Add more PAN-OS 11.1 references and URLs.

This commit is contained in:
2026-04-15 11:15:27 -05:00
parent 245c34705f
commit d5b54d5a6b
22 changed files with 11450 additions and 20 deletions
+875
View File
@@ -0,0 +1,875 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-278088</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">show system resources follow</span> CLI
command was not available.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-276546</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a session lost the PBF rule mapping after a
configuration change or commit.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273994</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-0111"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-0111</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273971</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-0108"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-0108</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273300</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where upgrading to PAN-OS 11.0.4-h2 failed
with a validation error.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273278</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-0109"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-0109</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273245</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
issue where upgrading an HA firewall pair from PAN-OS 10.2.11-h1 to
PAN-OS 11.1.5 caused the firewalls to enter a nonfunctional loop due
to repeated HA path monitoring failures.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273129</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where the
<span class="ph uicontrol">negate</span> option was visible when you
clicked on the rule name, but not when you viewed the target options
from the <span class="ph uicontrol">rulebase</span> attribute.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273085</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where you were unable to edit or
create policy rules.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273026</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic logs did not display correctly when
filters were applied.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273021</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where 25G port links did not come up due to a change in
the handling of 25G DAC modules.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272959</b></div>
</td>
<td class="entry relcol">
Fixed an issue where the firewall generated BGP update packets larger
than 1500 bytes when the interface MTU was 1500 bytes and jumbo frames
were enabled globally.
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272849</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where log forwarding to a UDP syslog server stopped
when an unreachable TCP syslog server was configured and applied.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272538</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding during a commit-all validation when there
were uncommitted changes and
<span class="ph systemoutput">share-unused-objects-with-devices</span>
was set to off.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272006</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not trigger a kernel core dump
as a large core when the CPLD (Complex Programmable Logic Device) sent
a Non-Maskable Interrupt (NMI) to the CPU.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271926</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TLS 1.3 decryption failed with a bad record MAC
error when the firewall was configured to decrypt and inspect TLS
traffic.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271912</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding when filtering in the configuration audit
window after upgrading to PAN-OS 11.1.3.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271613</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where configuration pushes from Panorama to the
firewall failed due to an OOXML commit error.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271314</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where pushing changes to a prefix list used for BGP
from Panorama affected OSPF routes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270607</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/passive HA configurations only</tt
>) Fixed an issue where OSPF failed to establish after a failover from
the active firewall to the passive firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270549</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where some TLS connections were not handled correctly,
which led to instability in the dataplane.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270471</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in active/active configurations only</tt
>) Fixed an issue where the firewall did not detect configuration
changes when only the interface of an IKE gateway was changed, which
caused IPSec tunnels to not come up after migrating the IKE gateway IP
address from a subinterface to a physical interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269956</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process stopped responding, which caused internal path monitor
failures.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269899</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama web interface was slower than
expected when querying for device tags.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269737</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the followig critical error displayed repeatedly:
<span class="ph systemoutput">/mnt/cdrom is mounted as Read-Only</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269731</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not display logs from firewalls
after upgrading to PAN-OS 10.2.11 on devices due to Elasticsearch (ES)
getting restarted continuously.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269499</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding when receiving a
high number of logs.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269106</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">wifclient</span> might crash during
server cert verification for MICA gRPC connections and cause the
dataplane to restart when using a cloud-based ML detection engine
(MICA). On certain platforms, this caused the firewall to reboot
periodically.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268972</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama was slower than expected when using a
high number of device group tags in a non-shared context.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268815</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue that caused the firewall to reboot due to the
<span class="ph systemoutput">wifclient</span> exiting multiple times
when using IoT Security.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268465</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with firewalls in active/passive HA configurations
where the the total user count in the registered users was different
between the active and passive firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267781</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not display the
<span class="ph uicontrol">Source Dynamic Address Group</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267762</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Panorama virtual appliances in Management-Only mode</tt
>) Fixed a issue where the maximum configuration size was lower than
expected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267671</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted unexpectedly due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task process</a
>
restarting with an OOM condition due to a memory leak on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267662</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall experienced a memory out-of-bounds
access when the firewall was configured with SD-WAN and the SD-WAN
plugin was loading, which caused the firewall to stop responding and
drop VPN tunnels.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267097</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the replay database size increased significantly
due to local and special configurations not being purged after
commits.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-266354</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Hybrid-SWG explicit proxy connections failed when
the number of destination domains exceeded 1024.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-265745</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall displayed incorrect MAC receive
error counters for VMWare devices hosted in ESXi.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-265219</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
GRE traffic did not work properly.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-265179</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a kernel race condition caused the firewall to
reboot with a kernel panic.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-264423</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall sent a 503 response when a client
connected to a web server when the firewall was configured as a web
proxy and authentication bypass for Kerberos was enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-262946</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where logging in via the CLI or web
interface did not work due to increased memory usage.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-262383</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to decompress the HTTP2
header, which caused the session to be classified as unknown-tcp
instead of web-browsing.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260461</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic logs showed a non-zero destination port
number on ICMP echo sessions through the firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260290</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue for fixed model licenses to support new content size
requirements by reducing the total sessions supported to be equivalent
to their flex memory counterpart.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260235</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall sent Threat logs and URL logs to an
external syslog server without Security profile settings when Enhanced
Application Logging was enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260149</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the management plane DNS cache size was lower
than expected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259078</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where WildFire Analysis reports were not generated and
the following error message was displayed:
<span class="ph systemoutput">Error 500: Internal Server Error</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-258149</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dropped the SYN-ACK when using the
TCP Fast Open option.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-255323</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7050 firewalls only</tt>) Fixed an issue where
the Network Processing Card (NPC), Data Processing Card (DPC), and Log
forwarding Card (LFC) remained in a starting state after an unexpected
power cycle.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-254904</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a core file was generated by
/usr/local/bin/logd during a restart.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-254293</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an explicit proxy caused intermittent SSL
handshake failures to SAP applications accessing public URLs.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-252381</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama web interface was slower than
expected when opening interfaces, virtual routers, and zones in a
template or template stack.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-251484</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall web interface displayed incorrect
PPPoE configuration options under the subinterface of an Aggregate
Ethernet interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-250585</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall CPU use increased after upgrading
from PAN-OS 10.2.4-h4 to PAN-OS 10.2.8 due to a change in system
resource reporting by the REST API.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-248508</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Amazon Web Services (AWS) environments
only</tt
>) Fixed an issue where the firewall did not perform MSS clamping when
GWLB endpoints were mapped to static subinterfaces.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-246699</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where
<span class="ph uicontrol">Rule Usage</span> and
<span class="ph uicontrol">Apps Seen</span> under Security policy
rules stopped incrementing.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-233647</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama management servers generated duplicate
configuration logs.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-233581</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on firewalls in active/active HA configurations where
SYN+ACK packets of asymmetric TCP sessions were dropped because of a
session synchronization issue.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-224152</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where device tags for devices in a child device group
were not available in the parent shared device group.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-216054</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue that caused the firewall's fan speed to increase while
it was idle.
</div>
</td>
</tr>
</tbody>
</table>
+678
View File
@@ -0,0 +1,678 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286897</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process stopped responding when the firewall attempted to forward
files to the WildFire public cloud, which caused the dataplane to
experience heartbeat failures.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-285590</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Amazon Web Services (AWS) GWLB environments
only</tt
>) Fixed an issue where the firewall CPU usage reached 100% after
upgrading to PAN-OS 11.1.6-h1.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-284066</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after an upgrade, the SNMP polled values for
<span class="ph systemoutput">IF-MIB::ifInErrors</span> displayed a
high number of errors that did not match the values in the CLI show
interface command.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-283789</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
issue where, after an upgrade, the
<span class="ph uicontrol">mac receive error</span> counter in
<span class="ph uicontrol">receive incoming errors</span> increased,
which resulted in SNMP alerts.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-283467</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-3400 Series firewalls only</tt>) Fixed an issue
where the firewall unexpectedly rebooted and entered maintenance mode
due to a ctd-agent out-of-memory (OOM) condition. This occurred during
advanced services load testing and a high volume of IoT EAL log
forwarding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-282640</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where custom reports showed incomplete data when
exported in CSV format from Panorama.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-280477</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface were you were unable to scroll up
or down to view source zones in a NAT policy rule.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-280335</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with an SNMPv3 EngineBoots value discrepancy that
prevented to SNMP server from logging.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273614</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where packets were dropped initially when a SYN cookie
with activation threshold 0 was enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272605</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not display VPC endpoints when
there was a large amount of VPC endpoints to interface mappings.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271560</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DNS requests to malware sites were not blocked as
expected, and the
<span class="ph systemoutput">dns-security-categories log-level</span>
and action displayed default values instead of
<span class="ph systemoutput">unavailable</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271152</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-7000 Series firewalls in HA configurations only</tt
>) Fixed an issue where the firewall failed over into a non-functional
state, and the LFC LED was blinking on the passive firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270849</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a memory leak issue related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process that occurred when running consecutive commits for multiple
days.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269193</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall redirected the user to the first
application instead of the portal page with a list of applications
when multiple applications were configured for GlobalProtect
clientless VPN along with any user match.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269139</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls with DPDK enabled in Azure, GCP, AWS, and KVM
environments only</tt
>) Fixed an issue where, after an upgrade to PAN-OS 11.1.4, the
<span class="ph uicontrol">mac receive error </span>counter increased
without an error even though traffic was not impacted.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-264982</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls on KVM only</tt>) Fixed an
issue where the firewall entered maintenance mode after an auto-commit
when sending an ARP packet through the loopback interface using an
IPv6 address.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-264477</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not start Elasticsearch after a
commit if Elasticsearch was not previously enabled and started.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261429</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput"
>show auth radius-require-msg-authentic</span
>
command CLI displayed no output.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-254524</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where, when the
<span class="ph uicontrol">Commit and Push</span> button was clicked
during a selective
<span class="ph uicontrol">Commit and Push</span> operation, the
window stopped responding, which caused the operation to be delayed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-284116</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where mTLS decryption bypass did not work when the
decryption profile was configured with the maximum TLS version as TLS
1.3.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-281882</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where OSPF redistributed connected routes beyond the
intended loopback IP address.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-280698</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall removed the TCP timestamp from
client hello messages that did not fit in a single packet, which
resulted in connection issues.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-280532</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after disabling and re-enabling the external
syslog server, the TCP session was not resumed, which caused all logs
that were forwarded to the syslog server to be dropped.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279621</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where processes stopped responding when HTTPS Forward
traffic was run.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-278981</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DNS domain resolutions experienced intermittent
delays due to the firewall not connecting to the DNS Security cloud.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-262373</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the error message
<span class="ph systemoutput">Failed to reload config</span> files
displayed in the system logs even when device telemetry was not
enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-277417</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an memory leak issue related to TLS inbound decryption.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-274806</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5250 firewalls only</tt>) Fixed an issue where
IPv6 pings experienced a high number of dropped packets when forwarded
to another dataplane, which resulted in ping failures. This occurred
when initiating a ping to the link local address of the firewall and
the packet drop percentage depended on the number of dataplanes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-274569</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the QSPF transceiver interface displayed an
incorrect range figure on the temperature alarm.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-274496</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the root partition reached 100% which caused the
system to become non-functional and failover even when aggressive
cleaning was enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273422</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic failed when Inline cloud analysis
(Advanced Threat Prevention) was enabled in the Anti-Spyware profile
with the action set to anything other than
<span class="ph uicontrol">allow</span> or
<span class="ph uicontrol">alert</span> and the maximum latency
condition was reached.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272812</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SNMP monitoring of tunnel interfaces displayed
zero values for received bytes and packets.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271700</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where User-ID connections were lost after an HA
failover.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271184</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Device Telemetry failed due to an issue with the
encoding of characters in the log file path.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271151</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect client did not automatically
initiate a Kerberos SSO connection after logging in to Windows.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270379</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where socket files created in the /tmp directory were
not cleared.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270192</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not display the management IP
address of devices onboarded via ZTP.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268705</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an intermittent issue where the firewall failed to process FTP
traffic after upgrading to PAN-OS 10.1.14.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267707</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where BFD sessions did not come up even when BGP
peering was established.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267001</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where multicast streams were unstable with ECMP and
dropped every 30 seconds.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-266704</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where filtering BGP routes by peer name in Advanced
Routing Engine (ARE) did not display the correct routes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-266574</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where users were unable connect to the portal due to
Certificate Revocation List (CRL) checks due to the downloaded CRL
file being expired, which caused the CRL cache to be bypassed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-266312</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where BFD sessions took longer than expected to
establish after an HA failover due to BGP.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261999</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls in Microsoft Azure environments only</tt
>) Fixed an issue where enabling flow basic on firewalls caused ARP
entries to be removed on both firewalls.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261570</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/active HA configurations only</tt
>) Fixed an issue where packet loss occurred when dataport was used
for HA3 for asymmetrically routed traffic during commits and a virtual
wire was configured.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260229</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where HA path monitoring using VWire did not work as
expected after a reboot.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-257442</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-0123"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-0123</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-245064</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Multi-vsys firewalls only</tt>) Fixed an issue
where commits failed on the firewall after selecting
<span class="ph uicontrol">Export or push device config bundle</span>
on Panorama and a force push was required.
</div>
</td>
</tr>
</tbody>
</table>
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
+436
View File
@@ -0,0 +1,436 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300906</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where XML API commands failed with a
<span class="ph systemoutput">Method not found (policy_xml)</span>
error in dagger.log. The issue was due to missing XML-related
functions for inline-cloud-proxy and session-distribution commands in
dagger files handling.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300096</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a local commit on a firewall breaks template
stack overrides, preventing the enabling of LACP (Link Aggregation
Control Protocol). After a local commit, the LACP enable check was
unexpectedly unchecked, causing an outage. Attempting to re-enable
LACP through the web interface was unsuccessful, requiring manual
removal of the LACP configuration from the Panorama CLI.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297972</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a dataplane crash occurred when traffic matched
Inline Cloud Analysis pre-filtering signatures, even when Inline Cloud
Analysis features were not enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297240</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where attempting to generate reports in a WildFire FIPS
Private Cloud or WF-500 deployment returned 401 errors.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-296490</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">FIPS CC mode enabled only</tt>) Fixed an issue
where Panorama on GCP reboots every hour after upgrading to
11.1.6-h10. Panorama will run for up to an hour and then crash.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-296453</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where decryption exclusion lists were not working for
untrusted certificates, and SSL sessions were still being decrypted
even after adding them to the exclusion list. This occurred because
the firewall was not adding sessions to the exclude cache until after
receiving a non-RFC alert (BadCertificate) from the server. The fix
ensures that the first session is added to the exclude cache, allowing
subsequent sessions to skip decryption. This issue affects firewalls
configured as clients in server-client communication.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-295944</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where static routes remained active in the FIB and RIB
even when the associated physical port interface was down, which
resulted in traffic being incorrectly routed through a non-operational
interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-295560</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading Panorama and Log Collectors,
tunnel logs were not visible in Panorama or Splunk even though traffic
and threat logs were received.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-294893</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls with the
<span class="ph uicontrol"
>Send handshake messages to CTD for inspection</span
>
setting enabled caused incorrect security policy rules to be matched.
Specifically, traffic not identified as openai-base or openai-chatgpt
applications was incorrectly matched by the
ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected
response page for blocked URLs was not displayed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-294524</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls and Panorama management servers were
unable to view or download WildFire reports from a WF-500 appliance,
resulting in a 401 error in the report tab.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-292393</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TFTP file transfers intermittently timed out in
active-active HA pairs when the TFTP control channel was processed by
one firewall and the data channel was processed by the other. This
occurred because the firewall receiving the data channel failed to
match the predicted session due to asynchronous processing of HA
messages.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-292229</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama was unable to retrieve userid logs from
the firewall for subscribed user-ip-mappings after Panorama was
rebooted.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291288</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted unexpectedly due to a
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process restart related to page allocation failures.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-289249</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory leak occurred on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process when a WildFire update was initiated while device telemetry
data collection was in progress. This resulted in an OOM condition.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287803</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading firewalls to PAN-OS 11.1.6-h1,
certain websites weren't accessible when the accumulation proxy was
enabled. The proxy did not use the same DF bit state as the original
traffic, causing it to be fragmented and dropped elsewhere in the
network.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287782</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls configured in vwire mode modified DSCP
values from AF11 to CS0 on traffic passing through the firewall, even
when QoS policy rules and DSCP rewrite settings were not configured.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287622</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IPv6 traffic was affected after upgrading the
firewall to PAN-OS 11.1.6-h4 and later versions. With SSL decryption
enabled and a decryption policy configured for the traffic, the
firewall dropped packets due to receiving a
<span class="ph systemoutput">Packet Too Big</span> ICMP message. This
occurred because the PathMTU information update was incorrect for the
TCB (pan-server) when the firewall was acting as a server.
Additionally, the flow label under the IPv6 header was set to zero
while the packet was being transmitted out of the firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287423</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where content loading issues occurred on IPv6 websites
due to the firewall incorrectly setting the IPv6 header flow label to
0.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-285648</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process crashed on PA-7050 firewalls due to system log processing
threads becoming blocked when the queue was full. This resulted in a
heartbeat failure.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-283053</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall experienced high disk space
utilization, which caused the firewall to become non-functional.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-282854</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Elasticsearch cluster did not start after
deploying dedicated log collectors in a multi-collector environment.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-277306</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the XML API and REST API failed to run commands
and displayed an error.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-277135</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding when a DNS client
closed or reset a TCP connection while the firewall was sending a
response.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-277034</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where WildFire reports were not fully displayed and
were not downloadable due to static resources not being found.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267450</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process stopped responding with a SIGSEGV at
<span class="ph systemoutput">schedule_report_es_response</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260185</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a dataplane crash occurred in Inline Cloud
Analysis action lookup because there were no vulnerability or
anti-spyware profiles in the security policy rule.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-253963</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Panorama appliances in Panorama mode and Log Collector mode
only</tt
>) Fixed an issue where autocommits took longer than expected to
complete.
</div>
</td>
</tr>
</tbody>
</table>
+242
View File
@@ -0,0 +1,242 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-303737</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where XML API commands failed with a
<span class="ph systemoutput">Method not found (policy_xml)</span>
error in dagger.log. The issue was due to session-distribution
commands in dagger files handling.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-299772</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls in active/passive configurations only</tt
>) Fixed an issue where, after an HA failover event, the newly active
firewall DHCP client interfaces failed to obtain IP addresses
automatically. This occurred because the DHCP client processes did not
initiate the necessary DHCP discover or renew requests
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-298654</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall generate false positive threat logs
during updates to a large domain list (EDL) when a DNS lookup for a
domain being added or removed occurred during the update process. This
resulted in a threat log being generated for a different, unrelated
domain that remained on the list.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-298505</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading an HA pair of PA-7050 firewalls,
the vsys ID changed in sequence, causing autocommit failures with
validation errors. This occurred when the multi-vsys firewall had
virtual systems created and pushed from Panorama, and the vsys ID was
not in a correct sequence because the unused vsys was deleted from
Panorama and pushed to devices.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297797</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, during a refresh of a large External Dynamic
List (EDL), traffic that matched a domain on the list was incorrectly
identified as a different domain, which resulted in false positive
threat logs.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-295221</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading Panorama and Log Collectors from
PAN-OS 10.2.9 to PAN-OS 11.1.6-h6, Traffic and Threat logs were not
forwarded to a Splunk server over UDP.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-293848</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama failed to push the default value of
<span class="ph systemoutput">None</span> for the secondary NTP server
address to managed firewalls, resulting in a commit validation error.
This occurred even when configuring the secondary NTP server address
as
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>None</a
>
in Panorama's web interface, and affected both newly deployed and
long-standing production firewalls after upgrading.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291716</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where PA-460 firewalls experienced out-of-memory (OOM)
conditions, leading to device crashes and reboots.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-289859</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama virtual appliances only</tt>) Fixed an
issue where Panorama failed to mount logging disks larger than 2TB due
to a partitioning error.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-288388</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after an EDL certificate update or repository
migration, authentication failures caused the firewall to not fall
back to the last successfully cached EDL entries, which led to policy
rules that referenced the EDL to not be enforced.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287693</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not use the configured proxy
settings to check WildFire private cloud content and instead connected
directly to the WildFire device using the management interface. This
occurred even when
<span class="ph uicontrol">Use Proxy Settings for Private Cloud</span>
was enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-284872</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where ENA (Elastic Network Adapter) extended statistics
(conntrack allowance metric) were unavailable in DPDK 22.11.x. This
metric is now available through AWS Cloudwatch.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-277682</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where moving an address object from a device group to
<span class="ph uicontrol">shared</span> and renaming it did not
reflect in the address group, which caused commits to fail.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-262444</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not refresh the external dynamic
list due to the first entry in the list being removed from the global
external list and breaking out of the loop.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-257515</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Possible Domain Fronting Detection for HTTP/2
generated false positives. With this change, domain fronting is
limited to HTTP/1.
</div>
</td>
</tr>
</tbody>
</table>
+424
View File
@@ -0,0 +1,424 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-299815</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on multi-vsys firewalls where a host was not removed
from the quarantine list after receiving a redistribution message from
Panorama. This occurred when Panorama was configured to redistribute
quarantine messages to a firewall cluster, and the GlobalProtect
configuration and redistribution were built out in a vsys other than
vsys1.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-299615</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the Network Packet Broker feature was
enabled, forward TLS (non-decrypted) traffic was not working as
expected when there were segmented client hellos and a no-decrypt rule
existed. This issue occurred when Zone Protection profiles were
configured for trust/untrust zones but not attached to NPB zones.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297782</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where reassociating a vsys from one device
group to another in a multi-vsys environment resulted in another vsys
from the same firewall being removed from the original device group.
This resulted in the device being moved into the
<span class="ph uicontrol">no device groups attached</span> group, a
superuser was required to manually reattach the device.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297775</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to an affected PAN-OS release,
the <span class="ph uicontrol">Visible Virtual Systems</span> field
started to reference the vsys name instead of the vsys ID, which
caused inter-vsys routing to fail. This occurred when a vsys display
name matched one of the vsys IDs.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"> PAN-296752</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall experienced high management CPU
usage and repeatedly rebooted when attempting to retrieve SMART data.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-295470</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process continuously increased its memory consumption, which resulted
in an OOM condition that caused the firewall to restart.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-293847</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where EAL logs for traffic matching the
intrazone-default Security policy rule were not forwarded to the IoT
Security portal.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-292261</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall repeatedly reported an unreachable
syslog server as <span class="ph systemoutput">back online</span> when
the server remained unavailable. This resulted in misleading
alternating connection status messages in the system logs.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291661</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama appliances and Log Collectors where, after
an upgrade, Elasticsearch intermittently entered into a Red state
before automatically recovering.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291653</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect host ID field was
intermittently blank in traffic logs on Prisma Access, even when the
user was connected and had the correct host ID information. This
occurred when the IP address to host ID entry expired and the entry
was re-insterted without the dataplane flag being set.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-289405</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Added the CLI
command
<span class="ph systemoutput">no-refresh-discard-session</span> to
address an issue where the discarded session time to live (TTL) did
not refresh at the default value.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-289067</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading Panorama in a High Availability
(HA) pair, the configuration logs stopped synchronizing from the
primary Panorama to the secondary Panorama. This issue occurred
because the log forwarding flag was permanently disabled due to the
connection state not being active when the
<span class="ph systemoutput">log-fwd-ctrl</span> message was
received.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-288930</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic from cloud applications intermittently
matched an incorrect
<span class="ph uicontrol">cloud-apps</span> policy rule when ACE
(App-ID Cloud Engine) was enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-288761</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process stopped responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-288097</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where on the firewall where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>routed</a
>
process stopped responding after changing the MTU or any link state
parameters when OSPF and PIM were enabled on the same interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287314</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with firewalls in active/passive HA configurations
where an OOM condition occurred and caused a failover due to a memory
leak associated with the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-285169</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where Kerberos superusers were unable to
edit policy rules because the target device tab was grayed out.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-283954</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding due to a circular reference between address
groups.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-282093</b></div>
</td>
<td class="entry relcol">
<div class="p">
Enhanced the CLI command
<span class="ph systemoutput">request legacy reset</span> to delete
the legacy certificate files that were being used to connect with the
secondary Panorama appliance.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-274797</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a DPC on slot 3 failed intermittently due to the
<span class="ph systemoutput">pktlog_forwarding</span> process
restarting, which resulted in an unexpected HA failover.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"> PAN-272539</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Panorama appliances on Microsoft Azure environments only</tt
>) Fixed an issue where user to IP address mapping was missing for
some users connected to specific Prisma Access gateways, which caused
the collection layer Azure firewall to not form the mapping.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272175</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where session rematch caused ACE cloud application
traffic to match the wrong policy rule.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271507</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
the DPC on slot 3 intermittently stopped responding due an
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
restart.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-258039</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall displayed the incorrect rule name
when a threat log was generated for Inline Cloud Analyzed CMD
Injection Traffic Detection.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-251715</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall closed the SSL connection to the
user ID agent.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,36 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-306226</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the TLS handshake did not complete and the
session did not go through. This occurred if the HTTP header insertion
applied to an HTTP CONNECT request passing through the firewall, the
scan-handshake feature was enabled, the session matched a decryption
policy rule with the decrypt action, and if the TLS client hello was
in a single packet and TLS 1.2 or below.
</div>
</td>
</tr>
</tbody>
</table>
+407
View File
@@ -0,0 +1,407 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-306502</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TLS connection failure occurred when traffic was
over TLS1.2 or below, header insertion was enabled on the firewall,
<span class="ph uicontrol">send TLS handshake to CTD</span> was
enabled, and traffic hit a decryption policy rule configured with the
<span class="ph uicontrol">no-decrypt</span> action.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-304636</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where BGP aggregate routes were not created and discard
routes were not installed in the routing table.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-306226</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the TLS handshake did not complete and the
session did not go through. This occurred if the HTTP header insertion
applied to an HTTP CONNECT request passing through the firewall, the
scan-handshake feature was enabled, the session matched a decryption
policy rule with the decrypt action, and if the TLS client hello was
in a single packet and TLS 1.2 or below.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-304496</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after unregistering an IP tag and registering a
different IP tag for the same IP address via XML API, the dynamic
address group membership was not updated on the dataplane, which
resulted in Security policy rules being enforced incorrectly.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-303954</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when configuring Safenet HSMs in HA and
authentication HSM manually, the second HSM server failed to
authenticate due to the firewall overwriting the first HSM server's
certificate with the second HSM server's certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-303051</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a memory leak occurred related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process due to retaining memory that was temporarily used for report
generation instead of releasing the memory for reuse, which resulted
in continuous accumulation and memory exhaustion.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-301801</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Log Collectors where the Elasticsearch process
fluctuated intermittently between green and red states, which led to
interruptions in log collection. This issue occurred when the number
of shards exceeded the cluster's maximum supported threshold of
greater than 1000 shards per Elasticsearch instance.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-300637</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Microsoft Azure environments only</tt
>) Fixed an issue where the firewall unexpectedly rebooted due to
repeated
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>varrcvr</a
>
process restarts.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300548</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where using the IKEv2 multiplier setting for VPN
re-authentication resulted in the firewall not re-authenticating at
the expected intervals when both sides initiated rekeying. The
internal re-authentication counter incremented when the local side
triggered the rekey, but not when the peer side triggered it.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-297975</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama was unable to push the Trusted Root CA
configuration to Log Collectors via a Collector Group push due to the
Log Collector not supporting the
<span class="ph systemoutput">trusted-root-CA</span> configuration.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-297708</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a long-lived session with many Machine Learning
(ML) model triggers caused a memory leak of feature states associated
with the ML model runs. This resulted in Spyware_State failure
increases, allocation max outs, and impaired policy matching.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297610</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall became unresponsive after an upgrade
due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>fsck</a
>
command scanning drive partitions in parallel with the root partition,
which caused the process to take an extended amount of time.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-297295</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls in Microsoft Azure environments only</tt
>) Fixed an issue where the firewall repeatedly restarted due to high
packet rates on the synthetic path in DPDK mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-288158</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the firewall became inaccessible via the web interface and SSH and
remained in an initializing state.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-287611</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading, the firewall incorrectly
calculated the UDP checksum for RTP traffic after NAT and Security
policy application, which led to dropped packets and silent calls in
applications.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-284866</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the LFC failed to validate Certificate Revocation
Lists (CRL) for SSL syslog connections, which caused a failure to
forward logs to external syslog servers.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-278126</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the number of registered IP Tags on Panorama did
not match the number of registered IP Tags on the managed firewalls
due to a change in file format between PAN-OS releases.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-274697</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where push operations from Panorama failed on passive
firewalls when an application was removed from a Security policy rule
and the policy rule was referenced in a device group.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270554</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect client (UWP) or metered hotspot
connections triggered TLS resumption for GlobalProtect portal
authentication, which caused the portal authentication to fail with a
<span class="ph systemoutput">valid cert required</span> error.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260090</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where commit all operations failed when the application
<span class="ph systemoutput">openair-psa</span> was used as a keyword
on a remote network instance that was upgraded to an affected release.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257616</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where selective push operations from Panorama to
managed firewalls failed with the error message
<span class="ph uicontrol"
>Failed to generate selective push configuration. Schema validation
failed. Please try a full push</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257362</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect traffic destined for the internet
did not follow the path-based forwarding (PBF) rule and was sent out
the wrong interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255253</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not establish a syslog
connection to the probe VM syslog server in ADEM Regressions.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-242602</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients experienced slow SMB-V3
download throughput when passing through a Prisma IPSec tunnel and the
firewall and the SMB-V3 session owner dataplane was the same as the
IPSec-ESP tunnel on the multi-dataplane firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-241694</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where memory leaks related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
process occurred when downloading and pushing updates from the App-ID
Cloud Engine to the dataplane.
</div>
</td>
</tr>
</tbody>
</table>
+480
View File
@@ -0,0 +1,480 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-308060</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/active HA configurations only</tt
>) Fixed an issue where the BFD session went down and did not recover
even though the BGP remained in an established state, which caused the
firewall to cease route learning and advertisement with the peer, even
though BGP keep-alives were exchanged correctly.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-307795</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama incorrectly generated system logs
indicating a lost connection to its peer after an upgrade even when
High Availability was not configured.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-305412</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Logging Service License Status displays a
license failure when the license status transitions from valid to
expired and then back to valid even when the connection to the
Security Logging Service (SLS) was working.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-305301</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the timing of GlobalProtect lifetime expiry or
inactivity logout notifications used for GlobalProtect SSL tunnels
could cause the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process to stop responding and the dataplane to restart.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-303959</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic is incorrectly identified as
unknown-tcp/unknown-udp due to App-ID resource leak and eventually
dropped.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-302551</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall displayed as disconnected in the SLS
due to the serial number not being retrieved
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-301975</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
issue where the passive firewall incorrectly triggered PBP alerts even
with low packet rates.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-301912</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama stopped responding when deploying
dynamic updates to managed devices.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-301600</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where, after upgrading Panorama, OSPF
adjacencies remained in the exchange start state, which resulted in an
incomplete routing table.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-301456</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the
<span class="ph codeph">debug system reset-ztp</span> CLI command was
unavailable.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-301409</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama failed to perform a selective push to a
managed device when device tags were added or modified on the policy
rules. The selective push failed with the error message
<span class="ph systemoutput"
>Failed to generate selective push configuration. Schema validation
failed. Please try a full push</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300837</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls experienced multiple reboots due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process restarting with a SIGSEGV signal. This occurred because the
client-to-firewall side assumed TLS 1.3 for the firewall-server side.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-299751</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to connect to the
Subscription License Service (SLS) due to a public and private key
pair mismatch with the device certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-298907</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on PA-VM in AWS where, in a two-arm deployment
integrated with Gateway Load Balancer (GWLB), the firewall did not
preserve the GENEVE source port for internet traffic, resulting in
increased latency. The fix ensures the firewall preserves the outer
UDP source port of GENEVE encapsulation when sending traffic back to
GWLB.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-298872</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-400 Series firewalls in HA configurations only</tt
>) Fixed an issue where ports went down after an HA failover.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297263</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5220 firewalls only</tt>) Fixed an issue where
the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>ikemgr</a
>
process crashed intermittently, causing IPSec tunnels to go down
randomly. The fix ensures that the IKE security association data
structures are accessed in a thread-safe manner. This prevents the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>ikemgr</a
>
process from referencing an invalid memory pointer during teardown
operations and provides stability.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-296208</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not accept address groups in the
filter condition of a Log Forwarding Match list.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-290241</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process became unresponsive, which caused User-ID CLI commands to time
out.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-289652</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue related to external URL lists where pushing
configuration changes from Panorama failed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-288427</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where commit jobs were not queued and the
system reported that the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
was not connected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287921</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the maximum registered IP address for was incorrectly set to 100,000
instead of the expected 500,000.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-285208</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not automatically recover after
a machine check exception (MCE) occurred.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-281588</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where packet buffer depletion occurred due to the a
high number of
<span class="ph systemoutput">tcp_pkt_queued</span> packets when Jumbo
was enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272731</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where commits took longer than expected due
to the
<span class="ph codeph">show object dynamic-address-group all</span>
CLI command holding the devicetable lock for an extended period.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263691</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted unexpectedly due to a
memory leak in the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-253921</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall displayed the following error
message:
<span class="ph systemoutput"
>critical userid registe 0 fail to integrate the update of
registered ip addresses since 2 seconds ago; critical system log
alerts observed</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-185731</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to parse the URL path and
host when the host header was located in a different packet, which
resulted in the firewall not logging the URL path in the first packet.
The fix is disabled by default. The following CLI commands can be used
to enable/disable the feature:
<ul id="panos-addressed-issues-11.1.6-h25_ul-fmq_kc3_yhc" class="ul">
<li class="li">
<span class="ph systemoutput"
>set system setting ctd url-crosspkt-host-path-caching
enable</span
>
</li>
<li class="li">
<span class="ph systemoutput"
>set system setting ctd url-crosspkt-host-path-caching
disable</span
>
</li>
<li class="li">
<span class="ph systemoutput"
>set system setting ctd url-crosspkt-host-path-caching
default</span
>
</li>
</ul>
</div>
</td>
</tr>
</tbody>
</table>
+405
View File
@@ -0,0 +1,405 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-316911</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Amazon Web Services (AWS) environments
only</tt
>) Fixed an issue where a newly bootstrapped firewall required a
management server restart, relicensing, or license push from Panorama
to invoke the device certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-314061</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic was disrupted during IPSec rekey
operations due to a 2 second delay in sending the DELETE message for
the previous Security Association (SA) to the peer gateway after a new
SA was negotiated.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-313850</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-1400 Series firewalls in HA configurations only</tt
>) Fixed an issue where a split-brain condition occurred and HA1/HA2
links went down while upgrading when the HA configuration used
dataplane interfaces for HA1 and a combination of HSCI and Ethernet
interfaces for HA2.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-313623</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">/opt/pancfg/mgmt/ssl/private/</span>
directory on Palo Alto Networks devices with TPM support became 100%
utilized due to an accumulation of undeleted
<span class="ph systemoutput">.pub_pem</span> files. This occurred
because executing the
<span class="ph systemoutput">show device-certificate status</span>
CLI command initiated a process that generated these files but failed
to remove them, which prevented the fetching of new device
certificates.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-312706</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewalls restarted due to a function lacking
a NULL-pointer sanity check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-311250</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances and Log Collectors only</tt>)
Fixed an issue where logs from multiple devices were not visible on
Panorama even though the Elasticsearch health status on the dedicated
Log Collectors appeared green.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-309300</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where management plane system resources configuration
size exceeded 28 MB for over 4 hours, and the following error message
was displayed:
<span class="ph systemoutput"
>Configuration size reaching device capacity limit</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-308786</b></div>
</td>
<td class="entry relcol">
<div class="p">
(Panorama appliances only) Fixed an issue where traffic log queries
using the <span class="ph systemoutput">device_name</span> filter
returned no results, and complex log queries that included negation
operators produced incorrect outputs.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-308654</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Elasticsearch Close Indices process closed
more indices than expected and dropped the number of open shards below
the minimum of 800 per Elasticsearch instance. This occurred because
the process did not correctly account for the number of Elasticsearch
instances when calculating the maximum number of allowed open shards.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-308507</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama managed firewalls only</tt>) Fixed an
issue where the firewall intermittently failed to maintain active log
forwarding streams to Cortex Data Lake even when duplicate logging and
enhanced application logging were enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-306555</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding, which led to
service outages.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"> PAN-304718</b></div>
</td>
<td class="entry relcol">
Fixed an issue where OSPF and BGP outages occurred due to an
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process restart during clientless VPN content rewrite processing.
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-304696</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Cloud User-ID connection timed out because
the firewall took too long to process the OCSP response.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-298945</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where OSCP HTTP POST requests were not formatted
correctly, which caused failures with strict responders.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-298617</b></div>
</td>
<td class="entry relcol">
<div class="p">
Optimized the commit workflow to reduce the size of the effective
configuration, resulting in lower memory consumption.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-297005</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where exporting custom reports resulted in empty CSV
files.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-296694</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process repeatedly restarting during an IP-port data type writes to
the redis from multiple sources such as TSA or XML in a scale
environment.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-296202</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/active HA configurations only</tt
>) Added a log enhancement to capture an issue where, when a commit
operation was in progress, newly deployed IP address tags that used
the XML API were not immediately reflected in address group
resolution, which delayed IP address mapping to address groups and
caused traffic to be incorrectly allowed or denied.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291067</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
process periodically exceeded its virtual memory limit and restarted,
which led to intermittent outages.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-290157</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding when filtering in the
<span class="ph uicontrol">Config Audit</span> window, which caused
Panorama to restart unexpectedly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-288175</b></div>
</td>
<td class="entry relcol">
<div class="p">
Addressed a stack buffer overflow memory leak under plugin management
code path.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287584</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where the address object pop up
window only displayed a maximum of four address objects in the policy
rule even after expanding the window.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-278688</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DNS Security threat logs were not displayed on
the firewall when packet capture was enabled and the domain name
length was 62 characters.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273158</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7000 Series firewalls only</tt>) Fixed an issue
where an incorrect ASIC configuration caused silent packet drops or
application slowness when receiving a mix of jumbo and non-jumbo
packets.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-271643</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when a commit job ID was higher than 65535, the
XML API truncated the ID to a 16-bit unsigned integer due to an
incorrect type case during printing, which resulted in an incorrect
job ID being reported compared to the CLI output for the same commit.
</div>
</td>
</tr>
</tbody>
</table>
+347
View File
@@ -0,0 +1,347 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279604</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where scheduled SaaS application usage reports were
generated incorrectly, and the login page was displayed instead of the
report content.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-274791</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall might reboot when traffic matches
with certain Advanced features (such as Advanced Threat Prevention and
Advanced URL Filtering with properly configured URL
Filtering/Anti-Spyware/Vulnerability security profiles) and Shared
Pool Type 32 becomes depleted.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-274592</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
issue where the firewall did not fail over when the active firewall
experienced data plane issues.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273949</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall generated the following error
message in the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>snmpd</a
>
logs:
<span class="ph systemoutput"
>pan_get_keystr_from_cryptod(pan_snmpinterface.c:181): Key
X2F1dGhfa2V5 import from cryptod failed</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273019</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an intermittent issue where SSL decryption failed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271723</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding, which caused the passive firewall to
repeatedly reboot.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270248</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall failed to forward logs to a SNMP
trap server if the SNMP manager IP address was unable to be resolved.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269091</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>varrcvr</a
>
process stopped responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268909</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IP address tags were removed from firewalls after
a management server or
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process restart. This occurred when a Panorama serial-number based
configuration was used for User-ID redistribution.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268800</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a large number of logs caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process to stop responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267995</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where after migrating to a new platform, DLP verdicts
were not displayed in the Cloud Manager or logs.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267204</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama port 9300 did not adhere to restricted
TLS versions and ciphers.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-266559</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where partial commits failed when objects that were
referenced in a high number of Security policy rules were renamed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-266116</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where URLs did not work due to certificate revocation
list (CRL) requests failing.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-263291</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Microsoft Outlook did not work as expected when
the GlobalProtect clientless VPN was configured.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261998</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall configuration process restarted
during an External Dynamic List refresh or a commit and push
operation.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260300</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-5410, PA-5420, PA-5430, PA-5440 and PA-5445 firewalls only</tt
>) Fixed an issue related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process where DPC slot 3 stopped responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259076</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall displayed an OCSP/CRL check failure
when accessing websites.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-258570</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall might reboot unexpectedly due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>varrcvr</a
>
process progressively using more memory when WildFire file forwarding
is handling PE files.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-255619</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an intermittent issue where file downloads from websites failed
when decrypting HTTP/2 traffic.
</div>
</td>
</tr>
</tbody>
</table>
+221
View File
@@ -0,0 +1,221 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-282236</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where large IPv6 packets were reassembled on the
firewall when the packets arrived fragmented over an IPv4 tunnel.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-280471</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where navigating
<span class="ph menucascade"
><span class="ph uicontrol">Panorama</span
><span class="ph uicontrol">Monitor</span
><span class="ph uicontrol">Logs</span></span
>
was slower than expected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279746</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SMTP packets were not sent out when the Client
Hello arrived at the firewall in multiple out-of-order segments and
the traffic was not subject to SSL decryption.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279191</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a GlobalProtect gateway stopped responding when
handling HTTP/1.1 traffic with web inspection enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-278684</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-445 firewalls only</tt>) Fixed an issue where
the firewall did not properly power cycle during a reboot.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-277147</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where daily scheduled reports were not generated and
emailed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-276062</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where importing a firewall with a large number of
address objects into Panorama did not work and remained at 99%
completion.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-275905</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama web interface was slower than
expected and Elasticsearch CPU usage was high.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-275754</b></div>
</td>
<td class="entry relcol">
<div class="p">
Added support for bootstrapping Panorama virtual appliances on ESXi.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-275032</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">M-600 appliances only</tt>) Fixed an issue where
the Elasticsearch cluster certificate (CC) status displayed with a
past expiration date, which caused all shards to be unassigned.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273141</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients experienced slow file
transfer download throughput when passing through an IPSec tunnel.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272085</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall might crash and reboot when DoH is
enabled for DNS Security and multiple DoH transactions are sent in a
single HTTP/1 connection.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270744</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where API calls to Panorama failed with the error
<span class="ph systemoutput"
>Server error : Timed out while getting config lock. Please try
again</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269291</b></div>
</td>
<td class="entry relcol">
Fixed an issue where the scheduled report generation script did not
return debug information.
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268279</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where autocommits failed if the management IPv6 gateway
was the same as the dataplane interface IP address.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267650</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not detect the eth1/1 and eth1/2
interfaces when you created a firewall on an ESXi 8 server.
</div>
</td>
</tr>
</tbody>
</table>
+32
View File
@@ -0,0 +1,32 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-282022</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed the support limitation for the Panorama M-600 and M-700
appliances.
</div>
</td>
</tr>
</tbody>
</table>
+647
View File
@@ -0,0 +1,647 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-282022</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed the support limitation for the Panorama M-600 and M-700
appliances.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-281885</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when exporting and importing CSV files, the hash
values of pre-shared key variables set at template and template stack
levels changed inconsistently, which resulted in both variables
displaying the same hash value.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-281269</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5220, PA-5250, and PA-5420 firewalls</tt>) Fixed
an issue where the firewall management server memory usage
continuously increased.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-281264</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>routed</a
>
process memory usage continuously increased when Advanced Routing was
enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-280505</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the web interface did not display a message to
commit prior changes before attempting a partial configuration load.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-280243</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall lost the pre-shared key
configuration assigned from a PSK variable when an unrelated device
group configuration was loaded.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279336</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the CLI did not display a message to commit prior
changes before loading a partial configuration.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279176</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the configuration audit displayed inaccurate
information after partially loading the configuration via the CLI,
which caused the audit to flag the configuration as deleted or
changed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279065</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall sent logs with
<span class="ph uicontrol">connection succeeded</span> to the syslog
server every time a connection was established, which resulted in
excessive logs.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-278296</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the system MAC address of the aggregate interface
was the same on the active firewall and the passive firewall after an
upgrade.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-277762</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
unexpected failovers occurred on firewalls running PAN-OS 11.2.2-h2.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-277631</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process discarded logs due to a full queue.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-275718</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama stopped forwarding logs to a Syslog
server after upgrading to PAN-OS 11.1.5-h1.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-275713</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>dscd</a
>
process stopped responding when
<span class="ph uicontrol">Endpoint Serial Number</span> was enabled,
which resulted in the
<span class="ph uicontrol">Active Directory</span> returning a list of
serial numbers for a specific firewall from the Cloud Identity Engine.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-275077</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DNS Security intermittently logs malicious domain
URLs as Alert instead of taking a Sinkhole action, even when
configured to Sinkhole malicious DNS domains.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-274750</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the detailed log view in Panorama did not display
all packet details for traffic logs received from the cloud.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273694</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted due to an out-of-bounds
memory access that occurred as a result of the SIP content length
value being split across packets.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273453</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where restarting the firewall did not initiate an
autocommit job, which caused the firewall to stop responding and the
HA interface to go down.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272746</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-440 firewalls only</tt>) Fixed an issue where
the firewall entered an unstable state after committing changes or
onboarding to Panorama.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272171</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dropped the AAAA DNS server response
and caused delays in traffic from Ubuntu or Linux clients when DNS
Security was enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271498</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-7000 Series firewalls, PA-5200 firewalls, and PA-5400f firewalls
in FIPS mode only</tt
>) Fixed an issue where decrypted traffic repeatedly failed and
frequent reboots were required.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271351</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-0116"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-0116</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270193</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama management server changed its
certificate authority (CA) unexpectedly, which caused managed
firewalls to disconnect.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269052</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic was blocked by a URL filtering profile
even though the Security policy rule did not have a URL filtering
profile configured.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268629</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic did not match the correct security policy
when using an application-filter that references a cloud application.
This occurred when a high number of cloud applications were attached
with a custom tag.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267518</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where WildFire submission logs incorrectly reported
allowed malicious samples even when they were blocked by threat
prevention profiles.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-266695</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a cyclic nested address group
configuration caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process to stop responding after a commit.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-262063</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not display the converted
configurations before a commit and reboot, and the commit failed when
attempting to migrate from MS to FRR mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261825</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic was dropped when Data Loss Prevention or
Advanced URL Filtering were enabled. This occurred when the payload
size was greater than 3.5 KB.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261739</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls in Microsoft Azure environments only</tt
>) Fixed an issue where the firewall displayed 0 for the physical port
counters read from MAC.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261597</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph uicontrol">all_pktproc</span> process stopped
responding, which caused the firewall to become unavailable.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261312</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a commit for a policy and configuration dump
overlapped, which resulted in a null pointer exception.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260059</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">Device Telemetry Regions</span> did not
show up with the latest content due to content files not being parsed
for the region list when Telemetry was turned off.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259767</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect users were unable to connect when
the option
<span class="ph uicontrol"
>Block sessions if the certificate was not issued to the
authenticating device</span
>
was enabled in the certificate profile.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-258743</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when you attempted to select a redistribution
profile when creating a BGP Redistribute policy rule, the firewall
displayed an empty dropdown.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-258680</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where, when you removed Security profile
groups from a Security policy rule via the CLI and committed the
change, the Security policy rule was deleted.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-257183</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dropped DNS traffic when using DNS
Security.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-256904</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall inconsistently blocked URLs due to
intermittent URL category misidentification.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-253127</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to PAN-OS 11.0.2-h3, the
hardware pool DFLT became highly utilized, and the packet buffer
gradually increased.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-251724</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where users matched incorrect Security policy rules
with a HIP profile.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-235733</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the displayed NTP information was incorrect if
the DNS servers timed out.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-234993</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where CPU base gateway auto-scaling failed, which
caused performance issues.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-233868</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall took an incorrect action for
overlapping custom and edl-url-categories in a policy rule.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-212889</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where different threat names were used when
querying a threat under
<span class="ph uicontrol">Threat Monitor</span> (<span
class="ph uicontrol"
>Monitor &gt; App Scope</span
>) and the ACC. This resulted in the ACC displaying no data after
clicking a threat name in
<span class="ph uicontrol">Threat Monitor</span> and filtering it in
the global filters.
</div>
</td>
</tr>
</tbody>
</table>
+391
View File
@@ -0,0 +1,391 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286255</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the firewall received an unexpected
termination request for SSL sessions, the dataplane experienced a slow
buffer resource leak.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-285941</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where high memory consumption occurred on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-285651</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Panorama appliances in active/passive HA configurations on
Microsoft Azure environments only</tt
>) Fixed an issue on Panorama that caused firewalls to disconnect
unexpectedly.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-285597</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>routed</a
>
process memory leak occurred when advanced routing was enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-282391</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a memory leak occurred after cloning
a template, resulting in an increase in memory use, which caused OOM
errors.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-282206</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where configuring Secure Web Gateway (SWG) in
<span class="ph uicontrol">no-auth</span> mode led to latency when no
decryption policy rules or
<span class="ph uicontrol">No-decrypt</span> policy rules were
present.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-282069</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where Security policy rules were removed
from device groups when you cloned or edited Security policy rules
that used more than 63 characters.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-281649</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the index size limit was incorrectly calculated
and indices rolled over earlier than expected, which resulted in high
memory and OOM errors.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-280942</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process stopped responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279691</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/passive HA configurations only</tt
>) Fixed an issue where the firewall didn't synchronize IPSec SAs
(security associations) to the passive firewall if the tunnel was not
initially established by the active firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-274671</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where empty traffic
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logdb</a
>
folders were generated for each day even when trafcfic logs were not
received by the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-274570</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
process restarted after a failed commit due to an invalid memory
access.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271701</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Advanced Services, App-ID Cloud Engine (ACE), and
Enhanced Application Log stopped working due to incorrect memory usage
accounting, which caused memory usage to remain at 99% after an
extended period of time.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271273</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where dynamic update downloads failed when
<span class="ph uicontrol">IPv6 firewalling</span> was enabled on the
firewall and both IPv4 and IPv6 were configured on the management
interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271175</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding with a SIGABRT.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269027</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue related to external dynamic lists that caused commit
times on the firewall to be higher than expected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268614</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where, when all rules were
highlighted when a read-only admin user clicked the
<span class="ph uicontrol">Highlight Unused Rules</span> checkbox.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268118</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on firewalls in active/passive HA configurations where,
after a failover, irrelevant routing FIB entries were seen in the
routing table on the newly active firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267444</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where large file downloads or uploads failed or
remained in an incomplete state when using DLP HTTP2 mirror mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260015</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where the dataplane restarted due to
insufficient allocation of memory buffers.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-256867</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process stopped responding while processing session logs for
forwarding to the LFC.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-255914</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Amazon Web Services (AWS) environments
only</tt
>) Fixed an issue where a newly bootstrapped firewall required a
management server restart, relicensing, or license push from Panorama
to invoke the device certificate.
</div>
</td>
</tr>
</tbody>
</table>
+707
View File
@@ -0,0 +1,707 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-273215</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a syntax error in the index generation script
caused a high management plane CPU load after upgrading.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-271913</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on firewalls in high availability (HA) configurations
where, when using the Cloud Identity Engine (CIE), the firewall
experienced consistent memory leaks on the active firewall, which
caused unexpected failovers.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-270224</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where indices were not opened after a query.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-269539</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where whitespace was added before the timestamp in
syslog logs forwarded from Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-269000</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding due to a NULL
pointer dereference when path monitoring failed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-268951</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a CPS counter query issue that caused SNMP polling timeouts on
the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-268727</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic was dropped when the accumulation proxy
was enabled and header insertion modified packets.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-268474</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where the PAN-DB URL Filtering license
displayed as <span class="ph uicontrol">Valid</span> even when the
firewall did not have the license, which caused traffic to drop.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-268419</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">Managed Devices &gt; Summary</span>
displayed incorrect subcolumns.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-268319</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">Receive Time</span> and
<span class="ph uicontrol">Time Generated</span> were not visible as
attributes in the <span class="ph uicontrol">Filter Builder</span> for
system logs and URL filtering logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-268229</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding during session
setup for ECMP hit-count updates.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-268228</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama administrators were unable to select
<span class="ph uicontrol">Edit Selection</span> when pushing changes
to devices if they logged in using TACACS authentication.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-267934</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where commits remained at 98%, which resulted in the
BGP connection flapping.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-267590</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a lock usage error that caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>ikemgr</a
>
process to stop responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-267348</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where
<span class="ph uicontrol">WildFire Activity by File Type</span> in
the ACC did not display the file type name.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-267321</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where packets were dropped when BFD inter-dataplane
packet forwarding failed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-267285</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a port was able to be connected from outside the
network. With this fix, the port is restricted to the local interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-267091</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where Elasticsearch repeatedly restarted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-266900</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where you were unable to
click <span class="ph uicontrol">OK</span> after selecting an install
package type and file from the dropdown and selecting a firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-266639</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where administrators were unable to edit or add virtual
router configurations when a filter was applied to the viewer.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-266581</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a failed SSL connection to a syslog server
resulted in a
<span class="ph systemoutput">/tmp/srvr.crt.xxxxxx</span> file not
being removed, which caused index node (inode) exhaustion.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-266167</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph uicontrol">restart</span> option for IPSec tunnels was
greyed out (<span class="ph uicontrol"
>Network &gt; IPSec Tunnels &gt; IKE Info</span
>).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-266003</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where a configuration policy push
caused both active and passive firewalls to go down when a high number
of spyware profiles and vulnerability profiles were pushed to the
dataplane.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-265621</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph uicontrol">restart</span> option for IPSec tunnels was
greyed out when you attempted to restart the tunnel from
<span class="ph uicontrol"
>Network &gt; IPSec Tunnels &gt; IKE Info</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-265399</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DNS queries for uppercase internal domain (SRV
record) timed out when DNS Security was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-265366</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewall experienced frequent reboots when ipv6
trafic is routed to explicit proxy, causing explicit proxy to crash.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-265160</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall created multiple connections to a
syslog server and remained in the FINWAIT1 state, which caused logs to
drop while being forwarded to the syslog server.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-264981</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where it took longer than
expected to edit Security policy rules.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-264883</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7080 appliances with LPCs only</tt>) Fixed an
issue where syslog forwarding over TCP stopped after upgrading.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-264678</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">Preview Changes</span> did not display
configuration changes in
<span class="ph uicontrol">Commit and push</span> &gt;
<span class="ph uicontrol">Push Scope</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-264662</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where HTTP POST requests were blocked for URLs that had
the <span class="ph uicontrol">block-continue</span> category
configured.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263843</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the firewall received no-license packet buffers instead of memory
based packet buffer numbers.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263208</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5440 and PA-5445 firewalls only</tt>) Fixed an
issue where interrupts were generated at a certain packet rate, and
dataplane processes missed heartbeats, which caused the dataplane to
go down.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263012</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where commits failed from a Panorama appliance with a
default master key to a firewall with a master key configured and a VM
Information source configured.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262973</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where changes made by a custom role Panorama
administrator did not display in the push scope for other custom role
administrators when a full commit was performed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262540</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where application traffic transactions that reused TCP
ports did not work with decryption.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262511</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on firewalls in HA configurations where OSPF neighbors
were not established after an HA failover.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260796</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where servers were not accessible through an active SSL
GlobalProtect VPN tunnel until a new connection was established or the
session was cleared on the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260604</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall displayed inaccurate throughput
utilization stats in NetFlow analyzer tools.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260417</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where
<span class="ph systemoutput">UpdateLicDB</span> was triggered every
few minutes when firewalls with PAYG licenses were onboarded.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257736</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
traffic to benign applications was impacted by holding TCP sequential
segments for MLC inspection and not releasing the full chain after a
benign verdict was received.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256552</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
stopped responding, which caused the firewall to restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255747</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where CLI commands returned
<span class="ph systemoutput"
>Server error: op command for client dagger timed out as client is
not available</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255653</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an HA failover issue where, when Management Processing Card
(MPC) or Base Card (BC) failures occurred, the HA link went down,
which caused fpp-down events on one firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253485</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/passive HA configurations only</tt
>) Fixed an issue where dataplane packet capture filter configuration
failed on the active firewall with the error
<span class="ph systemoutput"
>op command for client dagger timed out as client is not
available</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252669</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>ikemgr</a
>
process stopped responding with a
<span class="ph systemoutput">SIGSEGV</span> error.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-251973</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not detect evasions due to TCP
checksum offloading not being enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-249581</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where stale BGP routes were advertised to peers even
when they were not present in the local RIB table.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-249384</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where configuration locks were observed
during a partial rulebase commit.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-243920</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall name was truncated in the logs when
the name used more than 31 characters.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-233197</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the CLI command to set the FEC parameter for the
front panel ports was not supported on platforms supporting 25G and
100G.
</div>
</td>
</tr>
</tbody>
</table>
+33
View File
@@ -0,0 +1,33 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279604</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where scheduled SaaS application usage reports were
generated incorrectly, and the login page was displayed instead of the
report content.
</div>
</td>
</tr>
</tbody>
</table>
File diff suppressed because it is too large Load Diff
+99
View File
@@ -0,0 +1,99 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300227</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dropped packets due to the incoming
flow being hashed to a flow bucket that was full.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-290453</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where PA-7500 firewalls experienced silent traffic
drops. During migration from PA-7050 to PA-7500 firewalls connected in
series, intermittent connection losses occurred for some applications.
Traffic leaving the PA-7050 was not received or processed by the
PA-7500, even with direct connections and replaced cables/SFPs. Global
counters did not indicate any drops on the PA-7500.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-289304</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7500 firewalls only</tt>) Fixed an issue where
SNMP polling failed due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>snmpd</a
>
process becoming unresponsive to incoming requests, which resulted in
high CPU usage.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279604</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where scheduled SaaS application usage reports were
generated incorrectly, and the login page was displayed instead of the
report content.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-253778</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-7500 Series firewalls in a cluster configuration only</tt
>) Fixed an issue where users were able to enable or disable certain
configurations.
</div>
</td>
</tr>
</tbody>
</table>
+395
View File
@@ -0,0 +1,395 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273245</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
issue where upgrading an HA firewall pair from PAN-OS 10.2.11-h1 to
PAN-OS 11.1.5 caused the firewalls to enter a nonfunctional loop due
to repeated HA path monitoring failures.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-272849</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where log forwarding to a UDP syslog server stopped
when an unreachable TCP syslog server was configured and applied.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-272538</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding during a commit-all validation when there
were uncommitted changes and
<span class="ph uicontrol">share-unused-objects-with-devices</span>
was set to off.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-272006</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not trigger a kernel core dump
as a large core when the CPLD (Complex Programmable Logic Device) sent
a Non-Maskable Interrupt (NMI) to the CPU.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-271926</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TLS 1.3 decryption failed with a bad record MAC
error when the firewall was configured to decrypt and inspect TLS
traffic.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-271912</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding when filtering in the configuration audit
window after upgrading to PAN-OS 11.1.3.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271828</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after an accumulation proxy changed to
no-decrypt or no proxy, only the Client Hello was sent to Content
Threat Detection.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-271314</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where pushing changes to a prefix list used for BGP
from Panorama affected OSPF routes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-270607</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/passive HA configurations only</tt
>) Fixed an issue where OSPF failed to establish after a failover from
the active firewall to the passive firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-270471</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in active/active configurations only</tt
>) Fixed an issue where the firewall did not detect configuration
changes when only the interface of an IKE gateway was changed, which
caused IPSec tunnels to not come up after migrating the IKE gateway IP
address from a subinterface to a physical interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-269956</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process stopped responding, which caused internal path monitor
failures.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-269731</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not display logs from firewalls
after upgrading to PAN-OS 10.2.11 on devices due to Elasticsearch (ES)
getting restarted continuously.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-269337</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the cluster compatibility timer was limited to
300 to 3600 seconds.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-268465</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with firewalls in active/passive HA configurations
where the total user count in the registered users was different
between the active and passive firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-267781</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not display the
<span class="ph uicontrol">Source Dynamic Address Group</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-267097</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the replay database size increased significantly
due to local and special configurations not being purged after
commits.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-265219</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
GRE traffic did not work properly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-265179</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a kernel race condition caused the firewall to
reboot with a kernel panic.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262946</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where logging in via the CLI or web
interface did not work due to increased memory usage.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262043</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Voice over WiFi (VoWiFi) stopped working after
switching from a PA-5200 Series firewall to a PA-7500 Series firewall
in NGFW clustering mode with NATT IPSec Passthrough and NAT policy
enabled. To use this fix, enter the CLI command
<span class="ph userinput">show tunnel-acceleration</span>, disable
tunnel acceleration, and reboot the PA-7500 Series firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260235</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall sent Threat logs and URL logs to an
external syslog server without Security profile settings when Enhanced
Application Logging was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259078</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where WildFire Analysis reports were not generated and
the following error message was displayed:
<span class="ph uicontrol">Error 500: Internal Server Error</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-258149</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dropped the SYN-ACK when using the
TCP Fast Open option.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-246699</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where
<span class="ph uicontrol">Rule Usage</span> and
<span class="ph uicontrol">Apps Seen</span> under Security policy
rules stopped incrementing.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-240529</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where cloud application information was not displayed
in the traffic log in NGFW cluster nodes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-212889</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where different threat names were used when
querying a threat under
<span class="ph uicontrol">Threat Monitor</span> (<span
class="ph uicontrol"
>Monitor &gt; App Scope</span
>) and the ACC. This resulted in the ACC displaying no data after
clicking a threat name in
<span class="ph uicontrol">Threat Monitor</span> and filtering it in
the global filters.
</div>
</td>
</tr>
</tbody>
</table>