Add PAN-OS 11.0 addressed issues
This commit is contained in:
@@ -0,0 +1,18 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.0-h1
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-202450
|
||||||
|
|
||||||
|
Fixed an issue where the
|
||||||
|
device-client-cert was set to
|
||||||
|
expire on December 31, 2023. With this fix, the expiration date has
|
||||||
|
been extended.
|
||||||
|
|
||||||
|
## PAN-198372
|
||||||
|
|
||||||
|
Fixed an issue where the root-cert was
|
||||||
|
set to expire on December 31, 2023. With this fix, the expiration
|
||||||
|
date has been extended.
|
||||||
@@ -0,0 +1,43 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.0-h2
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-238792
|
||||||
|
|
||||||
|
Fixed the following device certificate issues:
|
||||||
|
|
||||||
|
- The firewall was unable to automatically renew the device
|
||||||
|
certificate.
|
||||||
|
- Fetching device certificates failed incorrectly with the error
|
||||||
|
message OTP is not valid.
|
||||||
|
- Firewalls disconnected from Cortex Data Lake after renewing the
|
||||||
|
device certificate.
|
||||||
|
- The device certificate was not correctly generated on the log
|
||||||
|
forwarding card (LFC).
|
||||||
|
- WildFire cloud logs did not log thermite certificate usage
|
||||||
|
status.
|
||||||
|
|
||||||
|
## PAN-237876
|
||||||
|
|
||||||
|
Extended the firewall Panorama root CA certificate which was
|
||||||
|
previously set to expire on April 7th, 2024.
|
||||||
|
|
||||||
|
## PAN-231771
|
||||||
|
|
||||||
|
Fixed an issue where the firewall issued /box/getserv/ requests with
|
||||||
|
PAN-OS 7.1.0 and did not take device certificates.
|
||||||
|
|
||||||
|
## PAN-227568
|
||||||
|
|
||||||
|
When a device certificate is installed, renewed, or removed, the
|
||||||
|
firewall will reconnect to the WildFire cloud to use the newest
|
||||||
|
certificate.
|
||||||
|
|
||||||
|
## PAN-215576
|
||||||
|
|
||||||
|
Fixed an issue where the userID-Agent
|
||||||
|
and TS-Agent certificates were set to
|
||||||
|
expire on November 18, 2024. With this fix, the expiration date has
|
||||||
|
been extended to January 2032.
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.0-h3
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-252214
|
||||||
|
|
||||||
|
A fix was made to address CVE-2024-3400.
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.0-h4
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-272809
|
||||||
|
|
||||||
|
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and
|
||||||
|
CVE-2024-9474.
|
||||||
@@ -0,0 +1,143 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.0
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-231823
|
||||||
|
|
||||||
|
A fix was made to address CVE-2024-5916.
|
||||||
|
|
||||||
|
## PAN-207505
|
||||||
|
|
||||||
|
Fixed an issue where Email schedules (MonitorPDF ReportsEmail Scheduler) were not supported for SaaS Application Usage (MonitorPDF ReportsSaaS Application Usage) reports.
|
||||||
|
|
||||||
|
## PAN-204615
|
||||||
|
|
||||||
|
Fixed an issue where BGP sessions could flap even when an unrelated
|
||||||
|
configuration was committed. This resulted in the BGP session going
|
||||||
|
down and getting established again. As a result, BGP routes were
|
||||||
|
exchanged again, which could lead to momentary traffic disruption if
|
||||||
|
BGP routes were in use for establishing traffic.
|
||||||
|
|
||||||
|
## PAN-202783
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls with 100G NPC (Network Processing Cards) only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where sudden,
|
||||||
|
large bursts of traffic destined for an interface that was down
|
||||||
|
caused packet buffers to fill, which stalled path monitor heartbeat
|
||||||
|
packets.
|
||||||
|
|
||||||
|
## PAN-202535
|
||||||
|
|
||||||
|
Fixed an issue where the Device Telemetry
|
||||||
|
configuration for a region was unable to be set or edited via the
|
||||||
|
web interface.
|
||||||
|
|
||||||
|
## PAN-199726
|
||||||
|
|
||||||
|
Fixed an issue with firewalls in HA configurations
|
||||||
|
where both firewalls responded with gARP messages after a switchover.
|
||||||
|
|
||||||
|
## PAN-199654
|
||||||
|
|
||||||
|
Fixed an issue where ACC reports did not
|
||||||
|
work for custom RBAC users when more than 12 access domains were
|
||||||
|
associated with the username.
|
||||||
|
|
||||||
|
## PAN-198733
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5450 firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed
|
||||||
|
an issue where tcpdump was hardcoded
|
||||||
|
to eth0 instead of bond0.
|
||||||
|
|
||||||
|
## PAN-198332
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5400 Series only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an
|
||||||
|
issue where swapping Network Processing Cards (NPCs) caused high
|
||||||
|
root partition use.
|
||||||
|
|
||||||
|
## PAN-198244
|
||||||
|
|
||||||
|
Fixed an issue where using the load config partial CLI
|
||||||
|
command to x-paths removed address object entries from address groups.
|
||||||
|
|
||||||
|
## PAN-197383
|
||||||
|
|
||||||
|
Fixed an issue where, after upgrading to
|
||||||
|
PAN-OS 10.2 release, the firewall ran a RAID rebuild for the log
|
||||||
|
disk after ever every reboot.
|
||||||
|
|
||||||
|
## PAN-197341
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where, when you created multiple device group objects with the same
|
||||||
|
name in the shared device group and any additional device groups (PanoramaDevice Groups) under the same device group hierarchy that were used
|
||||||
|
in one or more policies, renaming the object with a shared name in
|
||||||
|
any device group caused the object name to change in the policies
|
||||||
|
that it was used in. This issue occurred with device group objects
|
||||||
|
that were referenced in a Security policy rule.
|
||||||
|
|
||||||
|
## PAN-196558
|
||||||
|
|
||||||
|
Fixed an issue where IP address tag policy
|
||||||
|
updates were delayed.
|
||||||
|
|
||||||
|
## PAN-196398
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series SMC-B firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not capture data when the
|
||||||
|
active management interface was MGT-B.
|
||||||
|
|
||||||
|
## PAN-194615
|
||||||
|
|
||||||
|
Fixed an issue where the packet broker session
|
||||||
|
timeout value did not match the master sessions timeout value after
|
||||||
|
the firewall received a TCP FIN or RST packet. The fix ensures that
|
||||||
|
Broker session times out within 1 second after the master session
|
||||||
|
timed out.
|
||||||
|
|
||||||
|
## PAN-194152
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5410, PA-5420, PA-5430, and PA-5440 firewalls in HA configurations only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where HA1-A
|
||||||
|
and HA1-B port information didn't match to front panel mappings.
|
||||||
|
|
||||||
|
## PAN-189270
|
||||||
|
|
||||||
|
Fixed an issue that caused a memory leak
|
||||||
|
on the reportd process.
|
||||||
|
|
||||||
|
## PAN-188096
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed
|
||||||
|
an issue where, on firewalls licensed with Software NGFW Credit
|
||||||
|
(VM-FLEX-4 and higher), HA clustering was unable to be established.
|
||||||
|
|
||||||
|
## PAN-171714
|
||||||
|
|
||||||
|
Fixed an issue where, when NetBIOS format
|
||||||
|
(domain\user) was used for the IP address-to-username mapping and
|
||||||
|
the firewall received the group mapping information from the Cloud
|
||||||
|
Identity Engine, the firewall did not match the user to the correct
|
||||||
|
group.
|
||||||
@@ -0,0 +1,70 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.1-h2
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-217431
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5400 Series firewalls with DPC (Data Processing Cards) only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue with slot 2 DPCs where URL filtering
|
||||||
|
did not work as expected after upgrading to PAN-OS 10.1.9.
|
||||||
|
|
||||||
|
## PAN-216710
|
||||||
|
|
||||||
|
Fixed an issue with firewalls in active/active high availability (HA)
|
||||||
|
configurations where GlobalProtect disconnected when the original
|
||||||
|
suspected Active-Primary firewall became Active-Secondary.
|
||||||
|
|
||||||
|
## PAN-215899
|
||||||
|
|
||||||
|
Fixed an issue with Panorama appliances in HA configurations where
|
||||||
|
configuration synchronization between the HA peers failed.
|
||||||
|
|
||||||
|
## PAN-215496
|
||||||
|
|
||||||
|
Fixed an issue where 100G ports did not come up with BIDI QSFP
|
||||||
|
modules.
|
||||||
|
|
||||||
|
## PAN-215461
|
||||||
|
|
||||||
|
Fixed an issue where the packet descriptor leaked over time with GRE
|
||||||
|
tunnels and keepalives.
|
||||||
|
|
||||||
|
## PAN-211870
|
||||||
|
|
||||||
|
Fixed an issue where path monitoring failure occurred, which caused
|
||||||
|
high availability failover.
|
||||||
|
|
||||||
|
## PAN-211519
|
||||||
|
|
||||||
|
Fixed an issue where RTP/RTCP packets were dropped for SIP calls by
|
||||||
|
SIP ALG when the source NAT translation type was persistent
|
||||||
|
Dynamic IP And Port.
|
||||||
|
|
||||||
|
## PAN-210607
|
||||||
|
|
||||||
|
Fixed an issue where enabling Inline Cloud Analysis on Anti-Spyware,
|
||||||
|
Vulnerability Protection, or URL Filtering Security profiles caused
|
||||||
|
the dataplane to stop responding.
|
||||||
|
|
||||||
|
## PAN-208189
|
||||||
|
|
||||||
|
Fixed an issue when traffic failed to match and reach all
|
||||||
|
destinations if a Security policy rule includes FQDN objects that
|
||||||
|
resolve to two or more IP addresses.
|
||||||
|
|
||||||
|
## PAN-206007
|
||||||
|
|
||||||
|
Fixed an issue where a debug command generated an incomplete core
|
||||||
|
file.
|
||||||
|
|
||||||
|
## PAN-202450
|
||||||
|
|
||||||
|
Fixed an issue where the
|
||||||
|
device-client-cert was set to
|
||||||
|
expire on December 31, 2023. With this fix, the expiration date has
|
||||||
|
been extended.
|
||||||
@@ -0,0 +1,43 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.1-h3
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-238792
|
||||||
|
|
||||||
|
Fixed the following device certificate issues:
|
||||||
|
|
||||||
|
- The firewall was unable to automatically renew the device
|
||||||
|
certificate.
|
||||||
|
- Fetching device certificates failed incorrectly with the error
|
||||||
|
message OTP is not valid.
|
||||||
|
- Firewalls disconnected from Cortex Data Lake after renewing the
|
||||||
|
device certificate.
|
||||||
|
- The device certificate was not correctly generated on the log
|
||||||
|
forwarding card (LFC).
|
||||||
|
- WildFire cloud logs did not log thermite certificate usage
|
||||||
|
status.
|
||||||
|
|
||||||
|
## PAN-237876
|
||||||
|
|
||||||
|
Extended the firewall Panorama root CA certificate which was
|
||||||
|
previously set to expire on April 7th, 2024.
|
||||||
|
|
||||||
|
## PAN-231771
|
||||||
|
|
||||||
|
Fixed an issue where the firewall issued /box/getserv/ requests with
|
||||||
|
PAN-OS 7.1.0 and did not take device certificates.
|
||||||
|
|
||||||
|
## PAN-227568
|
||||||
|
|
||||||
|
When a device certificate is installed, renewed, or removed, the
|
||||||
|
firewall will reconnect to the WildFire cloud to use the newest
|
||||||
|
certificate.
|
||||||
|
|
||||||
|
## PAN-215576
|
||||||
|
|
||||||
|
Fixed an issue where the userID-Agent
|
||||||
|
and TS-Agent certificates were set to
|
||||||
|
expire on November 18, 2024. With this fix, the expiration date has
|
||||||
|
been extended to January 2032.
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.1-h4
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-252214
|
||||||
|
|
||||||
|
A fix was made to address CVE-2024-3400.
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.1-h5
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-272809
|
||||||
|
|
||||||
|
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and
|
||||||
|
CVE-2024-9474.
|
||||||
@@ -0,0 +1,570 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.1
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-231823
|
||||||
|
|
||||||
|
A fix was made to address CVE-2024-5916.
|
||||||
|
|
||||||
|
## PAN-216656
|
||||||
|
|
||||||
|
Fixed an issue where the firewall was unable to fully process the user list from a child group when the child group contained more than 1,500 users.
|
||||||
|
|
||||||
|
## PAN-215911
|
||||||
|
|
||||||
|
Fixed an issue that resulted in a race condition, which caused the configd process
|
||||||
|
to stop responding.
|
||||||
|
|
||||||
|
## PAN-215488
|
||||||
|
|
||||||
|
Fixed an issue where an expired Trusted Root CA was used to sign the forward proxy leaf certificate during SSL Decryption.
|
||||||
|
|
||||||
|
## PAN-210561
|
||||||
|
|
||||||
|
Fixed an issue where the all_task process repeatedly restarted due to missed heartbeats.
|
||||||
|
|
||||||
|
## PAN-210513
|
||||||
|
|
||||||
|
Fixed an issue where Captive Portal authentication via SAML did not work.
|
||||||
|
|
||||||
|
## PAN-210481
|
||||||
|
|
||||||
|
Fixed an issue where botnet reports were not generated on the firewall.
|
||||||
|
|
||||||
|
## PAN-210449
|
||||||
|
|
||||||
|
Fixed an issue where the value for shared objects used in policy rules were not displayed on multi-vsys firewalls when pushed from Panorama.
|
||||||
|
|
||||||
|
## PAN-210331
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not send device telemetry files to Cortex Data Lake with the error message send the file to CDL receiver failed.
|
||||||
|
|
||||||
|
## PAN-210327
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where upgrading to PAN-OS 10.1.7, an internal loop caused an increase in the packets received per second.
|
||||||
|
|
||||||
|
## PAN-210237
|
||||||
|
|
||||||
|
Fixed an issue where system logs generated by Panorama for commit operations showed the severity as High instead of Informational.
|
||||||
|
|
||||||
|
## PAN-210080
|
||||||
|
|
||||||
|
Fixed an issue where the useridd process stopped responding when add and delete member parameters in an incremental sync query were empty.
|
||||||
|
|
||||||
|
## PAN-209799
|
||||||
|
|
||||||
|
Fixed an issue where logging was not disabled on passive nodes, which caused the logrcvr to stop responding.
|
||||||
|
|
||||||
|
## PAN-209491
|
||||||
|
|
||||||
|
Fixed an issue on the web interface where the Session Expire Time displayed a past date if the device time was in December.
|
||||||
|
|
||||||
|
## PAN-209069
|
||||||
|
|
||||||
|
Fixed an issue where IP addresses in the X-Forwarded-For (XFF) field were not logged when the IP address contained an associated port number.
|
||||||
|
|
||||||
|
## PAN-209036
|
||||||
|
|
||||||
|
Fixed an issue where the dataplane restarted, which led to slot failures occurring and a core file being generated.
|
||||||
|
|
||||||
|
## PAN-208987
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5400 Series only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where packets were not transmitted from the firewall if its fragments were received on different slots. This occurred when aggregate ethernet (AE) members in an AE interface were placed on a different slot.
|
||||||
|
|
||||||
|
## PAN-208922
|
||||||
|
|
||||||
|
A fix was made to address an issue where an authenticated
|
||||||
|
administrator was able to commit a specifically created
|
||||||
|
configuration to read local files and resources from the system
|
||||||
|
(CVE-2023-38046).
|
||||||
|
|
||||||
|
## PAN-208930
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where auto-tagging in log forwarding did not work.
|
||||||
|
|
||||||
|
## PAN-208902
|
||||||
|
|
||||||
|
Fixed an issue where, when a client sent a TCP/FIN packet, the firewall displayed the end reason as aged-out instead of tcp-fin.
|
||||||
|
|
||||||
|
## PAN-208724
|
||||||
|
|
||||||
|
Fixed an issue where port pause frame settings did not work as expected and incorrect pause frames occurred.
|
||||||
|
|
||||||
|
## PAN-208718
|
||||||
|
|
||||||
|
Additional debug information was added to capture internal details during traffic congestion.
|
||||||
|
|
||||||
|
## PAN-208711
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
The CLI command debug dataplane set pow no-desched yes/no was added to address an issue where the all_pktproc process stopped responding and caused traffic issues.
|
||||||
|
|
||||||
|
## PAN-208537
|
||||||
|
|
||||||
|
Fixed an issue where the licensed-device-capacity was reduced when multiple device management license key files were present.
|
||||||
|
|
||||||
|
## PAN-208525
|
||||||
|
|
||||||
|
Fixed an issue where Security policy rules with user groups did not match when Kerberos authentication was configured for explicit proxy.
|
||||||
|
|
||||||
|
## PAN-208485
|
||||||
|
|
||||||
|
Fixed an issue where NAT policies were not visible on the CLI if they contained more than 32 characters.
|
||||||
|
|
||||||
|
## PAN-208343
|
||||||
|
|
||||||
|
Fixed an issue where telemetry regions were not visible on Panorama.
|
||||||
|
|
||||||
|
## PAN-208157
|
||||||
|
|
||||||
|
Fixed an issue where malformed hints sent from the firewall caused the logd process to stop responding on Panorama, which caused a system reboot into maintenance mode.
|
||||||
|
|
||||||
|
## PAN-207940
|
||||||
|
|
||||||
|
Fixed an issue where platforms with RAID disk checks were performed weekly, which caused logs to incorrectly state that RAID was rebuilding.
|
||||||
|
|
||||||
|
## PAN-207740
|
||||||
|
|
||||||
|
Fixed an issue that resulted in a race condition, which caused the configd process to stop responding.
|
||||||
|
|
||||||
|
## PAN-207738
|
||||||
|
|
||||||
|
Fixed an issue where the ocsp-next-update-time CLI command did not execute for leaf certificates with certificate chains that did not specify OCSP or CRL URLs. As a result, the next update time was 60 minutes even if a different time was set.
|
||||||
|
|
||||||
|
## PAN-207663
|
||||||
|
|
||||||
|
Fixed a Clientless VPN issue where JSON stringify caused issues with the application rewrite.
|
||||||
|
|
||||||
|
## PAN-207629
|
||||||
|
|
||||||
|
Fixed an issue where a selective push to firewalls failed if the
|
||||||
|
firewalls were enabled with multiple vsys and the push scope
|
||||||
|
contained shared objects in device groups.
|
||||||
|
|
||||||
|
## PAN-207610
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 Series and PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where Log Admin Activity was not visible on the web interface.
|
||||||
|
|
||||||
|
## PAN-207601
|
||||||
|
|
||||||
|
Fixed an issue where URL cloud connections were unable to resolve the proxy server hostname.
|
||||||
|
|
||||||
|
## PAN-207426
|
||||||
|
|
||||||
|
Fixed an issue where a selective push did not include the Share Unused Address and Service Objects with Devices option on Panorama, which caused the firewall to not receive the objects during the configuration push.
|
||||||
|
|
||||||
|
## PAN-207400
|
||||||
|
|
||||||
|
Fixed an issue on Octeon based platforms where fragmented VLAN tagged packets dropped on an aggregate interface.
|
||||||
|
|
||||||
|
## PAN-207390
|
||||||
|
|
||||||
|
Fixed an issue where, even after disabling Telemetry, Telemetry system logs were still generated.
|
||||||
|
|
||||||
|
## PAN-207260
|
||||||
|
|
||||||
|
A commit option was enabled for Device Group and Template administrators after a password change.
|
||||||
|
|
||||||
|
## PAN-207045
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-800 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where PAN-SFP-SX transceivers used on ports 5 to 8 did not renegotiate with peer ports after a reload.
|
||||||
|
|
||||||
|
## PAN-206963
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
M-700 Appliances only
|
||||||
|
```
|
||||||
|
|
||||||
|
A CLI command was added to check the status of each physical port of a bond1 interface.
|
||||||
|
|
||||||
|
## PAN-206858
|
||||||
|
|
||||||
|
Fixed an issue where a segmentation fault occurred due to the useridd process being restarted.
|
||||||
|
|
||||||
|
## PAN-206755
|
||||||
|
|
||||||
|
Fixed an issue when a scheduled multi-device group push occurred, the configd process stopped responding, which caused the push to fail.
|
||||||
|
|
||||||
|
## PAN-206684
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls with Log Forwarding Cards (LFCs) only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where, after upgrading the firewall from a PAN-OS 10.0 release to a PAN-OS 10.1 release, the firewall did not duplicate logs to local log collectors or to Cortex Data Lake when a device certificate was already installed.
|
||||||
|
|
||||||
|
## PAN-206658
|
||||||
|
|
||||||
|
Fixed a timeout issue in the Intel ixgbe driver that resulted in internal path monitoring failure.
|
||||||
|
|
||||||
|
## PAN-206466
|
||||||
|
|
||||||
|
Fixed an issue where the push scope was displaying duplicate shared objects for each device group that were listed under the shared-object group.
|
||||||
|
|
||||||
|
## PAN-206393
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5280 firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where memory allocation errors caused decryption failures that disrupted traffic with SSL forward proxy enabled.
|
||||||
|
|
||||||
|
## PAN-206382
|
||||||
|
|
||||||
|
Fixed an issue where authentication sequences were not populated in the drop down when selecting authentication profiles during administrator creation in a template.
|
||||||
|
|
||||||
|
## PAN-206251
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls with Log Forwarding Cards (LFCs) only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the logrcvr process did not send the system-start SNMP trap during startup.
|
||||||
|
|
||||||
|
## PAN-206233
|
||||||
|
|
||||||
|
Fixed an issue where the pan_comm process stopped responding when a content update and a cloud application update occurred at the same time.
|
||||||
|
|
||||||
|
## PAN-206128
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls with NPCs (Network Processing Cards) only
|
||||||
|
```
|
||||||
|
|
||||||
|
Improved debugging capability for an issue where the firewall restarted due to heartbeat failures and then failed with the following error message: Power not OK.
|
||||||
|
|
||||||
|
## PAN-206069
|
||||||
|
|
||||||
|
Fixed an issue where the firewall was unable to boot up on older Intel CPUs.
|
||||||
|
|
||||||
|
## PAN-206017
|
||||||
|
|
||||||
|
Fixed an issue where the show dos-protection rule command displayed a character limit error.
|
||||||
|
|
||||||
|
## PAN-206005
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1400 Series, PA-3400 Series, and PA-5440 firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the
|
||||||
|
l7_misc memory pool was undersized
|
||||||
|
and caused connectivity loss when the limit was reached.
|
||||||
|
|
||||||
|
## PAN-205877
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5450 firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Added debug commands for an issue where a MAC address flap occurred on a neighbor firewall when connecting both MGT-A and MGT-B interfaces.
|
||||||
|
|
||||||
|
## PAN-205829
|
||||||
|
|
||||||
|
Fixed an issue where logs did not display Host-ID details for GlobalProtect users despite having a quarantine Security policy rule. This occurred due to a missed local cache lookup.
|
||||||
|
|
||||||
|
## PAN-205804
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where a WildFire scheduled update for managed devices triggered multiple UploadInstall jobs per minute.
|
||||||
|
|
||||||
|
## PAN-205729
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series and PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the CPLD watchdog timeout caused the firewall to reboot unexpectedly.
|
||||||
|
|
||||||
|
## PAN-205699
|
||||||
|
|
||||||
|
Fixed an issue where the cloud plugin configuration was automatically deleted from Panorama after a reboot or a configd process restart.
|
||||||
|
|
||||||
|
## PAN-205698
|
||||||
|
|
||||||
|
Fixed an issue where GlobalProtect authentication did not work on Apple MacOS devices when the authentication method used was CIE with SAML Authentication.
|
||||||
|
|
||||||
|
## PAN-205590
|
||||||
|
|
||||||
|
Fixed an issue where the fan tray fault LED light was on even though no alarm was reported in the system environment.
|
||||||
|
|
||||||
|
## PAN-205453
|
||||||
|
|
||||||
|
Fixed an issue where running reports or queries under a user group caused the reportd process to stop responding.
|
||||||
|
|
||||||
|
## PAN-205396
|
||||||
|
|
||||||
|
Fixed an issue where SD-WAN adaptive SaaS path monitoring did not work correctly during a next hop link down failure.
|
||||||
|
|
||||||
|
## PAN-205260
|
||||||
|
|
||||||
|
Fixed an issue where there was an IP address conflict after a reboot due to a transaction ID collision.
|
||||||
|
|
||||||
|
## PAN-205255
|
||||||
|
|
||||||
|
Fixed a rare issue that caused the dataplane to restart unexpectedly.
|
||||||
|
|
||||||
|
## PAN-205231
|
||||||
|
|
||||||
|
Fixed an issue where a commit operation remained at 55% for longer than expected if more than 7,500 Security policy rules were configured.
|
||||||
|
|
||||||
|
## PAN-205211
|
||||||
|
|
||||||
|
Fixed an issue where the reportd process stopped responding while querying logs (Monitor > Logs > <logtype>).
|
||||||
|
|
||||||
|
## PAN-205096
|
||||||
|
|
||||||
|
Fixed an issue where promoted sessions were not synced with all cluster members in an HA cluster.
|
||||||
|
|
||||||
|
## PAN-204749
|
||||||
|
|
||||||
|
Fixed an issue where sudden, large bursts of traffic destined for an interface that was down caused packet buffers to fill, which stalled path monitor heartbeat packets.
|
||||||
|
|
||||||
|
## PAN-204581
|
||||||
|
|
||||||
|
Fixed an issue where, when accessing a web application via the GlobalProtect Clientless VPN, the web application landing page continuously reloaded.
|
||||||
|
|
||||||
|
## PAN-204575
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls with Log Forwarding Cards (LFCs) only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not forward logs to the log collector.
|
||||||
|
|
||||||
|
## PAN-204572
|
||||||
|
|
||||||
|
Fixed an issue where python scripts were not working as expected.
|
||||||
|
|
||||||
|
## PAN-204456
|
||||||
|
|
||||||
|
Fixed an issue related to the logd process that caused high memory consumption.
|
||||||
|
|
||||||
|
## PAN-204335
|
||||||
|
|
||||||
|
Fixed an issue where Panorama became unresponsive, and when refreshed, the error 504 Gateway not Reachable was displayed.
|
||||||
|
|
||||||
|
## PAN-203964
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls in FIPS-CC mode only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall went into maintenance mode due to downloading a corrupted software image, which resulted in the error message FIPS-CC failure. Image File Authentication Error.
|
||||||
|
|
||||||
|
## PAN-203851
|
||||||
|
|
||||||
|
Fixed an issue with firewalls in HA configurations where host information profile (HIP) sync did not work between peer firewalls.
|
||||||
|
|
||||||
|
## PAN-203681
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama appliances in FIPS-CC mode only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where a leaf certificate was unable to be imported into a template stack.
|
||||||
|
|
||||||
|
## PAN-203663
|
||||||
|
|
||||||
|
Fixed an issue where administrators were unable to change the password of a local database for users configured as a local admin user via an authentication profile.
|
||||||
|
|
||||||
|
## PAN-203453
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where the log query failed due to a high number of User-ID redistribution messages.
|
||||||
|
|
||||||
|
## PAN-203430
|
||||||
|
|
||||||
|
Fixed an issue where, when the User-ID agent had collector name/secret configured, the configuration was mandatory on clients on PAN-OS 10.0 and later releases.
|
||||||
|
|
||||||
|
## PAN-203339
|
||||||
|
|
||||||
|
Fixed an issue where services failed due to the RAID rebuild not being completed on time.
|
||||||
|
|
||||||
|
## PAN-203147
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls in FIPS-CC mode only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall unexpectedly rebooted when downloading a new PAN-OS software image.
|
||||||
|
|
||||||
|
## PAN-203137
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5450 firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where HSCI ports did not come up when QSFP DAC cables were used.
|
||||||
|
|
||||||
|
## PAN-202543
|
||||||
|
|
||||||
|
An enhancement was made to improve path monitor data collection by verifying the status of the control network.
|
||||||
|
|
||||||
|
## PAN-202248
|
||||||
|
|
||||||
|
Fixed an issue where, due to a tunnel content inspection (TCI) policy match, IPSec traffic did not pass through the firewall when NAT was performed on the traffic.
|
||||||
|
|
||||||
|
## PAN-201701
|
||||||
|
|
||||||
|
Fixed an issue where the firewall generated system log alerts if the raid for a system or log disk was corrupted.
|
||||||
|
|
||||||
|
## PAN-201580
|
||||||
|
|
||||||
|
Fixed an issue where the useridd process stopped responding due to an invalid vsys_id request.
|
||||||
|
|
||||||
|
## PAN-200845
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
M-600 Appliances in Management-only mode only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where XML API queries failed due to the configuration size being larger than expected.
|
||||||
|
|
||||||
|
## PAN-200160
|
||||||
|
|
||||||
|
Fixed a memory leak issue on Panorama related to the logd process that caused an out-of-memory (OOM) condition.
|
||||||
|
|
||||||
|
## PAN-200116
|
||||||
|
|
||||||
|
Fixed an issue where Elasticsearch displayed red due to frequent tunnel check failures between HA clusters.
|
||||||
|
|
||||||
|
## PAN-199965
|
||||||
|
|
||||||
|
Fixed an issue where the reportd process stopped responding on log collectors during query and report operations due to a race condition between request handling threads.
|
||||||
|
|
||||||
|
## PAN-199807
|
||||||
|
|
||||||
|
Fixed an issue where the dataplane frequently restarted due to high memory usage on wifclient.
|
||||||
|
|
||||||
|
## PAN-196597
|
||||||
|
|
||||||
|
Fixed an issue where the dnsproxyd process stopped
|
||||||
|
responding due to corruption.
|
||||||
|
|
||||||
|
## PAN-198306
|
||||||
|
|
||||||
|
Fixed an issue where the useridd process stopped responding when booting up the firewall.
|
||||||
|
|
||||||
|
## PAN-198266
|
||||||
|
|
||||||
|
Fixed an issue where, when predicts for UDP packets were created, a configuration change occurred that triggered a new policy lookup, which caused the dataplane stopped responding when converting the predict. This resulted in a dataplane restart.
|
||||||
|
|
||||||
|
## PAN-198038
|
||||||
|
|
||||||
|
A CLI command was added to address an issue where long-lived sessions were aging out even when there was ongoing traffic.
|
||||||
|
|
||||||
|
## PAN-197872
|
||||||
|
|
||||||
|
Fixed an issue where the useridd process generated false positive critical errors.
|
||||||
|
|
||||||
|
## PAN-197298
|
||||||
|
|
||||||
|
Fixed an issue where the audit comment archive for Security rule changes output had overlapping formats.
|
||||||
|
|
||||||
|
## PAN-196410
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to customize the risk value in Risk-of-app.
|
||||||
|
|
||||||
|
## PAN-195756
|
||||||
|
|
||||||
|
Fixed an issue that caused an API request timeout when parsing requests using large header buffers.
|
||||||
|
|
||||||
|
## PAN-194805
|
||||||
|
|
||||||
|
Fixed an issue where scheduled configuration backups to the SCP
|
||||||
|
server failed with error message No ECDSA host key is
|
||||||
|
known.
|
||||||
|
|
||||||
|
## PAN-194068
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall unexpectedly rebooted with the log message Heartbeat failed previously.
|
||||||
|
|
||||||
|
## PAN-192513
|
||||||
|
|
||||||
|
Fixed an issue where log migration did not work when converting a Legacy mode Panorama appliance to Log Collector mode.
|
||||||
|
|
||||||
|
## PAN-192282
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-415 and PA-445 firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where, in
|
||||||
|
1G mode, the MGT and Ethernet 1/1 port LEDs incorrectly displayed as
|
||||||
|
amber instead of green.
|
||||||
|
|
||||||
|
## PAN-191222
|
||||||
|
|
||||||
|
Fixed an issue where Panorama became inaccessible when after a push to the collector group.
|
||||||
|
|
||||||
|
## PAN-190502
|
||||||
|
|
||||||
|
Fixed an issue where the Policy filter and Policy optimizer filter were required to have the exact same syntax, including nested conditions with rules that contained more than one tag when filtering via the neq operator.
|
||||||
|
|
||||||
|
## PAN-189335
|
||||||
|
|
||||||
|
Fixed an issue where the varrcvr process restarted repeatedly, which caused the firewall to restart.
|
||||||
|
|
||||||
|
## PAN-189200
|
||||||
|
|
||||||
|
Fixed an issue where sinkholes did not occur for AWS Gateway Load Balancer dig queries.
|
||||||
|
|
||||||
|
## PAN-186412
|
||||||
|
|
||||||
|
Fixed an issue where invalid packet-ptr was seen in work entries.
|
||||||
|
|
||||||
|
## PAN-186270
|
||||||
|
|
||||||
|
Fixed an issue where, when HA was enabled and a dynamic update schedule was configured, the configd process unexpectedly stopped responding during configuration commits.
|
||||||
|
|
||||||
|
## PAN-183375
|
||||||
|
|
||||||
|
Fixed an issue where traffic arriving on a tunnel with a bad IP address header checksum was not dropped.
|
||||||
|
|
||||||
|
## PAN-180948
|
||||||
|
|
||||||
|
Fixed an issue where an external dynamic list fetch failed with the error message Unable to fetch external dynamic list. Couldn't resolve host name. Using old copy for refresh.
|
||||||
|
|
||||||
|
## PAN-179174
|
||||||
|
|
||||||
|
Fixed an issue where exported PDF report of the ACC was the incorrect color after upgrading from a PAN-OS 10.1 or later release.
|
||||||
|
|
||||||
|
## PAN-178594
|
||||||
|
|
||||||
|
Fixed an issue where the descriptions of options under the set syslogng ssl-conn-validation CLI command were not accurate.
|
||||||
|
|
||||||
|
## PAN-175142
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where executing a debug command caused the logrcvr process to stop responding.
|
||||||
|
|
||||||
|
## PAN-170414
|
||||||
|
|
||||||
|
Fixed an issue related to an OOM condition in the dataplane, which was caused by multiple panio commands using extra memory.
|
||||||
@@ -0,0 +1,52 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.2-h1
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-225184
|
||||||
|
|
||||||
|
Fixed an issue where disk space utilization was higher than expected
|
||||||
|
due to excessive logging for a KNI: Out of
|
||||||
|
memory event under a specific traffic load
|
||||||
|
condition.
|
||||||
|
|
||||||
|
## PAN-222712
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5450 firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed a low frequency DPC restart
|
||||||
|
issue.
|
||||||
|
|
||||||
|
## PAN-221984
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls in Microsoft Azure environments only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where an interface went down after a hotplug event
|
||||||
|
and was only recoverable by restarting the firewall.
|
||||||
|
|
||||||
|
## PAN-220921
|
||||||
|
|
||||||
|
Fixed an issue where return tunnel traffic was dropped with the
|
||||||
|
counter flow_tunnel_encap_err when
|
||||||
|
Enforce Symmetric Return was enabled in a
|
||||||
|
Policy Based Forwarding rule.
|
||||||
|
|
||||||
|
## PAN-195439
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls in Microsoft Azure environments only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the dataplane interface status went down after
|
||||||
|
a hotplug event triggered by Azure infrastructure.
|
||||||
|
|
||||||
|
## PAN-193004
|
||||||
|
|
||||||
|
Fixed an issue where /opt/pancfg
|
||||||
|
partition utilization reached 100%, which caused access to the
|
||||||
|
Panorama web interface to fail.
|
||||||
@@ -0,0 +1,42 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.2-h2
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-230250
|
||||||
|
|
||||||
|
Fixed an issue where selected applications serving partial content
|
||||||
|
were dropped when Inline Cloud Analysis in Anti-Spyware was
|
||||||
|
enabled.
|
||||||
|
|
||||||
|
## PAN-223787
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-400 Series and PA-1400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an
|
||||||
|
issue where commits failed with the error message
|
||||||
|
Error unserializing profile objects failed to
|
||||||
|
handle CONFIG_UPDATE_START.
|
||||||
|
|
||||||
|
## PAN-222957
|
||||||
|
|
||||||
|
Fixed an issue where managed firewalls did not reflect changes pushed
|
||||||
|
by users that were not in a Superuser role.
|
||||||
|
|
||||||
|
## PAN-218107
|
||||||
|
|
||||||
|
Fixed an issue with ciphers used for SSH tunnels where packet lengths
|
||||||
|
were too large, which made the SSH tunnel unstable.
|
||||||
|
|
||||||
|
## PAN-214942
|
||||||
|
|
||||||
|
Fixed an issue where SD-WAN traffic failed over to a non-member path
|
||||||
|
after a flap of an SD-WAN virtual interface.
|
||||||
|
|
||||||
|
## PAN-204868
|
||||||
|
|
||||||
|
Fixed an issue where disk utilization was continuously high due to
|
||||||
|
the log purger not sufficiently reducing the utilization level.
|
||||||
@@ -0,0 +1,43 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.2-h3
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-238792
|
||||||
|
|
||||||
|
Fixed the following device certificate issues:
|
||||||
|
|
||||||
|
- The firewall was unable to automatically renew the device
|
||||||
|
certificate.
|
||||||
|
- Fetching device certificates failed incorrectly with the error
|
||||||
|
message OTP is not valid.
|
||||||
|
- Firewalls disconnected from Cortex Data Lake after renewing the
|
||||||
|
device certificate.
|
||||||
|
- The device certificate was not correctly generated on the log
|
||||||
|
forwarding card (LFC).
|
||||||
|
- WildFire cloud logs did not log thermite certificate usage
|
||||||
|
status.
|
||||||
|
|
||||||
|
## PAN-237876
|
||||||
|
|
||||||
|
Extended the firewall Panorama root CA certificate which was
|
||||||
|
previously set to expire on April 7th, 2024.
|
||||||
|
|
||||||
|
## PAN-231771
|
||||||
|
|
||||||
|
Fixed an issue where the firewall issued /box/getserv/ requests with
|
||||||
|
PAN-OS 7.1.0 and did not take device certificates.
|
||||||
|
|
||||||
|
## PAN-227568
|
||||||
|
|
||||||
|
When a device certificate is installed, renewed, or removed, the
|
||||||
|
firewall will reconnect to the WildFire cloud to use the newest
|
||||||
|
certificate.
|
||||||
|
|
||||||
|
## PAN-215576
|
||||||
|
|
||||||
|
Fixed an issue where the userID-Agent
|
||||||
|
and TS-Agent certificates were set to
|
||||||
|
expire on November 18, 2024. With this fix, the expiration date has
|
||||||
|
been extended to January 2032.
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.2-h4
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-252214
|
||||||
|
|
||||||
|
A fix was made to address CVE-2024-3400.
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.2-h5
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-272809
|
||||||
|
|
||||||
|
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and
|
||||||
|
CVE-2024-9474.
|
||||||
@@ -0,0 +1,473 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.2
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-231823
|
||||||
|
|
||||||
|
A fix was made to address CVE-2024-5916.
|
||||||
|
|
||||||
|
## PAN-221708
|
||||||
|
|
||||||
|
Fixed an issue where temporary files remained under /opt/pancfg/tmp/sw-images/ even after manually uploading the content or AV file to the firewall.
|
||||||
|
|
||||||
|
## PAN-221519
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the all_task process stopped responding due to DPDK driver compatibility issues.
|
||||||
|
|
||||||
|
## PAN-219686
|
||||||
|
|
||||||
|
Fixed an issue where a device group push operation from Panorama
|
||||||
|
failed with the following error on managed firewalls.
|
||||||
|
|
||||||
|
vsys -> vsys1 -> plugins unexpected
|
||||||
|
here
|
||||||
|
|
||||||
|
vsys is invalid
|
||||||
|
|
||||||
|
Commit failed
|
||||||
|
|
||||||
|
## PAN-218644
|
||||||
|
|
||||||
|
Fixed an issue where the firewall generated incorrect VSA attribute codes when radius was configured with EAP based authentication protocols.
|
||||||
|
|
||||||
|
## PAN-218335
|
||||||
|
|
||||||
|
Fixed an issue with hardware destination MAC filtering on the Log Processing Card (LPC) that caused the logging card interface to be susceptible to unicast flooding.
|
||||||
|
|
||||||
|
## PAN-218264
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3400 and PA-1400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where packet drops occurred due to slow servicing of internal hardware queries.
|
||||||
|
|
||||||
|
## PAN-217681
|
||||||
|
|
||||||
|
Fixed an issue caused by out of order TCP segments where the FIN flag and TCP data was truncated in a packet, which resulted in retransmission failure.
|
||||||
|
|
||||||
|
## PAN-217581
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not initiate scheduled log uploads to the FTP server.
|
||||||
|
|
||||||
|
## PAN-217493
|
||||||
|
|
||||||
|
Fixed an issue where superusers with read-only privileges were unable to view SCEP object configurations.
|
||||||
|
|
||||||
|
## PAN-217484
|
||||||
|
|
||||||
|
Fixed an issue where the rasmgr process used 100% CPU due to a maximum duration timer not being set, which caused the GlobalProtect gateway to be unavailable.
|
||||||
|
|
||||||
|
## PAN-217477
|
||||||
|
|
||||||
|
Fixed an issue where the drop counter was incremented incorrectly. Drop counter calculations did not account for failures to send out logs from logrcvr/logd to syslog-ng.
|
||||||
|
|
||||||
|
## PAN-217284
|
||||||
|
|
||||||
|
Fixed an intermittent issue where LACP flap occurred when the LACP transmission rate was set to Fast.
|
||||||
|
|
||||||
|
## PAN-216996
|
||||||
|
|
||||||
|
Fixed an issue where, after upgrading Panorama to PAN-OS 10.1.9, multiple User-ID alerts were generated every 10 minutes.
|
||||||
|
|
||||||
|
## PAN-216821
|
||||||
|
|
||||||
|
Fixed an issue where the reportd process stopped responding after upgrading an M-200
|
||||||
|
appliance to PAN-OS 11.0.1.
|
||||||
|
|
||||||
|
## PAN-216710
|
||||||
|
|
||||||
|
Fixed an issue with firewalls in active/active HA configurations where GlobalProtect disconnected when the original suspected Active-Primary firewall became Active-Secondary.
|
||||||
|
|
||||||
|
## PAN-216590
|
||||||
|
|
||||||
|
Fixed an issue where User-ID logs in Panorama displayed incorrect results for the filter not (ugflags has user-group-found).
|
||||||
|
|
||||||
|
## PAN-216360
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where No Default Selections under Push to Devices was intermittently deselected after performing a commit operation.
|
||||||
|
|
||||||
|
## PAN-216170
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-400 Series firewalls in HA configurations only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an
|
||||||
|
issue where an HA switchover took longer than expected to bring up ports
|
||||||
|
on the newly active firewall.
|
||||||
|
|
||||||
|
## PAN-216036
|
||||||
|
|
||||||
|
Fixed an issue where the all_pktproc process stopped responding, which caused the firewall to enter a nonfunctional state.
|
||||||
|
|
||||||
|
## PAN-215911
|
||||||
|
|
||||||
|
Fixed an issue that resulted in a race condition, which caused the configd process to stop responding.
|
||||||
|
|
||||||
|
## PAN-215899
|
||||||
|
|
||||||
|
Fixed an issue with Panorama appliances in high availability (HA) configurations where
|
||||||
|
configuration synchronization between the HA peers failed.
|
||||||
|
|
||||||
|
## PAN-215857
|
||||||
|
|
||||||
|
Fixed an issue where the option to reboot the entire firewall was visible to vsys admins.
|
||||||
|
|
||||||
|
## PAN-215808
|
||||||
|
|
||||||
|
Fixed an issue where after upgrading to PAN-OS 10.1, the log-forwarding rate towards the Syslog server was reduced. The overall log-forwarding rate has also been improved.
|
||||||
|
|
||||||
|
## PAN-215780
|
||||||
|
|
||||||
|
Fixed an issue where, changes to Zone Protection profiles made via XML API were not reflected in the Zone Protection configuration.
|
||||||
|
|
||||||
|
## PAN-215778
|
||||||
|
|
||||||
|
Fixed an issue where API Get requests for /config timed out due to insufficient buffer size.
|
||||||
|
|
||||||
|
## PAN-215503
|
||||||
|
|
||||||
|
Fixed a memory related issue where the MEMORY_POOL address was mapped incorrectly.
|
||||||
|
|
||||||
|
## PAN-215496
|
||||||
|
|
||||||
|
Fixed an issue where 100G ports did not come up with BIDI QSFP modules.
|
||||||
|
|
||||||
|
## PAN-215324
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5400 Series firewalls with Jumbo Frames enabled only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue with CPU throttling and buffer depletion.
|
||||||
|
|
||||||
|
## PAN-215315
|
||||||
|
|
||||||
|
Fixed an issue where the dataplane stopped responding due to ager and inline packet processing occurring concurrently on different cores for the same session.
|
||||||
|
|
||||||
|
## PAN-215125
|
||||||
|
|
||||||
|
Fixed an issue where false negatives occurred for some script samples.
|
||||||
|
|
||||||
|
## PAN-214925
|
||||||
|
|
||||||
|
Fixed an issue where temporary files remained in their temporary locations even after manually uploading the files to the firewall.
|
||||||
|
|
||||||
|
## PAN-214889
|
||||||
|
|
||||||
|
Fixed an issue where commits took longer than expected due to application dependency checks.
|
||||||
|
|
||||||
|
## PAN-214847
|
||||||
|
|
||||||
|
Fixed an issue where, when certificate authentication for admin user authentication was enabled, vulnerability scans that used usernames or passwords against the management interface reported a vulnerability due to a missing HSTS header in the Access Denied response page.
|
||||||
|
|
||||||
|
## PAN-214634
|
||||||
|
|
||||||
|
Fixed an issue where an elink parser did not work.
|
||||||
|
|
||||||
|
## PAN-214337
|
||||||
|
|
||||||
|
Fixed an issue on the firewall related to the gp_broker configuration transform that led to longer commit times.
|
||||||
|
|
||||||
|
## PAN-214187
|
||||||
|
|
||||||
|
Fixed an issue where superreaders were able to execute the request restart
|
||||||
|
system CLI command.
|
||||||
|
|
||||||
|
## PAN-214100
|
||||||
|
|
||||||
|
Fixed an issue where selecting a threat name under Threat Monitor displayed the threat ID instead of the threat name.
|
||||||
|
|
||||||
|
## PAN-214037
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5440, PA-5430, PA-5420, and PA-5410 firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where firewalls in active/active HA configurations experienced packet drop when running asymmetric traffic.
|
||||||
|
|
||||||
|
## PAN-214026
|
||||||
|
|
||||||
|
Fixed an issue where, when using an ECMP weighted-round-robin algorithm, traffic was not redistributed among the links proportionally as expected from the configuration.
|
||||||
|
|
||||||
|
## PAN-213942
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-400 Series firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall required an explicit allow rule to forward broadcast traffic.
|
||||||
|
|
||||||
|
## PAN-213932
|
||||||
|
|
||||||
|
Fixed an issue where, when an incorrect log filter was configured, the commit did not fail.
|
||||||
|
|
||||||
|
## PAN-213746
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where the Hostkey displayed as **undefined** if a SSH Service Profile
|
||||||
|
Hostkey configured in a Template from the Template Stack was
|
||||||
|
overridden.
|
||||||
|
|
||||||
|
## PAN-212848
|
||||||
|
|
||||||
|
Fixed an issue where attempting to change the disk-usage cleanup threshold to 90 resulted in the error message Server error : op command for client dagger timed out as client is not available.
|
||||||
|
|
||||||
|
## PAN-212726
|
||||||
|
|
||||||
|
Fixed an issue where RTP/RTCP packets were dropped for SIP calls by SIP ALG when the source NAT translation type was persistent Dynamic IP And Port.
|
||||||
|
|
||||||
|
## PAN-212530
|
||||||
|
|
||||||
|
Fixed an issue on log collectors where root partition reached 100% utilization.
|
||||||
|
|
||||||
|
## PAN-212409
|
||||||
|
|
||||||
|
Fixed an issue where there were duplicate IPSec Security Associations (SAs) for the same tunnel, gateway, or proxy ID.
|
||||||
|
|
||||||
|
## PAN-211997
|
||||||
|
|
||||||
|
Fixed an issue where large OSPF control packets were fragmented, which caused the neighborship to fail.
|
||||||
|
|
||||||
|
## PAN-211887
|
||||||
|
|
||||||
|
Fixed an issue on Panorama that caused recently committed changes to not be displayed when previewing the changes to push to device groups.
|
||||||
|
|
||||||
|
## PAN-211843
|
||||||
|
|
||||||
|
Fixed an issue where renaming a Zone Protection profile failed with the error message Obj does not exist.
|
||||||
|
|
||||||
|
## PAN-211602
|
||||||
|
|
||||||
|
Fixed an issue where, when viewing a WildFire Analysis Report via the web interface, the detailed log view was not accessible if the browser window was resized.
|
||||||
|
|
||||||
|
## PAN-211519
|
||||||
|
|
||||||
|
Fixed an issue where RTP/RTCP packets were dropped for SIP calls by SIP ALG when the source NAT translation type was persistent Dynamic IP And Port.
|
||||||
|
|
||||||
|
## PAN-211422
|
||||||
|
|
||||||
|
Fixed an issue where the show session packet-buffer-protection buffer-latency CLI command randomly displayed incorrect values.
|
||||||
|
|
||||||
|
## PAN-211242
|
||||||
|
|
||||||
|
Fixed an issue where missed heartbeats caused the Data Processing Card (DPC) and its corresponding Network Processing Card (NPC) to restart due to internal packet path monitoring failure.
|
||||||
|
|
||||||
|
## PAN-211041
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama virtual appliances only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where DHCP assigned interfaces did not send ICMP unreachable - Fragmentation needed messages when the received packets were higher than the maximum transmission unit (MTU).
|
||||||
|
|
||||||
|
## PAN-210921
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama appliances in Legacy Mode only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where Blocked Browsing Summary by Website in the user activity report contained scrambled characters.
|
||||||
|
|
||||||
|
## PAN-210919
|
||||||
|
|
||||||
|
Fixed an issue where the Data Processing Card remained in a Starting state after a restart.
|
||||||
|
|
||||||
|
## PAN-210875
|
||||||
|
|
||||||
|
Fixed an issue where the pan_task process stopped responding due to software packet buffer 3 trailer corruption, which caused the firewall to restart.
|
||||||
|
|
||||||
|
## PAN-210736
|
||||||
|
|
||||||
|
Fixed an issue where configuration changes related to the SSH service profile were not reflected when pushed from Panorama. With this fix, the deletion of ciphers, MAC, and kex fields of SSH server profiles and HA profiles won't clear the values under template stacks and will retain the values configured from templates.
|
||||||
|
|
||||||
|
## PAN-210661
|
||||||
|
|
||||||
|
Fixed an issue where firewalls disconnected from Cortex Data Lake after renewing the device certificate.
|
||||||
|
|
||||||
|
## PAN-210563
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where Security policy rules with a Tag target did not appear in the pre-rule list of a dynamic address group that was part of the tag.
|
||||||
|
|
||||||
|
## PAN-209898
|
||||||
|
|
||||||
|
Fixed an issue where the logrcvr process stopped due to memory corruption.
|
||||||
|
|
||||||
|
## PAN-209696
|
||||||
|
|
||||||
|
Fixed an issue where link-local address communication for IPv6, BFD, and OSPFv3 neighbors was dropped when IP address spoofing check was enabled in a Zone Protection profile.
|
||||||
|
|
||||||
|
## PAN-209683
|
||||||
|
|
||||||
|
Fixed an issue where Panorama was unable to retrieve IP address-to-username mapping from a firewall on a PAN-OS 8.1 release.
|
||||||
|
|
||||||
|
## PAN-209660
|
||||||
|
|
||||||
|
Fixed an issue where a selective push from Panorama to multiple firewalls failed due to a missing configuration file, which caused a communication error.
|
||||||
|
|
||||||
|
## PAN-209617
|
||||||
|
|
||||||
|
Fixed an issue with firewalls in active/passive HA configurations where the passive firewall created an incorrect SCTP association due to the HA sync messages from the active firewall having an incorrect value.
|
||||||
|
|
||||||
|
## PAN-209275
|
||||||
|
|
||||||
|
Fixed an issue where Override cookie authentication into the GlobalProtect gateway failed when an allow list was configured under the authentication profile.
|
||||||
|
|
||||||
|
## PAN-209021
|
||||||
|
|
||||||
|
Fixed an issue where packets were fragmented when SD-WAN VPN tunnel was configured on aggregate ethernet interfaces and sub-interfaces.
|
||||||
|
|
||||||
|
## PAN-208877
|
||||||
|
|
||||||
|
Fixed an issue where the all_task process stopped responding when freeing the HTTP2 stream, which caused the dataplane to go down.
|
||||||
|
|
||||||
|
## PAN-208737
|
||||||
|
|
||||||
|
Fixed an issue where domain information wasn't populated in IP address-to-username matching after a successful GlobalProtect authentication using an authentication override cookie.
|
||||||
|
|
||||||
|
## PAN-208325
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5400 Series, PA-3400 Series, and PA-400 Series only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall was unable to automatically renew the device certificate.
|
||||||
|
|
||||||
|
## PAN-208201
|
||||||
|
|
||||||
|
Fixed an issue on the firewall where the modified date and time was incorrectly updated after a commit operation, PAN-OS upgrade, or reboot.
|
||||||
|
|
||||||
|
## PAN-207842
|
||||||
|
|
||||||
|
Fixed an issue where WildFire Analysis Reports were not visible when the WF-500 appliance was on private cloud.
|
||||||
|
|
||||||
|
## PAN-207741
|
||||||
|
|
||||||
|
Fixed an issue where Large Scale VPN (LSVPN) Portal authentication failed with the error invalid http response. return error(Authentication failed; Retry authentication when the satellite connected to more than one portal.
|
||||||
|
|
||||||
|
## PAN-207700
|
||||||
|
|
||||||
|
Fixed an issue where the show system info and show system ztp status CLI commands displayed a different Zero Touch Provisioning (ZTP) status if a firewall upgrade was initiated from Panorama before the initial commit push succeeded.
|
||||||
|
|
||||||
|
## PAN-207562
|
||||||
|
|
||||||
|
Fixed an issue where the shard count displayed by the show log-collector-es-cluster health CLI command was higher than the recommended limit. The recommended limit can be calculated with the formula 20* heap-memory * no-of-data-nodes.
|
||||||
|
|
||||||
|
## PAN-206396
|
||||||
|
|
||||||
|
Fixed an issue where HIP report flip and HIP checks failed when a user was part of multiple user groups with different domains.
|
||||||
|
|
||||||
|
## PAN-206333
|
||||||
|
|
||||||
|
Fixed an issue where the Include/Exclude IP filter under Data Distribution did not work correctly.
|
||||||
|
|
||||||
|
## PAN-206253
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1400 Series and PA-3400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the default log rate was too low and the maximum configurable log rate was incorrectly capped, which caused the firewall to not generate logs at more than 6826 logs per second.
|
||||||
|
|
||||||
|
## PAN-205955
|
||||||
|
|
||||||
|
Fixed an issue where RAID rebuilds occurred even with healthy disks and a clean shutdown.
|
||||||
|
|
||||||
|
## PAN-205513
|
||||||
|
|
||||||
|
Fixed an issue where the stats dump file generated by Panorama for a device firewall differed from the stats dump file generated by the managed device.
|
||||||
|
|
||||||
|
## PAN-205086
|
||||||
|
|
||||||
|
Fixed an issue where DNS Security categories were able to be deleted from Spyware profiles.
|
||||||
|
|
||||||
|
## PAN-204838
|
||||||
|
|
||||||
|
Fixed an issue where the dot1q VLAN tag was missing in ARP reply packets.
|
||||||
|
|
||||||
|
## PAN-204718
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where, after upgrading to PAN-OS 10.1.6-h3, a TACACS user login displayed the following error message during the first login attempt: Could not chdir to home directory /opt/pancfg/home/user: Permission denied.
|
||||||
|
|
||||||
|
## PAN-204238
|
||||||
|
|
||||||
|
Fixed an issue where, when View Rulebase as Groups was enabled, the Tags field did not display a scroll down arrow for navigation.
|
||||||
|
|
||||||
|
## PAN-204068
|
||||||
|
|
||||||
|
Fixed an issue where a newly created vsys (virtual system) in a template was not able to be pushed from Panorama to the firewall.
|
||||||
|
|
||||||
|
## PAN-203330
|
||||||
|
|
||||||
|
Fixed an issue where the certificate for an External Dynamic List (EDL) incorrectly changed from invalid to valid, which caused the EDL file to be removed.
|
||||||
|
|
||||||
|
## PAN-202963
|
||||||
|
|
||||||
|
Fixed an issue where the system log message dsc HA state is changed from 1 to 0 was generated with the severity High. With this fix, the severity was changed to Info.
|
||||||
|
|
||||||
|
## PAN-202795
|
||||||
|
|
||||||
|
Fixed an issue where file identification failed with a large HTTP header.
|
||||||
|
|
||||||
|
## PAN-201721
|
||||||
|
|
||||||
|
Fixed an issue with firewalls in HA configurations where HA setup generated the error mismatch due to device update during a content update even though the version was the same.
|
||||||
|
|
||||||
|
## PAN-200019
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where Virtual Routers (Network > Virtual Routers) was not available when configuring a custom Panorama admin role (Panorama > Admin Roles).
|
||||||
|
|
||||||
|
## PAN-199557
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where virtual memory usage exceeded the set limit, which caused the configd process to restart.
|
||||||
|
|
||||||
|
## PAN-197121
|
||||||
|
|
||||||
|
Fixed an issue where incorrect user details were displayed under the USER DETAIL drop-down (ACC > Network activity > User activity).
|
||||||
|
|
||||||
|
## PAN-196309
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5450 firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where a firewall configured with a Policy-Based Forwarding policy flapped when a commit was performed, even when the next hop was reachable.
|
||||||
|
|
||||||
|
## PAN-195788
|
||||||
|
|
||||||
|
Fixed an issue where zip files did not download when applying Security inspection and the following error message displayed: resources-unavailable.
|
||||||
|
|
||||||
|
## PAN-195695
|
||||||
|
|
||||||
|
Fixed an issue where the AppScope Summary report and PDF report export function did not work as expected.
|
||||||
|
|
||||||
|
## PAN-192456
|
||||||
|
|
||||||
|
Fixed an issue where GlobalProtect SSL VPN processing during a high traffic load caused the dataplane to stop responding.
|
||||||
|
|
||||||
|
## PAN-189666
|
||||||
|
|
||||||
|
Fixed an issue where GlobalProtect portal connections failed after random commits when multiple agent configurations were provisioned and configuration selection criteria using certificate profile was used.
|
||||||
|
|
||||||
|
## PAN-187763
|
||||||
|
|
||||||
|
Fixed an issue where DNS Security logs did not display a threat category, threat name, or threat ID when domain names contained 64 or more characters.
|
||||||
|
|
||||||
|
## PAN-187279
|
||||||
|
|
||||||
|
Fixed an issue where not all quarantined devices were displayed as expected.
|
||||||
|
|
||||||
|
## PAN-184630
|
||||||
|
|
||||||
|
Fixed an issue where TLS clients, such as those using OpenSSL 3.0,
|
||||||
|
enforced the TLS renegotiation extension (RFC 5746).
|
||||||
@@ -0,0 +1,46 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.3-h10
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-252214
|
||||||
|
|
||||||
|
A fix was made to address CVE-2024-3400.
|
||||||
|
|
||||||
|
## PAN-246707
|
||||||
|
|
||||||
|
Fixed an issue where failover was not triggered when multiple
|
||||||
|
processes stopped responding.
|
||||||
|
|
||||||
|
## PAN-244493
|
||||||
|
|
||||||
|
Fixed a memory limitation with mapping subinterfaces to VPCE
|
||||||
|
endpoints for GCP IPS, Amazon Web Services (AWS) integration with
|
||||||
|
GWLB, and NSX service chain mapping.
|
||||||
|
|
||||||
|
## PAN-240347
|
||||||
|
|
||||||
|
Fixed an issue with the web interface where the
|
||||||
|
Dashboard and a Device
|
||||||
|
Group policy rule took longer than expected to
|
||||||
|
load.
|
||||||
|
|
||||||
|
## PAN-240166
|
||||||
|
|
||||||
|
Fixed an issue where, when explicit proxy was configured on the
|
||||||
|
firewall, websites loaded more slowly than expected or did not load
|
||||||
|
due to DNS using TCP.
|
||||||
|
|
||||||
|
## PAN-239279
|
||||||
|
|
||||||
|
Fixed an issue related to web proxy where the masterd
|
||||||
|
process monitoring envoy process memory restarted when it reached an
|
||||||
|
unexpected limit.
|
||||||
|
|
||||||
|
## PAN-230746
|
||||||
|
|
||||||
|
Fixed an issue on the web interface where device groups with a large
|
||||||
|
number of managed firewalls displayed the
|
||||||
|
Policy page more slowly than
|
||||||
|
expected.
|
||||||
@@ -0,0 +1,40 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.3-h12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-253317
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls on Microsoft Azure environments only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to log in to the firewall after
|
||||||
|
a private data reset.
|
||||||
|
|
||||||
|
## PAN-246960
|
||||||
|
|
||||||
|
Fixed an issue where firewalls failed to fetch content updates from
|
||||||
|
the Wildfire Private Cloud due to an Unsupported
|
||||||
|
protocol error.
|
||||||
|
|
||||||
|
## PAN-244648
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 Series only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did
|
||||||
|
not boot up after a factory reset, and, with FIPS mode enabled, the
|
||||||
|
firewall rebooted into maintenance mode.
|
||||||
|
|
||||||
|
## PAN-238769
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls in FIPS-CC mode only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue
|
||||||
|
where upgrading Panorama caused all locally created Security policy rule
|
||||||
|
actions to Deny.
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.3-h13
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-272809
|
||||||
|
|
||||||
|
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and
|
||||||
|
CVE-2024-9474.
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.3-h1
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-237871
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
WF-500 appliances and PAN-DB private cloud deployments only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the
|
||||||
|
root-cert was set to expire on
|
||||||
|
December 31, 2023. With this fix, the expiration date has been
|
||||||
|
extended.
|
||||||
@@ -0,0 +1,91 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.3-h3
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-239769
|
||||||
|
|
||||||
|
Fixed an issue where object references in a rule were renamed, and
|
||||||
|
while doing a selective revert of the changes with Commit
|
||||||
|
changes by me caused a reference error.
|
||||||
|
|
||||||
|
## PAN-237876
|
||||||
|
|
||||||
|
Extended the firewall Panorama root CA certificate which was
|
||||||
|
previously set to expire on April 7th, 2024.
|
||||||
|
|
||||||
|
## PAN-235476
|
||||||
|
|
||||||
|
Fixed an issue where threat logs from different Security zones were
|
||||||
|
aggregated into one log.
|
||||||
|
|
||||||
|
## PAN-233039
|
||||||
|
|
||||||
|
Fixed an issue where GENEVE encapsulated packets coming from a GFE
|
||||||
|
Proxy mapped to an incorrect Security policy rule.
|
||||||
|
|
||||||
|
## PAN-231507
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-1400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where, when
|
||||||
|
an HSCI interface was used as an HA2 interface, HA2 packets were
|
||||||
|
intermittently dropped on the passive firewall, which caused the HA2
|
||||||
|
connection to flap due to missing HA2 keepalive messages.
|
||||||
|
|
||||||
|
## PAN-230092
|
||||||
|
|
||||||
|
Fixed an issue where the routed process stopped
|
||||||
|
responding when committing routing-related changes if Advanced
|
||||||
|
routing was enabled.
|
||||||
|
|
||||||
|
## PAN-227568
|
||||||
|
|
||||||
|
When a device certificate is installed, renewed, or removed, the
|
||||||
|
firewall will reconnect to the WildFire cloud to use the newest
|
||||||
|
certificate.
|
||||||
|
|
||||||
|
## PAN-227064
|
||||||
|
|
||||||
|
Fixed an issue with high availability (HA) sync failure when
|
||||||
|
performing a partial commit after creating a Security policy via
|
||||||
|
REST API.
|
||||||
|
|
||||||
|
## PAN-226792
|
||||||
|
|
||||||
|
Fixed an issue where the logrcvr process stored older
|
||||||
|
content versions in the shared memory even when newer content
|
||||||
|
updates were installed.
|
||||||
|
|
||||||
|
## PAN-225886
|
||||||
|
|
||||||
|
Fixed an issue where, when explicit proxy mode was enabled for the
|
||||||
|
web proxy, intermittent errors and unexpected TCP reconnections
|
||||||
|
occurred.
|
||||||
|
|
||||||
|
## PAN-218620
|
||||||
|
|
||||||
|
Fixed an issue where scheduled configuration exports and SCP server
|
||||||
|
connection testing failed.
|
||||||
|
|
||||||
|
## PAN-215576
|
||||||
|
|
||||||
|
Fixed an issue where the userID-Agent
|
||||||
|
and TS-Agent certificates were set to
|
||||||
|
expire on November 18, 2024. With this fix, the expiration date has
|
||||||
|
been extended to January 2032.
|
||||||
|
|
||||||
|
## PAN-202361
|
||||||
|
|
||||||
|
Fixed an issue where packets queued to the pan_task
|
||||||
|
process were still transmitted when the process was not
|
||||||
|
responding.
|
||||||
|
|
||||||
|
## PAN-193004
|
||||||
|
|
||||||
|
Fixed an issue where /opt/pancfg
|
||||||
|
partition utilization reached 100%, which caused access to the
|
||||||
|
Panorama web interface to fail.
|
||||||
@@ -0,0 +1,153 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.3-h5
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-242561
|
||||||
|
|
||||||
|
Fixed an issue where GlobalProtect tunnels disconnected shortly after
|
||||||
|
being established when SSL was used as the transfer protocol.
|
||||||
|
|
||||||
|
## PAN-241772
|
||||||
|
|
||||||
|
Fixed an issue where, when TLSv1.3 was used, an incorrect error
|
||||||
|
message invalid padding was displayed
|
||||||
|
instead of the expected error message Invalid server
|
||||||
|
certificate.
|
||||||
|
|
||||||
|
## PAN-240786
|
||||||
|
|
||||||
|
Fixed an issue on firewalls in HA configurations where VXLAN sessions
|
||||||
|
were allocated, but not installed or freed, which resulted in a
|
||||||
|
constant high session table usage that was not synced between the
|
||||||
|
firewalls. This resulted in a session count mismatch.
|
||||||
|
|
||||||
|
## PAN-240487
|
||||||
|
|
||||||
|
Fixed an issue where fan speed increased significantly after
|
||||||
|
upgrading the firewall.
|
||||||
|
|
||||||
|
## PAN-240197
|
||||||
|
|
||||||
|
Fixed an issue where configuration changes made in Panorama and
|
||||||
|
pushed to the firewall were not reflected on the firewall.
|
||||||
|
|
||||||
|
## PAN-238996
|
||||||
|
|
||||||
|
Fixed an issue where commits did not complete and remained in a
|
||||||
|
pending state due to a race condition. With this fix, the commit
|
||||||
|
will fail after 60 seconds and not remain in a pending state.
|
||||||
|
|
||||||
|
## PAN-238769
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls in FIPS-CC mode only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue
|
||||||
|
where upgrading Panorama caused all locally created Security policy
|
||||||
|
rule actions to Deny.
|
||||||
|
|
||||||
|
## PAN-236120
|
||||||
|
|
||||||
|
Fixed an issue where the /opt/panlogs partition reached capacity due
|
||||||
|
to the logdb-quota for the User-ID log folder not being matched.
|
||||||
|
|
||||||
|
## PAN-234929
|
||||||
|
|
||||||
|
Fixed an issue where tabs in the ACC such as
|
||||||
|
Network Activity
|
||||||
|
Threat Activity and Blocked
|
||||||
|
Activity did not display data when you applied a
|
||||||
|
Time filter of Last 15
|
||||||
|
Minutes, Last Hour,
|
||||||
|
Last 6 Hours, or Last 12
|
||||||
|
Hours, and the data that was displayed with the
|
||||||
|
Last 24 Hours filter was not accurate.
|
||||||
|
Reports that were run against summary logs also did not display
|
||||||
|
accurate results.
|
||||||
|
|
||||||
|
## PAN-232800
|
||||||
|
|
||||||
|
Fixed an issue where critical disk usage for /opt/pancfg increased
|
||||||
|
continuously and the system logs displayed the following message:
|
||||||
|
Disk usage for /opt/pancfg exceeds limit,
|
||||||
|
<value> percent in use.
|
||||||
|
|
||||||
|
## PAN-231802
|
||||||
|
|
||||||
|
Fixed an issue where an Advanced Routing BGP session flapped with
|
||||||
|
commits when BGP peer authentication was enabled.
|
||||||
|
|
||||||
|
## PAN-230746
|
||||||
|
|
||||||
|
Fixed an issue on the web interface where device groups with a large
|
||||||
|
number of managed firewalls displayed the
|
||||||
|
Policy page more slowly than
|
||||||
|
expected.
|
||||||
|
|
||||||
|
## PAN-229691
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where configuration lock timeout errors
|
||||||
|
were observed during normal operational commands by increasing
|
||||||
|
thread stack size on Panorama.
|
||||||
|
|
||||||
|
## PAN-228515
|
||||||
|
|
||||||
|
Fixed an issue where the Elasticsearch cluster health status
|
||||||
|
displayed as yellow or red due to Elasticsearch SSH tunnel
|
||||||
|
flaps.
|
||||||
|
|
||||||
|
## PAN-228187
|
||||||
|
|
||||||
|
Fixed an issue where the management server restarted due to the
|
||||||
|
virtual memory exceeding the limit.
|
||||||
|
|
||||||
|
## PAN-227397
|
||||||
|
|
||||||
|
Fixed an issue where selective pushes on Panorama removed a
|
||||||
|
previously pushed configuration from the firewalls.
|
||||||
|
|
||||||
|
## PAN-227368
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect app was unable to connect to a
|
||||||
|
portal or gateway and GlobalProtect Clientless VPN users were unable
|
||||||
|
to access applications if authentication took more than 20
|
||||||
|
seconds.
|
||||||
|
|
||||||
|
## PAN-223798
|
||||||
|
|
||||||
|
Fixed an issue on the firewall where, when Advanced Routing was
|
||||||
|
enabled, PIM join messages were not sent to the RN due to a missing
|
||||||
|
OIF.
|
||||||
|
|
||||||
|
## PAN-223259
|
||||||
|
|
||||||
|
Fixed an issue where selective pushes failed with the error message
|
||||||
|
Failed to generate selective push configuration.
|
||||||
|
Unable to retrieve last in-sync configuration for the device,
|
||||||
|
either a push was never done or version is too old. Please try a
|
||||||
|
full push.
|
||||||
|
|
||||||
|
## PAN-220907
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where large
|
||||||
|
packets were dropped from the dataplane to the management plane,
|
||||||
|
which caused OSPF neighborship to fail.
|
||||||
|
|
||||||
|
## PAN-220659
|
||||||
|
|
||||||
|
Fixed an issue on the firewall where scheduled Antivirus updates
|
||||||
|
failed when external dynamic lists were configured on the
|
||||||
|
firewall.
|
||||||
|
|
||||||
|
## PAN-218928
|
||||||
|
|
||||||
|
Fixed an issue where the reportd process stopped
|
||||||
|
responding after querying logs or generating ACC reports with some
|
||||||
|
filters.
|
||||||
@@ -0,0 +1,642 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.3
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-231823
|
||||||
|
|
||||||
|
A fix was made to address CVE-2024-5916.
|
||||||
|
|
||||||
|
## PAN-233954
|
||||||
|
|
||||||
|
Fixed an issue where the firewall was unable to retrieve correct groups from the LDAP server.
|
||||||
|
|
||||||
|
## PAN-232059
|
||||||
|
|
||||||
|
Fixed an issue with memory management when processing large certificates using TLSv1.3.
|
||||||
|
|
||||||
|
## PAN-229691
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where configuration lock timeout errors were observed during normal operational commands by increasing thread stack size on Panorama.
|
||||||
|
|
||||||
|
## PAN-228877
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7050 firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue with OOM conditions which caused slot restarts
|
||||||
|
due to pan_cmd consuming more than 300
|
||||||
|
MB.
|
||||||
|
|
||||||
|
## PAN-227639
|
||||||
|
|
||||||
|
Fixed an issue where the ACC displayed an incorrect DNS-base application traffic byte count.
|
||||||
|
|
||||||
|
## PAN-227376
|
||||||
|
|
||||||
|
Fixed an issue where a memory overrun caused the all_task process to stop responding.
|
||||||
|
|
||||||
|
## PAN-227179
|
||||||
|
|
||||||
|
Fixed an issue where routes were not updated in the forwarding table.
|
||||||
|
|
||||||
|
## PAN-226418
|
||||||
|
|
||||||
|
A CLI command was added to address an issue where long-lived sessions aged out even when there was ongoing traffic.
|
||||||
|
|
||||||
|
## PAN-226198
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where the configd process repeatedly restarted when attempting to make configuration changes.
|
||||||
|
|
||||||
|
## PAN-225920
|
||||||
|
|
||||||
|
Fixed an issue where duplicate predict sessions didn't release NAT resources.
|
||||||
|
|
||||||
|
## PAN-225183
|
||||||
|
|
||||||
|
Fixed an issue where SSH tunnels were unstable due to ciphers used as part of the high availability SSH configuration.
|
||||||
|
|
||||||
|
## PAN-225169
|
||||||
|
|
||||||
|
Added a CLI command to view Cortex Data Lake queue usage.
|
||||||
|
|
||||||
|
## PAN-224145
|
||||||
|
|
||||||
|
Fixed an issue in multi-vsys environments where, when Panorama was on a PAN-OS 10.2 release and the firewall was on a PAN-OS 10.1 release, commits failed on the firewall when inbound inspection mode was configured in the decryption policy rule.
|
||||||
|
|
||||||
|
## PAN-223852
|
||||||
|
|
||||||
|
Fixed an issue where all_pktproc stopped responding when network packet broker or decryption broker chains failed.
|
||||||
|
|
||||||
|
## PAN-223741
|
||||||
|
|
||||||
|
Fixed an issue where the mprelay process stopped responding, which caused a slot restart when another slot rebooted.
|
||||||
|
|
||||||
|
## PAN-223501
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 Series and PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where diagnostic information for the dataplane in the dp-monitor.log file was not complete.
|
||||||
|
|
||||||
|
## PAN-223488
|
||||||
|
|
||||||
|
Fixed an issue where closed ElasticSearch shards were not deleted, which resulted in shard
|
||||||
|
purging not working as expected.
|
||||||
|
|
||||||
|
## PAN-223457
|
||||||
|
|
||||||
|
Fixed an issue where, if the number of group queries exceeded the Okta rate limit threshold, the firewall cleared the cache for the groups.
|
||||||
|
|
||||||
|
## PAN-223317
|
||||||
|
|
||||||
|
Fixed an issue where SSL traffic failed with the error message: Error: General TLS protocol error.
|
||||||
|
|
||||||
|
## PAN-223185
|
||||||
|
|
||||||
|
Fixed an issue where the distributord process stopped responding.
|
||||||
|
|
||||||
|
## PAN-222957
|
||||||
|
|
||||||
|
Fixed an issue where managed firewalls did not reflect changes pushed by users who were not in a
|
||||||
|
superuser role.
|
||||||
|
|
||||||
|
## PAN-222941
|
||||||
|
|
||||||
|
Fixed an issue where viewing the latest logs took longer than expected due to log indexer failures.
|
||||||
|
|
||||||
|
## PAN-222533
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls on Microsoft Azure and Amazon Web Services (AWS) environments
|
||||||
|
```
|
||||||
|
|
||||||
|
Added support for high availability (HA) link monitoring and path monitoring.
|
||||||
|
|
||||||
|
## PAN-222418
|
||||||
|
|
||||||
|
Fixed an issue where the firewall intermittently recorded a reconnection message to the authentication server as an error, even if no disconnection occurred.
|
||||||
|
|
||||||
|
## PAN-222162
|
||||||
|
|
||||||
|
Fixed an issue where the show transceiver <interface> CLI command
|
||||||
|
showed the RX and TX powers as 0.00 mW.
|
||||||
|
|
||||||
|
## PAN-221984
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls in Microsoft Azure environments only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where an interface went down after a hotplug event and was only recoverable by restarting the firewall.
|
||||||
|
|
||||||
|
## PAN-221836
|
||||||
|
|
||||||
|
Fixed an issue where improper SNI detection caused incorrect URL categorization.
|
||||||
|
|
||||||
|
## PAN-221787
|
||||||
|
|
||||||
|
Fixed an issue where a User Principal Name (UPN) was incorrectly required in the pre-logon machine certificate.
|
||||||
|
|
||||||
|
## PAN-221647
|
||||||
|
|
||||||
|
Fixed an issue where the Apps seen value was not reflected on Panorama.
|
||||||
|
|
||||||
|
## PAN-221577
|
||||||
|
|
||||||
|
Fixed an issue where a static route for a branch or hub over the respective virtual interface was not installed in the routing table even when the tunnel to the branch or hub was active.
|
||||||
|
|
||||||
|
## PAN-221208
|
||||||
|
|
||||||
|
Fixed an issue where the tunnel monitor was unable to remain up when zone protection with Strict
|
||||||
|
IP was enabled and NAT Traversal was applied.
|
||||||
|
|
||||||
|
## PAN-221126
|
||||||
|
|
||||||
|
Fixed an issue where Email server profiles (Device > Server Profiles > Email and
|
||||||
|
Panorama > Server Profiles > Email) to forward
|
||||||
|
logs as email notifications were not forwarded in a readable
|
||||||
|
format.
|
||||||
|
|
||||||
|
## PAN-220910
|
||||||
|
|
||||||
|
Fixed an issue where an internal management plane NIC caused a kernel panic when doing a transmit due to the driver reinitializing under certain failure or change conditions on the same interface during transmit.
|
||||||
|
|
||||||
|
## PAN-220899
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to choose the manual GlobalProtect gateway.
|
||||||
|
|
||||||
|
## PAN-220747
|
||||||
|
|
||||||
|
Fixed an issue where logs were not visible after restarting the log collector.
|
||||||
|
|
||||||
|
## PAN-220626
|
||||||
|
|
||||||
|
Fixed an issue where system warning logs were written every 24 hours.
|
||||||
|
|
||||||
|
## PAN-220448
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect client connection remained at the prelogin stage when
|
||||||
|
Kerberos SSO failed and was unable to fall back to the realm
|
||||||
|
authentication.
|
||||||
|
|
||||||
|
## PAN-220401
|
||||||
|
|
||||||
|
Fixed an issue where, during a reboot, an unexpected error message was displayed that the syslog configuration file format was too old.
|
||||||
|
|
||||||
|
## PAN-220281
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7080 firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where autocommitting changes after rebooting the
|
||||||
|
Log Forwarding Card (LFC) caused the logrcvr process to
|
||||||
|
fail to read the configuration file.
|
||||||
|
|
||||||
|
## PAN-220180
|
||||||
|
|
||||||
|
Fixed an issue where configured botnet reports (Monitor > Botnet) were not generated.
|
||||||
|
|
||||||
|
## PAN-219813
|
||||||
|
|
||||||
|
Fixed an issue where the configuration log displayed incorrect information after a multidevice
|
||||||
|
group Validate-all operation.
|
||||||
|
|
||||||
|
## PAN-219659
|
||||||
|
|
||||||
|
Fixed an issue where root partition frequently filled up and the following error message was displayed: Disk usage for / exceeds limit, xx percent in use, cleaning filesystem.
|
||||||
|
|
||||||
|
## PAN-219644
|
||||||
|
|
||||||
|
Fixed an issue where firewalls that forwarded logs to a syslog server over TLS (Objects > Log Forwarding) used the default Palo Alto Networks certificate instead of the configured custom certificate.
|
||||||
|
|
||||||
|
## PAN-219623
|
||||||
|
|
||||||
|
Fixed an issue where, when a multidynamic group validate job was pushed on the firewall, logs
|
||||||
|
displayed Panorama push instead of
|
||||||
|
ValidateAll push.
|
||||||
|
|
||||||
|
## PAN-219498
|
||||||
|
|
||||||
|
Fixed an issue where the Threat ID/Name detail in Threat logs was not
|
||||||
|
included in syslog messages sent to Splunk.
|
||||||
|
|
||||||
|
## PAN-219300
|
||||||
|
|
||||||
|
Fixed an issue where the task manager displayed only limited data.
|
||||||
|
|
||||||
|
## PAN-219253
|
||||||
|
|
||||||
|
Fixed an issue where, after making changes in a template, the Commit and Push option was grayed out.
|
||||||
|
|
||||||
|
## PAN-218988
|
||||||
|
|
||||||
|
Fixed an issue in FIPS mode where, when importing a certificate with a new private key, and the certificate used the name of an existing certificate on the Panorama, the following error message was displayed: Mismatched public and private keys.
|
||||||
|
|
||||||
|
## PAN-218947
|
||||||
|
|
||||||
|
Fixed an issue where logs were not displayed in Elasticsearch under ingestion load.
|
||||||
|
|
||||||
|
## PAN-218697
|
||||||
|
|
||||||
|
Fixed an issue where the ElasticSearch status frequently changed to red or yellow after a PAN-OS upgrade.
|
||||||
|
|
||||||
|
## PAN-218663
|
||||||
|
|
||||||
|
A fix was made to address CVE-2024-2433
|
||||||
|
|
||||||
|
## PAN-218404
|
||||||
|
|
||||||
|
Fixed an issue where ikemgr stopped responding due to receiving CREATE_CHILD messages with a malformed SA payload.
|
||||||
|
|
||||||
|
## PAN-218340
|
||||||
|
|
||||||
|
Fixed an issue where selective pushes to template stack and multi device group pushes caused a buildup of resident memory, which caused the configd process to stop responding.
|
||||||
|
|
||||||
|
## PAN-218318
|
||||||
|
|
||||||
|
Fixed an issue where the firewall changed the time zone automatically instead of retrieving the correct time zone from the NTP server.
|
||||||
|
|
||||||
|
## PAN-218273
|
||||||
|
|
||||||
|
Fixed an issue where TCP keepalive packets from the client to the server weren't forwarded when SSL decryption was enabled.
|
||||||
|
|
||||||
|
## PAN-218267
|
||||||
|
|
||||||
|
Fixed an issue where a commit and push operation from Panorama to managed firewalls did not complete or took longer to complete than expected.
|
||||||
|
|
||||||
|
## PAN-218252
|
||||||
|
|
||||||
|
Fixed an issue where the slot-1 data processor showed the status as down during an SNMP
|
||||||
|
query.
|
||||||
|
|
||||||
|
## PAN-218107
|
||||||
|
|
||||||
|
Fixed an issue with ciphers used for SSH tunnels where packet lengths were too large, which made the SSH tunnel unstable.
|
||||||
|
|
||||||
|
## PAN-218046
|
||||||
|
|
||||||
|
Fixed an issue where the Virtual Routers (Network > Virtual Routers) setting was not available when configuring a custom admin role (Device > Admin Roles).
|
||||||
|
|
||||||
|
## PAN-218001
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where shutdown commands rebooted the system instead of correctly triggering a shutdown.
|
||||||
|
|
||||||
|
## PAN-217650
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls and Panorama virtual appliances in Microsoft Azure environments only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where management interface
|
||||||
|
Speed/Duplex was reported as unknown.
|
||||||
|
|
||||||
|
## PAN-217493
|
||||||
|
|
||||||
|
Fixed an issue where superusers with read-only privileges were unable to view SCEP object configurations.
|
||||||
|
|
||||||
|
## PAN-217169
|
||||||
|
|
||||||
|
Fixed an issue where the logrcvr stopped forwarding logs to the syslog server after a restart.
|
||||||
|
|
||||||
|
## PAN-217053
|
||||||
|
|
||||||
|
Fixed an issue where the configd process stopped responding after a selective push to multiple device groups failed.
|
||||||
|
|
||||||
|
## PAN-216957
|
||||||
|
|
||||||
|
Fixed an issue where allow list checks in an authentication profile did not work if the group
|
||||||
|
Distinguished Name contains the ampersand ( & ) character.
|
||||||
|
|
||||||
|
## PAN-216775
|
||||||
|
|
||||||
|
Fixed an issue where the devsrvr process stopped responding at pan_cloud_agent_get_curl_connection() and the URL cloud could not be connected.
|
||||||
|
|
||||||
|
## PAN-216366
|
||||||
|
|
||||||
|
Fixed an issue where, when custom signatures used a certain syntax, false positives were generated on devices on a PAN-OS 10.0 release.
|
||||||
|
|
||||||
|
## PAN-216214
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama managed firewalls in active/active HA configurations only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the HA status displayed as Out of Sync (Panorama > Managed Devices > Health) if local firewall configurations were made on one of the HA peers. This caused the next HA configuration sync to overwrite the local firewall configuration made on the HA peer.
|
||||||
|
|
||||||
|
## PAN-216048
|
||||||
|
|
||||||
|
Fixed an issue where, when upgrading from a PAN-OS 9.1 release to a PAN-OS 10.0 release, commits failed with the error message: hip profiles unexpected here.
|
||||||
|
|
||||||
|
## PAN-215767
|
||||||
|
|
||||||
|
Fixed an issue where, after a high availability failover, IKE SA negotiation failed with the error message INVALID_SPI, which resulted in temporary loss of traffic over some proxy IDs.
|
||||||
|
|
||||||
|
## PAN-215655
|
||||||
|
|
||||||
|
Fixed an issue where, after a multidynamic group push, Security policy rules with the target
|
||||||
|
device tag were added to a firewall that did not have the tag.
|
||||||
|
|
||||||
|
## PAN-215338
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the inner VLAN tag for Q-in-Q traffic was stripped when forwarding.
|
||||||
|
|
||||||
|
## PAN-215317
|
||||||
|
|
||||||
|
Fixed an issue where the dataplane stopped responding unexpectedly with the error message comm exited with signal of 10.
|
||||||
|
|
||||||
|
## PAN-215066
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where push scope rendering caused the Commit and Push or Push to Devices operation window to hang for several minutes.
|
||||||
|
|
||||||
|
## PAN-214990
|
||||||
|
|
||||||
|
Fixed an issue where firewall copper ports flapped intermittently when device telemetry was enabled.
|
||||||
|
|
||||||
|
## PAN-214987
|
||||||
|
|
||||||
|
Fixed an issue where Application Filter names were not random, and they matched or included internal protocol names.
|
||||||
|
|
||||||
|
## PAN-214815
|
||||||
|
|
||||||
|
Fixed an issue where SNMP queries were not replied to due to an internal process timeout.
|
||||||
|
|
||||||
|
## PAN-214727
|
||||||
|
|
||||||
|
Fixed an issue where a memory leak related to the useridd process resulted in an OOM
|
||||||
|
condition, which caused the process to stop responding.
|
||||||
|
|
||||||
|
## PAN-214669
|
||||||
|
|
||||||
|
Fixed an issue where FIN and RESET packets were sent in reverse order.
|
||||||
|
|
||||||
|
## PAN-214463
|
||||||
|
|
||||||
|
Fixed an issue where IKE re-key negotiation failed with a third-party vendor and the firewall
|
||||||
|
acting as the initiator received a response with the VENDOR_ID
|
||||||
|
payload and the error message unexpected critical
|
||||||
|
payload (type 43).
|
||||||
|
|
||||||
|
## PAN-214201
|
||||||
|
|
||||||
|
Fixed an issue where, after exporting custom reports to CSV format, the letter b appeared at the beginning of each column.
|
||||||
|
|
||||||
|
## PAN-214186
|
||||||
|
|
||||||
|
Fixed an issue where category length was incorrect, which caused the
|
||||||
|
dataplane to restart.
|
||||||
|
|
||||||
|
## PAN-213956
|
||||||
|
|
||||||
|
Fixed an issue where the firewall interface did not go down even after the peer link/switch port went down.
|
||||||
|
|
||||||
|
## PAN-213931
|
||||||
|
|
||||||
|
Fixed an issue where the logrcvr process cache was not in sync with the mapping on the firewall.
|
||||||
|
|
||||||
|
## PAN-213296
|
||||||
|
|
||||||
|
Fixed an issue where Single Log-out (SLO) was not correctly triggered from the firewall toward
|
||||||
|
the client, which caused the client to not initiate the SLO request
|
||||||
|
toward the identity provider (IdP). This resulted in the IdP not
|
||||||
|
making the SLO callback to the firewall to remove the user.
|
||||||
|
|
||||||
|
## PAN-213162
|
||||||
|
|
||||||
|
Fixed an issue where an SD-WAN object was not displayed under a child device group.
|
||||||
|
|
||||||
|
## PAN-213112
|
||||||
|
|
||||||
|
Fixed an issue where executing the show report directory-listing CLI command resulted in no output after upgrading to a PAN-OS 10.1 release.
|
||||||
|
|
||||||
|
## PAN-212978
|
||||||
|
|
||||||
|
Fixed an issue where the firewall stopped responding when executing an SD-WAN debug CLI
|
||||||
|
command.
|
||||||
|
|
||||||
|
## PAN-212726
|
||||||
|
|
||||||
|
Fixed an issue where RTP/RTCP packets were dropped for SIP calls by SIP ALG when the source NAT translation type was persistent Dynamic IP And Port.
|
||||||
|
|
||||||
|
## PAN-212577
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 Series and PA-7080 firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where commits took longer than expected when more than 45,000 Security policy rules were configured.
|
||||||
|
|
||||||
|
## PAN-212240
|
||||||
|
|
||||||
|
Fixed an issue where packet capture was logged for an unknown application session when packet capture logging was disabled.
|
||||||
|
|
||||||
|
## PAN-212057
|
||||||
|
|
||||||
|
Fixed an issue where Advanced Threat Prevention caused SSL delays when no URL licenses were present.
|
||||||
|
|
||||||
|
## PAN-211441
|
||||||
|
|
||||||
|
Fixed a memory leak issue related to SSL crypto operations that resulted in failed commits.
|
||||||
|
|
||||||
|
## PAN-211398
|
||||||
|
|
||||||
|
Fixed an issue where dataplane processes stopped responding when handling HTTP/2 streams.
|
||||||
|
|
||||||
|
## PAN-211384
|
||||||
|
|
||||||
|
Fixed an issue where the size of the redisthost_1 in the Redis database continuously increased, which caused an OOM condition.
|
||||||
|
|
||||||
|
## PAN-210640
|
||||||
|
|
||||||
|
Fixed an issue where applications were not displayed after authenticating into the clientless VPN.
|
||||||
|
|
||||||
|
## PAN-210502
|
||||||
|
|
||||||
|
Fixed an issue where Panorama was unable to convert to PAN-OS 9.1 syntax for WF-500
|
||||||
|
appliances.
|
||||||
|
|
||||||
|
## PAN-210456
|
||||||
|
|
||||||
|
Fixed an issue where high latency occurred on PA-850-ZTP when SSL decryption was enabled.
|
||||||
|
|
||||||
|
## PAN-210452
|
||||||
|
|
||||||
|
Fixed an issue where application packet capture (pcap) was not generated when Security policy
|
||||||
|
rules were used as a filter.
|
||||||
|
|
||||||
|
## PAN-210429
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the HTTP service failed to come up on DHCP dataplane interfaces after rebooting the firewall, which resulted in health-check failure on HTTP/80 with a 503 error code on the public load balancer.
|
||||||
|
|
||||||
|
## PAN-210364
|
||||||
|
|
||||||
|
Fixed an issue where high latency was observed when accessing internal web applications, which interrupted development activities related to the web server.
|
||||||
|
|
||||||
|
## PAN-209585
|
||||||
|
|
||||||
|
The Palo Alto Networks QoS implementation now supports a new QoS mode called lockless QoS for PA-3400, PA-5410, PA-5420, PA-5430, and PA-5440 firewalls. For firewalls with higher bandwidth QoS requirements, the lockless QoS dedicates cores to the QoS function that improves QoS performance, resulting in improved throughput and latency.
|
||||||
|
|
||||||
|
## PAN-209375
|
||||||
|
|
||||||
|
Fixed an issue on the firewall where log filtering did not work as expected.
|
||||||
|
|
||||||
|
## PAN-209288
|
||||||
|
|
||||||
|
Fixed an issue where generating certificates with SCEP did not work.
|
||||||
|
|
||||||
|
## PAN-209172
|
||||||
|
|
||||||
|
Fixed an issue where the firewall was unable to handle GRE packets for Point-to-Point Tunneling Protocol (PPTP) connections.
|
||||||
|
|
||||||
|
## PAN-209108
|
||||||
|
|
||||||
|
Fixed an issue where a Panorama in Management Only mode was unable to display logs from log
|
||||||
|
collectors due to missing schema files.
|
||||||
|
|
||||||
|
## PAN-208567
|
||||||
|
|
||||||
|
Fixed an issue with email formatting where, when a scheduled email contained two or more attachments, only one attachment was visible.
|
||||||
|
|
||||||
|
## PAN-208438
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where Security policy rules incorrectly displayed as disabled.
|
||||||
|
|
||||||
|
## PAN-208395
|
||||||
|
|
||||||
|
Fixed an issue where user authentication failed in multi-vsys environments with the error message User is not in allowlist when an authentication profile was created in a shared configuration space.
|
||||||
|
|
||||||
|
## PAN-208316
|
||||||
|
|
||||||
|
Fixed an issue where user-group names were unable to be configured as the source user via the test security-policy-match command.
|
||||||
|
|
||||||
|
## PAN-208240
|
||||||
|
|
||||||
|
Fixed an issue where, when attempting to replace an existing certificate, importing a new certificate with the same name as the existing certificate failed due to mismatched public and private keys.
|
||||||
|
|
||||||
|
## PAN-208198
|
||||||
|
|
||||||
|
Fixed an issue with firewalls in active/passive HA configurations where, after rebooting the passive firewall, interfaces were briefly shown as powered up, and then shown as down or shutdown.
|
||||||
|
|
||||||
|
## PAN-208090
|
||||||
|
|
||||||
|
Fixed an issue where the ACC report did not display data when querying the filter for the fields Source and Destination IP.
|
||||||
|
|
||||||
|
## PAN-207604
|
||||||
|
|
||||||
|
Fixed an issue where system logs continuously generated the log message Not enough space to load content to SHM.
|
||||||
|
|
||||||
|
## PAN-207577
|
||||||
|
|
||||||
|
Fixed an issue where Panorama > Setup > Interfaces was not accessible for users with custom admin roles even when the interface option was selected for the custom admin roles.
|
||||||
|
|
||||||
|
## PAN-206765
|
||||||
|
|
||||||
|
Fixed an issue where log forwarding filters involving negation did not work.
|
||||||
|
|
||||||
|
## PAN-205015
|
||||||
|
|
||||||
|
Fixed an issue where not all users were included in the user group after an incremental sync between the firewall and the Cloud Identity Engine.
|
||||||
|
|
||||||
|
## PAN-204868
|
||||||
|
|
||||||
|
Fixed an issue where disk utilization was continuously high due to the log purger not sufficiently reducing the utilization level.
|
||||||
|
|
||||||
|
## PAN-204718
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where, after upgrading to PAN-OS 10.1.6-h3, a TACACS user login displayed the following error message during the first login attempt: Could not chdir to home directory /opt/pancfg/home/user: Permission denied.
|
||||||
|
|
||||||
|
## PAN-203611
|
||||||
|
|
||||||
|
Fixed an issue where URL categorization was not recognized for URLs that contained more than 100 characters.
|
||||||
|
|
||||||
|
## PAN-202524
|
||||||
|
|
||||||
|
Fixed an issue where the session ID was missing in the session details section of the ingress-backlogs XML API output.
|
||||||
|
|
||||||
|
## PAN-199819
|
||||||
|
|
||||||
|
Fixed an issue where, if a decryption profile allowed TLSv1.3, but the server only supported
|
||||||
|
TLSv1.2, and the cipher used by the first connection to the server
|
||||||
|
was a CBC SHA2 cipher suite, the connection failed.
|
||||||
|
|
||||||
|
## PAN-198509
|
||||||
|
|
||||||
|
Fixed an issue where commits failed due to insufficient CFG memory.
|
||||||
|
|
||||||
|
## PAN-198453
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to resize the Description pop-up window (Policies > Security > Prerules).
|
||||||
|
|
||||||
|
## PAN-198050
|
||||||
|
|
||||||
|
Fixed an issue where Connection to update server is successful messages displayed even when connections failed.
|
||||||
|
|
||||||
|
## PAN-197339
|
||||||
|
|
||||||
|
Fixed an issue where template configuration for the User-ID agent was not reflected on the template stack on Panorama appliances on PAN-OS 10.2.1.
|
||||||
|
|
||||||
|
## PAN-196345
|
||||||
|
|
||||||
|
Fixed an issue where scheduled dynamic content updates failed to be retrieved by managed firewalls from Panorama when connectivity was slow.
|
||||||
|
|
||||||
|
## PAN-189328
|
||||||
|
|
||||||
|
Fixed an issue where traffic belonging to the same session was sent out from different ECMP enabled interfaces.
|
||||||
|
|
||||||
|
## PAN-187989
|
||||||
|
|
||||||
|
Fixed an issue where a user who did not have permissions of other access domains were able to view the commit and configuration lock.
|
||||||
|
|
||||||
|
## PAN-185360
|
||||||
|
|
||||||
|
Fixed an issue where, when Authentication Portal Authentication was configured,
|
||||||
|
l3svc_ngx_error.log and
|
||||||
|
l3svc_access.log did not roll over
|
||||||
|
after exceeding 10 megabytes, which caused the root partition to
|
||||||
|
reach full utilization.
|
||||||
|
|
||||||
|
## PAN-180082
|
||||||
|
|
||||||
|
Fixed an issue where errors in brdagent logs caused dataplane path monitoring failure.
|
||||||
|
|
||||||
|
## PAN-177227
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls on Amazon Web Services environments only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where traffic sent from a GENEVE tunnel to the firewall was dropped if the firewall attempted to encapsulate traffic into an IPSec tunnel.
|
||||||
|
|
||||||
|
## PAN-169586
|
||||||
|
|
||||||
|
Fixed an issue where scheduled log view reports in emails didn't match the monitor page query result for the same time interval.
|
||||||
|
|
||||||
|
## PAN-160633
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where
|
||||||
|
the dataplane restarted repeatedly due to an internal path
|
||||||
|
monitoring failure until a power cycle.
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.4-h1
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-252214
|
||||||
|
|
||||||
|
A fix was made to address CVE-2024-3400.
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.4-h2
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-252744
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where upgrading the firewall to
|
||||||
|
PAN-OS 11.0.4 or PAN-OS 11.0.4-h1 caused the firewall to go into a
|
||||||
|
non-functional state.
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.4-h5
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-247511
|
||||||
|
|
||||||
|
A fix was made to address CVE-2024-3596.
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.4-h6
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-272809
|
||||||
|
|
||||||
|
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and
|
||||||
|
CVE-2024-9474.
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,14 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.5-h1
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-261540
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the
|
||||||
|
firewall did not fully reboot after upgrading to PAN-OS 11.0.5.
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.5-h2
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-272809
|
||||||
|
|
||||||
|
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and
|
||||||
|
CVE-2024-9474.
|
||||||
@@ -0,0 +1,399 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.5
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-255868
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall entered maintenance mode after enabling kernel data collection during the silent reboot.
|
||||||
|
|
||||||
|
## PAN-255577
|
||||||
|
|
||||||
|
Fixed an issue where push scope changes remained empty and Edit selections >
|
||||||
|
OK did not work for admin-based users after
|
||||||
|
upgrading Panorama.
|
||||||
|
|
||||||
|
## PAN-253317
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls on Microsoft Azure environments only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to log in to the firewall after a private data reset.
|
||||||
|
|
||||||
|
## PAN-251563
|
||||||
|
|
||||||
|
Added CPLD enhancement to capture external power issues.
|
||||||
|
|
||||||
|
## PAN-251013
|
||||||
|
|
||||||
|
Fixed an issue on the web interface where the Virtual Router and Virtual System configurations for the template incorrectly showed as none.
|
||||||
|
|
||||||
|
## PAN-249019
|
||||||
|
|
||||||
|
Fixed an issue where the all_pktproc process stopped responding, which caused the firewall to become unresponsive.
|
||||||
|
|
||||||
|
## PAN-248427
|
||||||
|
|
||||||
|
Fixed an issue where push operations took longer than expected to complete.
|
||||||
|
|
||||||
|
## PAN-248105
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect SSL VPN tunnel immediately disconnected due to a keep-alive timeout.
|
||||||
|
|
||||||
|
## PAN-247403
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama virtual appliances only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the push scope CLI command took longer than expected, which caused the web interface to be slow.
|
||||||
|
|
||||||
|
## PAN-246772
|
||||||
|
|
||||||
|
Fixed an issue on the firewall where the dataplane went down due to a path monitor failure caused by an OOM condition related to the pan_task process.
|
||||||
|
|
||||||
|
## PAN-246431
|
||||||
|
|
||||||
|
Fixed an issue where a Push to Device operation remained at the state None when performing a selective push to device groups and templates that included both connected and disconnected firewalls.
|
||||||
|
|
||||||
|
## PAN-246215
|
||||||
|
|
||||||
|
Fixed an issue where the sleep time for a suspended pan_task process caused configuration and policy updates to be blocked.
|
||||||
|
|
||||||
|
## PAN-245850
|
||||||
|
|
||||||
|
Fixed an issue on Panorama appliances in active/passive HA configurations where the firewalls entered an HA out-of-sync status and jobs failed on the passive appliance with the error message Could not merged running config from file.
|
||||||
|
|
||||||
|
## PAN-245125
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls in Microsoft Azure environments only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where file descriptors were not closed due to invalid configurations.
|
||||||
|
|
||||||
|
## PAN-245041
|
||||||
|
|
||||||
|
Fixed an issue where the WF-500 appliance returned an error verdict for every sample in FIPS mode.
|
||||||
|
|
||||||
|
## PAN-244907
|
||||||
|
|
||||||
|
Fixed an issue where ports did not go down when moving from an active state to a suspended state.
|
||||||
|
|
||||||
|
## PAN-244894
|
||||||
|
|
||||||
|
Fixed an issue where turning off mprelay logging caused mprelay heartbeat failure.
|
||||||
|
|
||||||
|
## PAN-244836
|
||||||
|
|
||||||
|
A knob was introduced to toggle the default behavior of BGP in the Advanced Routing stack to not suppress duplicate updates. By default, the prefix updates are suppressed for optimization.
|
||||||
|
|
||||||
|
## PAN-244746
|
||||||
|
|
||||||
|
Fixed an issue where changes committed on Panorama were not reflected on the firewall after a successful push.
|
||||||
|
|
||||||
|
## PAN-244622
|
||||||
|
|
||||||
|
Fixed an issue where FIB repush did not work with Advanced Routing enabled.
|
||||||
|
|
||||||
|
## PAN-244548
|
||||||
|
|
||||||
|
Fixed an issue where ECMP sessions changed destination MAC addresses mid-session, which caused connections to be reset.
|
||||||
|
|
||||||
|
## PAN-244227
|
||||||
|
|
||||||
|
Fixed an issue where inconsistent FIB entries across the dataplane were not detected.
|
||||||
|
|
||||||
|
## PAN-243463
|
||||||
|
|
||||||
|
Fixed an issue where high Enhanced Application log traffic used excess system resources and
|
||||||
|
caused processes to not work.
|
||||||
|
|
||||||
|
## PAN-242309
|
||||||
|
|
||||||
|
Fixed an issue where a higher byte count (s2c) was observed for DNS-Base application.
|
||||||
|
|
||||||
|
## PAN-241018
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls in Microsoft Azure environments only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed a Data Plane
|
||||||
|
Development Kit (DPDK) issue where interfaces remained in a
|
||||||
|
link-down stage after an Azure hot plug event.
|
||||||
|
|
||||||
|
## PAN-240596
|
||||||
|
|
||||||
|
Fixed an issue where all_task stopped responding due to an invalid memory address.
|
||||||
|
|
||||||
|
## PAN-240477
|
||||||
|
|
||||||
|
Fixed a temporary hardware issue that caused PAN-SFP-PLUS-CU-5M to not be able to link up on PA-3400 and PA-1400 Series firewalls.
|
||||||
|
|
||||||
|
## PAN-240174
|
||||||
|
|
||||||
|
Fixed an issue where, when LSVPN serial numbers and IP address authentication were enabled, IPv6 address ranges and complete IPv6 addresses that were manually added to the IP address allow or exclude list were not usable after a restart of the gp_broker process or the firewall.
|
||||||
|
|
||||||
|
## PAN-239662
|
||||||
|
|
||||||
|
Fixed an issue where the NSSA default route from the firewall was not generated to advertise even though the backbone area default route was advertised during a graceful restart.
|
||||||
|
|
||||||
|
## PAN-239337
|
||||||
|
|
||||||
|
Fixed an issue where the log_index was suspended and corrupted BDX files flooded the
|
||||||
|
index_log.
|
||||||
|
|
||||||
|
## PAN-238625
|
||||||
|
|
||||||
|
Fixed an issue where, when the physical interface went down, the SD-WAN Ethernet connection state
|
||||||
|
still showed UP/path-monitor due to the
|
||||||
|
Active URL SaaS monitor connection state remaining
|
||||||
|
UP/path-monitor.
|
||||||
|
|
||||||
|
## PAN-238610
|
||||||
|
|
||||||
|
Fixed an issue with the Panorama virtual appliance where, after the mgmtsrvr
|
||||||
|
restarted on the passive appliance, stale IP address tags were
|
||||||
|
pushed to the connected firewalls with the message
|
||||||
|
clear all registered ip
|
||||||
|
addresses.
|
||||||
|
|
||||||
|
## PAN-238592
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3410 firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not boot up after upgrading due to a TPM lockout condition that persisted for over 24 hours.
|
||||||
|
|
||||||
|
## PAN-237991
|
||||||
|
|
||||||
|
Fixed an issue where the log collector sent fewer logs than expected to the syslog server.
|
||||||
|
|
||||||
|
## PAN-237657
|
||||||
|
|
||||||
|
Fixed an issue with 100% CPU utilization in the varrcvr process that occurred during an incremental WildFire update.
|
||||||
|
|
||||||
|
## PAN-237614
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where the API command request system disk add failed.
|
||||||
|
|
||||||
|
## PAN-237208
|
||||||
|
|
||||||
|
Fixed an issue where the reportd process stopped and the firewall rebooted.
|
||||||
|
|
||||||
|
## PAN-236261
|
||||||
|
|
||||||
|
Fixed an issue where a proxy server was used for external dynamic list communication even when
|
||||||
|
the dataplane interface was configured through service routes.
|
||||||
|
|
||||||
|
## PAN-236244
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to select authentication profiles via the web interface.
|
||||||
|
|
||||||
|
## PAN-235807
|
||||||
|
|
||||||
|
Fixed an issue where static ND entries were not reachable after a reboot.
|
||||||
|
|
||||||
|
## PAN-235585
|
||||||
|
|
||||||
|
Fixed an issue where, when custom signatures and predefined signatures shared the same literal pattern part, the custom signature caused an incorrect calculation for the length of the predefined signature, which resulted in App-ID not detecting correctly.
|
||||||
|
|
||||||
|
## PAN-234489
|
||||||
|
|
||||||
|
Fixed an issue where a User Principle Name (UPN) was incorrectly required in the pre-logon machine certificate.
|
||||||
|
|
||||||
|
## PAN-234169
|
||||||
|
|
||||||
|
Fixed an issue where downloading files failed or was slower than expected due to malware scanning
|
||||||
|
even when the session was matched to a Security policy rule with no
|
||||||
|
Anti-Virus profile attached.
|
||||||
|
|
||||||
|
## PAN-233684
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where Push to Devices or Commit and Push operations took longer than expected on the web interface.
|
||||||
|
|
||||||
|
## PAN-233207
|
||||||
|
|
||||||
|
Fixed an issue where the configd process stopped responding when a partial configuration revert operation was performed.
|
||||||
|
|
||||||
|
## PAN-231439
|
||||||
|
|
||||||
|
Fixed an issue where, when a VoIP call using dynamic IP and NAT was put on hold, the audio became one-way due to early termination of NAT ports.
|
||||||
|
|
||||||
|
## PAN-229832
|
||||||
|
|
||||||
|
Fixed an intermittent issue where MLAV and URL cloud connectivity were lost.
|
||||||
|
|
||||||
|
## PAN-228624
|
||||||
|
|
||||||
|
Fixed an issue where FIB entries were deleted due to a sysd process connection error.
|
||||||
|
|
||||||
|
## PAN-228386
|
||||||
|
|
||||||
|
Fixed an issue with session caching where the reportd process stopped responding due to null values.
|
||||||
|
|
||||||
|
## PAN-228043
|
||||||
|
|
||||||
|
Fixed an issue on firewalls on active/active HA configurations where packets dropped during
|
||||||
|
commit operations when forwarding traffic via an HA3 link when an
|
||||||
|
Aggregate Ethernet interface or data interface was used as an HA3
|
||||||
|
link.
|
||||||
|
|
||||||
|
## PAN-227641
|
||||||
|
|
||||||
|
Fixed an issue where Preview Changes and Change Summary when saving changes did not open a new window when clicked.
|
||||||
|
|
||||||
|
## PAN-227233
|
||||||
|
|
||||||
|
Fixed an issue where the combination signature aggregation criteria in a Vulnerability Protection
|
||||||
|
profile was incorrectly blank even though a value was set.
|
||||||
|
|
||||||
|
## PAN-226489
|
||||||
|
|
||||||
|
Fixed an issue where Panorama was unable to push scheduled Dynamic Updates to firewalls with the
|
||||||
|
error message Failed to add deploy job. Too many (30)
|
||||||
|
deploy jobs pending for device.
|
||||||
|
|
||||||
|
## PAN-226260
|
||||||
|
|
||||||
|
Fixed an issue where support for CBC ciphers with some authentication algorithms was only available in FIPS mode.
|
||||||
|
|
||||||
|
## PAN-226108
|
||||||
|
|
||||||
|
Fixed an issue where the masterd process was unable to start or stop the sysd process.
|
||||||
|
|
||||||
|
## PAN-225963
|
||||||
|
|
||||||
|
Fixed an issue where the IP address-to-user mapping was not correct.
|
||||||
|
|
||||||
|
## PAN-225228
|
||||||
|
|
||||||
|
Fixed an issue where filtering Threat logs using any value under THREAT
|
||||||
|
ID/NAME displayed the error Invalid
|
||||||
|
term.
|
||||||
|
|
||||||
|
## PAN-223418
|
||||||
|
|
||||||
|
Fixed an issue where heartbeats to the brdagent process were lost, resulting in the
|
||||||
|
process not responding, which caused the firewall to reboot.
|
||||||
|
|
||||||
|
## PAN-222253
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where policy rulebase reordering under View Rulebase by Groups (Policy > <policy-rulebase>) did not persist if you reordered the policy rulebase by dragging and dropping individual policy rules and then moved the entire tag group.
|
||||||
|
|
||||||
|
## PAN-221571
|
||||||
|
|
||||||
|
Fixed an issue on the web interface where the Security policy rule hit count remained at 0 for
|
||||||
|
some rules even though the Traffic logs showed live hits.
|
||||||
|
|
||||||
|
## PAN-221041
|
||||||
|
|
||||||
|
Fixed an issue where the following error message was seen frequently in the system logs: Clearing snmpd.log due to log overflow.
|
||||||
|
|
||||||
|
## PAN-221003
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to uncheck firewalls in HA configurations from the device group when Group HA Peers was enabled.
|
||||||
|
|
||||||
|
## PAN-220640
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-220 firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall CPU percentage was miscalculated, and the values that were displayed were incorrect.
|
||||||
|
|
||||||
|
## PAN-220601
|
||||||
|
|
||||||
|
Fixed an issue with missing logs when one log collector in a log Collector Group became
|
||||||
|
unreachable.
|
||||||
|
|
||||||
|
## PAN-219690
|
||||||
|
|
||||||
|
Fixed an issue where GlobalProtect authentication failed when authentication was SAML with CAS and the portal was resolved with IPv6.
|
||||||
|
|
||||||
|
## PAN-218521
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
M-600 Appliances in Log Collector mode only
|
||||||
|
```
|
||||||
|
|
||||||
|
) Fixed an issue where Panorama continuously rebooted and became unresponsive, which consumed excessive logging disk space and prevented new log ingestion.
|
||||||
|
|
||||||
|
## PAN-218331
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to export or download packet captures from the firewall when context switching from Panorama.
|
||||||
|
|
||||||
|
## PAN-217674
|
||||||
|
|
||||||
|
Fixed an issue where RADIUS authentication failed when the destination route of the service route was configured with an IPv4 address with more than 14 characters.
|
||||||
|
|
||||||
|
## PAN-217489
|
||||||
|
|
||||||
|
Fixed an issue with firewalls in active/passive HA configurations where the passive firewall MAC flapping occurred when the passive firewall was rebooted.
|
||||||
|
|
||||||
|
## PAN-215905
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3400 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where silent packet drops were observed on interfaces.
|
||||||
|
|
||||||
|
## PAN-215430
|
||||||
|
|
||||||
|
Fixed an issue where dynamic IP address NAT with SIP intermittently failed to convert RTP Predict
|
||||||
|
sessions.
|
||||||
|
|
||||||
|
## PAN-214682
|
||||||
|
|
||||||
|
Fixed an issue where the firewall sent incorrectly encoded the supported_groups extension in the Client Hello when acting as a forward proxy with decryption profile max version TLSv1.2.
|
||||||
|
|
||||||
|
## PAN-213173
|
||||||
|
|
||||||
|
Fixed an issue where Preview Changes under Scheduled Pushes did not launch the Change Preview window.
|
||||||
|
|
||||||
|
## PAN-212553
|
||||||
|
|
||||||
|
Fixed an issue where the ikemgr process stopped responding due to memory corruption, which caused VPN tunnels to go down.
|
||||||
|
|
||||||
|
## PAN-209574
|
||||||
|
|
||||||
|
Fixed an issue with HTTP2 traffic where downloading large files did not work when decryption was enabled.
|
||||||
|
|
||||||
|
## PAN-207972
|
||||||
|
|
||||||
|
Fixed an issue on the web interface where the BGP routing table did not display advertised routes.
|
||||||
|
|
||||||
|
## PAN-205482
|
||||||
|
|
||||||
|
Fixed an issue related to the configd process where Panorama displayed the error
|
||||||
|
Server not responding when editing policy
|
||||||
|
rules.
|
||||||
|
|
||||||
|
## PAN-200946
|
||||||
|
|
||||||
|
Fixed an issue with firewalls in active/passive HA configurations where GRE tunnels went down due to recursive routing when the passive firewall was booting up. When the passive firewall became active and no recursive routing was configured, the GRE tunnel remained down.
|
||||||
|
|
||||||
|
## PAN-196146
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where hostname validation failed due to the firewall not taking the hostname provided in init.cfg.
|
||||||
|
|
||||||
|
## PAN-194968
|
||||||
|
|
||||||
|
Fixed an issue on the web interface where Antivirus updates were not able to be downloaded and installed unless Apps and Threads updates were downloaded and installed first, and the Antivirus content list displayed as blank. The resulting error message from the update server was also not reflected in the web interface.
|
||||||
|
|
||||||
|
## PAN-174454
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not fetch group and user membership due to the Okta sync domain not matching the active directory sync domain.
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.6-h1
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-272809
|
||||||
|
|
||||||
|
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and
|
||||||
|
CVE-2024-9474.
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 11.0.6
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-254181
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
CN-Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where firewall pods and application pods repeatedly restarted.
|
||||||
|
|
||||||
|
## PAN-253400
|
||||||
|
|
||||||
|
Fixed an issue where the logrcvr process stopped responding.
|
||||||
@@ -174,6 +174,44 @@
|
|||||||
"11.1.12_2026-03-16.md",
|
"11.1.12_2026-03-16.md",
|
||||||
"11.1.13_2026-03-16.md"
|
"11.1.13_2026-03-16.md"
|
||||||
]
|
]
|
||||||
|
},
|
||||||
|
"11.0": {
|
||||||
|
"addressed": [
|
||||||
|
"11.0.0_2026-03-16.md",
|
||||||
|
"11.0.0-h1_2026-03-16.md",
|
||||||
|
"11.0.0-h2_2026-03-16.md",
|
||||||
|
"11.0.0-h3_2026-03-16.md",
|
||||||
|
"11.0.0-h4_2026-03-16.md",
|
||||||
|
"11.0.1_2026-03-16.md",
|
||||||
|
"11.0.1-h2_2026-03-16.md",
|
||||||
|
"11.0.1-h3_2026-03-16.md",
|
||||||
|
"11.0.1-h4_2026-03-16.md",
|
||||||
|
"11.0.1-h5_2026-03-16.md",
|
||||||
|
"11.0.2_2026-03-16.md",
|
||||||
|
"11.0.2-h1_2026-03-16.md",
|
||||||
|
"11.0.2-h2_2026-03-16.md",
|
||||||
|
"11.0.2-h3_2026-03-16.md",
|
||||||
|
"11.0.2-h4_2026-03-16.md",
|
||||||
|
"11.0.2-h5_2026-03-16.md",
|
||||||
|
"11.0.3_2026-03-16.md",
|
||||||
|
"11.0.3-h1_2026-03-16.md",
|
||||||
|
"11.0.3-h3_2026-03-16.md",
|
||||||
|
"11.0.3-h5_2026-03-16.md",
|
||||||
|
"11.0.3-h10_2026-03-16.md",
|
||||||
|
"11.0.3-h12_2026-03-16.md",
|
||||||
|
"11.0.3-h13_2026-03-16.md",
|
||||||
|
"11.0.4_2026-03-16.md",
|
||||||
|
"11.0.4-h1_2026-03-16.md",
|
||||||
|
"11.0.4-h2_2026-03-16.md",
|
||||||
|
"11.0.4-h5_2026-03-16.md",
|
||||||
|
"11.0.4-h6_2026-03-16.md",
|
||||||
|
"11.0.5_2026-03-16.md",
|
||||||
|
"11.0.5-h1_2026-03-16.md",
|
||||||
|
"11.0.5-h2_2026-03-16.md",
|
||||||
|
"11.0.6_2026-03-16.md",
|
||||||
|
"11.0.6-h1_2026-03-16.md"
|
||||||
|
],
|
||||||
|
"known": []
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"10": {
|
"10": {
|
||||||
|
|||||||
Reference in New Issue
Block a user