83236
|
||||
|
||||
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||
|
||||
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||
|
||||
## PAN-83215
|
||||
|
||||
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||
|
||||
## PAN-81521
|
||||
|
||||
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||
|
||||
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||
|
||||
## PAN-79423
|
||||
|
||||
Panorama cannot push address group objects from device groups to managed firewalls when zones specify the objects in the User Identification ACL include or exclude lists (**Network** > **Zones**) and the **Share Unused Address and Service Objects with Devices** option is disabled (**Panorama** > **Setup** > **Management** > **Panorama Settings**).
|
||||
|
||||
## PAN-77125
|
||||
|
||||
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||
|
||||
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||
|
||||
## PAN-75457
|
||||
|
||||
```caveat
|
||||
PAN-OS 8.0.1 and later releases
|
||||
```
|
||||
|
||||
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||
|
||||
## PAN-73530
|
||||
|
||||
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||
|
||||
## PAN-73401
|
||||
|
||||
```caveat
|
||||
PAN-OS 8.0.1 and later releases
|
||||
```
|
||||
|
||||
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||
|
||||
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||
|
||||
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||
|
||||
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||
- Configure a worker list on the cluster controller:
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||
or
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||
|
||||
## PAN-71329
|
||||
|
||||
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
|
||||
|
||||
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
|
||||
|
||||
## PAN-70906
|
||||
|
||||
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||
|
||||
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||
|
||||
## PAN-69505
|
||||
|
||||
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||
|
||||
## PAN-41558
|
||||
|
||||
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||
|
||||
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||
|
||||
## PAN-40079
|
||||
|
||||
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||
|
||||
## PAN-39636
|
||||
|
||||
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||
|
||||
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||
|
||||
## PAN-38255
|
||||
|
||||
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||
|
||||
## PAN-31832
|
||||
|
||||
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||
|
||||
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||
|
||||
## PAN-25046
|
||||
|
||||
Firewalls store SSH host keys used for SCP log exports in the known hosts file. In an HA deployment, PAN-OS synchronizes the SCP log export configuration between the firewall HA peers (**Device** > **Scheduled Log Export**), but not the known host file. When a failover occurs, the SCP log export fails.
|
||||
|
||||
**Workaround:** Log in to each peer in HA, select **Device** > **Scheduled Log Export** > **<log_export_configuration>**, and **Test SCP server connection** to confirm the host key so that SCP log forwarding continues to work after a failover.
|
||||
@@ -0,0 +1,607 @@
|
||||
---
|
||||
type: Known
|
||||
product: PAN-OS
|
||||
version: 9.0.6
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||
|
||||
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
A Panorama management server running PAN-OS 9.0 does not currently support management of appliances running WildFire 7.1 or earlier releases. Even though these management options are visible on the Panorama 9.0 web interface (**Panorama** > **Managed WildFire Clusters** and **Panorama** > **Managed WildFire Appliances**), making changes to these settings for appliances running WildFire 7.1 or an earlier release has no effect.
|
||||
|
||||
## WF500-4200
|
||||
|
||||
The Create Date shown when using the `show wildfire global sample-status sha256 equal<hash>` or `show wildfire global sample-analysis` CLI command is two hours behind the actual time for WF-500 appliance samples.
|
||||
|
||||
## PLUG-1854
|
||||
|
||||
```caveat
|
||||
PAN-OS 9.0.2 and later releases on AWS and GCP only
|
||||
```
|
||||
|
||||
You cannot swap the management interface.
|
||||
|
||||
## PLUG-1827
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
The firewall drops packets due to larger than expected packet sizes when Accelerated networking is enabled on the firewall (**Settings** > **Networking**).
|
||||
|
||||
## PLUG-1709
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
There is an intermittent issue where the secondary IP address becomes associated with the passive firewall after multiple failovers.
|
||||
|
||||
**Workaround:** Reassign IP addresses to the active and passive firewalls in Azure as needed.
|
||||
|
||||
## PLUG-1694
|
||||
|
||||
```caveat
|
||||
PAYG licenses only
|
||||
```
|
||||
|
||||
Your pay-as-you-go (PAYG) license is not retained when you upgrade from a PAN-OS 8.1 release to a PAN-OS 9.0 release.
|
||||
|
||||
**Workaround:** Upgrade to VM-Series plugin 1.0.2 (or later) after you upgrade to a PAN-OS 9.0 release and then reboot the firewall to recover your PAYG license.
|
||||
|
||||
## PLUG-1681
|
||||
|
||||
If you bootstrap a PAN-OS 9.0.1 image while using VM-Series plugin 1.0.0, the firewall will not apply the capacity license. To downgrade the VM-Series plugin from version 1.0.2 to 1.0.0, first bootstrap the PAN-OS 9.0.1 image and then downgrade the plugin.
|
||||
|
||||
## PLUG-1642
|
||||
|
||||
```caveat
|
||||
This issue is resolved with VM-Series plugin 1.0.2.
|
||||
```
|
||||
|
||||
After a high availability (HA) failover, the dataplane interface on a VM-Series firewall on Azure with Accelerated Networking (SR-IOV) becomes disabled when, as a result of the failover, the secondary IP address is detached from or attached to the firewall and moved to its HA peer.
|
||||
|
||||
## PLUG-1503
|
||||
|
||||
```caveat
|
||||
This issue is resolved with VM-Series plugin 1.0.3.
|
||||
```
|
||||
|
||||
When a VM-Series firewall on AWS running on a C5 or M5 instance experiences a high availability (HA) failover, the dataplane interfaces from the previously active firewall are not moved to the newly active (previously passive) peer.
|
||||
|
||||
**Workaround:** Check for the latest VM-Series plugin version and install the VM-Series plugin 9.0.0 version; the built-in version is 9.0.0-c29.
|
||||
|
||||
## PLUG-1074
|
||||
|
||||
On the VM-Series firewall on AWS, when you change the instance type, the firewall no longer has a serial number or a license. Additionally, if you manage this firewall using Panorama, it is no longer connected to Panorama.
|
||||
|
||||
## PLUG-380
|
||||
|
||||
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||
|
||||
## PAN-178194
|
||||
|
||||
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
|
||||
|
||||
## PAN-154247
|
||||
|
||||
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
|
||||
|
||||
**Workaround:** Log out and back in to the Panorama web interface.
|
||||
|
||||
## PAN-151909
|
||||
|
||||
On the Panorama management server, Preview Changes (**Commit** > **Commit to Panorama**) incorrectly displays an existing route as Added and the new route as an existing route in the Candidate Configuration when you configure a new virtual router route (**Network** > **Virtual Router**).
|
||||
|
||||
## PAN-140084
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. See PAN-OS 9.0.11 Addressed Issues.
|
||||
```
|
||||
|
||||
There is an issue where the default Dynamic IP and Port (DIPP) NAT oversubscription rate is set to 2.
|
||||
|
||||
## PAN-136701
|
||||
|
||||
```caveat
|
||||
PA-7000b Series firewalls only
|
||||
```
|
||||
|
||||
Packets for new sessions drop when handling predict sessions.
|
||||
|
||||
**Workaround:** (PAN-OS 9.0.8 and later PAN-OS 9.0 versions only) Use the following CLi commands to bypass this issue:
|
||||
|
||||
- `set session hwpredict disable yes`
|
||||
- `show session hwpredict status`
|
||||
|
||||
## PAN-131915
|
||||
|
||||
There is an issue when you implement a new firewall bootstrap with a USB drive where the bootstrap fails and displays the following error message: `no USB device found`.
|
||||
|
||||
**Workaround:** Perform a factory reset or run the `request system private-data-reset` CLI command and then proceed with bootstrapping.
|
||||
|
||||
## PAN-131792
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. SeePAN-OS 9.0.9 Addressed Issues.
|
||||
```
|
||||
|
||||
The Name log filter (**Monitor** > **Logs** > **Traffic**) is not maintained when viewing the Log Viewer for a Security policy rule (**Policies** > **Security**) from the drop-down menu.
|
||||
|
||||
## PAN-124956
|
||||
|
||||
There is an issue where VM-Series firewalls do not support packet buffer protection.
|
||||
|
||||
## PAN-120440
|
||||
|
||||
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||
|
||||
## PAN-120303
|
||||
|
||||
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||
|
||||
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||
|
||||
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||
2. **Commit** your changes.
|
||||
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||
4. **Commit** your changes.
|
||||
- Restart the firewall (devsrvr) process.
|
||||
1. Log in to the firewall CLI.
|
||||
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||
|
||||
## PAN-118414
|
||||
|
||||
```caveat
|
||||
PAN-OS 9.0.2 and later releases only
|
||||
```
|
||||
|
||||
There is an intermittent issue where a Panorama management server and managing Prisma™ Access or Cortex™ Data Lake fails to authorize one-time-password (OTP) submissions during the onboarding process.
|
||||
|
||||
**Workaround:** Downgrade to PAN-OS 9.0.1.
|
||||
|
||||
## PAN-117043
|
||||
|
||||
There is an issue on the Panorama management server and all supported firewalls where special characters contained in the tag names of the Security policy rules returns the following error message: `group-tag is invalid` when you commit or push a configuration.
|
||||
|
||||
**Workaround:** Modify the tags and group tags (**Objects** > **Tags**) to exclude special characters.
|
||||
|
||||
## PAN-116017
|
||||
|
||||
```caveat
|
||||
Google Cloud Platform (GCP) only
|
||||
```
|
||||
|
||||
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||
|
||||
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||
|
||||
## PAN-115816
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||
|
||||
**Workaround:** Reboot the firewall.
|
||||
|
||||
## PAN-115733
|
||||
|
||||
```caveat
|
||||
PAN-OS firewalls in an HA configuration only
|
||||
```
|
||||
|
||||
There is a rare issue where data interfaces do not come up after you reboot the firewall when running a C5 or M5 instance type in AWS.
|
||||
|
||||
**Workaround:** Reboot the firewall.
|
||||
|
||||
## PAN-114495
|
||||
|
||||
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||
|
||||
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||
|
||||
## PAN-113117
|
||||
|
||||
A newly launched firewall does not get its configuration from Panorama when it first connects if you installed the VM-Series plugin on Panorama. When a newly launched firewall that is bootstrapped connects to Panorama, a process restart occurs on Panorama. Upon restart, you are logged out of the user interface and you need to log in and push the device group and template configuration to the newly connected firewall.
|
||||
|
||||
## PAN-113098
|
||||
|
||||
In the firewall web interface, you can temporarily submit change requests for the following URL categories: insufficient-content, high-risk, medium-risk, low-risk, and newly-registered-domains. However, Palo Alto Networks does not support or process change requests for these categories.
|
||||
|
||||
## PAN-112983
|
||||
|
||||
```caveat
|
||||
Firewalls with multiple virtual systems only; no impact to Panorama
|
||||
```
|
||||
|
||||
If you select any Location other than Shared when you generate or import a new CA Certificate in a Certificate Profile (**Device** > **Certificate Management** > **Certificate Profile**), the firewall adds the newly generated or imported certificate to vsys1. For example, if you specify vsys3 as the **Location**, **Add** a CA Certificate, and then **Generate** a new certificate, the firewall adds the certificate to vsys1 instead of vsys3. When you click **OK** to configure the Certificate Profile, the firewall returns an `Operation Failed` error message because it sees a certificate for vsys1 added to vsys3.
|
||||
|
||||
**Workaround 1:**
|
||||
|
||||
1. Generate or import the new certificate in a Certificate Profile (**Device** > **Certificate Management** > **Certificates** > **Device Certificates**) and select the appropriate vsys **Location** when you generate or import the certificate.
|
||||
2. When you create or edit the Certificate Profile, specify the vsys **Location** and **Add** the certificate that you generated (or imported) from the list of existing certificates.
|
||||
|
||||
**Workaround 2:** When you generate or import a new certificate when you configure a Certificate Profile for a vsys other than vsys1, specify the **Location** as Shared.
|
||||
|
||||
## PAN-112694
|
||||
|
||||
```caveat
|
||||
Firewalls with multiple virtual systems only
|
||||
```
|
||||
|
||||
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||
|
||||
## PAN-112626
|
||||
|
||||
When you upgrade to PAN-OS 9.0 with a PAYG Bundle 2 license, the new DNS Security subscription is not available on your VM-Series firewall.
|
||||
|
||||
This subscription is included with the BYOL and VM-Series ELA when you upgrade.
|
||||
|
||||
## PAN-112562
|
||||
|
||||
The **Log Forwarding Card** (LFC) subinterface incorrectly uses the interface IP address instead of the subinterface IP address for all services that forward logs (such as syslog, email, and SNMP) for selected virtual systems.
|
||||
|
||||
## PAN-112456
|
||||
|
||||
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
|
||||
|
||||
## PAN-111928
|
||||
|
||||
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||
|
||||
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||
|
||||
## PAN-111866
|
||||
|
||||
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||
|
||||
**Workaround:** Perform one of the following tasks.
|
||||
|
||||
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||
- Manually select the devices that belong to the modified device group and template configurations.
|
||||
|
||||
## PAN-111729
|
||||
|
||||
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||
|
||||
## PAN-111670
|
||||
|
||||
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||
|
||||
## PAN-110794
|
||||
|
||||
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||
|
||||
## PAN-110603
|
||||
|
||||
In some cases, when a port on an PA-7000 Series 100Gbps Network Processor Card (NPC) has an SFP+ transceiver inserted but no cable is connected, the system detects a signal and attempts to tune and link with that port. As a result, if the device at the other end of the connection is rebooted or has an HA failover event, the link is sometimes held down for an extended period of time while the interface attempts to tune itself.
|
||||
|
||||
**Workaround:** Connect a cable to the installed SFP+ transceiver to allow the system to tune and link. Then, when you disconnect the cable, the system will correctly detect that the link is down. Alternatively, remove the SFP+ transceiver from the port.
|
||||
|
||||
## PAN-109526
|
||||
|
||||
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||
|
||||
## PAN-106989
|
||||
|
||||
There is a display-only issue on Panorama that results in a `commit failed` status for Template Last Commit State (**Panorama** > **Managed Devices** > **Summary**).
|
||||
|
||||
**Workaround:** Push templates to managed devices.
|
||||
|
||||
## PAN-106675
|
||||
|
||||
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||
|
||||
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||
|
||||
## PAN-105210
|
||||
|
||||
```caveat
|
||||
Panorama in FIPS mode only when managing non-FIPS firewalls
|
||||
```
|
||||
|
||||
You cannot configure a GlobalProtect portal on Panorama in FIPS mode when managing a non-FIPS firewall. If you attempt to do so, you will receive the following error message: `agent-user-override-key unexpected here Portal_fips.`
|
||||
|
||||
## PAN-104780
|
||||
|
||||
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||
|
||||
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||
|
||||
## PAN-103336
|
||||
|
||||
```caveat
|
||||
HA configurations only
|
||||
```
|
||||
|
||||
When you downgrade a VM-Series firewall on Azure from PAN-OS 9.0 to an earlier release, you do not receive warnings. Do not downgrade your firewall without saving and exporting your current configuration.
|
||||
|
||||
**Workaround:** Because HA is not supported in earlier versions of VM-Series firewalls on Azure, to prevent the loss of your configuration:
|
||||
|
||||
- Save and export the configuration before you downgrade.
|
||||
- After you downgrade, load the saved configuration and commit your changes. The firewall will resume operation without the HA configuration.
|
||||
|
||||
## PAN-103276
|
||||
|
||||
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||
|
||||
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||
|
||||
## PAN-103018
|
||||
|
||||
```caveat
|
||||
Panorama plugins
|
||||
```
|
||||
|
||||
When you use the AND/OR boolean operators to define the match criteria for Dynamic Address Groups on Panorama, the boolean operators do not function properly. The member IP addresses are not included in the address group as expected.
|
||||
|
||||
## PAN-101688
|
||||
|
||||
```caveat
|
||||
Panorama plugins
|
||||
```
|
||||
|
||||
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||
|
||||
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||
|
||||
## PAN-101537
|
||||
|
||||
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||
|
||||
**Workaround:** Specify the vsys in the query string:
|
||||
|
||||
`admin>` `set system target-vsys <vsys-name>`
|
||||
|
||||
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||
|
||||
## PAN-98803
|
||||
|
||||
If you configure the Panorama plugin to monitor virtual machines or endpoints in your AWS, Azure, or Cisco ACI environment without installing the NSX plugin, the IP-address-to-tag mappings for Dynamic Address Groups are not displayed on Panorama.
|
||||
|
||||
**Workaround:** Install the NSX plugin (you do not need to use the NSX plugin for the installation to resolve this display issue).
|
||||
|
||||
## PAN-98520
|
||||
|
||||
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||
|
||||
## PAN-97757
|
||||
|
||||
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||
|
||||
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||
|
||||
## PAN-97524
|
||||
|
||||
```caveat
|
||||
Panorama management server only
|
||||
```
|
||||
|
||||
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||
|
||||
## PAN-96985
|
||||
|
||||
The `request shutdown system` command does not shut down the Panorama management server.
|
||||
|
||||
## PAN-96960
|
||||
|
||||
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
|
||||
|
||||
## PAN-96446
|
||||
|
||||
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||
|
||||
## PAN-95773
|
||||
|
||||
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||
|
||||
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||
|
||||
## PAN-95717
|
||||
|
||||
After 30,000 or more end users log in to the GlobalProtect gateway within a two- to three-hour period, the firewall web interface responds slowly, commits take longer than expected or intermittently fail, and Tech Support File generation times out and fails.
|
||||
|
||||
## PAN-95602
|
||||
|
||||
In a deployment where a Log Collector connects to Panorama management servers in a high availability (HA) configuration, after you switch the Log Collector appliance to Panorama mode, commit operations fail on the appliance.
|
||||
|
||||
**Workaround:** Remove the following node from the running-config.xml file on the Log Collector before switching it to Panorama mode: `devices/entry[@name='localhost.localdomain']/deviceconfig/system/panorama-server-2`
|
||||
|
||||
## PAN-95511
|
||||
|
||||
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||
|
||||
## PAN-95028
|
||||
|
||||
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||
|
||||
## PAN-94966
|
||||
|
||||
After you delete disconnected and connected Terminal Server (TS) agents in the same operation, the firewall still displays the IP address-to-port-user mappings (`show user ip-port-user-mapping` CLI command) for the disconnected TS agents you deleted (**Device** > **User Identification** > **Terminal Services Agents**).
|
||||
|
||||
**Workaround:** Do not delete both disconnected and connected TS agents in the same operation.
|
||||
|
||||
## PAN-94846
|
||||
|
||||
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||
|
||||
## PAN-94093
|
||||
|
||||
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||
|
||||
## PAN-93968
|
||||
|
||||
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||
|
||||
## PAN-93842
|
||||
|
||||
The logging status of a Panorama Log Collector deployed on AWS or Azure displays as disconnected when you configure the ethernet1/1 to ethernet1/5 interfaces for log collection (**Panorama** > **Managed Collectors** > **Interfaces**). This results in firewalls not sending logs to the Log Collector.
|
||||
|
||||
**Workaround:** Configure the management (MGT) interface for log collection.
|
||||
|
||||
## PAN-93607
|
||||
|
||||
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||
|
||||
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||
|
||||
## PAN-93532
|
||||
|
||||
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||
|
||||
## PAN-93193
|
||||
|
||||
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||
|
||||
- Switch to the firewall **Context** on the Panorama management server.
|
||||
- Commit changes when a dynamic update is being installed.
|
||||
- Generate a custom report when a dynamic update is being installed.
|
||||
- Generate custom reports during a commit.
|
||||
|
||||
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||
|
||||
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||
|
||||
## PAN-91802
|
||||
|
||||
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||
|
||||
## PAN-86903
|
||||
|
||||
In rare cases, PA-800 Series firewalls shut themselves down due to a false over-current measurement.
|
||||
|
||||
## PAN-83610
|
||||
|
||||
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||
|
||||
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session off load for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||
|
||||
## PAN-83598
|
||||
|
||||
VM-Series firewalls cannot monitor more than 500 virtual machine (VM) information sources (**Device** > **VM Information Sources**).
|
||||
|
||||
## PAN-83236
|
||||
|
||||
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||
|
||||
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||
|
||||
## PAN-83215
|
||||
|
||||
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||
|
||||
## PAN-81521
|
||||
|
||||
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||
|
||||
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||
|
||||
## PAN-79423
|
||||
|
||||
Panorama cannot push address group objects from device groups to managed firewalls when zones specify the objects in the User Identification ACL include or exclude lists (**Network** > **Zones**) and the **Share Unused Address and Service Objects with Devices** option is disabled (**Panorama** > **Setup** > **Management** > **Panorama Settings**).
|
||||
|
||||
## PAN-77125
|
||||
|
||||
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||
|
||||
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||
|
||||
## PAN-75457
|
||||
|
||||
```caveat
|
||||
PAN-OS 8.0.1 and later releases
|
||||
```
|
||||
|
||||
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||
|
||||
## PAN-73530
|
||||
|
||||
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||
|
||||
## PAN-73401
|
||||
|
||||
```caveat
|
||||
PAN-OS 8.0.1 and later releases
|
||||
```
|
||||
|
||||
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||
|
||||
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||
|
||||
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||
|
||||
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||
- Configure a worker list on the cluster controller:
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||
or
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||
|
||||
## PAN-71329
|
||||
|
||||
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
|
||||
|
||||
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
|
||||
|
||||
## PAN-70906
|
||||
|
||||
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||
|
||||
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||
|
||||
## PAN-69505
|
||||
|
||||
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||
|
||||
## PAN-41558
|
||||
|
||||
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||
|
||||
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||
|
||||
## PAN-40079
|
||||
|
||||
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||
|
||||
## PAN-39636
|
||||
|
||||
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||
|
||||
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||
|
||||
## PAN-38255
|
||||
|
||||
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||
|
||||
## PAN-31832
|
||||
|
||||
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||
|
||||
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||
|
||||
## PAN-25046
|
||||
|
||||
Firewalls store SSH host keys used for SCP log exports in the known hosts file. In an HA deployment, PAN-OS synchronizes the SCP log export configuration between the firewall HA peers (**Device** > **Scheduled Log Export**), but not the known host file. When a failover occurs, the SCP log export fails.
|
||||
|
||||
**Workaround:** Log in to each peer in HA, select **Device** > **Scheduled Log Export** > **<log_export_configuration>**, and **Test SCP server connection** to confirm the host key so that SCP log forwarding continues to work after a failover.
|
||||
@@ -0,0 +1,609 @@
|
||||
---
|
||||
type: Known
|
||||
product: PAN-OS
|
||||
version: 9.0.7
|
||||
source: common-crawl
|
||||
crawl: CC-MAIN-2026-12
|
||||
---
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||
|
||||
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
A Panorama management server running PAN-OS 9.0 does not currently support management of appliances running WildFire 7.1 or earlier releases. Even though these management options are visible on the Panorama 9.0 web interface (**Panorama** > **Managed WildFire Clusters** and **Panorama** > **Managed WildFire Appliances**), making changes to these settings for appliances running WildFire 7.1 or an earlier release has no effect.
|
||||
|
||||
## WF500-4200
|
||||
|
||||
The Create Date shown when using the `show wildfire global sample-status sha256 equal<hash>` or `show wildfire global sample-analysis` CLI command is two hours behind the actual time for WF-500 appliance samples.
|
||||
|
||||
## PLUG-1854
|
||||
|
||||
```caveat
|
||||
PAN-OS 9.0.2 and later releases on AWS and GCP only
|
||||
```
|
||||
|
||||
You cannot swap the management interface.
|
||||
|
||||
## PLUG-1827
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
The firewall drops packets due to larger than expected packet sizes when Accelerated networking is enabled on the firewall (**Settings** > **Networking**).
|
||||
|
||||
## PLUG-1709
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
There is an intermittent issue where the secondary IP address becomes associated with the passive firewall after multiple failovers.
|
||||
|
||||
**Workaround:** Reassign IP addresses to the active and passive firewalls in Azure as needed.
|
||||
|
||||
## PLUG-1694
|
||||
|
||||
```caveat
|
||||
PAYG licenses only
|
||||
```
|
||||
|
||||
Your pay-as-you-go (PAYG) license is not retained when you upgrade from a PAN-OS 8.1 release to a PAN-OS 9.0 release.
|
||||
|
||||
**Workaround:** Upgrade to VM-Series plugin 1.0.2 (or later) after you upgrade to a PAN-OS 9.0 release and then reboot the firewall to recover your PAYG license.
|
||||
|
||||
## PLUG-1681
|
||||
|
||||
If you bootstrap a PAN-OS 9.0.1 image while using VM-Series plugin 1.0.0, the firewall will not apply the capacity license. To downgrade the VM-Series plugin from version 1.0.2 to 1.0.0, first bootstrap the PAN-OS 9.0.1 image and then downgrade the plugin.
|
||||
|
||||
## PLUG-1642
|
||||
|
||||
```caveat
|
||||
This issue is resolved with VM-Series plugin 1.0.2.
|
||||
```
|
||||
|
||||
After a high availability (HA) failover, the dataplane interface on a VM-Series firewall on Azure with Accelerated Networking (SR-IOV) becomes disabled when, as a result of the failover, the secondary IP address is detached from or attached to the firewall and moved to its HA peer.
|
||||
|
||||
## PLUG-1503
|
||||
|
||||
```caveat
|
||||
This issue is resolved with VM-Series plugin 1.0.3.
|
||||
```
|
||||
|
||||
When a VM-Series firewall on AWS running on a C5 or M5 instance experiences a high availability (HA) failover, the dataplane interfaces from the previously active firewall are not moved to the newly active (previously passive) peer.
|
||||
|
||||
**Workaround:** Check for the latest VM-Series plugin version and install the VM-Series plugin 9.0.0 version; the built-in version is 9.0.0-c29.
|
||||
|
||||
## PLUG-1074
|
||||
|
||||
On the VM-Series firewall on AWS, when you change the instance type, the firewall no longer has a serial number or a license. Additionally, if you manage this firewall using Panorama, it is no longer connected to Panorama.
|
||||
|
||||
## PLUG-380
|
||||
|
||||
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||
|
||||
## PAN-178194
|
||||
|
||||
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
|
||||
|
||||
## PAN-154247
|
||||
|
||||
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
|
||||
|
||||
**Workaround:** Log out and back in to the Panorama web interface.
|
||||
|
||||
## PAN-151909
|
||||
|
||||
On the Panorama management server, Preview Changes (**Commit** > **Commit to Panorama**) incorrectly displays an existing route as Added and the new route as an existing route in the Candidate Configuration when you configure a new virtual router route (**Network** > **Virtual Router**).
|
||||
|
||||
## PAN-140084
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. See PAN-OS 9.0.11 Addressed Issues.
|
||||
```
|
||||
|
||||
There is an issue where the default Dynamic IP and Port (DIPP) NAT oversubscription rate is set to 2.
|
||||
|
||||
## PAN-136701
|
||||
|
||||
```caveat
|
||||
PA-7000b Series firewalls only
|
||||
```
|
||||
|
||||
Packets for new sessions drop when handling predict sessions.
|
||||
|
||||
**Workaround:** (PAN-OS 9.0.8 and later PAN-OS 9.0 versions only) Use the following CLi commands to bypass this issue:
|
||||
|
||||
- `set session hwpredict disable yes`
|
||||
- `show session hwpredict status`
|
||||
|
||||
## PAN-131915
|
||||
|
||||
There is an issue when you implement a new firewall bootstrap with a USB drive where the bootstrap fails and displays the following error message: `no USB device found`.
|
||||
|
||||
**Workaround:** Perform a factory reset or run the `request system private-data-reset` CLI command and then proceed with bootstrapping.
|
||||
|
||||
## PAN-131792
|
||||
|
||||
```caveat
|
||||
This issue is now resolved. See PAN-OS 9.0.9 Addressed Issues.
|
||||
```
|
||||
|
||||
The Name log filter (**Monitor** > **Logs** > **Traffic**) is not maintained when viewing the Log Viewer for a Security policy rule (**Policies** > **Security**) from the drop-down menu.
|
||||
|
||||
## PAN-124956
|
||||
|
||||
There is an issue where VM-Series firewalls do not support packet buffer protection.
|
||||
|
||||
## PAN-120440
|
||||
|
||||
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||
|
||||
## PAN-120303
|
||||
|
||||
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server even when you configured the Eth1/1 interface.
|
||||
|
||||
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||
|
||||
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||
2. **Commit** your changes.
|
||||
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||
4. **Commit** your changes.
|
||||
- Restart the firewall (devsrvr) process.
|
||||
1. Log in to the firewall CLI.
|
||||
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||
|
||||
## PAN-118414
|
||||
|
||||
```caveat
|
||||
PAN-OS 9.0.2 and later releases only
|
||||
```
|
||||
|
||||
There is an intermittent issue where a Panorama management server and managing Prisma™ Access or Cortex™ Data Lake fails to authorize one-time-password (OTP) submissions during the onboarding process.
|
||||
|
||||
**Workaround:** Downgrade to PAN-OS 9.0.1.
|
||||
|
||||
## PAN-116017
|
||||
|
||||
```caveat
|
||||
Google Cloud Platform (GCP) only
|
||||
```
|
||||
|
||||
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||
|
||||
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||
|
||||
## PAN-115816
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||
|
||||
**Workaround:** Reboot the firewall.
|
||||
|
||||
## PAN-115733
|
||||
|
||||
```caveat
|
||||
PAN-OS firewalls in an HA configuration only
|
||||
```
|
||||
|
||||
There is a rare issue where data interfaces do not come up after you reboot the firewall when running a C5 or M5 instance type in AWS.
|
||||
|
||||
**Workaround:** Reboot the firewall.
|
||||
|
||||
## PAN-1114914
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
If you replace the small form-factor pluggable (SFP) module with the PAN-SFP-PLUS-10GBASE-T module, a system reboot is required.
|
||||
|
||||
## PAN-114495
|
||||
|
||||
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||
|
||||
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||
|
||||
## PAN-113117
|
||||
|
||||
A newly launched firewall does not get its configuration from Panorama when it first connects if you installed the VM-Series plugin on Panorama. When a newly launched firewall that is bootstrapped connects to Panorama, a process restart occurs on Panorama. Upon restart, you are logged out of the user interface and you need to log in and push the device group and template configuration to the newly connected firewall.
|
||||
|
||||
## PAN-113098
|
||||
|
||||
In the firewall web interface, you can temporarily submit change requests for the following URL categories: insufficient-content, high-risk, medium-risk, low-risk, and newly-registered-domains. However, Palo Alto Networks does not support or process change requests for these categories.
|
||||
|
||||
## PAN-112983
|
||||
|
||||
```caveat
|
||||
Firewalls with multiple virtual systems only; no impact to Panorama
|
||||
```
|
||||
|
||||
If you select any Location other than Shared when you generate or import a new CA Certificate in a Certificate Profile (**Device** > **Certificate Management** > **Certificate Profile**), the firewall adds the newly generated or imported certificate to vsys1. For example, if you specify vsys3 as the **Location**, **Add** a CA Certificate, and then **Generate** a new certificate, the firewall adds the certificate to vsys1 instead of vsys3. When you click **OK** to configure the Certificate Profile, the firewall returns an `Operation Failed` error message because it sees a certificate for vsys1 added to vsys3.
|
||||
|
||||
**Workaround 1:**
|
||||
|
||||
1. Generate or import the new certificate in a Certificate Profile (**Device** > **Certificate Management** > **Certificates** > **Device Certificates**) and select the appropriate vsys **Location** when you generate or import the certificate.
|
||||
2. When you create or edit the Certificate Profile, specify the vsys **Location** and **Add** the certificate that you generated (or imported) from the list of existing certificates.
|
||||
|
||||
**Workaround 2:** When you generate or import a new certificate when you configure a Certificate Profile for a vsys other than vsys1, specify the **Location** as Shared.
|
||||
|
||||
## PAN-112694
|
||||
|
||||
```caveat
|
||||
Firewalls with multiple virtual systems only
|
||||
```
|
||||
|
||||
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||
|
||||
## PAN-112626
|
||||
|
||||
When you upgrade to PAN-OS 9.0 with a PAYG Bundle 2 license, the new DNS Security subscription is not available on your VM-Series firewall.
|
||||
|
||||
This subscription is included with the BYOL and VM-Series ELA when you upgrade.
|
||||
|
||||
## PAN-112562
|
||||
|
||||
The **Log Forwarding Card** (LFC) subinterface incorrectly uses the interface IP address instead of the subinterface IP address for all services that forward logs (such as syslog, email, and SNMP) for selected virtual systems.
|
||||
|
||||
## PAN-112456
|
||||
|
||||
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
|
||||
|
||||
## PAN-111928
|
||||
|
||||
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||
|
||||
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||
|
||||
## PAN-111866
|
||||
|
||||
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||
|
||||
**Workaround:** Perform one of the following tasks.
|
||||
|
||||
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||
- Manually select the devices that belong to the modified device group and template configurations.
|
||||
|
||||
## PAN-111729
|
||||
|
||||
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||
|
||||
## PAN-111670
|
||||
|
||||
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||
|
||||
## PAN-110794
|
||||
|
||||
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||
|
||||
## PAN-110603
|
||||
|
||||
In some cases, when a port on an PA-7000 Series 100Gbps Network Processor Card (NPC) has an SFP+ transceiver inserted but no cable is connected, the system detects a signal and attempts to tune and link with that port. As a result, if the device at the other end of the connection is rebooted or has an HA failover event, the link is sometimes held down for an extended period of time while the interface attempts to tune itself.
|
||||
|
||||
**Workaround:** Connect a cable to the installed SFP+ transceiver to allow the system to tune and link. Then, when you disconnect the cable, the system will correctly detect that the link is down. Alternatively, remove the SFP+ transceiver from the port.
|
||||
|
||||
## PAN-109526
|
||||
|
||||
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||
|
||||
## PAN-106989
|
||||
|
||||
There is a display-only issue on Panorama that results in a `commit failed` status for Template Last Commit State (**Panorama** > **Managed Devices** > **Summary**).
|
||||
|
||||
**Workaround:** Push templates to managed devices.
|
||||
|
||||
## PAN-106675
|
||||
|
||||
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||
|
||||
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||
|
||||
## PAN-105210
|
||||
|
||||
```caveat
|
||||
Panorama in FIPS mode only when managing non-FIPS firewalls
|
||||
```
|
||||
|
||||
You cannot configure a GlobalProtect portal on Panorama in FIPS mode when managing a non-FIPS firewall. If you attempt to do so, you will receive the following error message: `agent-user-override-key unexpected here Portal_fips.`
|
||||
|
||||
## PAN-104780
|
||||
|
||||
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||
|
||||
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||
|
||||
## PAN-103336
|
||||
|
||||
```caveat
|
||||
HA configurations only
|
||||
```
|
||||
|
||||
When you downgrade a VM-Series firewall on Azure from PAN-OS 9.0 to an earlier release, you do not receive warnings. Do not downgrade your firewall without saving and exporting your current configuration.
|
||||
|
||||
**Workaround:** Because HA is not supported in earlier versions of VM-Series firewalls on Azure, to prevent the loss of your configuration:
|
||||
|
||||
- Save and export the configuration before you downgrade.
|
||||
- After you downgrade, load the saved configuration and commit your changes. The firewall will resume operation without the HA configuration.
|
||||
|
||||
## PAN-103276
|
||||
|
||||
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||
|
||||
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||
|
||||
## PAN-103018
|
||||
|
||||
```caveat
|
||||
Panorama plugins
|
||||
```
|
||||
|
||||
When you use the AND/OR boolean operators to define the match criteria for Dynamic Address Groups on Panorama, the boolean operators do not function properly. The member IP addresses are not included in the address group as expected.
|
||||
|
||||
## PAN-101688
|
||||
|
||||
```caveat
|
||||
Panorama plugins
|
||||
```
|
||||
|
||||
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||
|
||||
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||
|
||||
## PAN-101537
|
||||
|
||||
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||
|
||||
**Workaround:** Specify the vsys in the query string:
|
||||
|
||||
`admin>` `set system target-vsys <vsys-name>`
|
||||
|
||||
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||
|
||||
## PAN-98803
|
||||
|
||||
If you configure the Panorama plugin to monitor virtual machines or endpoints in your AWS, Azure, or Cisco ACI environment without installing the NSX plugin, the IP-address-to-tag mappings for Dynamic Address Groups are not displayed on Panorama.
|
||||
|
||||
**Workaround:** Install the NSX plugin (you do not need to use the NSX plugin for the installation to resolve this display issue).
|
||||
|
||||
## PAN-98520
|
||||
|
||||
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||
|
||||
## PAN-97757
|
||||
|
||||
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||
|
||||
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||
|
||||
## PAN-97524
|
||||
|
||||
```caveat
|
||||
Panorama management server only
|
||||
```
|
||||
|
||||
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||
|
||||
## PAN-96985
|
||||
|
||||
The `request shutdown system` command does not shut down the Panorama management server.
|
||||
|
||||
## PAN-96960
|
||||
|
||||
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
|
||||
|
||||
## PAN-96446
|
||||
|
||||
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||
|
||||
## PAN-95773
|
||||
|
||||
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||
|
||||
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||
|
||||
## PAN-95717
|
||||
|
||||
After 30,000 or more end users log in to the GlobalProtect gateway within a two- to three-hour period, the firewall web interface responds slowly, commits take longer than expected or intermittently fail, and Tech Support File generation times out and fails.
|
||||
|
||||
## PAN-95602
|
||||
|
||||
In a deployment where a Log Collector connects to Panorama management servers in a high availability (HA) configuration, after you switch the Log Collector appliance to Panorama mode, commit operations fail on the appliance.
|
||||
|
||||
**Workaround:** Remove the following node from the running-config.xml file on the Log Collector before switching it to Panorama mode: `devices/entry[@name='localhost.localdomain']/deviceconfig/system/panorama-server-2`
|
||||
|
||||
## PAN-95511
|
||||
|
||||
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||
|
||||
## PAN-95028
|
||||
|
||||
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||
|
||||
## PAN-94966
|
||||
|
||||
After you delete disconnected and connected Terminal Server (TS) agents in the same operation, the firewall still displays the IP address-to-port-user mappings (`show user ip-port-user-mapping` CLI command) for the disconnected TS agents you deleted (**Device** > **User Identification** > **Terminal Services Agents**).
|
||||
|
||||
**Workaround:** Do not delete both disconnected and connected TS agents in the same operation.
|
||||
|
||||
## PAN-94846
|
||||
|
||||
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||
|
||||
## PAN-94093
|
||||
|
||||
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||
|
||||
## PAN-93968
|
||||
|
||||
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||
|
||||
## PAN-93842
|
||||
|
||||
The logging status of a Panorama Log Collector deployed on AWS or Azure displays as disconnected when you configure the ethernet1/1 to ethernet1/5 interfaces for log collection (**Panorama** > **Managed Collectors** > **Interfaces**). This results in firewalls not sending logs to the Log Collector.
|
||||
|
||||
**Workaround:** Configure the management (MGT) interface for log collection.
|
||||
|
||||
## PAN-93607
|
||||
|
||||
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||
|
||||
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||
|
||||
## PAN-93532
|
||||
|
||||
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||
|
||||
## PAN-93193
|
||||
|
||||
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||
|
||||
- Switch to the firewall **Context** on the Panorama management server.
|
||||
- Commit changes when a dynamic update is being installed.
|
||||
- Generate a custom report when a dynamic update is being installed.
|
||||
- Generate custom reports during a commit.
|
||||
|
||||
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||
|
||||
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||
|
||||
## PAN-91802
|
||||
|
||||
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||
|
||||
## PAN-86903
|
||||
|
||||
In rare cases, PA-800 Series firewalls shut themselves down due to a false over-current measurement.
|
||||
|
||||
## PAN-83610
|
||||
|
||||
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||
|
||||
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session off load for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||
|
||||
## PAN-83598
|
||||
|
||||
VM-Series firewalls cannot monitor more than 500 virtual machine (VM) information sources (**Device** > **VM Information Sources**).
|
||||
|
||||
## PAN-83236
|
||||
|
||||
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||
|
||||
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||
|
||||
## PAN-83215
|
||||
|
||||
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||
|
||||
## PAN-81521
|
||||
|
||||
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||
|
||||
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||
|
||||
## PAN-79423
|
||||
|
||||
Panorama cannot push address group objects from device groups to managed firewalls when zones specify the objects in the User Identification ACL include or exclude lists (**Network** > **Zones**) and the **Share Unused Address and Service Objects with Devices** option is disabled (**Panorama** > **Setup** > **Management** > **Panorama Settings**).
|
||||
|
||||
## PAN-77125
|
||||
|
||||
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||
|
||||
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||
|
||||
## PAN-75457
|
||||
|
||||
```caveat
|
||||
PAN-OS 8.0.1 and later releases
|
||||
```
|
||||
|
||||
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||
|
||||
## PAN-73530
|
||||
|
||||
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||
|
||||
## PAN-73401
|
||||
|
||||
```caveat
|
||||
PAN-OS 8.0.1 and later releases
|
||||
```
|
||||
|
||||
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||
|
||||
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||
|
||||
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||
|
||||
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||
- Configure a worker list on the cluster controller:
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||
or
|
||||
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||
|
||||
## PAN-71329
|
||||
|
||||
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
|
||||
|
||||
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
|
||||
|
||||
## PAN-70906
|
||||
|
||||
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||
|
||||
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||
|
||||
## PAN-69505
|
||||
|
||||
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||
|
||||
## PAN-41558
|
||||
|
||||
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||
|
||||
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||
|
||||
## PAN-40079
|
||||
|
||||
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||
|
||||
## PAN-39636
|
||||
|
||||
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||
|
||||
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||
|
||||
## PAN-38255
|
||||
|
||||
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||
|
||||
## PAN-31832
|
||||
|
||||
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||
|
||||
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||
|
||||
## PAN-25046
|
||||
|
||||
Firewalls store SSH host keys used for SCP log exports in the known hosts file. In an HA deployment, PAN-OS synchronizes the SCP log export configuration between the firewall HA peers (**Device** > **Scheduled Log Export**), but not the known host file. When a failover occurs, the SCP log export fails.
|
||||
|
||||
**Workaround:** Log in to each peer in HA, select **Device** > **Scheduled Log Export** > **<log_export_configuration>**, and **Test SCP server connection** to confirm the host key so that SCP log forwarding continues to work after a failover.
|
||||
Reference in New Issue
Block a user