Add 9.1 issue data
This commit is contained in:
@@ -6,6 +6,10 @@ source: common-crawl
|
|||||||
crawl: CC-MAIN-2026-12
|
crawl: CC-MAIN-2026-12
|
||||||
---
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Fixed a Denial-of-Service (DoS) vulnerability in the GlobalProtect portal and gateway ([CVE-2021-3063](https://security.paloaltonetworks.com/CVE-2021-3063)).
|
||||||
|
|
||||||
## PAN-178283
|
## PAN-178283
|
||||||
|
|
||||||
Fixed an intermittent issue where connections to the URL cloud went down due to a failure to resolve DNS.
|
Fixed an intermittent issue where connections to the URL cloud went down due to a failure to resolve DNS.
|
||||||
|
|||||||
@@ -0,0 +1,47 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.0
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-130069
|
||||||
|
|
||||||
|
Fixed an issue where the firewall incorrectly interpreted an external dynamic list MineMeld instability error code as an empty external dynamic list.
|
||||||
|
|
||||||
|
## PAN-125546
|
||||||
|
|
||||||
|
Fixed an issue where a process failed to restart even when the system logs displayed the following message: virtual memory exceeded, restarting.
|
||||||
|
|
||||||
|
## PAN-125515
|
||||||
|
|
||||||
|
Fixed an issue on VM-Series firewalls where the firewall dropped all traffic traversing from the dataplane to the management plane.
|
||||||
|
|
||||||
|
## PAN-125008
|
||||||
|
|
||||||
|
Fixed an issue on the firewalls where traffic logs generated with incorrect policy rule names when the security policy rule names contained more than 58 characters.
|
||||||
|
|
||||||
|
## PAN-123322
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an intermittent issue where a process (all_pktproc) stopped responding due to a Work Query Entry (WQE) corruption that was caused by duplicate child sessions.
|
||||||
|
|
||||||
|
## PAN-122421
|
||||||
|
|
||||||
|
Fixed an issue where third-party VPN clients were unable to connect to GlobalProtect using IPSec due to a stale IKE/IPSec security association (SA).
|
||||||
|
|
||||||
|
## PAN-114856
|
||||||
|
|
||||||
|
A change was made to limit debug log visibility to superusers only.
|
||||||
|
|
||||||
|
## PAN-111708
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed a rare software issue that caused the dataplane to restart unexpectedly. To leverage this fix, you must run the debug dataplane set pow no-desched yes CLI command (increases CPU utilization).
|
||||||
@@ -0,0 +1,493 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.10
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## WF500-5568
|
||||||
|
|
||||||
|
Fixed an issue where a firewall in FIPS mode running PAN-OS 8.1.18 or a later version failed to connect with a WildFire appliance in normal mode.
|
||||||
|
|
||||||
|
## WF500-5513
|
||||||
|
|
||||||
|
Fixed an issue where cloud queries failed, which generated system logs. The issue occurred because a hash was not found in the cloud.
|
||||||
|
|
||||||
|
## PAN-169551
|
||||||
|
|
||||||
|
Fixed an issue where custom URL categories hit incorrect URL categories, which caused the firewall to miss or deny the security policies for the configured custom URL.
|
||||||
|
|
||||||
|
## PAN-168298
|
||||||
|
|
||||||
|
Fixed an issue where a firewall superuser using an LDAP authentication profile that was pushed from Panorama was unable to save the filter under **Monitor > Logs**.
|
||||||
|
|
||||||
|
## PAN-167306
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls on Microsoft Azure only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where, when a second disk was added, /opt/panlogs was mounted on an incorrect partition.
|
||||||
|
|
||||||
|
## PAN-167098
|
||||||
|
|
||||||
|
Fixed an issue where a configd process memory corruption occurred when Panorama was exposed to multiple XML API calls on Dynamic Address Groups updates.
|
||||||
|
|
||||||
|
## PAN-166570
|
||||||
|
|
||||||
|
Fixed an issue where authentication failure messages were overwritten when a commit was in progress.
|
||||||
|
|
||||||
|
## PAN-166328
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls with NPCs only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where path monitoring failure occurred while hot inserting a 100G NPC (network processing card) into the firewall.
|
||||||
|
|
||||||
|
## PAN-166306
|
||||||
|
|
||||||
|
Fixed an issue where commit jobs failed when validating HIP objects and profiles.
|
||||||
|
|
||||||
|
## PAN-166296
|
||||||
|
|
||||||
|
Fixed an issue where an unavailable certificate revocation list (CRL) from the server side caused an infinite loop on a process (sslmgr), which resulted in it not responding for other tasks.
|
||||||
|
|
||||||
|
## PAN-166241
|
||||||
|
|
||||||
|
A fix was made to address an improper restriction of XML external identity (XXE) reference in the PAN-OS web interface that enabled an authenticated administrator to read any arbitrary file from the file system and send a specifically crafted request to the firewall that caused the service to crash ([CVE-2021-3055](https://security.paloaltonetworks.com/CVE-2021-3055)).
|
||||||
|
|
||||||
|
## PAN-166021
|
||||||
|
|
||||||
|
Fixed an issue where log queries that included a username did not return with any output.
|
||||||
|
|
||||||
|
## PAN-164922
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where a context switch to a managed firewall running PAN-OS 8.1.0 to PAN-OS 8.1.19 failed.
|
||||||
|
|
||||||
|
## PAN-164846
|
||||||
|
|
||||||
|
Fixed an issue where packet buffers were depleted.
|
||||||
|
|
||||||
|
## PAN-164646
|
||||||
|
|
||||||
|
Fixed an issue where tunnel monitoring in the Large Scale VPN (LSVPN) displayed as down in both the CLI and the web interface due to incorrect dataplane ownership.
|
||||||
|
|
||||||
|
## PAN-164571
|
||||||
|
|
||||||
|
Fixed an issue where DHCP leases were not properly synchronized between high availability peers after a device or dhcpd process restart. With this fix, the DHCP lease details display correctly on both the active and the passive device.
|
||||||
|
|
||||||
|
## PAN-164392
|
||||||
|
|
||||||
|
Fixed an issue where an out-of-memory (OOM) condition occurred due to a memory leak related to a process (logrcvr).
|
||||||
|
|
||||||
|
## PAN-164338
|
||||||
|
|
||||||
|
Fixed an issue where, when using the CLI or API, configurations for policy rule services or applications that either used custom settings and default settings together, or used multiple default settings together, successfully commit instead of failing or displaying a warning.
|
||||||
|
|
||||||
|
**Note** To use this fix, you must delete previous application or service settings in the configuration.
|
||||||
|
|
||||||
|
## PAN-164056
|
||||||
|
|
||||||
|
Fixed a memory issue for LSVPNs with multiple dataplane systems.
|
||||||
|
|
||||||
|
## PAN-163587
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where a user with an admin role was able to set the **Block IP List** option via the CLI but not the web interface.
|
||||||
|
|
||||||
|
## PAN-162663
|
||||||
|
|
||||||
|
Fixed an intermittent issue on the firewall where packets dropped in decrypted SSL/TLS sessions.
|
||||||
|
|
||||||
|
## PAN-162600
|
||||||
|
|
||||||
|
Fixed an issue where, when the GlobalProtect client sent UDP/4501 traffic that was destined for the GlobalProtect gateway inside the GlobalProtect tunnel, the firewall still processed the traffic, which caused routing loops.
|
||||||
|
|
||||||
|
## PAN-162594
|
||||||
|
|
||||||
|
Fixed an issue where blank configuration for tokens in a content-driven FreeDNS Afraid.org Dynamic API v1 DDNS configuration were not enabled.
|
||||||
|
|
||||||
|
## PAN-161869
|
||||||
|
|
||||||
|
Fixed an issue where a core dump occurred on a process (flow_ctrl) after a commit if a policy-based forwarding (PBF) rule referenced an interface that had a DHCP IP address assignment.
|
||||||
|
|
||||||
|
## PAN-161544
|
||||||
|
|
||||||
|
Fixed an issue where the **Device Name**field was missing when GlobalProtect logs were exported to CSV from the Panorama management server.
|
||||||
|
|
||||||
|
## PAN-161260
|
||||||
|
|
||||||
|
Fixed a memory leak issue related to a process (useridd) that occurred when processing high amount of HIP reports as well as aa memory leak issue related to the sslvpn process that occurred when the firewall was configured as a GlobalProtect satellite.
|
||||||
|
|
||||||
|
## PAN-161112
|
||||||
|
|
||||||
|
Fixed an issue where a process (useridd) repeatedly exceeded the virtual memory limit, which caused the process to stop responding.
|
||||||
|
|
||||||
|
## PAN-161025
|
||||||
|
|
||||||
|
Fixed an issue in Panorama where an administrator with the role of Panorama administrator did not have the option to download or install GlobalProtect clients (**Panorama > Device Deployment > GlobalProtect**).
|
||||||
|
|
||||||
|
## PAN-160997
|
||||||
|
|
||||||
|
Fixed an issue where the metadata from the firewall's authentication profile was unable to export. This issue occurred when the authentication profile and the SAML Identity Provider sever profile were created with **VSYS** in the **Location** and pushed from Panorama template stack values. To utilize this fix, you must upgrade both Panorama and the firewall.
|
||||||
|
|
||||||
|
## PAN-160870
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
ZTP-capable firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the default Zero Touch Provisioning (ZTP) configuration was still present on the firewall even when ZTP was disabled, which caused commit failures.
|
||||||
|
|
||||||
|
## PAN-160540
|
||||||
|
|
||||||
|
Fixed an issue where tunnel traffic was dropped intermittently when a Quality of Service (QoS) Profile was assigned but the profile had no limits defined.
|
||||||
|
|
||||||
|
## PAN-160247
|
||||||
|
|
||||||
|
Fixed an issue where system logs incorrectly displayed as **Critical**.
|
||||||
|
|
||||||
|
## PAN-160238
|
||||||
|
|
||||||
|
Fixed an issue where intermittent VXLAN packet drops occurred if the TCI was not configured for inspecting VXLAN traffic. This issue occurred when traffic was migrated from a firewall running a PAN-OS version earlier than PAN-OS 9.0 to a firewall running PAN-OS 9.0 or later.
|
||||||
|
|
||||||
|
## PAN-160053
|
||||||
|
|
||||||
|
Fixed an issue in Panorama where a process (configd) stopped responding due to a race condition in the mongodb process.
|
||||||
|
|
||||||
|
## PAN-159973
|
||||||
|
|
||||||
|
Fixed an issue where a local commit in the Panorama management server caused the status to get out of sync on the managed WildFire appliance.
|
||||||
|
|
||||||
|
## PAN-159592
|
||||||
|
|
||||||
|
Fixed an issue where a Japanese keyword search displayed garbled characters during SAML authentication.
|
||||||
|
|
||||||
|
## PAN-159499
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to select the configured QoS profile under the template stack.
|
||||||
|
|
||||||
|
## PAN-159295
|
||||||
|
|
||||||
|
Fixed an issue where scheduled configuration export files saved in the /tmp folder in root were not periodically purged, which caused the root partition to fill up.
|
||||||
|
|
||||||
|
## PAN-159224
|
||||||
|
|
||||||
|
Fixed an memory leak issue related to a process (mgmtsrvr), which was caused by a certificate loading operation.
|
||||||
|
|
||||||
|
## PAN-159054
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to add more than 500 DHCP relay agent objects in the firewall templates from Panorama.
|
||||||
|
|
||||||
|
## PAN-158932
|
||||||
|
|
||||||
|
Fixed an issue where an increase was observed on spyware_state, which caused latency.
|
||||||
|
|
||||||
|
## PAN-158161
|
||||||
|
|
||||||
|
Fixed an issue where the PBF monitor was failing on the tunnel interface when QoS was enabled.
|
||||||
|
|
||||||
|
## PAN-158119
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where TFTP traffic with a high packet rate was not offloaded even after hitting an application override policy with a custom application.
|
||||||
|
|
||||||
|
## PAN-158020
|
||||||
|
|
||||||
|
Fixed an issue where HIP reports were not visible on the web interface due to a domain override configuration.
|
||||||
|
|
||||||
|
## PAN-157964
|
||||||
|
|
||||||
|
Fixed an issue where adding a container application from the **Apps Seen** list did not remove the child application from the list.
|
||||||
|
|
||||||
|
## PAN-157908
|
||||||
|
|
||||||
|
Fixed an issue where false system alarms for the IP tag log database exceeded the alarm threshold value.
|
||||||
|
|
||||||
|
## PAN-157903
|
||||||
|
|
||||||
|
Fixed an issue where the **To** field of an email was truncated in threat logs when the original email exceeded 512 bytes.
|
||||||
|
|
||||||
|
## PAN-157632
|
||||||
|
|
||||||
|
Fixed an intermittent issue where the firewall dropped GPRS tunneling protocol (GTP-U) traffic with the message TEID=0x00000000.
|
||||||
|
|
||||||
|
## PAN-157570
|
||||||
|
|
||||||
|
Fixed an issue where device deployment from Panorama to the firewalls failed with the error message Failed to get DLSRVR client key. This issue occurred only on firewalls where the request system-private-data-reset CLI command had been issued in the past.
|
||||||
|
|
||||||
|
## PAN-157479
|
||||||
|
|
||||||
|
Fixed an issue on the firewall where a process (useridd) stopped responding when group-mapping profiles were configured with an LDAP server profile with the type **e-directory**.
|
||||||
|
|
||||||
|
## PAN-157472
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA_5200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where, after a factory reset, the firewall displayed the following error message: data_plane_X: Exited 1 times, must be manually recovered..
|
||||||
|
|
||||||
|
## PAN-157447
|
||||||
|
|
||||||
|
Fixed an issue where a process (flow_mgmt) repeatedly restarted with a segmentation violation (SIGSEGV) signal and the following trace: flow_mgmt:pan_flow_dos_ager_invoke pan_sw_timer_100ms pan_sw_timer_invoke.
|
||||||
|
|
||||||
|
## PAN-157311
|
||||||
|
|
||||||
|
Fixed an issue where, if the **OK** button is clicked before tags are loaded when editing an address object that contained tags via the firewall web interface, associated tags are removed.
|
||||||
|
|
||||||
|
## PAN-157213
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
ZTP firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall failed to connect to Panorama when ZTP was disabled.
|
||||||
|
|
||||||
|
## PAN-157074
|
||||||
|
|
||||||
|
Fixed an issue where a process (configd) stopped responding, which caused corruption.
|
||||||
|
|
||||||
|
## PAN-157035
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an intermittent issue where multicast packets traversing the firewall in VLAN configurations experienced higher drop rates than expected.
|
||||||
|
|
||||||
|
## PAN-157027
|
||||||
|
|
||||||
|
Fixed an issue where, when stateless GTP-U traffic hit a multi-dataplane firewall, an inter-dataplane fragmentation loop occurred, which caused high dataplane resource usage.
|
||||||
|
|
||||||
|
## PAN-156240
|
||||||
|
|
||||||
|
A fix was made to address an issue where a cryptographically weak pseudo-random number (PRNG) was used during authentication to the PAN-OS interface. As a result, attackers with the capability to observe their own authentication secrets over a long duration on the firewall had the ability to impersonate another authenticated web interface administrator’s session ([CVE-2021-3047](https://security.paloaltonetworks.com/CVE-2021-3047)).
|
||||||
|
|
||||||
|
## PAN-156113
|
||||||
|
|
||||||
|
Fixed an issue where the management interface incorrectly used the configured default gateway for local network traffic when service routes were configured.
|
||||||
|
|
||||||
|
## PAN-156098
|
||||||
|
|
||||||
|
Fixed an issue where netflow packets sent from the firewall contained excess padding, which resulted in the packet length exceeding 1400 bytes.
|
||||||
|
|
||||||
|
## PAN-155772
|
||||||
|
|
||||||
|
Fixed an issue where the Panorama web interface did not display the secondary IP address configuring it under the template stack.
|
||||||
|
|
||||||
|
## PAN-155758
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
7000-Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where, when a subinterface was configured as a Log Card interface, the commit failed unless an IP address was assigned to the parent interface.
|
||||||
|
|
||||||
|
## PAN-155659
|
||||||
|
|
||||||
|
Fixed an issue where individual users were unable to populate the **allowed user/user group** field when configuring the GlobalProtect Clientless VPN.
|
||||||
|
|
||||||
|
## PAN-155657
|
||||||
|
|
||||||
|
Fixed an issue where the default log level for mprelay was set to INFO and caused commits to stop working on VM-Series firewalls in AWS using EBS backed volumes when route monitor is configured.
|
||||||
|
|
||||||
|
## PAN-155593
|
||||||
|
|
||||||
|
Fixed an issue where the firewall was unable to match HIP objects with a 3-digit code version.
|
||||||
|
|
||||||
|
## PAN-155459
|
||||||
|
|
||||||
|
Fixed an issue where an interface placed in a pre-defined zone was removed by the SD-WAN plugin after a commit to the firewall.
|
||||||
|
|
||||||
|
## PAN-155126
|
||||||
|
|
||||||
|
Fixed an issue where editing the LDAP server IP address (**Device > Templates > Server Profiles > LDAP > LDAP Server Profile**) removed the bind password.
|
||||||
|
|
||||||
|
## PAN-154603
|
||||||
|
|
||||||
|
Fixed an issue where, when SSL/TLS was required, LDAP server authentication attempted StartTLS first.
|
||||||
|
|
||||||
|
## PAN-154526
|
||||||
|
|
||||||
|
Fixed an issue where a process (genindex.sh) caused high memory usage on the management plane. Due to the resulting OOM condition, multiple processes stopped responding.
|
||||||
|
|
||||||
|
## PAN-154441
|
||||||
|
|
||||||
|
Fixed an issue where the Radius EAP authentication stopped working and the authd process restarted.
|
||||||
|
|
||||||
|
## PAN-154433
|
||||||
|
|
||||||
|
Fixed an issue where the firewall was unable to detect end-user IP address spoofing on the GTP-U for a user data session when using an IPv6 address.
|
||||||
|
|
||||||
|
## PAN-154362
|
||||||
|
|
||||||
|
Fixed an issue where Panorama failed to push dynamic user groups to the managed firewalls.
|
||||||
|
|
||||||
|
## PAN-154334
|
||||||
|
|
||||||
|
Fixed an issue where the inactivity logout timeout did not reflect on the GlobalProtect mapping timeout.
|
||||||
|
|
||||||
|
## PAN-154145
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the management plane CPU was incorrectly reported to be high.
|
||||||
|
|
||||||
|
## PAN-154109
|
||||||
|
|
||||||
|
Fixed an issue where using XML special characters in the **Uninstalled GlobalProtect APP** password in the application configuration (**Networks > GlobalProtect > Portals > Agent > App**) disrupted portal connectivity.
|
||||||
|
|
||||||
|
## PAN-153952
|
||||||
|
|
||||||
|
Fixed an issue where the firewall treated external dynamic list entries with nested carets as invalid.
|
||||||
|
|
||||||
|
## PAN-153592
|
||||||
|
|
||||||
|
Fixed an issue where, after upgrading Panorama from PAN-OS 8.1.9 to PAN-OS 9.1.3, the option to preview changes for dynamic address groups or templates from Panorama did not work.
|
||||||
|
|
||||||
|
## PAN-153288
|
||||||
|
|
||||||
|
Fixed an issue where the software QoS shaping queue processing was not properly applied on multicast traffic.
|
||||||
|
|
||||||
|
## PAN-153228
|
||||||
|
|
||||||
|
Fixed an issue where, when IPSec tunnels had **tunnel-monitor** enabled, tunnel activation was sent every 3 seconds, even when the configured value was different. With this fix, tunnel activation will be sent according to the configured intervals and thresholds.
|
||||||
|
|
||||||
|
## PAN-151909
|
||||||
|
|
||||||
|
Modified the diff algorithm for when a configuration audit was performed because certain objects incorrectly displayed as either **New** or **Modified/Unchanged** due to the XML format being added.
|
||||||
|
|
||||||
|
## PAN-151751
|
||||||
|
|
||||||
|
Fixed an issue where GlobalProtect logs did not populate on the destination syslog server in Log Event Extended Format (LEEF) and common event format (CEF).
|
||||||
|
|
||||||
|
## PAN-151679
|
||||||
|
|
||||||
|
Fixed an issue where it was possible via the CLI to create a Security policy rule with the **any** and **application-default** options simultaneously configured.
|
||||||
|
|
||||||
|
## PAN-151302
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls with Log Forwarding Cards (LFC) only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the logging rate for the LFC was not displayed in **Panorama > Managed Devices > Health**.
|
||||||
|
|
||||||
|
## PAN-151273
|
||||||
|
|
||||||
|
Fixed an issue where the commit event was not recorded in the config logs during a **Commit and Push** on the Panorama management server.
|
||||||
|
|
||||||
|
## PAN-150530
|
||||||
|
|
||||||
|
Fixed an issue where, when printing External Dynamic List (EDL) log messages, the messages repeated until the end of the description.
|
||||||
|
|
||||||
|
## PAN-150388
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-220 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where a process (mgmtsrvr) stopped responding when viewing logs in the web interface.
|
||||||
|
|
||||||
|
## PAN-150337
|
||||||
|
|
||||||
|
A fix was made to address a reflect cross-site scripting (XSS) vulnerability in the PAN-OS web interface that enabled an authenticated network-based attacker to mislead another authenticated PAN-OS administrator to click on a specially crafted link that performed arbitrary actions in the web interface as the targeted authenticated administrator ([CVE-2021-3052](https://security.paloaltonetworks.com/CVE-2021-3052)).
|
||||||
|
|
||||||
|
## PAN-150110
|
||||||
|
|
||||||
|
Fixed an issue where Elasticsearch restarted unexpectedly when it ran out of memory. This was due to the vm.max-map-count value being set incorrectly in the newer version of Elasticsearch (starting from PAN-OS 9.0). With this fix, the value is set correctly.
|
||||||
|
|
||||||
|
## PAN-150080
|
||||||
|
|
||||||
|
Fixed an issue where, even when tunnel interface is set to **down**, the following alert displayed: Tunnel GRE_Tunnels is going down(critical).
|
||||||
|
|
||||||
|
## PAN-149867
|
||||||
|
|
||||||
|
Fixed an issue where a process (authd) ignored null domain authentication profiles in a sequence and only returned non-null domains to GlobalProtect.
|
||||||
|
|
||||||
|
## PAN-147827
|
||||||
|
|
||||||
|
Fixed an issue where, when SIP traffic traversing the firewall was sent with a high QoS Differentiated Services Code Point (DSCP) value, the DSCP value was reset to the default setting (CS0).
|
||||||
|
|
||||||
|
## PAN-147781
|
||||||
|
|
||||||
|
A fix was made to address an issue where an OS command argument injection vulnerability in the PAN-OS web interface enabled an authenticated administrator to read any arbitrary file from the file system ([CVE-2021-3045](https://security.paloaltonetworks.com/CVE-2021-3045)).
|
||||||
|
|
||||||
|
## PAN-147736
|
||||||
|
|
||||||
|
Fixed an issue on the firewall web interface where the Cortex Data Lake **Logging Service Status** pop-up window did not show correct information.
|
||||||
|
|
||||||
|
## PAN-147193
|
||||||
|
|
||||||
|
Fixed an issue with the Panorama web interface where, when all device groups and templates were selected, a load configuration operation failed. This was caused by the XML cache rebuilding for each device group and template iteration.
|
||||||
|
|
||||||
|
## PAN-146250
|
||||||
|
|
||||||
|
Fixed an issue where, in two separate but simultaneous sessions, the same software packet buffer was owned and processed.
|
||||||
|
|
||||||
|
## PAN-146048
|
||||||
|
|
||||||
|
Fixed an issue where a satellite firewall was unable to authenticate to an LSVPN gateway when the issued certificate from Simple Certificate Enrollment Protocol (SCEP) had encryption bits set to 3072. With this fix, the maximum private key size of 3072 bits, along with the 1024-bit size and the 2048-bit size, is able to authenticate when selected to create the SCEP profile.
|
||||||
|
|
||||||
|
## PAN-145190
|
||||||
|
|
||||||
|
Fixed an issue where administrators were unable to delete the **GlobalProtect Data File** update schedule (**Device > Dynamic Updates**).
|
||||||
|
|
||||||
|
## PAN-144305
|
||||||
|
|
||||||
|
Fixed an issue where merged configurations were unable to be exported from Panorama-managed firewalls using the PAN-OS XML API.
|
||||||
|
|
||||||
|
## PAN-144057
|
||||||
|
|
||||||
|
Fixed a rare issue where, when aggregate ethernet (AE) groups were deleted and re-added, the AE interface no longer had an SDB node to send link the location to. As a result, the dataplane was unable to identify a connected route for the interface address.
|
||||||
|
|
||||||
|
## PAN-143699
|
||||||
|
|
||||||
|
Fixed an issue where the firewall status was inaccurate (**Panorama > Device Deployment**).
|
||||||
|
|
||||||
|
## PAN-142199
|
||||||
|
|
||||||
|
Fixed an issue memory leak issue where a process (devsrvr) consumed excess memory, which resulted in OOM conditions.
|
||||||
|
|
||||||
|
## PAN-141750
|
||||||
|
|
||||||
|
Fixed an issue in Panorama where the GlobalProtect gateway configuration in the template stack for mobile users was not able to be overwritten.
|
||||||
|
|
||||||
|
## PAN-141495
|
||||||
|
|
||||||
|
Fixed an issue where the following settings were not pushed from Panorama to the firewall: **Minimum Length**, **Failed Attempts**, and **Lockout Time** (**Template > Device > Setup > Management**).
|
||||||
|
|
||||||
|
## PAN-140565
|
||||||
|
|
||||||
|
Added zram support to PAN-OS platforms.
|
||||||
|
|
||||||
|
## PAN-140443
|
||||||
|
|
||||||
|
Fixed an issue where period Windows Management Instrumentation (WMI) probing did not work until a process (useridd) was restarted.
|
||||||
|
|
||||||
|
## PAN-138869
|
||||||
|
|
||||||
|
Fixed an issue where some threat logs in Panorama were not displayed when filtered by Threat-ID name.
|
||||||
|
|
||||||
|
## PAN-136635
|
||||||
|
|
||||||
|
Fixed an issue where HIP-related objects were missing transformation logic, which caused commit failures.
|
||||||
|
|
||||||
|
## PAN-114642
|
||||||
|
|
||||||
|
Fixed an issue where firewall logs incorrectly include the end-user IP address in GTP message logs when you configure PAA IE with IPv4 and IPv6 dual stack in the Create Session Response message.
|
||||||
|
|
||||||
|
## PAN-113093
|
||||||
|
|
||||||
|
Fixed an intermittent issue where, when the DNS Security cloud was not reachable, DNS responses had bad UDP checksums.
|
||||||
|
|
||||||
|
## PAN-111553
|
||||||
|
|
||||||
|
Fixed an issue on the Panorama management server where the "Include Device and Network Templates" setting (*Commit>Push to Devices>Edit Selections" or "Commit>Commit and Push>Edit Selections*) was disabled by default and caused your push attempts to fail. With this fix, your push will "Include Device and Network Templates" by default.
|
||||||
@@ -0,0 +1,45 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.11-h2
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-178814
|
||||||
|
|
||||||
|
Fixed an issue where autocommits failed when upgrading from a PAN-OS 8.1 release to a PAN-OS 9.1 release due to large configurations with a high number of policies with reference to IP addresses.
|
||||||
|
|
||||||
|
## PAN-176661
|
||||||
|
|
||||||
|
Fixed an issue in Simple Certificate Enrollment Protocol (SCEP) ([CVE-2021-3060](https://security.paloaltonetworks.com/CVE-2021-3060)).
|
||||||
|
|
||||||
|
## PAN-176655
|
||||||
|
|
||||||
|
A fix was made to address an OS command injection vulnerability in the PAN-OS CLI that enabled an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges ([CVE-2021-3061](https://security.paloaltonetworks.com/CVE-2021-3061)).
|
||||||
|
|
||||||
|
## PAN-158334
|
||||||
|
|
||||||
|
A fix was made to address an OS command injection vulnerability in the PAN-OS CLI that enabled an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges ([CVE-2021-3061](https://security.paloaltonetworks.com/CVE-2021-3061)).
|
||||||
|
|
||||||
|
## PAN-176653
|
||||||
|
|
||||||
|
A fix was made to address an OS command injection vulnerability in the PAN-OS web interface that enabled an authenticated administrator with permissions to use XML API to execute arbitrary OS commands to escalate privileges ([CVE-2021-3058](https://security.paloaltonetworks.com/CVE-2021-3058)).
|
||||||
|
|
||||||
|
## PAN-176618
|
||||||
|
|
||||||
|
A fix was made to address an OS command injection vulnerability in PAN-OS that existed when performing dynamic updates ([CVE-2021-3059](https://security.paloaltonetworks.com/CVE-2021-3059)).
|
||||||
|
|
||||||
|
## PAN-176461
|
||||||
|
|
||||||
|
Fixed an issue where a process (mdb) stopped responding after downgrading from a PAN-OS 9.1 release to an earlier release due to discrepancies in the mongodb process version.
|
||||||
|
|
||||||
|
To utilize this fix, first install a PAN-OS 9.0 release on the web interface, and then, prior to reboot, run the following CLI command: debug mongo clear instance mdb. Running this command removes any historical operational data (such as rule hit counts, monitoring data, and so on) collected on Panorama.
|
||||||
|
|
||||||
|
## PAN-176131
|
||||||
|
|
||||||
|
Fixed an issue where the Simple Network Management Protocol (SNMP) object identifier (OID) for panSessionCps did not show the correct session count.
|
||||||
|
|
||||||
|
## PAN-169173
|
||||||
|
|
||||||
|
Fixed an issue where, if you continuously performed partial commits of a configuration with a high number of Dynamic Address Groups, Panorama became unresponsive and commits were slower than expected.
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.11-h3
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Fixed a Denial-of-Service (DoS) vulnerability in the GlobalProtect portal and gateway ([CVE-2021-3063](https://security.paloaltonetworks.com/CVE-2021-3063)).
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.11-h4
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-202450
|
||||||
|
|
||||||
|
Fixed an issue where the device-client-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
|
||||||
|
|
||||||
|
## PAN-198372
|
||||||
|
|
||||||
|
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.11-h5
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-237935
|
||||||
|
|
||||||
|
Extended the offline PAN-DB, Panorama, and WildFire certificates which were previously set to expire on September 2, 2024.
|
||||||
|
|
||||||
|
## PAN-215576
|
||||||
|
|
||||||
|
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
|
||||||
@@ -0,0 +1,467 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.11
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## WF500-5509
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
WF-500 appliance only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where cloud inquiries were logged under the **SD-WAN** subtype.
|
||||||
|
|
||||||
|
## PAN-174448
|
||||||
|
|
||||||
|
Fixed an issue where Zero-Touch Provisioning (ZTP) configuration wasn't removed after disabling it, which resulted in predefined configurations to be loaded after a reboot.
|
||||||
|
|
||||||
|
## PAN-174326
|
||||||
|
|
||||||
|
A fix was made to address an OS command injection vulnerability in the PAN-OS web interface that enabled an authenticated administrator to execute arbitrary OS commands to escalate privileges ([CVE-2021-3050](https://security.paloaltonetworks.com/CVE-2021-3050)).
|
||||||
|
|
||||||
|
## PAN-173848
|
||||||
|
|
||||||
|
Fixed an issue where DNS Security web service was not reachable and retransmission did not occur.
|
||||||
|
|
||||||
|
## PAN-172490
|
||||||
|
|
||||||
|
Fixed an issue on firewalls in a high availability (HA) configuration where HA-2 links continuously flapped on HSCI interfaces after upgrading to PAN-OS 8.1.19.
|
||||||
|
|
||||||
|
## PAN-172464
|
||||||
|
|
||||||
|
Fixed an issue where unicast DHCP discover or request packets were silently dropped.
|
||||||
|
|
||||||
|
## PAN-171290
|
||||||
|
|
||||||
|
Fixed an issue where Panorama deployed in Google Cloud Platform (GCP) failed to the renew management server DHCP IP.
|
||||||
|
|
||||||
|
## PAN-171174
|
||||||
|
|
||||||
|
Console debug output was enhanced to address issues that led to a loss of SSH and web interface access.
|
||||||
|
|
||||||
|
## PAN-170936
|
||||||
|
|
||||||
|
Fixed an issue where the firewall egressed offloaded frames out of order after an explicit commit (**Commit** on the firewall or **Commit All Changes** on Panorama) or an implicit comment such as an Antivirus update, Dynamic Update, or WildFire update.
|
||||||
|
|
||||||
|
**Note** This issue persists for a network-related configuration and commit.
|
||||||
|
|
||||||
|
## PAN-170825
|
||||||
|
|
||||||
|
Fixed an issue where, when a partial **Preview Change** job failed, a process (configd) stopped responding.
|
||||||
|
|
||||||
|
## PAN-170740
|
||||||
|
|
||||||
|
Fixed an issue with the google-docs-uploading application that occurred if a Security policy rule was applied to a Security profile and traffic was decrypted.
|
||||||
|
|
||||||
|
## PAN-170314
|
||||||
|
|
||||||
|
Fixed an issue where PAN-DB URL cloud updates failed because a process (devsrvr) did not fetch serial numbers, which prevented the PAN_DB URL cloud from connecting after first deployment.
|
||||||
|
|
||||||
|
## PAN-170103
|
||||||
|
|
||||||
|
Fixed an issue where a process (ikemgr) stopped responding while making configuration changes. This issue occurred if Site-to-Site IPSec was using certification-based authentication.
|
||||||
|
|
||||||
|
## PAN-169793
|
||||||
|
|
||||||
|
Fixed an issue where using cookies to authenticate MacOS users didn't work due to the client agent not providing the phpsessionid set from the sent GlobalProtect messages during the connection. As a result, the firewall was unable to find and include the portal authentication cookie in the response message.
|
||||||
|
|
||||||
|
## PAN-169197
|
||||||
|
|
||||||
|
Fixed a rare issue where generating a tech support file caused the useridd process to stop responding.
|
||||||
|
|
||||||
|
## PAN-169064
|
||||||
|
|
||||||
|
Fixed an issue where the management CPU remained at 100% due to a large number of configured User-ID agents.
|
||||||
|
|
||||||
|
## PAN-168921
|
||||||
|
|
||||||
|
Fixed an issue in an HA active/active configuration where traffic with complete packets showed up as incomplete and were disconnected due to a non-session owner device closing the session prematurely.
|
||||||
|
|
||||||
|
## PAN-167989
|
||||||
|
|
||||||
|
Fixed a timing issue between downloading and installing threads that occurred when Panorama pushed content updates and the firewall fetched content updates simultaneously.
|
||||||
|
|
||||||
|
## PAN-167872
|
||||||
|
|
||||||
|
Fixed an issue related to a process (all_pktproc) that occurred in long-lived sessions that spanned two content upgrades.
|
||||||
|
|
||||||
|
## PAN-167858
|
||||||
|
|
||||||
|
Fixed an issue where a DNS Security inspection identified a TCP DNS request that had two requests in one segment as a malformed packet and dropped the packet.
|
||||||
|
|
||||||
|
## PAN-167805
|
||||||
|
|
||||||
|
Fixed an intermittent issue where traffic ingressing through a VPN tunnel failed to match predict session, which resulted in child sessions failing.
|
||||||
|
|
||||||
|
## PAN-167637
|
||||||
|
|
||||||
|
Fixed an issue where users connecting to the US East gateway encountered a delay in DNS responses.
|
||||||
|
|
||||||
|
## PAN-167266
|
||||||
|
|
||||||
|
Fixed an issue on multi-dataplane firewalls with high CPU use on dataplane 0 that caused an internal loop of forward/host sessions on the firewall.
|
||||||
|
|
||||||
|
## PAN-167099
|
||||||
|
|
||||||
|
Fixed a configuration management issue that resulted in a process (ikemgr) failing to recognize changes in subsequent commits.
|
||||||
|
|
||||||
|
## PAN-166836
|
||||||
|
|
||||||
|
Fixed an issue where session failed due to resource unavailability.
|
||||||
|
|
||||||
|
## PAN-166572
|
||||||
|
|
||||||
|
Fixed an issue where a process (configd) restarted when browsing policies on Panorama.
|
||||||
|
|
||||||
|
## PAN-166557
|
||||||
|
|
||||||
|
Fixed an issue where ElasticSearch didn't register to the masterd process when setting up a new Log Collector configuration.
|
||||||
|
|
||||||
|
## PAN-166081
|
||||||
|
|
||||||
|
Fixed an issue where role based admin users with tag disabled were unable to view applications under **Objects** > **Application**.
|
||||||
|
|
||||||
|
## PAN-165913
|
||||||
|
|
||||||
|
Fixed an issue on United States GlobalProtect portals where HTTP health checks failed and no authentication events occurred for about 10 minutes.
|
||||||
|
|
||||||
|
## PAN-165843
|
||||||
|
|
||||||
|
Fixed an issue on the firewalls where generating SCEP Certificates did not work when the value of a Relative Distinguished Name (RDN) in the subject string contained a space.
|
||||||
|
|
||||||
|
## PAN-165661
|
||||||
|
|
||||||
|
Fixed an issue in an HA active/active configuration where an administrative shutdown message was not sent to the BGP peer when the firewall went into a suspended state, which delayed convergence.
|
||||||
|
|
||||||
|
## PAN-165660
|
||||||
|
|
||||||
|
Fixed an issue where, in scenarios with Fragmented Session Initiation Protocol (SIP), where the first packet arrived out of order, bypassing App-ID and Content and Threat Detection (CTD). With this fix, the out-of-order packet is transmitted after it has been queued and processed by App-ID and CTD.
|
||||||
|
|
||||||
|
## PAN-165179
|
||||||
|
|
||||||
|
Fixed an issue where Panorama missed address group objects during a template configuration due to Panorama not sending the required strings for a query.
|
||||||
|
|
||||||
|
## PAN-165120
|
||||||
|
|
||||||
|
Fixed an issue where the Application Command Center (ACC) did not display data when the Device Group was set with **VSYS** in its name.
|
||||||
|
|
||||||
|
## PAN-165025
|
||||||
|
|
||||||
|
Fixed an issue where, when default interzone and intrazone Security policy rules were overwritten, the rules did not display hit counts.
|
||||||
|
|
||||||
|
## PAN-164422
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
A fix was made to address improper access control that enabled an attacker with authenticated access to GlobalProtect portals and GlobalProtect gateways to connect to the EC2 instance metadata endpoint for VM-Series firewalls hosted on Amazon Web Services (AWS) ([CVE-2021-3062](https://security.paloaltonetworks.com/CVE-2021-3062)).
|
||||||
|
|
||||||
|
## PAN-164431
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall rebooted into maintenance mode after installing a capacity license in FIPS-CC mode.
|
||||||
|
|
||||||
|
## PAN-164429
|
||||||
|
|
||||||
|
Fixed an issue where the Panorama web interface displayed an unavailable setting.
|
||||||
|
|
||||||
|
## PAN-164402
|
||||||
|
|
||||||
|
A CLI command was added to immediately disable or enable restarting the syslog-ng connection during an FQDN refresh IP address change.
|
||||||
|
|
||||||
|
## PAN-163800
|
||||||
|
|
||||||
|
Fixed an intermittent issue where the presence of an Anti-Spyware profile in a Security policy rule that matched DNS traffic caused DNS responses to be malformed in transit.
|
||||||
|
|
||||||
|
## PAN-163695
|
||||||
|
|
||||||
|
Fixed an issue where multiple dataplane process (all_task, flow_mgmt, flow_ctrl, and pktlog_forwarding) stopped responding and caused the dataplane to restart. This issue occurred when the firewall received unexpected packets during an SSL handshake when SSL inbound inspection was configured.
|
||||||
|
|
||||||
|
## PAN-162884
|
||||||
|
|
||||||
|
Fixed a rare issue where an external dynamic list (EDL) entry became corrupt due to an erroneous string being inserted while generating the list.
|
||||||
|
|
||||||
|
## PAN-161618
|
||||||
|
|
||||||
|
Fixed an issue where the commit time increased after upgrading from PAN-OS 9.0 to PAN-OS 9.1.
|
||||||
|
|
||||||
|
## PAN-161289
|
||||||
|
|
||||||
|
Fixed an issue where predict session didn't update the associated rules when Security policies shifted after a commit.
|
||||||
|
|
||||||
|
## PAN-161218
|
||||||
|
|
||||||
|
The following CLI commands were added to enable the customer to set the dataplane utilization limit: debug dataplane show ctd wildfire max -debug dataplane set ctd wildfire max <0-5000> The default setting is the recommended value of 500; a value of 0 removes dataplane CTD limits.
|
||||||
|
|
||||||
|
## PAN-161208
|
||||||
|
|
||||||
|
Fixed an issue where the **Service Route Configuration** (**Device > Setup > Services > Service Route Configuration**) was unchangeable when the web interface language was set to a language other than English.
|
||||||
|
|
||||||
|
## PAN-160831
|
||||||
|
|
||||||
|
Fixed an intermittent issue where importing a new firewalls configuration into Panorama failed due to conflicting virtual system (vsys) names, even when the **Device Group Name Prefix** was used to make the name unique.
|
||||||
|
|
||||||
|
## PAN-160544
|
||||||
|
|
||||||
|
Fixed an issue where a user was able to clone, edit, and commit a configuration that had been locked by another user.
|
||||||
|
|
||||||
|
## PAN-160254
|
||||||
|
|
||||||
|
Fixed a memory leak issue related to a process (reportd) where memory was not freed after an ElasticSearch request.
|
||||||
|
|
||||||
|
## PAN-160253
|
||||||
|
|
||||||
|
Fixed an issue where only one medium-severity system log was generated if either the EDL file wasn't updated at the remote end or the downloaded file wasn't a text file.
|
||||||
|
|
||||||
|
## PAN-160150
|
||||||
|
|
||||||
|
Fixed an intermittent issue where, when a race condition occurred, a process (rasmgr) stopped responding, which caused GlobalProtect user authentication failure.
|
||||||
|
|
||||||
|
## PAN-159954
|
||||||
|
|
||||||
|
Fixed an issue where scheduled configuration bundle exports via Secure Copy (SCP) displayed following error message in the system log: Failed to export config bundle after already displaying a Success message in the log.
|
||||||
|
|
||||||
|
## PAN-159936
|
||||||
|
|
||||||
|
Fixed an issue where BGP routing stopped advertising a redistributed route when a similar new redistributed route was configured.
|
||||||
|
|
||||||
|
## PAN-159922
|
||||||
|
|
||||||
|
Fixed an issue where, when the DNS Security feature was enabled, Linux clients experienced a delay in resolving domain names if the clients simultaneously attempted A and AAAA resolution.
|
||||||
|
|
||||||
|
## PAN-159700
|
||||||
|
|
||||||
|
Fixed an issue where importing PAN-TRAPS.my to the SNMP manager caused the following error to display: Registration failed, registration failed, because there are unreferenced definition names in the MIB file.
|
||||||
|
|
||||||
|
## PAN-159536
|
||||||
|
|
||||||
|
Fixed an issue where, when the CLI command oscp-exclude-nonce-yes was enabled for a certificate profile, a nonce value was still included in the Online Certificate Status Protocol (OCSP) request.
|
||||||
|
|
||||||
|
## PAN-159435
|
||||||
|
|
||||||
|
Fixed an issue where SD-WAN routes weren't withdrawn after a bootup when all SD-WAN tunnels were down.
|
||||||
|
|
||||||
|
## PAN-159293
|
||||||
|
|
||||||
|
Fixed an issue where the Certification Revocation List (CRL) in Distinguished Encoding Rules (DER) format incorrectly returned errors despite being able to successfully pull the CRL to verify that the syslog server certificate was still valid.
|
||||||
|
|
||||||
|
## PAN-159122
|
||||||
|
|
||||||
|
Fixed an issue where, when a new tag was created, a custom application with the same name was also created.
|
||||||
|
|
||||||
|
## PAN-158958
|
||||||
|
|
||||||
|
Fixed an issue where the debug sslmgr view crl command failed when ampersand (&) character was included in the URL for the certificate revocation list (CRL).
|
||||||
|
|
||||||
|
## PAN-158654
|
||||||
|
|
||||||
|
Fixed a memory leak issue in the management server process.
|
||||||
|
|
||||||
|
## PAN-158649
|
||||||
|
|
||||||
|
Fixed an issue where commits to the Prisma Access Remote networks from Panorama were failing when the management server on the cloud firewall failed to exit cleanly and reported the following error: pan_check_cert_status(pan_crl_ocsp.c:284): sysd write failed (TIMEOUT)
|
||||||
|
|
||||||
|
## PAN-158450
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where, for SNMPv2-MIB:sysServices, snmpwalk returned the following error message: No Such Instance currently exists at this OID.
|
||||||
|
|
||||||
|
## PAN-158439
|
||||||
|
|
||||||
|
Fixed a memory leak on the management server process on Firewall.
|
||||||
|
|
||||||
|
## PAN-158372
|
||||||
|
|
||||||
|
Fixed a buffer overflow issue related to the useridd process.
|
||||||
|
|
||||||
|
## PAN-158337
|
||||||
|
|
||||||
|
Fixed an issue where warnings displayed during a commit or validate when BGP peers used in an import/export rule were disabled.
|
||||||
|
|
||||||
|
## PAN-158043
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped packets due to a race condition.
|
||||||
|
|
||||||
|
## PAN-157938
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls with multiple DHCP interfaces only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where leases renewed more quickly than needed, which caused unnecessary SPF recalculations.
|
||||||
|
|
||||||
|
## PAN-157835
|
||||||
|
|
||||||
|
Fixed an issue where DNS Proxy rules that contained uppercase characters were not normalized to lowercase, which prevented the rules from being matched.
|
||||||
|
|
||||||
|
## PAN-157725
|
||||||
|
|
||||||
|
Fixed an issue where, when decryption was enabled, the following error was displayed: Cannot contact reCAPTCHA. Check your connection and try again.
|
||||||
|
|
||||||
|
## PAN-157715
|
||||||
|
|
||||||
|
Fixed an intermittent issue where SMB file transfer operations failed due to packet drops that were caused by the Content and Threat Detection (CTD) queue filling up quickly. This fix introduces a new CLI command which, when enabled, prevents these failures: set system setting ctd nonblocking-pattern-match-qsizecheck [enable|disable].
|
||||||
|
|
||||||
|
## PAN-157710
|
||||||
|
|
||||||
|
Fixed an issue where admin users with custom roles were unable to create VLANs.
|
||||||
|
|
||||||
|
## PAN-157620
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls deployed in Amazon Web Services (AWS) instance types M5 and C5 only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where a Panorama Virtual Appliance in an HA configuration entered a suspended state due to a virtual machine (VM) memory size mismatch.
|
||||||
|
|
||||||
|
## PAN-157518
|
||||||
|
|
||||||
|
Fixed an issue where using tags to target a device group in a Security policy rule did not work, and the rule was displayed in all device groups (**Preview Rules**).
|
||||||
|
|
||||||
|
## PAN-157459
|
||||||
|
|
||||||
|
Fixed an issue where, after updating an address in an Address Group, a commit did not update GlobalProtect split tunnel access routes.
|
||||||
|
|
||||||
|
## PAN-157089
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama appliances in Log Collector mode only
|
||||||
|
```
|
||||||
|
|
||||||
|
The following CLI command was added to disable No valid device certificate found messages in the system log: debug skip-cert-renewal-check-syslog yes.
|
||||||
|
|
||||||
|
## PAN-157027
|
||||||
|
|
||||||
|
Fixed an issue where, when stateless GTP-U traffic hit a multi-dataplane firewall, an inter-dataplane fragmentation loop occurred, which caused high dataplane resource usage.
|
||||||
|
|
||||||
|
## PAN-157026
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not display unified logs.
|
||||||
|
|
||||||
|
## PAN-156766
|
||||||
|
|
||||||
|
Fixed an issue where, after upgrading to PAN-OS 9.1.5, VM-Series firewalls in HA configurations went into a non-functional state due to a virtual machine (VM) license mismatch.
|
||||||
|
|
||||||
|
## PAN-156482
|
||||||
|
|
||||||
|
Fixed a packet buffer issue where HTTP2 packets were held for category lookup and the HTTP request was across multiple packets.
|
||||||
|
|
||||||
|
## PAN-156393
|
||||||
|
|
||||||
|
Fixed an issue where NetFlow updates were sent without honoring the configured active timeout value.
|
||||||
|
|
||||||
|
## PAN-156388
|
||||||
|
|
||||||
|
Fixed an issue where a process (useridd) stopped responding while attempting to remove all HIP reports on the disk.
|
||||||
|
|
||||||
|
## PAN-155563
|
||||||
|
|
||||||
|
Fixed an intermittent issue where the Panorama Cloud Services plugin reported the following error for its Cortex Data Lake status: Failed to validate server certificate for endpoint api.paloaltonetworks.com.
|
||||||
|
|
||||||
|
## PAN-154905
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama appliances on PAN-OS 10.0 releases only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue with Security policy rule configuration where, in the **Source** and **Destination** tabs, the **Query Traffic** setting was not available for Address Groups.
|
||||||
|
|
||||||
|
## PAN-154876
|
||||||
|
|
||||||
|
Fixed an issue where the web interface did not display **Release Date** when updating the dynamic updates manually.
|
||||||
|
|
||||||
|
## PAN-153382
|
||||||
|
|
||||||
|
Fixed an issue where the per-minute resource monitor was three minutes behind.
|
||||||
|
|
||||||
|
## PAN-153308
|
||||||
|
|
||||||
|
Fixed an issue that caused the mouse cursor to remove focus from the search bar when hovering over a hyperlink inside of a cell menu (e.g., source zone, source address, destination zone, destination address, etc.).
|
||||||
|
|
||||||
|
## PAN-153113
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect gateway failed with the following error message: gateway does not exist.
|
||||||
|
|
||||||
|
## PAN-151469
|
||||||
|
|
||||||
|
Fixed an issue where packets were dropped unexpectedly due to errors parsing the IP version field.
|
||||||
|
|
||||||
|
## PAN-149911
|
||||||
|
|
||||||
|
Fixed an issue where URL filtering logs for credential phishing displayed a slash character (/) in the URL field.
|
||||||
|
|
||||||
|
## PAN-149853
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where the **loc** attribute was not set as **shared** when creating dynamic-address-group-specific configurations during a Panorama commit.
|
||||||
|
|
||||||
|
## PAN-147684
|
||||||
|
|
||||||
|
Fixed an issue where a daemon (ikemgr) repeatedly restarted, which resulted in the firewall rebooting.
|
||||||
|
|
||||||
|
## PAN-143426
|
||||||
|
|
||||||
|
Fixed a memory leak issue where a process (devsrvr) restarted due to the memory limit being exceeded.
|
||||||
|
|
||||||
|
## PAN-141494
|
||||||
|
|
||||||
|
Fixed an issue with the group-mapping mode credential detection feature that failed to block users when logging in using corporate credentials.
|
||||||
|
|
||||||
|
## PAN-138859
|
||||||
|
|
||||||
|
Fixed an issue on Panorama appliances where exporting or pushing a device configuration bundle to PA-5000, PA-5200, PA-7000, or PA-7000b series firewalls failed with the following error message: Config bundle is too large to be exported to device.
|
||||||
|
|
||||||
|
## PAN-138727
|
||||||
|
|
||||||
|
A fix was made to address a time-of-check to time-of-use (TOCTOU) race condition in the PAN-OS web interface that enabled an authenticated administrator with permission to upload plugins to execute arbitrary code with root user privileges ([CVE-2021-3054](https://security.paloaltonetworks.com/CVE-2021-3054)).
|
||||||
|
|
||||||
|
## PAN-136505
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 Series and PA-7000 Series firewalls with Log Processing Cards (LPCs) only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the log quota (**Logging and Reporting Settings > Session Log Storage > Session Log Quota)** exceeded 100%.
|
||||||
|
|
||||||
|
## PAN-134390
|
||||||
|
|
||||||
|
Fixed an issue where commits didn't complete due to a race condition in the log receiver.
|
||||||
|
|
||||||
|
## PAN-133782
|
||||||
|
|
||||||
|
Fixed an issue where Panorama was not accessible via the web interface due to insufficient available disk space in the opt/mongobuffer partition, which caused the mongodb process to stop responding.
|
||||||
|
|
||||||
|
## PAN-130003
|
||||||
|
|
||||||
|
Fixed an issue where the show logging-status CLI command did not display any output on the firewall even though the firewall was connected to Panorama and was successfully forwarding logs.
|
||||||
|
|
||||||
|
## PAN-124956
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where packet buffer protection was not supported.
|
||||||
|
|
||||||
|
## PAN-118846
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to locally override a user-group-mapping setting pushed from Panorama.
|
||||||
|
|
||||||
|
## PAN-116515
|
||||||
|
|
||||||
|
Fixed an issue where IKE Gateway configurations with different crypto profiles on the same IP address with dynamic peers failed with the following error message: IKEv1 gateway should use the same crypto profiles configured on the same interface or local IP address.
|
||||||
|
|
||||||
|
With this fix, you are able to configure IKE Gateways with different crypto profiles on the same IP address with dynamic peers when IKEv1 auto mode is applied.
|
||||||
|
|
||||||
|
## PAN-108197
|
||||||
|
|
||||||
|
Fixed an issue in a multi-tenant deployment where, when a user-made configuration changed, the changes were unable to be committed, and the web interface displayed the following error message: No pending change to commit. With this fix, users with multiple access domains will now be able to see plugin information.
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.12-h3
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-184592
|
||||||
|
|
||||||
|
A fix was made to address a remote code execution vulnerability in Elasticsearch included with Panorama management servers known as Log4Shell ([CVE-2021-44228](https://security.paloaltonetworks.com/CVE-2021-44228)).
|
||||||
|
|
||||||
|
## PAN-183767
|
||||||
|
|
||||||
|
Fixed an issue where downloading Dynamic Updates files failed when connected to the static update server at us-static.updates.paloaltonetworks.com.
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.12-h4
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-184445
|
||||||
|
|
||||||
|
Fixed an issue where, after upgrading Panorama and enabling **Share Unused Address and Service Objects with Devices**, address objects using tags to dynamic address groups were removed after a full commit.
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.12-h7
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-237935
|
||||||
|
|
||||||
|
Extended the offline PAN-DB, Panorama, and WildFire certificates which were previously set to expire on September 2, 2024.
|
||||||
|
|
||||||
|
## PAN-215576
|
||||||
|
|
||||||
|
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
|
||||||
@@ -0,0 +1,422 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.12
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-181076
|
||||||
|
|
||||||
|
Fixed an issue where commit failures occurred when an External Dynamic List (EDL) that contained many IP addresses was used in a Security policy.
|
||||||
|
|
||||||
|
## PAN-179750
|
||||||
|
|
||||||
|
A CLI command was added to set the virtual memory limit in dedicated log collectors.
|
||||||
|
|
||||||
|
## PAN-179581
|
||||||
|
|
||||||
|
Fixed an issue on firewalls in high availability configurations where a process (brdagent) stopped responding on a suspended active peer, which caused the suspended firewall to continue sending traffic.
|
||||||
|
|
||||||
|
## PAN-179356
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
5200-Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where configuration commits failed due to the dataplane running out of memory in the policy cache.
|
||||||
|
|
||||||
|
## PAN-178953
|
||||||
|
|
||||||
|
Fixed an issue with the GlobalProtect Clientless VPN where, when an application sent a negative max age value on a cookie, part of the cookie was retained by PAN-OS and used for the subsequent connection on the user session.
|
||||||
|
|
||||||
|
## PAN-178363
|
||||||
|
|
||||||
|
Fixed an issue where a process (mgmtsrvr) wasn't restarted after the virtual memory limit was exceeded.
|
||||||
|
|
||||||
|
## PAN-176862
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall didn't attempt to connect to a log collector when the management IP address used DHCP.
|
||||||
|
|
||||||
|
## PAN-176461
|
||||||
|
|
||||||
|
Fixed an issue where a process (mdb) stopped responding after downgrading from a PAN-OS 9.1 release to an earlier release due to discrepancies in the mongodb process version.
|
||||||
|
|
||||||
|
**Note**: To utilize this fix, first install a PAN-OS 9.0 release on the web interface, and then, prior to reboot, run the following CLI command: debug mongo clear instance mdb.
|
||||||
|
|
||||||
|
## PAN-176364
|
||||||
|
|
||||||
|
Fixed an issue where multiple operations (such as a commit or dynamic updates) failed due to a race condition in the cryptod fallback mechanism.
|
||||||
|
|
||||||
|
## PAN-176131
|
||||||
|
|
||||||
|
Fixed an issue where the Simple Network Management Protocol (SNMP) object identifier (OID) for panSessionCps did not show the correct session count.
|
||||||
|
|
||||||
|
## PAN-176032
|
||||||
|
|
||||||
|
Fixed an issue where a process (authd) process stopped responding, which caused authentication to fail.
|
||||||
|
|
||||||
|
## PAN-175934
|
||||||
|
|
||||||
|
Fixed an issue where packed-based zone protection settings (such as Strict IP Address Check) were not applied to return traffic.
|
||||||
|
|
||||||
|
## PAN-175652
|
||||||
|
|
||||||
|
Fixed an issue where SSL decryption failed for websites when they were accessed from Google Chrome version 92 or higher.
|
||||||
|
|
||||||
|
## PAN-175307
|
||||||
|
|
||||||
|
Fixed an issue where Panorama commits were slower than expected and the configd process stopped responding due to a memory leak.
|
||||||
|
|
||||||
|
## PAN-174894
|
||||||
|
|
||||||
|
Fixed an issue where, when the time-to-live (TTL) value for symmetric MAC entries weren't updated to other dataplanes and HA peers, timeouts occurred for traffic using policy-based forwarding (PBF) with symmetric returns.
|
||||||
|
|
||||||
|
## PAN-174886
|
||||||
|
|
||||||
|
Fixed an issue where scheduled customer reports displayed as empty when the configured destination was an address group.
|
||||||
|
|
||||||
|
## PAN-174864
|
||||||
|
|
||||||
|
Fixed an issue on the Panorama interface where **Deploying Master Key** to low-end devices resulted in a **Failed to communicate** message, even when the new master key was updated on the end device. This issue occurred because a master key deployment had insufficient time to process due to a connection timeout.
|
||||||
|
|
||||||
|
## PAN-174161
|
||||||
|
|
||||||
|
Fixed an issue in Panorama that occurred when attempting to **disable override** on an object from a child device group did not work after cloning and renaming the object.
|
||||||
|
|
||||||
|
## PAN-174055
|
||||||
|
|
||||||
|
Fixed an issue where SNMP readings reported as 0 for dataplane interface packet statistics for Amazon Web Services (AWS) m5n.4xlarge instance types. This issue occurred because the physical port counters read from MAC addresses were reported as 0.
|
||||||
|
|
||||||
|
## PAN-173978
|
||||||
|
|
||||||
|
Fixed an issue where the Elasticsearch process continuously restarted if zero-length files were present.
|
||||||
|
|
||||||
|
## PAN-173893
|
||||||
|
|
||||||
|
Fixed a memory leak issue related to the (useridd) process that occurred when group mapping is enabled.
|
||||||
|
|
||||||
|
## PAN-173753
|
||||||
|
|
||||||
|
Fixed an issue where a bar or point on a **Network Monitor** graph had to be clicked more than once to properly redirect to the corresponding ACC report.
|
||||||
|
|
||||||
|
## PAN-173545
|
||||||
|
|
||||||
|
Fixed an issue where exporting a device summary to CSV failed and displayed the following error message: Error while exporting.
|
||||||
|
|
||||||
|
## PAN-173509
|
||||||
|
|
||||||
|
Fixed an issue where Superuser administrators with read-only privileges (**Device > Administrators and Panorama > Administrators**) were unable to view the hardware ACL blocking setting and duration in the CLI using the following commands:
|
||||||
|
|
||||||
|
- show system setting hardware-acl-blocking-enable
|
||||||
|
- show system setting hardware-acl-blocking-duration
|
||||||
|
|
||||||
|
## PAN-173157
|
||||||
|
|
||||||
|
Fixed an issue with the HA1 monitor hold timer where the configured value was not assigned to the HA1 backup interface, which used the default hold timer (3000 milliseconds), which resulted in failover events taking longer than expected.
|
||||||
|
|
||||||
|
## PAN-173076
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama appliances in FIPS mode only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the FIPS Panorama / FIPS firewall schema didn't prune non-FIPS options from the GlobalProtect Clientless VPN.
|
||||||
|
|
||||||
|
## PAN-172834
|
||||||
|
|
||||||
|
Fixed a memory leak issue related to the useridd process that occurred when processing IP-address-to-username mappings.
|
||||||
|
|
||||||
|
## PAN-172783
|
||||||
|
|
||||||
|
Fixed an issue on an HA active/passive configuration where old GPRS tunneling protoc0l (GTP-U) tunnel sessions did not sync to the passive firewall during some upgrades, such as upgrading from a PAN-OS 8.1 release version to a 9.0 release version or upgrading from a 9.0 release version to a 9.1 release version.
|
||||||
|
|
||||||
|
## PAN-172775
|
||||||
|
|
||||||
|
Fixed an issue in Panorama where the configd process stopped responding due to a memory issue with memcpy bson_append.
|
||||||
|
|
||||||
|
## PAN-172748
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where a process (all_task) stopped responding.
|
||||||
|
|
||||||
|
## PAN-172396
|
||||||
|
|
||||||
|
Fixed a memory leak issue related to the useridd process.
|
||||||
|
|
||||||
|
## PAN-172324
|
||||||
|
|
||||||
|
Fixed an issue on the Panorama web interface where custom vulnerability signature IDs weren't populated in the drop-down when creating a custom combination signature.
|
||||||
|
|
||||||
|
## PAN-172316
|
||||||
|
|
||||||
|
Fixed an issue where the internal interface flow control that caused the monitoring process to incorrectly determine the interface to be malfunctioning.
|
||||||
|
|
||||||
|
## PAN-172200
|
||||||
|
|
||||||
|
Fixed an issue where a process (configd) restarted due to memory corruption in the show dynamic-address-group CLI command during commits, commit and push operations, and high availability Panorama syncs.
|
||||||
|
|
||||||
|
## PAN-171696
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-800 and PA-400 Series firewalls and PA-220 firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the management plane CPU was incorrectly reported to be high.
|
||||||
|
|
||||||
|
## PAN-171367
|
||||||
|
|
||||||
|
Fixed an issue in active/active HA configuration where session disconnected during an upgrade from a PAN-OS 9.0 release to a PAN-OS 9.1 release.
|
||||||
|
|
||||||
|
## PAN-171203
|
||||||
|
|
||||||
|
Fixed an issue in an HA configuration where, when one firewall was active and its peer was in a suspended state, the suspended firewall continued to send traffic, which triggered the detection of duplicate MAC addresses.
|
||||||
|
|
||||||
|
## PAN-171159
|
||||||
|
|
||||||
|
Fixed a memory leak on the configd process on Panorama caused during multi-clone operations for rules.
|
||||||
|
|
||||||
|
## PAN-170936
|
||||||
|
|
||||||
|
Fixed an issue where the firewall egressed offloaded frames out of order after an explicit commit (**Commit** on the firewall or **Commit All Changes** on Panorama) or an implicit comment such as an Antivirus update, Dynamic Update, or WildFire update.
|
||||||
|
|
||||||
|
**Note** This issue persists for a network-related configuration and commit.
|
||||||
|
|
||||||
|
## PAN-170595
|
||||||
|
|
||||||
|
Fixed an issue with Content and Threat Detection where traffic patterns created a bus error, which caused the all_pktproc process to stop responding and the dataplane to restart.
|
||||||
|
|
||||||
|
## PAN-170466
|
||||||
|
|
||||||
|
Fixed an memory reference issue related to the devsrvr process that caused the process to stop responding.
|
||||||
|
|
||||||
|
## PAN-169899
|
||||||
|
|
||||||
|
Fixed an issue on firewalls with offload processors where the ECMP forced symmetric return feature didn't work for CRE traffic after the session was offloaded.
|
||||||
|
|
||||||
|
## PAN-169347
|
||||||
|
|
||||||
|
Fixed an issue where a process (authd) stopped responding due to an invalid null pointer.
|
||||||
|
|
||||||
|
## PAN-169300
|
||||||
|
|
||||||
|
Debug logs were added to troubleshoot WildFire submission issues.
|
||||||
|
|
||||||
|
## PAN-169173
|
||||||
|
|
||||||
|
Fixed an issue where, if you continuously performed partial commits of a configuration with a high number of Dynamic Address Groups, Panorama became unresponsive and commits were slower than expected.
|
||||||
|
|
||||||
|
## PAN-168261
|
||||||
|
|
||||||
|
Fixed a cosmetic issue where the WildFire submission log displayed the sha256 of the original email link.
|
||||||
|
|
||||||
|
## PAN-168189
|
||||||
|
|
||||||
|
Fixed an issue where, even when there was active multicast traffic, the firewall sent Protocol Independent Multicast (PIM) prune messages.
|
||||||
|
|
||||||
|
## PAN-167560
|
||||||
|
|
||||||
|
Fixed an issue where the Panorama appliance didn't return inherited device group locations pertaining to Security policies for REST API queries.
|
||||||
|
|
||||||
|
## PAN-167329
|
||||||
|
|
||||||
|
Fixed an issue where Zero Touch Provisioning (ZTP) flow did not complete.
|
||||||
|
|
||||||
|
## PAN-167115
|
||||||
|
|
||||||
|
Fixed an issue where, after upgrading to 10.0.3, admin sessions on Panorama were not logged out after the idle timeout expired.
|
||||||
|
|
||||||
|
## PAN-167087
|
||||||
|
|
||||||
|
Fixed an issue where the focus was not set on the free text field when requesting a token code on the Authentication Portal.
|
||||||
|
|
||||||
|
## PAN-166686
|
||||||
|
|
||||||
|
Fixed an issue where EDNS responses dropped when the original request was DNS.
|
||||||
|
|
||||||
|
## PAN-166202
|
||||||
|
|
||||||
|
Fixed an issue with an extra character in HTTP Strict Transport Security (HSTS) regression tests when accessing the GlobalProtect gateway.
|
||||||
|
|
||||||
|
## PAN-166180
|
||||||
|
|
||||||
|
Fixed an issue with snmpv3 trap not processed by snmptrap receiver after firewall reboot.
|
||||||
|
|
||||||
|
## PAN-166091
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped policy-based forwarding (PBF) keepalive responses.
|
||||||
|
|
||||||
|
## PAN-165433
|
||||||
|
|
||||||
|
Fixed an intermittent issue where Cortex Data Lake failed to reconnect after a disconnect if a management IP address used for logging had an IP address assignment type of DHCP.
|
||||||
|
|
||||||
|
## PAN-165147
|
||||||
|
|
||||||
|
Fixed an issue where, when there was a high volume of traffic for sessions with **Application Block Pages** enabled, other regular packets were dropped.
|
||||||
|
|
||||||
|
## PAN-162374
|
||||||
|
|
||||||
|
Fixed an issue where the firewall rebooted unexpectedly and displayed the following message: Reboot SYSTEM REBOOT Masterd Initiated.
|
||||||
|
|
||||||
|
## PAN-162174
|
||||||
|
|
||||||
|
Fixed an issue where, when the firewall received a configuration from Panorama with no URL category, it was automatically configured as **Any**.
|
||||||
|
|
||||||
|
## PAN-161964
|
||||||
|
|
||||||
|
Fixed an issue where email header from fields in threat logs were truncated due to line folding in the original message.
|
||||||
|
|
||||||
|
## PAN-161940
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not honor the peer RX interval timeout in a Bidirectional Forwarding Detection (BFD) INIT state.
|
||||||
|
|
||||||
|
## PAN-161726
|
||||||
|
|
||||||
|
Fixed an issue where the show high-availability all output incorrectly displayed the VM-Series firewall license type on physical firewalls.
|
||||||
|
|
||||||
|
## PAN-161496
|
||||||
|
|
||||||
|
Fixed an issue when calculating the incremental checksum after a post-NAT translation where the arguments to pan_in_cksm32_diff overflowed the 32-bit integer.
|
||||||
|
|
||||||
|
## PAN-161031
|
||||||
|
|
||||||
|
Fixed an issue where authentication via LDAP server failed in FIPS-CC mode when the LDAP server profile was configured with the root certificate chain and **Verify server certificate for SSL sessions** options enabled.
|
||||||
|
|
||||||
|
## PAN-160708
|
||||||
|
|
||||||
|
Fixed an issue where the dataplane restarted after configuring a **deny_all** policy.
|
||||||
|
|
||||||
|
## PAN-158931
|
||||||
|
|
||||||
|
Fixed an issue where the email header subject field in the threat logs were truncated due to line folding in the original message.
|
||||||
|
|
||||||
|
## PAN-158753
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama virtual appliances in Legacy mode only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where GlobalProtect logs were not forwarded to the external syslog server over TCP.
|
||||||
|
|
||||||
|
## PAN-158056
|
||||||
|
|
||||||
|
Fixed an issue where DDNS updates generated contradictory system logs, the first displaying that the update failed with critical severity and the second displaying that the update was successful.
|
||||||
|
|
||||||
|
## PAN-157365
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7050 firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where a process (all_pktproc) stopped responding after an upgrade.
|
||||||
|
|
||||||
|
## PAN-156478
|
||||||
|
|
||||||
|
Fixed an issue where a process (allpktproc) restarted while processing SMTP traffic.
|
||||||
|
|
||||||
|
## PAN-155448
|
||||||
|
|
||||||
|
Fixed an issue where credential detection didn't work in IP address-to-username mapping mode because the firewall compared the unnormalized IP-address-to-username mapping format to the normalized username extracted from the payload where the username and password were submitted.
|
||||||
|
|
||||||
|
## PAN-154305
|
||||||
|
|
||||||
|
Fixed an issue where a process (mgmtsrvr) stopped responding when a license fetch operation was performed.
|
||||||
|
|
||||||
|
## PAN-153527
|
||||||
|
|
||||||
|
Fixed an issue where DNS security wasn't triggered when the DNS Security profile was incorrectly internally duplicated to a null DNS Security profile.
|
||||||
|
|
||||||
|
## PAN-151264
|
||||||
|
|
||||||
|
Fixed an issue where using the ampersand (&) character in URLs submitted via XML API caused an error.
|
||||||
|
|
||||||
|
## PAN-150848
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped TCP FIN traffic due to the server-to-client FIN traffic being out of order.
|
||||||
|
|
||||||
|
## PAN-150445
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not translate IP addresses in Layer 7 payloads as per NAT translation for Oracle Application Server traffic.
|
||||||
|
|
||||||
|
## PAN-149314
|
||||||
|
|
||||||
|
Fixed an issue where lookup of a security rule with a custom URL category on a multi-virtual system (vsys) failed when vsys<id>+ was not in the beginning the category name.
|
||||||
|
|
||||||
|
## PAN-148554
|
||||||
|
|
||||||
|
Fixed an issue where the user was able to bypass URL credential phishing by changing the username from lower case to upper case.
|
||||||
|
|
||||||
|
## PAN-147256
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls in HA configurations only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where connections to the SafeNet hardware security module (HSM) were lost after upgrading to a new major PAN-OS release.
|
||||||
|
|
||||||
|
## PAN-147228
|
||||||
|
|
||||||
|
Fixed an issue where an application's domain name didn't resolve if the cache was disabled on the DNS Proxy object being used in the GlobalProtect Clientless VPN.
|
||||||
|
|
||||||
|
## PAN-145833
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall stopped recording dataplane diagnostic data in dp-monitor.log after a few hours of uptime.
|
||||||
|
|
||||||
|
## PAN-144340
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where some slots in the firewall did not get registered as up in a process (useridd), which caused the process to ignore IP address-to-user mappings to those slots.
|
||||||
|
|
||||||
|
## PAN-141454
|
||||||
|
|
||||||
|
Fixed an issue where the output of the CLI command show running resource-monitor ingress-backlogs displayed an incorrect total utilization value.
|
||||||
|
|
||||||
|
## PAN-141037
|
||||||
|
|
||||||
|
Fixed an issue where Windows-1252 encoded filenames triggered an Unknown Binary File (52081) type signature.
|
||||||
|
|
||||||
|
## PAN-129147
|
||||||
|
|
||||||
|
Fixed an intermittent issue on the web interface where new threat IDs did not appear under **Exception** settings (**Objects > Security Profiles > Anti-Spyware > Exceptions** or **Objects > Security Profiles > Vulnerability Protection > Exceptions**).
|
||||||
|
|
||||||
|
## PAN-128590
|
||||||
|
|
||||||
|
Fixed an issue where connection collisions occurred between BGP peers.
|
||||||
|
|
||||||
|
## PAN-123935
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where packets with a specific MAC address were misinterpreted as 802.1QA tunneled packets, which resulted in incorrect VLAN tags that caused the packets to be dropped.
|
||||||
|
|
||||||
|
## PAN-119198
|
||||||
|
|
||||||
|
Fixed an issue where ECMP strict-source-path did not work with IPSec.
|
||||||
|
|
||||||
|
## PAN-113046
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where a process (*brdagent*) stopped responding, which caused the management plane to stop responding.
|
||||||
|
|
||||||
|
## PAN-112674
|
||||||
|
|
||||||
|
Fixed an issue where an escape ( \ ) character was added to HTTP logs when a log contained a comma.
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.13-h1
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-187151
|
||||||
|
|
||||||
|
Fixed an issue where tunnel-monitoring interface was incorrectly shown as up instead of down.
|
||||||
|
|
||||||
|
## PAN-186937
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped packets decrypted using the SSL Decryption feature and Encapsulating Security Payload (ESP) IPSec packets that originated from the same firewall. This occurred when **Strict IP Address Check** was enabled in the zone protection profile (**Packet Based Attack** > **IP Drop**) and the packet's source IP address was the same as the egress interface address.
|
||||||
|
|
||||||
|
## PAN-171104
|
||||||
|
|
||||||
|
Fixed an issue where a race-condition check returned a false negative, which caused a process (all_task) to stop responding and generate a core file.
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.13-h3
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-190175
|
||||||
|
|
||||||
|
A fix was made to address an OpenSSL infinite loop vulnerability in the PAN-OS software ([CVE-2022-0778](https://security.paloaltonetworks.com/CVE-2022-0778)).
|
||||||
|
|
||||||
|
## PAN-190223
|
||||||
|
|
||||||
|
A fix was made to address an OpenSSL infinite loop vulnerability in the PAN-OS software ([CVE-2022-0778](https://security.paloaltonetworks.com/CVE-2022-0778)).
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.13-h4
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-202450
|
||||||
|
|
||||||
|
Fixed an issue where the device-client-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
|
||||||
|
|
||||||
|
## PAN-198372
|
||||||
|
|
||||||
|
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
|
||||||
|
|
||||||
|
## PAN-193004
|
||||||
|
|
||||||
|
Fixed an issue where /opt/pancfg partition utilization reached 100%, which caused access to the Panorama web interface to fail.
|
||||||
@@ -0,0 +1,31 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.14-h1
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-194395
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped all decrypted outbound (SSL Forward Proxy) HTTP/2 traffic and cleartext HTTP/2 traffic after an upgrade to PAN-OS 9.1.14, which caused websites that used HTTP/2 to become inaccessible.
|
||||||
|
|
||||||
|
## PAN-191463
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not handle packets at Fastpath when the interface pointer was null.
|
||||||
|
|
||||||
|
## PAN-188036
|
||||||
|
|
||||||
|
Fixed an issue where SIP TCP sequence numbers were calculated incorrectly when SIP cleartext proxy was disabled.
|
||||||
|
|
||||||
|
## PAN-182244
|
||||||
|
|
||||||
|
Fixed an issue where Session Initiation Protocol (SIP) REGISTER packets did not get transmitted when application-level gateway (ALG) and SIP Proxy were enabled, which caused a SIP-registration issue in environments where TCP retransmission occurred.
|
||||||
|
|
||||||
|
## PAN-174347
|
||||||
|
|
||||||
|
Fixed an issue where sequence numbers were calculated incorrectly for traffic that was subject to SIP ALG when SIP TCP Clear Text Proxy was disabled.
|
||||||
|
|
||||||
|
## PAN-89479
|
||||||
|
|
||||||
|
Fixed an issue in SIP over TCP and HTTP header insertion features where PAN-OS built-in clear text proxy inserted extra data into the TCP stream when the initial data packets were received out of order.
|
||||||
@@ -0,0 +1,31 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.14-h4
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-195628
|
||||||
|
|
||||||
|
Fixed an issue that caused the pan_task process to miss heartbeats and stop responding.
|
||||||
|
|
||||||
|
## PAN-195482
|
||||||
|
|
||||||
|
Fixed an issue on multi-dataplane platforms where IPSec tunnels continuously flapped.
|
||||||
|
|
||||||
|
## PAN-194456
|
||||||
|
|
||||||
|
Fixed an issue where the sysd process disconnected from the pan_dha process after a high availability (HA) failover or reboot.
|
||||||
|
|
||||||
|
## PAN-192999
|
||||||
|
|
||||||
|
A fix was made to address [CVE-2022-0028](https://security.paloaltonetworks.com/CVE-2022-0028).
|
||||||
|
|
||||||
|
## PAN-192726
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped TCP traffic inside IPSec tunnels.
|
||||||
|
|
||||||
|
## PAN-189114
|
||||||
|
|
||||||
|
Fixed an issue where the dataplane went down, which caused an HA failover.
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.14-h7
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-202450
|
||||||
|
|
||||||
|
Fixed an issue where the device-client-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
|
||||||
|
|
||||||
|
## PAN-198372
|
||||||
|
|
||||||
|
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.14-h8
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-237935
|
||||||
|
|
||||||
|
Extended the offline PAN-DB, Panorama, and WildFire certificates which were previously set to expire on September 2, 2024.
|
||||||
|
|
||||||
|
## PAN-215576
|
||||||
|
|
||||||
|
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
|
||||||
@@ -0,0 +1,171 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.14
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-189665
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
FIPS-CC enabled firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall was unable to connect to log collectors after an upgrade due to missing cipher suites.
|
||||||
|
|
||||||
|
## PAN-189468
|
||||||
|
|
||||||
|
Fixed an issue where the firewall onboard packet processor used by the PAN-OS content-inspection (CTD) engine can generate high dataplane resource usage when overwhelmed by a session with an unusually high number of packets. This can result in resource-unavailable messages due to the content inspection queue filling up. Factors related to the likelihood of an occurrence include enablement of content-inspection based features that are configured in such a way that might process thousands of packets in rapid succession (such as SMB file transfers). This can cause poor performance for the affected session and other sessions using the same packet processor. PA-3000 series and VM-Series firewalls are not impacted.
|
||||||
|
|
||||||
|
## PAN-189010
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where a deadlock in the configd process caused both the web interface and the CLI to be inaccessible.
|
||||||
|
|
||||||
|
## PAN-188336
|
||||||
|
|
||||||
|
Fixed an issue with the dnsproxyd process that caused the firewall to unexpectedly reboot.
|
||||||
|
|
||||||
|
## PAN-187151
|
||||||
|
|
||||||
|
Fixed an issue where tunnel-monitoring interface was incorrectly shown as up instead of down.
|
||||||
|
|
||||||
|
## PAN-186937
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped packets decrypted using the SSL Decryption feature and Encapsulating Security Payload (ESP) IPSec packets that originated from the same firewall. This occurred when **Strict IP Address Check** was enabled in the zone protection profile (**Packet Based Attack > IP Drop**) and the packet's source IP address was the same as the egress interface address.
|
||||||
|
|
||||||
|
## PAN-185616
|
||||||
|
|
||||||
|
Fixed an issue where the firewall sent fewer logs to the system log server than expected. With this fix, the firewall accommodates a larger send queue for syslog forwarding to TCP syslog receivers.
|
||||||
|
|
||||||
|
## PAN-184621
|
||||||
|
|
||||||
|
Fixed an issue on FIPS-enabled devices where modifying any configuration of an existing GlobalProtect portal failed with the following error message: Operation failed : Malformed request.
|
||||||
|
|
||||||
|
## PAN-184068
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5220 firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall generated pause frames, which caused network latency.
|
||||||
|
|
||||||
|
## PAN-183826
|
||||||
|
|
||||||
|
Fixed an issue where, after clicking **WildFire Analysis Report**, the web interface failed to display the report with the following error message: refused to connect.
|
||||||
|
|
||||||
|
## PAN-183788
|
||||||
|
|
||||||
|
Fixed an issue with SCEP certificate enrollment where the incorrect Registration Authority (RA) certificate was chosen to encrypt the enrollment request.
|
||||||
|
|
||||||
|
## PAN-182173
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama appliances in HA configurations only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where, when using Prisma Access multitenancy, the passive appliance didn't correctly update the tenant information after the tenant was deleted on the active appliance.
|
||||||
|
|
||||||
|
## PAN-181039
|
||||||
|
|
||||||
|
Fixed an issue with DNS cache depletion that caused continuous DNS retries.
|
||||||
|
|
||||||
|
## PAN-180147
|
||||||
|
|
||||||
|
Fixed an issue where the bcm.log and brdagent_stdout.log-<datestamp> files filled up the root disk space.
|
||||||
|
|
||||||
|
## PAN-177671
|
||||||
|
|
||||||
|
Fixed an issue where, when SIP traffic traversing the firewall was sent with a high Quality of Service (QoS) differentiated service code (DSCP) value, the DSCP value was reset to the default setting (CS0) for the first data packet.
|
||||||
|
|
||||||
|
## PAN-177063
|
||||||
|
|
||||||
|
Fixed an issue where decrypting large packets introduced congestion during content inspection, which caused processes to stop responding due to missed heartbeats.
|
||||||
|
|
||||||
|
## PAN-177133
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls in HA configurations only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the HA1 heartbeat backup flapped with the following error message: Unable to send icmp packet:(errno: 105) No buffer space available.
|
||||||
|
|
||||||
|
## PAN-176703
|
||||||
|
|
||||||
|
Fixed an issue that occurred after upgrading to a PAN-OS 9.0 or later release where commits to the firewall configuration failed with the following error message: statistics-service is invalid.
|
||||||
|
|
||||||
|
## PAN-176437
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where multiple processes stopped responding, which caused the firewall to reboot.
|
||||||
|
|
||||||
|
## PAN-175883
|
||||||
|
|
||||||
|
Fixed an issue where the following operational mode commands were not reboot persistent:
|
||||||
|
|
||||||
|
- set system setting ctd pkt-proc-loop-low <value>
|
||||||
|
- set system setting ctd pkt-proc-loop-high <value>
|
||||||
|
- set system setting ctd max-sess-hash-limit <value>
|
||||||
|
|
||||||
|
## PAN-175509
|
||||||
|
|
||||||
|
Fixed an issue where a deadlock on CONFIG_LOCK caused both the web interface and CLI commands to time out until the mgmtsrvr process was restarted.
|
||||||
|
|
||||||
|
## PAN-175161
|
||||||
|
|
||||||
|
Fixed an issue where changing SSL connection validation settings for system logs caused the mgmtsrvr process to stop responding.
|
||||||
|
|
||||||
|
## PAN-175016
|
||||||
|
|
||||||
|
Fixed an issue where PDF summary reports were empty when they were generated by a user in a custom admin role.
|
||||||
|
|
||||||
|
## PAN-174998
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
M-200 and M-500 appliances only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed a capacity issue that was caused by high operational activity and large configurations. This fix increases the virtual memory limit on the configd process to 32GB.
|
||||||
|
|
||||||
|
## PAN-174988
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-220 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the `runtime-state` parameter was missing in the CLI command `request high-availability sync-to-remote`.
|
||||||
|
|
||||||
|
## PAN-172766
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where a commit push to managed firewalls failed with sctp-init is invalid error even though SCTP settings were not configured in the corresponding template.
|
||||||
|
|
||||||
|
## PAN-171104
|
||||||
|
|
||||||
|
Fixed an issue where a race-condition check returned a false negative, which caused a process (all_task) to stop responding and generate a core file.
|
||||||
|
|
||||||
|
## PAN-166368
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where long FQDN queries did not resolve due to the character limit being 64 characters.
|
||||||
|
|
||||||
|
## PAN-163245
|
||||||
|
|
||||||
|
Fixed an issue where a commit-all or push to the firewall from Panorama failed with the following error message: client routed requesting last config in the middle of a commit/validate. Aborting current commit/validate.
|
||||||
|
|
||||||
|
## PAN-162047
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls in active/passive high availability configurations only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed a routing table mis-sync issue where routes were missing on the passive firewall when GRE tunnels with keepalives were configured.
|
||||||
|
|
||||||
|
## PAN-152026
|
||||||
|
|
||||||
|
Fixed an issue where the session browser did not display results when filtered for IPv6 addresses with more than 31 characters.
|
||||||
|
|
||||||
|
## PAN-130172
|
||||||
|
|
||||||
|
Fixed an issue where Dynamic User Group lists were missing after disabling group-mapping configurations under that virtual system (vsys).
|
||||||
@@ -0,0 +1,191 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.15
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-201872
|
||||||
|
|
||||||
|
Fixed an issue where SMB performance caused overall network latency after an upgrade.
|
||||||
|
|
||||||
|
## PAN-201136
|
||||||
|
|
||||||
|
Fixed an issue where IGMP packets were offloaded with frequent IGMP Join and Leave messages from the client.
|
||||||
|
|
||||||
|
## PAN-197859
|
||||||
|
|
||||||
|
Fixed an issue where firewalls running LSVPN with tunnel monitoring enabled where, after an upgrade to PAN-OS 9.1.14 or a later PAN-OS release, LSVPN tunnels flapped.
|
||||||
|
|
||||||
|
## PAN-195628
|
||||||
|
|
||||||
|
Fixed an issue that caused the pan_task process to miss heartbeats and stop responding.
|
||||||
|
|
||||||
|
## PAN-195625
|
||||||
|
|
||||||
|
Fixed an issue where authd frequently created SSL sessions, which resulted in a out of memory (OOM) condition.
|
||||||
|
|
||||||
|
## PAN-194025
|
||||||
|
|
||||||
|
Fixed an issue where the ikemgr process stopped responding due to a timing issue, which caused VPN tunnels to go down.
|
||||||
|
|
||||||
|
## PAN-193579
|
||||||
|
|
||||||
|
Fixed an issue where new logs viewed from the CLI (show log <log_type>) and new syslogs forwarded to a syslog server contained additional, erroneous entries.
|
||||||
|
|
||||||
|
## PAN-193132
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-220 firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where a commit and push from Panorama caused high dataplane CPU utilization.
|
||||||
|
|
||||||
|
## PAN-193008
|
||||||
|
|
||||||
|
Fixed an issue that caused the processing of incoming packets to take more time than expected, which caused latency-sensitive traffic and applications timeouts.
|
||||||
|
|
||||||
|
## PAN-192404
|
||||||
|
|
||||||
|
Fixed an issue where ARP broadcasts occurring in the same time interval and network segment as high availability (HA) path monitoring pings triggered an ARP cache request, which prevented the firewall from sending ICMP echo requests to the monitored destination IP address and caused an HA path monitoring failover.
|
||||||
|
|
||||||
|
## PAN-192052
|
||||||
|
|
||||||
|
Fixed an issue where, when next hop MAC address entries weren't found on the offload processor for active traffic, update messages flooded the firewall, which caused resource contention and traffic disruption.
|
||||||
|
|
||||||
|
## PAN-191726
|
||||||
|
|
||||||
|
Fixed an issue where an SCP export of the device state from the firewall added single quotes ( ' ) to the filename.
|
||||||
|
|
||||||
|
## PAN-191463
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not handle packets at Fastpath when the interface pointer was null.
|
||||||
|
|
||||||
|
## PAN-191288
|
||||||
|
|
||||||
|
Fixed an issue where the firewall restarted due to a dnsproxy process crash.
|
||||||
|
|
||||||
|
## PAN-191269
|
||||||
|
|
||||||
|
Fixed an issue where the NAT pool leaked for passive mode FTP predict sessions.
|
||||||
|
|
||||||
|
## PAN-189867
|
||||||
|
|
||||||
|
Fixed an issue where, when logging in to the GlobalProtect gateway, the authentication cookie was not reused.
|
||||||
|
|
||||||
|
## PAN-189861
|
||||||
|
|
||||||
|
Fixed an issue on firewalls in HA configurations where intermittent system alerts on the active firewall caused the pan_comm process to restart continuously.
|
||||||
|
|
||||||
|
## PAN-189762
|
||||||
|
|
||||||
|
Fixed an issue where a predict session didn't match with the traffic when both source NAT and destination NAT were enabled.
|
||||||
|
|
||||||
|
## PAN-189414
|
||||||
|
|
||||||
|
Fixed an issue where TCP packets were dropped during the first zone transfer when DNS security was enabled.
|
||||||
|
|
||||||
|
## PAN-189214
|
||||||
|
|
||||||
|
Fixed an issue where, when the Advanced Threat Prevention license was present on a firewall without a Threat Prevention license, the antivirus signature update packages that were normally available to install (**Device > Dynamic Updates**) were not displayed.
|
||||||
|
|
||||||
|
## PAN-189114
|
||||||
|
|
||||||
|
Fixed an issue where the dataplane went down, which caused a HA failover.
|
||||||
|
|
||||||
|
## PAN-188867
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped packets when the session payload was too large.
|
||||||
|
|
||||||
|
## PAN-188338
|
||||||
|
|
||||||
|
Fixed an issue where canceling a commit caused the commit process to remain at 70% and the firewall had to be rebooted.
|
||||||
|
|
||||||
|
## PAN-188036
|
||||||
|
|
||||||
|
Fixed an issue where SIP TCP sequence numbers were calculated incorrectly when SIP cleartext proxy was disabled.
|
||||||
|
|
||||||
|
## PAN-186024
|
||||||
|
|
||||||
|
Fixed an issue where URL category match did not work for External Dynamic List URLS due to a leak related to the devsrvr process.
|
||||||
|
|
||||||
|
## PAN-184291
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect portal generated a cookie with a domain as NULL instead of empty-domain, which caused users to be identified incorrectly.
|
||||||
|
|
||||||
|
## PAN-183327
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls in HA configurations only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where policy based forwarding (PBF) sessions between virtual systems (vsys) weren't pushed to the high availability peer.
|
||||||
|
|
||||||
|
## PAN-183184
|
||||||
|
|
||||||
|
Fixed an issue where enabling SSL decryption with a Hardware Security Model (HSM) caused a dataplane restart.
|
||||||
|
|
||||||
|
## PAN-182244
|
||||||
|
|
||||||
|
Fixed an issue where Session Initiation Protocol (SIP) REGISTER packets did not get transmitted when application-level gateway (ALG) and SIP Proxy were enabled, which caused a SIP-registration issue in environments where TCP retransmission occurred.
|
||||||
|
|
||||||
|
## PAN-181366
|
||||||
|
|
||||||
|
Fixed an issue where the firewall sent an incorrect IP address on ICMP sessions in NetFlow packets when NAT was applied to the target traffic.
|
||||||
|
|
||||||
|
## PAN-181098
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-800 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall rebooted during a software install job due to a kernel panic situation.
|
||||||
|
|
||||||
|
## PAN-180916
|
||||||
|
|
||||||
|
Fixed an issue where DNS security caused the (time-to-live) value of the pointer record (PTR) to be overwritten with a value of 30 seconds.
|
||||||
|
|
||||||
|
## PAN-178243
|
||||||
|
|
||||||
|
Fixed an issue where **Shared Gateway** was not visible in the **Virtual System** drop down when configuring a Layer3 aggregate subinterface.
|
||||||
|
|
||||||
|
## PAN-177562
|
||||||
|
|
||||||
|
Fixed an issue where PDF reports were not translated to the configured local language.
|
||||||
|
|
||||||
|
## PAN-176341
|
||||||
|
|
||||||
|
Fixed an issue where a delay to detect when an interface was down after a cable pull caused traffic to be black-holed to the downed link for 10 or more seconds.
|
||||||
|
|
||||||
|
## PAN-174660
|
||||||
|
|
||||||
|
Fixed an issue where the devsrvr process stopped responding after a local or Panorama pushed commit. This occurred when a single NAT policy contained more than 64 address objects.
|
||||||
|
|
||||||
|
## PAN-173437
|
||||||
|
|
||||||
|
Fixed an issue where the firewall did not detect that the management port was down the first time after booting up the system.
|
||||||
|
|
||||||
|
## PAN-168635
|
||||||
|
|
||||||
|
Fixed an issue on the firewall where, when attempting to change the master key, the existing master key was not validated first. As a result, all firewall keys were corrupted.
|
||||||
|
|
||||||
|
## PAN-168179
|
||||||
|
|
||||||
|
Fixed an issue where DHCP IP address renewal failed on the management interface
|
||||||
|
|
||||||
|
## PAN-159702
|
||||||
|
|
||||||
|
Fixed an issue where FQDN refresh did not work with the error message No name servers found!, and no subsequent retries occurred.
|
||||||
|
|
||||||
|
## PAN-151469
|
||||||
|
|
||||||
|
Fixed an issue where packets were dropped unexpectedly due to errors parsing the IP version field.
|
||||||
|
|
||||||
|
## PAN-135527
|
||||||
|
|
||||||
|
Fixed an issue where verbose mode did not display additional data for the fe20 flow lookup command.
|
||||||
|
|
||||||
|
## PAN-82223
|
||||||
|
|
||||||
|
Fixed an issue where links to severity level GIFs in HIP Check log entry details did not work.
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.16-h3
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-227523
|
||||||
|
|
||||||
|
A fix was made to address a customer bug ([CVE-2023-38802](https://security.paloaltonetworks.com/CVE-2023-38802)).
|
||||||
|
|
||||||
|
## PAN-202450
|
||||||
|
|
||||||
|
Fixed an issue where the device-client-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
|
||||||
|
|
||||||
|
## PAN-198372
|
||||||
|
|
||||||
|
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.16-h5
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-237935
|
||||||
|
|
||||||
|
Extended the offline PAN-DB, Panorama, and WildFire certificates which were previously set to expire on September 2, 2024.
|
||||||
|
|
||||||
|
## PAN-215576
|
||||||
|
|
||||||
|
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
|
||||||
@@ -0,0 +1,223 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.16
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-235168
|
||||||
|
|
||||||
|
Fixed an issue where disk space became full even after clearing old logs and content images.
|
||||||
|
|
||||||
|
## PAN-216656
|
||||||
|
|
||||||
|
Fixed an issue where the firewall was unable to fully process the user list from a child group when the child group contained more than 1,500 users.
|
||||||
|
|
||||||
|
## PAN-215911
|
||||||
|
|
||||||
|
Fixed an issue that resulted in a race condition, which caused the configd process to stop responding.
|
||||||
|
|
||||||
|
## PAN-215488
|
||||||
|
|
||||||
|
Fixed an issue where an expired Trusted Root CA was used to sign the forward proxy leaf certificate during SSL Decryption.
|
||||||
|
|
||||||
|
## PAN-211997
|
||||||
|
|
||||||
|
Fixed an issue where large OSPF control packets were fragmented, which caused the neighborship to fail.
|
||||||
|
|
||||||
|
## PAN-211602
|
||||||
|
|
||||||
|
Fixed an issue where, when viewing a WildFire Analysis Report via the web interface, the **detailed log view** was not accessible if the browser window was resized.
|
||||||
|
|
||||||
|
## PAN-209696
|
||||||
|
|
||||||
|
Fixed an issue where link-local address communication for IPv6, BFD, and OSPFv3 neighbors was dropped when IP address spoofing check was enabled in a Zone Protection profile.
|
||||||
|
|
||||||
|
## PAN-207740
|
||||||
|
|
||||||
|
Fixed an issue that resulted in a race condition, which caused the configd process to stop responding.
|
||||||
|
|
||||||
|
## PAN-205453
|
||||||
|
|
||||||
|
Fixed an issue where running reports or queries under a user group caused the reportd process to stop responding.
|
||||||
|
|
||||||
|
## PAN-203563
|
||||||
|
|
||||||
|
Fixed an issue with Content and Threat Detection allocation storage space where performing a commit failed with a CUSTOM_UPDATE_BLOCK error message.
|
||||||
|
|
||||||
|
## PAN-203402
|
||||||
|
|
||||||
|
Fixed an intermittent issue where forward session installs were delayed, which resulted in latencies.
|
||||||
|
|
||||||
|
## PAN-203147
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls in FIPS-CC mode only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall unexpectedly rebooted when downloading a new PAN-OS software image.
|
||||||
|
|
||||||
|
## PAN-201910
|
||||||
|
|
||||||
|
PAN-OS security profiles might consume a large amount of memory depending on the profile configuration and quantity. In some cases, this might reduce the number of supported security profiles below the stated maximum for a given platform.
|
||||||
|
|
||||||
|
## PAN-201639
|
||||||
|
|
||||||
|
Fixed an issue with Saas Application Usage reports where **Applications with Risky Characteristics** displayed only two applications per section.
|
||||||
|
|
||||||
|
## PAN-199612
|
||||||
|
|
||||||
|
Fixed a sync issue with firewalls in active/active HA configurations.
|
||||||
|
|
||||||
|
## PAN-198871
|
||||||
|
|
||||||
|
Fixed an issue when both URL and Advanced URL licenses were installed, the expiry date was not correctly checked.
|
||||||
|
|
||||||
|
## PAN-198693
|
||||||
|
|
||||||
|
Fixed an issue where decrypted SSH sessions were interrupted with a decryption error.
|
||||||
|
|
||||||
|
## PAN-198038
|
||||||
|
|
||||||
|
A CLI command was added to address an issue where long-lived sessions were aging out even when there was ongoing traffic.
|
||||||
|
|
||||||
|
## PAN-197919
|
||||||
|
|
||||||
|
Fixed an issue where, when path monitoring for a static route was configured with a new Ping Interval value, the value was not used as intended.
|
||||||
|
|
||||||
|
## PAN-197847
|
||||||
|
|
||||||
|
Fixed an issue where disabling the enc-algo-aes-128-gcm cipher did not work when using an SSL/TLS profile.
|
||||||
|
|
||||||
|
## PAN-197729
|
||||||
|
|
||||||
|
Fixed an issue where repeated configuration pushes from Panorama resulted in a management server memory leak.
|
||||||
|
|
||||||
|
## PAN-197576
|
||||||
|
|
||||||
|
Fixed an issue where commits pushed from Panorama caused a memory leak related to the mgmtsrvr process.
|
||||||
|
|
||||||
|
## PAN-197219
|
||||||
|
|
||||||
|
Fixed an issue where the following error message was not sent from multi-factor authentication PingID and did not display in the browser: Your company has enhanced its VPN authentication with PingID. Please install the PingID app for iOS or Android, and use pairing key:<key>. To connect, type "ok".
|
||||||
|
|
||||||
|
## PAN-195790
|
||||||
|
|
||||||
|
Fixed an issue where syslog traffic that was sent from the management interface to the syslog server even when a destination IP address service route was configured.
|
||||||
|
|
||||||
|
## PAN-195583
|
||||||
|
|
||||||
|
Fixed an issue where, after renaming an object, configuration pushes from Panorama failed with the commit error **object name is not an allowed keyword**.
|
||||||
|
|
||||||
|
## PAN-194175
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where a commit push to managed firewalls failed when objects were added as source address exclusions in a Security policy and **Share Unused Address and Service Objects with Devices** was unchecked.
|
||||||
|
|
||||||
|
## PAN-193808
|
||||||
|
|
||||||
|
Fixed a memory leak issue in the mgmtsrvr process that resulted in an OOM condition.
|
||||||
|
|
||||||
|
## PAN-193763
|
||||||
|
|
||||||
|
Fixed an issue on the firewall where the dataplane CPU spiked, which caused traffic to be affected during commits or content updates.
|
||||||
|
|
||||||
|
## PAN-192681
|
||||||
|
|
||||||
|
Fixed an issue where HIP database storage on the firewall reached full capacity due to the firewall not purging older HIP reports.
|
||||||
|
|
||||||
|
## PAN-190950
|
||||||
|
|
||||||
|
Fixed an issue where creating or modifying a GlobalProtect portal configuration failed in FIPS mode with the following error message: clientless-vpn enc-algo-rc4 unexpected here.
|
||||||
|
|
||||||
|
## PAN-189518
|
||||||
|
|
||||||
|
Fixed an issue where incoming DNS packets with looped compression pointers caused the dnsproxyd process to stop responding.
|
||||||
|
|
||||||
|
## PAN-189379
|
||||||
|
|
||||||
|
Fixed an issue where FQDN based Security policy rules did not match correctly.
|
||||||
|
|
||||||
|
## PAN-187829
|
||||||
|
|
||||||
|
Fixed an issue where the web_backend and httpd processes leaked descriptors, which caused activities that depended on the processes, such as logging in to the web interface, to fail.
|
||||||
|
|
||||||
|
## PAN-187761
|
||||||
|
|
||||||
|
Fixed an issue where, during HA failover, the newly passive firewall continued to pass traffic after the active firewall had already taken over.
|
||||||
|
|
||||||
|
## PAN-184537
|
||||||
|
|
||||||
|
Fixed an issue where GlobalProtect requested for passwords that contained non ASCII characters (ö) to be reentered when refreshing the connection.
|
||||||
|
|
||||||
|
## PAN-183319
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where commits remained at 99% due to multiple firewalls sending out CSR singing requests every 10 minutes.
|
||||||
|
|
||||||
|
## PAN-183297
|
||||||
|
|
||||||
|
Fixed an issue where, when the firewall received a large amount of user information, the firewall was unable to output IP-address to username mapping information via XML API.
|
||||||
|
|
||||||
|
## PAN-183126
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where you were able to attempt to push a number of active schedules to the firewall that was greater than the firewall's maximum capacity.
|
||||||
|
|
||||||
|
## PAN-182845
|
||||||
|
|
||||||
|
Fixed an issue that caused devices to be removed from Panorama when one device was added by one user, but a Commit and Push operation was completed by a second user before the first user completed a Commit of the added device change.
|
||||||
|
|
||||||
|
## PAN-181839
|
||||||
|
|
||||||
|
Fixed an issue where Panorama Global Search reported **No Matches found** while still returning results for matching entries on large configurations.
|
||||||
|
|
||||||
|
## PAN-181759
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls in active/active HA configurations only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where firewall configuration files were not synced.
|
||||||
|
|
||||||
|
## PAN-181295
|
||||||
|
|
||||||
|
Fixed an issue where clicking on a rule in the **App Dependency** tab after a commit or commit all did not display the rule correctly.
|
||||||
|
|
||||||
|
## PAN-179624
|
||||||
|
|
||||||
|
Fixed an issue where setting the password complexity to **Require Password Change on First Login** caused the user to be prompted with certificate authentication.
|
||||||
|
|
||||||
|
## PAN-177942
|
||||||
|
|
||||||
|
Fixed an issue where, when grouping HA peers, access domains that were configured using multi-vsys firewalls deselected devices or virtual systems that were in other configured access domains.
|
||||||
|
|
||||||
|
## PAN-177054
|
||||||
|
|
||||||
|
Fixed an issue where, when you disabled a NAT rule, the **Destination Translation** value **none** displayed in blue and was still able to be modified to a different value.
|
||||||
|
|
||||||
|
## PAN-175176
|
||||||
|
|
||||||
|
Fixed an issue in which CBC ciphers for TLS traffic to port 28443 on Panorama were enabled.
|
||||||
|
|
||||||
|
## PAN-174680
|
||||||
|
|
||||||
|
Fixed an issue where, when adding new configurations, Panorama didn't display a list of suggested template variables when typing in a relevant field.
|
||||||
|
|
||||||
|
## PAN-173179
|
||||||
|
|
||||||
|
Fixed an issue where the rem_addr field in Terminal Access Controller Access-Control System (TACACS+) authentication displayed the management or service route IP address of the firewall instead of the source IP address of the user.
|
||||||
|
|
||||||
|
## PAN-161958
|
||||||
|
|
||||||
|
Fixed an issue where the FQDN refresh timer was pushed from Panorama appliances on PAN-OS 9.0 and later releases to firewalls running a PAN-OS 8.1 release.
|
||||||
|
|
||||||
|
## PAN-158511
|
||||||
|
|
||||||
|
Fixed an issue where configurations loaded and committed to Panorama changed external dynamic list references on Security policy rules to **NONE** when Antivirus Protection was not installed.
|
||||||
|
|
||||||
|
## PAN-143930
|
||||||
|
|
||||||
|
Fixed an issue where a process (routed) restarted due to the number of BGP peers exceeding the supported configuration.
|
||||||
|
|
||||||
|
## PAN-78762
|
||||||
|
|
||||||
|
Fixed an issue where you were unable to reset a VPN tunnel via the firewall web interface (**Network > IPSec Tunnels > Tunnel Info > Restart**).
|
||||||
@@ -0,0 +1,99 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.17
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-237935
|
||||||
|
|
||||||
|
Extended the offline PAN-DB, Panorama, and WildFire certificates which were previously set to expire on September 2, 2024.
|
||||||
|
|
||||||
|
## PAN-228043
|
||||||
|
|
||||||
|
Fixed an issue on firewalls on active/active HA configurations where packets dropped during commit operations when forwarding traffic via an HA3 link when an aggregate ethernet interface or data interface was used as an HA3 link.
|
||||||
|
|
||||||
|
## PAN-223317
|
||||||
|
|
||||||
|
Fixed an issue where SSL traffic failed with the error message: Error: General TLS protocol error.
|
||||||
|
|
||||||
|
## PAN-221637
|
||||||
|
|
||||||
|
Fixed an issue where User ID logs for logout events displayed incorrect factor completion times.
|
||||||
|
|
||||||
|
## PAN-218404
|
||||||
|
|
||||||
|
Fixed an issue where ikemgr stopped responding due to receiving CREATE_CHILD messages with a malformed SA payload.
|
||||||
|
|
||||||
|
## PAN-217681
|
||||||
|
|
||||||
|
Fixed an issue caused by out of order TCP segments where the TCP retransmission failed when the TCP segment had the FIN flag and the TCP data was truncated.
|
||||||
|
|
||||||
|
## PAN-215576
|
||||||
|
|
||||||
|
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
|
||||||
|
|
||||||
|
## PAN-210883
|
||||||
|
|
||||||
|
Fixed an issue where SSL proxy traffic was dropped when DoS Zone protection was enabled.
|
||||||
|
|
||||||
|
## PAN-207003
|
||||||
|
|
||||||
|
Fixed an issue where the logrcvr process netflow buffer was not reset which resulted in duplicate netflow records.
|
||||||
|
|
||||||
|
## PAN-202593
|
||||||
|
|
||||||
|
Fixed an issue where expanding Global Find results displayed only the top level and second level of a searched item.
|
||||||
|
|
||||||
|
## PAN-199557
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where virtual memory usage exceeded the set limit, which caused the configd process to restart.
|
||||||
|
|
||||||
|
## PAN-198372
|
||||||
|
|
||||||
|
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
|
||||||
|
|
||||||
|
## PAN-198174
|
||||||
|
|
||||||
|
Fixed an issue where, when viewing traffic or threat logs from the **Application Command Center** (ACC) or **Monitor** tabs, performing a reverse DNS lookup caused the dnsproxy process to restart if DNS server settings were not configured.
|
||||||
|
|
||||||
|
## PAN-197935
|
||||||
|
|
||||||
|
Fixed an intermittent issue where XML API IP address tag registration failed on firewalls in a multivsys environment.
|
||||||
|
|
||||||
|
## PAN-197426
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where, when attempting to view the **Monitor** page, the error message **invalid term** was displayed.
|
||||||
|
|
||||||
|
## PAN-196956
|
||||||
|
|
||||||
|
Fixed an issue where URL filtering logs did not display matching entries when filtered by device name.
|
||||||
|
|
||||||
|
## PAN-192431
|
||||||
|
|
||||||
|
Fixed an issue where unmanaged tags were set to NULL, which caused unmanaged devices to match the HIP rule for managed devices. As a result, you were unable to distinguish between managed and unmanaged devices.
|
||||||
|
|
||||||
|
## PAN-191867
|
||||||
|
|
||||||
|
Fixed an issue where CPU stalls resulted in a slot restart.
|
||||||
|
|
||||||
|
## PAN-190903
|
||||||
|
|
||||||
|
Fixed an issue where MAC addresses in threat capture were swapped between the source MAC and destination MAC addresses.
|
||||||
|
|
||||||
|
## PAN-189182
|
||||||
|
|
||||||
|
Fixed an issue where the change summary didn't work after upgrading the Panorama appliance.
|
||||||
|
|
||||||
|
## PAN-184630
|
||||||
|
|
||||||
|
Fixed an issue where TLS clients, such as those using OpenSSL 3.0, enforced the TLS renegotiation extension (RFC 5746).
|
||||||
|
|
||||||
|
## PAN-160633
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the dataplane restarted repeatedly due to an internal path monitoring failures until a power cycle.
|
||||||
@@ -0,0 +1,103 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.1
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## WF500-5185
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
WF-500 Series only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where high disk use was observed due to an inadequate rotation of log files.
|
||||||
|
|
||||||
|
## WF500-5137
|
||||||
|
|
||||||
|
Fixed an issue where the show wildfire global last-device-registration all CLI command incorrectly returned an error message: Failed, even when you registered the firewall correctly.
|
||||||
|
|
||||||
|
## PAN-134096
|
||||||
|
|
||||||
|
Fixed an issue where uploads for custom logos failed.
|
||||||
|
|
||||||
|
## PAN-133329
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where when viewing **Unused** Rule Usage in Policy Optimizer, devices without a hit count had the incorrect date and time instead of displaying no values. Now, if the rule has not been used, the dates and times are displayed with a hyphen (-).
|
||||||
|
|
||||||
|
## PAN-133048
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 and PA-7000 Series only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where traffic was processed asymmetrically when using Internet Protocol (IP) classifiers on virtual wire (vwire) subinterfaces.
|
||||||
|
|
||||||
|
## PAN-133040
|
||||||
|
|
||||||
|
Fixed an issue on WF-500 where a VM-Series firewall controller crashed, which caused the WF-500 to stop file analysis.
|
||||||
|
|
||||||
|
## PAN-132449
|
||||||
|
|
||||||
|
Fixed an issue where the pan_task process crashed when debug was set as debug dataplane packet-diag set log counter flow_fwd_drop_noxmit.
|
||||||
|
|
||||||
|
## PAN-130262
|
||||||
|
|
||||||
|
Fixed a rare issue where 200 OK messages were dropped during the offload of traffic for App-ID inspection.
|
||||||
|
|
||||||
|
## PAN-129692
|
||||||
|
|
||||||
|
Fixed an issue where VM-Series firewalls on Microsoft Azure experienced traffic latency due to an incompatible driver.
|
||||||
|
|
||||||
|
## PAN-129658
|
||||||
|
|
||||||
|
Fixed an issue where GTP inspection stopped functioning after unrelated changes in policy and a commit followed by a high availability (HA) failover.
|
||||||
|
|
||||||
|
## PAN-128269
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5250, PA-5260, and PA-5280 firewalls with 100GB AOC cables only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where after you upgraded the first peer in a high availability (HA) configuration to a PAN-OS 9.0 release, the High Speed Chassis Interconnect (HSCI) port did not come up due to an FEC mismatch until after you finished upgrading the second peer.
|
||||||
|
|
||||||
|
## PAN-125122
|
||||||
|
|
||||||
|
A fix was made to address a cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS and Panorama that disclosed an authenticated PAN-OS administrator's PAN-OS session cookie ([CVE-2020-2013](https://security.paloaltonetworks.com/CVE-2020-2013)).
|
||||||
|
|
||||||
|
## PAN-124212
|
||||||
|
|
||||||
|
Fixed an issue where DHCP configuration was overriding the maximum transmission unit (MTU) information set on the management interface by the user.
|
||||||
|
|
||||||
|
## PAN-120350
|
||||||
|
|
||||||
|
Fixed an issue where an Address Resolution Protocol (ARP) broadcast storm potentially overloaded the Log Processing Card (LPC) and caused the device to reboot.
|
||||||
|
|
||||||
|
## PAN-120105
|
||||||
|
|
||||||
|
Fixed an issue where email header information intermittently was not present in threat logs.
|
||||||
|
|
||||||
|
## PAN-118091
|
||||||
|
|
||||||
|
Fixed an issue where application dependency warnings were displayed after a commit when the policy rules containing the dependent applications used different sources (one used user and the other used groups).
|
||||||
|
|
||||||
|
## PAN-116383
|
||||||
|
|
||||||
|
Fixed an issue with Panorama on AWS where the configuration of the high availability (HA) pair became out of sync due to different plugin versions being detected even though the same versions were installed on both peers.
|
||||||
|
|
||||||
|
## PAN-111611
|
||||||
|
|
||||||
|
Fixed an issue where the connection between the firewall and Cortex Data Lake flapped if connections decreased.
|
||||||
|
|
||||||
|
## PAN-108992
|
||||||
|
|
||||||
|
A fix was made to address an improper authorization vulnerability in PAN-OS ([CVE-2020-1998](https://security.paloaltonetworks.com/CVE-2020-1998)).
|
||||||
|
|
||||||
|
## PAN-100734
|
||||||
|
|
||||||
|
A fix was made to address a buffer flow vulnerability in the PAN-OS management interface where authenticated users were able to crash system processes or execute arbitrary code with root privileges ([CVE-2020-2015](https://security.paloaltonetworks.com/CVE-2020-2015)).
|
||||||
|
|
||||||
|
## PAN-100415
|
||||||
|
|
||||||
|
A fix was made to address an external control of filename vulnerability in the command processing of PAN-OS ([CVE-2020-2003](https://security.paloaltonetworks.com/CVE-2020-2003)).
|
||||||
@@ -0,0 +1,403 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.2
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## WF500-5343
|
||||||
|
|
||||||
|
Fixed an issue on WF-500 that caused cloud queries to fail when the cloud verdict did not match the local verdict.
|
||||||
|
|
||||||
|
## PAN-142084
|
||||||
|
|
||||||
|
Fixed an issue where upgrading a Panorama management server deployed on Amazon Web Services (AWS) using a C5 or M5 instance type to PAN-OS 9.1.1 caused the Panorama Virtual Appliance to stop responding.
|
||||||
|
|
||||||
|
## PAN-140509
|
||||||
|
|
||||||
|
Fixed an issue where performing private data resets during custom Amazon Machine Image (AMI) creation removed CloudWatch directories and caused the CloudWatch plugin to fail.
|
||||||
|
|
||||||
|
## PAN-140157
|
||||||
|
|
||||||
|
A fix was made to address a vulnerability where the password for a configured system proxy server for a PAN-OS appliance was displayed in cleartext when using the CLI in PAN-OS ([CVE-2020-2048](https://security.paloaltonetworks.com/CVE-2020-2048)).
|
||||||
|
|
||||||
|
## PAN-138003
|
||||||
|
|
||||||
|
Fixed an issue where a process (rasmgr) exited, which caused the firewall to reboot due to a null pointer dereference error when usr_info was null.
|
||||||
|
|
||||||
|
## PAN-137966
|
||||||
|
|
||||||
|
Fixed a configuration lock issue where Panorama timed out due to a process (configd) being unable to read another process (mongod).
|
||||||
|
|
||||||
|
## PAN-137709
|
||||||
|
|
||||||
|
Fixed an issue where dynamic DNS (DDNS) failed due to a Lua script error.
|
||||||
|
|
||||||
|
## PAN-137191
|
||||||
|
|
||||||
|
Fixed an issue where the **Custom URL Category** default action changed from **allow** to **none** after upgrading to PAN-OS 9.1.0.
|
||||||
|
|
||||||
|
## PAN-136724
|
||||||
|
|
||||||
|
Fixed an issue with a process (snmpd) and booting errors.
|
||||||
|
|
||||||
|
## PAN-136698
|
||||||
|
|
||||||
|
Fixed an issue where a process (all_pktproc) stopped responding and the dataplane restarted when the firewall processed a malformed GPRS tunneling protocol (GTP) packet.
|
||||||
|
|
||||||
|
## PAN-136696
|
||||||
|
|
||||||
|
Fixed an issue where the dataplane restarted due to excessive logs from the pan_comm process.
|
||||||
|
|
||||||
|
## PAN-136608
|
||||||
|
|
||||||
|
Fixed an issue in Panorama where the Security policy **Target** displayed the serial number of the targeted device instead of the hostname.
|
||||||
|
|
||||||
|
## PAN-136607
|
||||||
|
|
||||||
|
Fixed an issue with GPRS tunneling protocol (GTP) event packet capture (pcap) where enabling **Packet Capture** did not work.
|
||||||
|
|
||||||
|
## PAN-136453
|
||||||
|
|
||||||
|
Fixed an issue where performing a private data reset using the request system private-data-reset CLI command caused the unit to boot into maintenance mode.
|
||||||
|
|
||||||
|
## PAN-136390
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series with 100GB NPC only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue during firewall bootup where the following error message: Bootloader upgrade failed, ret 255 appeared when small form-factor pluggable (SPF) modules were installed.
|
||||||
|
|
||||||
|
## PAN-136304
|
||||||
|
|
||||||
|
Fixed an issue where clientless VPN rewrite failed due to incorrect parsing of the HTML webpage.
|
||||||
|
|
||||||
|
## PAN-135909
|
||||||
|
|
||||||
|
Fixed an issue where connections leading to the web interface were abruptly interrupted due to a double free condition (gPanUiPhpGlobal_secure_config_reset), which led to unexpected process restarts and core file generation.
|
||||||
|
|
||||||
|
## PAN-135703
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the switch ports connected to Quad Small Form-factor Pluggable (QSFP+) interfaces were up while Network Processing Cards (NPCs) were still rebooting.
|
||||||
|
|
||||||
|
## PAN-135587
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect gateway was unable to parse a large list of IP addresses assigned on a local machine.
|
||||||
|
|
||||||
|
## PAN-135570
|
||||||
|
|
||||||
|
Fixed an issue where management access to a VM-Series firewall deployed in Amazon Web Services (AWS) cloud was slow due to high disk input/output (I/O) operations caused by expired Large Scale VPN (LSVPN) certificates.
|
||||||
|
|
||||||
|
## PAN-135452
|
||||||
|
|
||||||
|
Fixed an issue where configuration related to virtual machine (VM) information sources caused a process (userid) to crash, which led to a firewall reboot.
|
||||||
|
|
||||||
|
## PAN-135260
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls running PAN-OS® 8.1.12 only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an intermittent issue where the dataplane process (all_pktproc_X) on a Network Processing Card (NPC) restarted when processing IPSec tunnel traffic.
|
||||||
|
|
||||||
|
## PAN-135141
|
||||||
|
|
||||||
|
Fixed an issue where the Log Processing Card (LPC) did not come up intermittently in a fully loaded PA-7000 Series.
|
||||||
|
|
||||||
|
## PAN-135103
|
||||||
|
|
||||||
|
A fix was made to address a format string vulnerability on PA-7000 Series firewalls with a Log Forwarding Card (LFC) ([CVE-2020-1992](https://security.paloaltonetworks.com/CVE-2020-1992)).
|
||||||
|
|
||||||
|
## PAN-135089
|
||||||
|
|
||||||
|
Fixed an issue where the CPU for a process (ikemgr) spiked when third-party VPN clients connected to the GlobalProtect gateway with more than three DNS servers configured.
|
||||||
|
|
||||||
|
## PAN-135039
|
||||||
|
|
||||||
|
Fixed an issue in Panorama where a memory leak occurred during a high availability (HA) sync commit.
|
||||||
|
|
||||||
|
## PAN-134981
|
||||||
|
|
||||||
|
Fixed an issue with a memory leak in a process (user-id) due to failed LDAP over SSL (LDAPS) requests.
|
||||||
|
|
||||||
|
## PAN-134810
|
||||||
|
|
||||||
|
Fixed an issue where **Resolve** in the web interface did not work for FQDN address objects with more than 63 characters.
|
||||||
|
|
||||||
|
## PAN-134714
|
||||||
|
|
||||||
|
Fixed an issue where Safe Search was not enabled after an application change.
|
||||||
|
|
||||||
|
## PAN-134571
|
||||||
|
|
||||||
|
Fixed an issue where DNS security incorrectly set bits to zero on compressed DNS packets, which caused DNS malformation.
|
||||||
|
|
||||||
|
## PAN-134547
|
||||||
|
|
||||||
|
Fixed an issue where the passive firewall in an active/passive high availability (HA) configuration deleted BGP-learned routes synchronized from the active firewall if the BGP configuration included the redistribution of the learned routes.
|
||||||
|
|
||||||
|
## PAN-134546
|
||||||
|
|
||||||
|
Fixed a rare issue on the firewall where a process (flow_mgmt) restarted due to an invalid packet received through the GlobalProtect agent or clientless VPN.
|
||||||
|
|
||||||
|
## PAN-134488
|
||||||
|
|
||||||
|
Fixed an issue where a process (all_pktproc) crashed while processing Clientless VPN traffic.
|
||||||
|
|
||||||
|
## PAN-134370
|
||||||
|
|
||||||
|
Fixed an issue where a process (mp-relay) restarted due to missing routes or next hops.
|
||||||
|
|
||||||
|
## PAN-134309
|
||||||
|
|
||||||
|
Fixed an issue where a process (devsrvr) restarted when it hit the limit of the number of custom patterns available in the allocated memory.
|
||||||
|
|
||||||
|
## PAN-134244
|
||||||
|
|
||||||
|
Fixed an issue where connections proxied by the firewall (such as SSL Decryption, GlobalProtect portal and gateway connections, and SIP over TCP) failed due to insufficient buffer allocation. Some connections failed with the following error message: proxy decrypt failure.
|
||||||
|
|
||||||
|
## PAN-134038
|
||||||
|
|
||||||
|
Fixed an issue where custom signatures did not properly detect the User-Agent header when the Origin header was also present.
|
||||||
|
|
||||||
|
## PAN-133915
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where configuring a BGP import rule from the CLI failed with the following error message: Server error : permission denied for the command set.
|
||||||
|
|
||||||
|
## PAN-133912
|
||||||
|
|
||||||
|
Fixed an issue where querying traffic logs based on address objects and address groups did not work.
|
||||||
|
|
||||||
|
## PAN-133883
|
||||||
|
|
||||||
|
Fixed an issue where a race condition caused "pan_task" and "pan_com" to exit unexpectedly.
|
||||||
|
|
||||||
|
## PAN-133880
|
||||||
|
|
||||||
|
Fixed an issue where RADIUS authentication failed due to an FQDN resolution failure after the VM-Series firewall rebooted.
|
||||||
|
|
||||||
|
## PAN-133731
|
||||||
|
|
||||||
|
Fixed an issue on the Panorama Virtual Appliance where the show interface all CLI command did not list any output.
|
||||||
|
|
||||||
|
## PAN-133614
|
||||||
|
|
||||||
|
Fixed an issue on the Panorama Virtual Appliance where SNMP Object IDs (OIDs) were missing for interfaces other than the **Management** interface.
|
||||||
|
|
||||||
|
## PAN-133609
|
||||||
|
|
||||||
|
Fixed an issue where the Authentication Portal did not work due to a large number of HTTP requests with unsupported Authorization headers.
|
||||||
|
|
||||||
|
## PAN-133582
|
||||||
|
|
||||||
|
Fixed an issue in the firewalls where some Dynamic Address Groups pushed from Panorama were missing member IP addresses.
|
||||||
|
|
||||||
|
## PAN-133527
|
||||||
|
|
||||||
|
A fix was made to address a NULL pointer dereference vulnerability in PAN-OS ([CVE-2020-1995](https://security.paloaltonetworks.com/CVE-2020-1995)).
|
||||||
|
|
||||||
|
## PAN-133491
|
||||||
|
|
||||||
|
Fixed an issue where Internet Protocol (IP) to user mappings were not synced from the HUB virtual system (vsys) to the non-hub vsys.
|
||||||
|
|
||||||
|
## PAN-133448
|
||||||
|
|
||||||
|
Fixed an issue where the mprelay process could crash during commit if the devsrvr process was restarted before or during the commit.
|
||||||
|
|
||||||
|
## PAN-133440
|
||||||
|
|
||||||
|
Fixed an issue where fragmented traffic caused high dataplane use and firewall performance issues.
|
||||||
|
|
||||||
|
## PAN-133411
|
||||||
|
|
||||||
|
Fixed an issue where after making configuration changes and selecting **Preview Changes**, a 500 Internal Server Error message displayed due to a memory leak.
|
||||||
|
|
||||||
|
## PAN-133378
|
||||||
|
|
||||||
|
Fixed an issue in Panorama where a process (configd) restarted while doing a commit using a RADIUS super admin role.
|
||||||
|
|
||||||
|
## PAN-133289
|
||||||
|
|
||||||
|
Fixed an issue where improper parsing of the URL database caused high device-server CPU usage.
|
||||||
|
|
||||||
|
## PAN-133288
|
||||||
|
|
||||||
|
Fixed an issue where the API key limit in the *HTTP server profile was 128 characters.
|
||||||
|
|
||||||
|
## PAN-133211
|
||||||
|
|
||||||
|
Fixed an issue where the policy order was not maintained when moved to a different device group.
|
||||||
|
|
||||||
|
## PAN-133179
|
||||||
|
|
||||||
|
Fixed a rare issue where the show ntp CLI command showed the status as rejected even when the NTP was synced with at least one NTP server.
|
||||||
|
|
||||||
|
## PAN-133042
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 and PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where firewalls dropped certain GPRS tunneling protocol (GTP) traffic even when gtp nodrop was enabled.
|
||||||
|
|
||||||
|
## PAN-132995
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series and PA-3200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where when jumbo frames were enabled, the maximum transmission unit (MTU) size limit was lower than expected.
|
||||||
|
|
||||||
|
## PAN-132766
|
||||||
|
|
||||||
|
Fixed an issue in Panorama where custom region objects were not visible in the GlobalProtect Portal **External Gateway** drop-down.
|
||||||
|
|
||||||
|
## PAN-132715
|
||||||
|
|
||||||
|
Fixed an issue where a child dynamic address group was not added as a member of the parent group.
|
||||||
|
|
||||||
|
## PAN-132697
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect portal did not generate certificate signing requests (CSRs) due to failed Simple Certificate Enrollment Protocol (SCEP) authentication cookie validation.
|
||||||
|
|
||||||
|
## PAN-132658
|
||||||
|
|
||||||
|
Fixed an issue where a nullification method for steam control transmission protocol (SCTP) data chunks did not work.
|
||||||
|
|
||||||
|
## PAN-131993
|
||||||
|
|
||||||
|
Fixed an issue where a process (reportd) would crash while running a log query.
|
||||||
|
|
||||||
|
## PAN-131501
|
||||||
|
|
||||||
|
Fixed an issue when configuring Clientless VPN and executing the portal-getconfig CLI command where user groups were retrieved but were not freed, which caused a memory leak on a process (sslvpn).
|
||||||
|
|
||||||
|
## PAN-131491
|
||||||
|
|
||||||
|
Fixed an issue where the **ACC** risk meter displayed as zero for long time periods with a large amount of logs.
|
||||||
|
|
||||||
|
## PAN-130776
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where Applications and Threats content update deployment failed due to the content version date check.
|
||||||
|
|
||||||
|
## PAN-130573
|
||||||
|
|
||||||
|
Fixed an issue where the software pool for Regex results was depleted and caused connection failures.
|
||||||
|
|
||||||
|
## PAN-130447
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped offloaded traffic every time there was an explicit commit (**Commit** on the firewall locally or **Commit All Changes** in Panorama) or an implicit commit (such as an Antivirus update, Dynamic Update, or WildFire® update) on the firewall.
|
||||||
|
|
||||||
|
## PAN-129281
|
||||||
|
|
||||||
|
Fixed an issue where a process (useridd) restarted due to a buffer overflow when the time-to-live (TTL) and **Idle Timeout** values were set to **Never**, a timing issue between user group context and a process (sysd) callback, and a group mapping issue when multiple group mappings fetched the same groups with different override domains.
|
||||||
|
|
||||||
|
## PAN-128879
|
||||||
|
|
||||||
|
Fixed an issue where the PAN-OS XML API inject was not working for IP address to user mappings or for the import of software, content, and plugins.
|
||||||
|
|
||||||
|
## PAN-128398
|
||||||
|
|
||||||
|
Fixed an issue where performing a factory reset or enabling FIPS mode would cause the VM-Series plugin to revert to the default VM-Series plugin 1.0.0.
|
||||||
|
|
||||||
|
## PAN-127438
|
||||||
|
|
||||||
|
Fixed an issue where GlobalProtect portal configuration selection based on certificate template OID failed.
|
||||||
|
|
||||||
|
## PAN-127260
|
||||||
|
|
||||||
|
Fixed an issue where the /opt/pancfg partition became full due to a large amount of botnet reports that were not automatically deleted.
|
||||||
|
|
||||||
|
## PAN-125534
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 Series and PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where firewalls experienced high packet descriptor (on-chip) usage during uploads to the WildFire Cloud or WF-500 appliance.
|
||||||
|
|
||||||
|
## PAN-125501
|
||||||
|
|
||||||
|
Fixed an issue where URL information in a URL **Custom Report** was blank when the report contained flexible size fields (such as **URL Category List**).
|
||||||
|
|
||||||
|
## PAN-124658
|
||||||
|
|
||||||
|
Fixed an issue where the timer system call activated more frequently than expected, which caused higher than expected CPU usage.
|
||||||
|
|
||||||
|
## PAN-123637
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where configuring 1G small form-factor pluggable (SFP) ports on the firewall in forced speed mode (of 1G) rendered the link unusable when the peer device also had forced speed mode (of 1G) enabled.
|
||||||
|
|
||||||
|
## PAN-122004
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the Quad Small Form-factor Pluggable (QSFP) 28 ports 21 and 22 did not respond when plugged in with a Finisar 100G AOC cable.
|
||||||
|
|
||||||
|
## PAN-121626
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an intermittent issue where firewalls dropped packets, which caused issues such as traffic latency, slow file transfers, reduced throughput, internal path monitoring failures, and application failures.
|
||||||
|
|
||||||
|
## PAN-119452
|
||||||
|
|
||||||
|
An enhancement was made to improve subsequent loading times of device groups after the first load.
|
||||||
|
|
||||||
|
## PAN-117043
|
||||||
|
|
||||||
|
Fixed an issue where using special characters in the tag names of the Security policy rules returned the following error message when committing or pushing a configuration: group-tag is invalid.
|
||||||
|
|
||||||
|
## PAN-116480
|
||||||
|
|
||||||
|
Fixed an issue in Panorama where the show system search-engine-quota CLI command, the show log-collector serial-number <log-collector_SN> CLI command, and **Statistics** (**Panorama > Managed Collectors > Statistics**) showed incorrect log retention data.
|
||||||
|
|
||||||
|
## PAN-116002
|
||||||
|
|
||||||
|
Fixed an issue where an incorrect optimization could cause IP address-to-user mapping to not update within 60 seconds.
|
||||||
|
|
||||||
|
## PAN-114966
|
||||||
|
|
||||||
|
Fixed an issue where trunk interfaces were not working on Hyper-V.
|
||||||
|
|
||||||
|
## PAN-114533
|
||||||
|
|
||||||
|
Fixed an issue where traffic was blocked by safe search enforcement before matching the intended allow rule.
|
||||||
|
|
||||||
|
## PAN-110960
|
||||||
|
|
||||||
|
Fixed an issue on Panorama M-Series and virtual appliances where commits failed when you configured an address group object in the Include List (*Network > Zone > <zone-name> > Include List*).
|
||||||
|
|
||||||
|
## PAN-110441
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-5200 Series firewall only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an intermittent issue where the internal path monitoring failed, which caused the firewall to unexpectedly restart.
|
||||||
|
|
||||||
|
## PAN-107207
|
||||||
|
|
||||||
|
Fixed an issue where the VPN tunnel operational status incorrectly displays "up" even though the VPN tunnel is down.
|
||||||
|
|
||||||
|
## PAN-98933
|
||||||
|
|
||||||
|
Fixed an issue on an M-Series appliances in a high availability (HA) active/passive configuration where the schedules (*Device > Dynamic Updates*) were unresponsive after a failover or restart of Panorama.
|
||||||
|
|
||||||
|
## PAN-88136
|
||||||
|
|
||||||
|
Fixed a rare issue where a URL update caused the dataplane to restart.
|
||||||
@@ -0,0 +1,583 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.3
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-148988
|
||||||
|
|
||||||
|
A fix was made to address a Security Assertion Markup Language (SAML) authentication issue ([CVE-2020-2021](https://security.paloaltonetworks.com/CVE-2020-2021)).
|
||||||
|
|
||||||
|
## PAN-148068
|
||||||
|
|
||||||
|
Fixed an issue where SSL connections were blocked if you enabled decryption with the option to block sessions that have expired certificates. This issue included servers that sent an expired AddTrust certificate authority (CA) in the certificate chain.
|
||||||
|
|
||||||
|
## PAN-147424
|
||||||
|
|
||||||
|
Fixed an issue with internal buffer and file sizes where logs were discarded due to slow log purging when the incoming log rate was high.
|
||||||
|
|
||||||
|
## PAN-145195
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
and PAN-145149
|
||||||
|
```
|
||||||
|
|
||||||
|
A fix was made to address a buffer overflow vulnerability in PAN-OS that allowed an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a malicious request to the Captive Portal or Multi-Factor Authentication interface ([CVE-2020-2040](https://security.paloaltonetworks.com/CVE-2020-2040)).
|
||||||
|
|
||||||
|
## PAN-145151
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
and PAN-145149
|
||||||
|
```
|
||||||
|
|
||||||
|
A fix was made to address a buffer overflow vulnerability in PAN-OS that allowed an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a malicious request to the Captive Portal or Multi-Factor Authentication interface ([CVE-2020-2040](https://security.paloaltonetworks.com/CVE-2020-2040)).
|
||||||
|
|
||||||
|
## PAN-145150
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
and PAN-145149
|
||||||
|
```
|
||||||
|
|
||||||
|
A fix was made to address a buffer overflow vulnerability in PAN-OS that allowed an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a malicious request to the Captive Portal or Multi-Factor Authentication interface ([CVE-2020-2040](https://security.paloaltonetworks.com/CVE-2020-2040)).
|
||||||
|
|
||||||
|
## PAN-145026
|
||||||
|
|
||||||
|
Fixed an issue where Cortex Data Lake certificates on the firewall were not automatically renewed after the certificates expired.
|
||||||
|
|
||||||
|
## PAN-144782
|
||||||
|
|
||||||
|
Fixed an issue where a configuration audit created a large number of opresult.out files, which filled up the session/pan/user_tmp directory in opt/pancfg. This caused a slow Panorama response until a device restart was performed or the files were manually deleted from the root of the device.
|
||||||
|
|
||||||
|
## PAN-144646
|
||||||
|
|
||||||
|
Fixed an issue where a process (varrcvr) stopped responding on the PA-7000 Series Log Forwarding Card (LFC) when it received a verdict from the WildFire cloud.
|
||||||
|
|
||||||
|
## PAN-144221
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Microsoft Azure only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where a process (brdagent) stopped responding, which caused the firewall to restart unexpectedly.
|
||||||
|
|
||||||
|
## PAN-144073
|
||||||
|
|
||||||
|
Fixed an issue where on the Panorama management server, hub and branch firewall latency, jitter, and packet loss data was not updated when monitoring SD-WAN link performance (**Panorama > SD-WAN > Monitoring**).
|
||||||
|
|
||||||
|
## PAN-143957
|
||||||
|
|
||||||
|
Fixed an issue where, after loading a saved configuration snapshot by API, a custom role-based administrator required Superuser privileges to perform a full commit.
|
||||||
|
|
||||||
|
## PAN-143845
|
||||||
|
|
||||||
|
Fixed an issue where the firewall repeatedly rebooted due to a process (rasmgr) restarting when GlobalProtect was used in pre-logon mode.
|
||||||
|
|
||||||
|
## PAN-143537
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where disk utilization of the root partition increased until it reached 100%.
|
||||||
|
|
||||||
|
## PAN-143493
|
||||||
|
|
||||||
|
Fixed an memory issue associated with a process (mgmtsrvr) due to a large number of ACK packets in logs on Panorama or the log collector.
|
||||||
|
|
||||||
|
## PAN-143442
|
||||||
|
|
||||||
|
Fixed an issue where Amazon Web Services (AWS) Nitro System based VM-Series firewalls unexpectedly rebooted due to input/output (I/O) errors caused by improper NMVE I/O timeout settings.
|
||||||
|
|
||||||
|
## PAN-143169
|
||||||
|
|
||||||
|
Fixed an issue where running a test security-policy-match API command truncated the rule name to 31 characters.
|
||||||
|
|
||||||
|
## PAN-143130
|
||||||
|
|
||||||
|
Fixed an issue where, in Panorama, cloning a shared Security policy rule failed if done via the web interface and resulted in a process (configd) restarting with the following error message: Failed security rule(s): undefined The request could not be handled.
|
||||||
|
|
||||||
|
## PAN-142674
|
||||||
|
|
||||||
|
Fixed an issue where a process (brdagent) failed in a high availability (HA) configuration using High Speed Chassis Interconnect (HSCI) ports due to a memory leak.
|
||||||
|
|
||||||
|
## PAN-142302
|
||||||
|
|
||||||
|
Fixed an issue where the firewalls faced connection issues with Cortex Data Lake.
|
||||||
|
|
||||||
|
## PAN-142089
|
||||||
|
|
||||||
|
Fixed an internal logging issue for a daemon (authd).
|
||||||
|
|
||||||
|
## PAN-141923
|
||||||
|
|
||||||
|
Fixed an issue where authentication stopped working after a commit and a process (authd) exited, which caused other processes to exit.
|
||||||
|
|
||||||
|
## PAN-141844
|
||||||
|
|
||||||
|
Fixed an issue where promiscuous VLAN mode did not work with the new host drivers being used on the ESXi and single-root input/output virtualization (SR-IOV) with VLAN tagging did not work as expected. Both Data Plane Development Kit and packet mmap mode did not work.
|
||||||
|
|
||||||
|
## PAN-141563
|
||||||
|
|
||||||
|
Fixed an issue where Slot 8 path monitoring failure occurred due to a memory buildup in a process (logrcvr) that was caused by slow communication and connection between log forwarding and Cortex Data Lake.
|
||||||
|
|
||||||
|
## PAN-141262
|
||||||
|
|
||||||
|
Fixed an issue where the resolution of FQDN for a policy on the web interface did not work as expected if the FQDN contained capital letters.
|
||||||
|
|
||||||
|
## PAN-141239
|
||||||
|
|
||||||
|
Fixed an issue where dataplane free memory was depleted, which affected new GlobalProtect connections to the firewall.
|
||||||
|
|
||||||
|
## PAN-141221
|
||||||
|
|
||||||
|
Fixed an issue where a commit or content update operation with an error was not prevented from executing in the dataplane, which caused corruption in the dataplane policy cache.
|
||||||
|
|
||||||
|
## PAN-140982
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where a process (mprelay) on the control plane was restarted due to an internal heartbeat miss.
|
||||||
|
|
||||||
|
## PAN-140846
|
||||||
|
|
||||||
|
Fixed an issue where the dataplane restarted during a commit when **Netflow** was enabled.
|
||||||
|
|
||||||
|
## PAN-140669
|
||||||
|
|
||||||
|
Fixed a memory leak issue caused by a process (mgmtsrvr).
|
||||||
|
|
||||||
|
## PAN-140628
|
||||||
|
|
||||||
|
Fixed an issue where a memory leak on a process (useridd) caused multiple processes to restart during device serial number checks.
|
||||||
|
|
||||||
|
## PAN-140618
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where SNMP monitoring of the logging rate per device was incorrect.
|
||||||
|
|
||||||
|
## PAN-140575
|
||||||
|
|
||||||
|
Fixed an issue where a process (masterd) did not restart another process (logrcvr) on the Log Forwarding Card (LFC) after the process (logrcvr) crashed.
|
||||||
|
|
||||||
|
## PAN-140465
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed connection issues between IPv6 peers when the IPv6 neighbor cache was synchronized in an HA cluster where, after failover, the newly active firewall did not send multicast neighbor solicitation from its global unicast address.
|
||||||
|
|
||||||
|
## PAN-140389
|
||||||
|
|
||||||
|
Fixed an issue on Panorama in Legacy mode where configuring Network File System (NFS) log storage (**Device > Setup > Operations**) caused all plugin installations to fail.
|
||||||
|
|
||||||
|
## PAN-140386
|
||||||
|
|
||||||
|
Fixed an intermittent issue where the firewall used IP addresses instead of domain names for URL category lookup after upgrading to 9.0.6.
|
||||||
|
|
||||||
|
## PAN-140375
|
||||||
|
|
||||||
|
Fixed an issue where a process (logrcvr) exited due to a race condition.
|
||||||
|
|
||||||
|
## PAN-140270
|
||||||
|
|
||||||
|
Added additional debugging to periodically collect the debug dataplane internal pdt bcm counters graphical CLI command's output in the Tech Support File (TSF).
|
||||||
|
|
||||||
|
## PAN-140121
|
||||||
|
|
||||||
|
Fixed an issue where a process (authid) used a large amount of memory due to many incomplete authentication requests, which caused an out-of-memory (OOM) condition.
|
||||||
|
|
||||||
|
## PAN-140043
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7050 firewalls running on PA-7000 100G NPCs only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the PA-7000 100G NPC Native Implemented Function (NIF) initialization took longer than expected, which caused internal path monitoring failure and sent the firewall into a non-functional state while rebooting.
|
||||||
|
|
||||||
|
## PAN-139935
|
||||||
|
|
||||||
|
Fixed an issue in the URL process where a process (devsrvr) stopped responding.
|
||||||
|
|
||||||
|
## PAN-139858
|
||||||
|
|
||||||
|
Fixed an issue where **Policy > Security > Test Policy Match** did not work when the source user or group length was greater than 20 characters.
|
||||||
|
|
||||||
|
## PAN-139727
|
||||||
|
|
||||||
|
Fixed an issue where disabling predefined trusted root certificates did not have any effect.
|
||||||
|
|
||||||
|
## PAN-139718
|
||||||
|
|
||||||
|
Fixed an issue where the firewall failed stateful inspection for GTP forward relocation requests greater than 1,500 bytes and could not parse Access Point Name (APN) information in forward relocation requests.
|
||||||
|
|
||||||
|
## PAN-139661
|
||||||
|
|
||||||
|
Fixed an issue that led to exhaustion of memory, which resulted in path monitoring failures when Cortex Data Lake was configured.
|
||||||
|
|
||||||
|
## PAN-139595
|
||||||
|
|
||||||
|
Fixed an issue on Panorama in Legacy mode where a process (logd) repeatedly restarted while processing incoming logs and caused Panorama to reboot.
|
||||||
|
|
||||||
|
## PAN-139555
|
||||||
|
|
||||||
|
Fixed an issue where after upgrading the passive firewall, the outer UDP sessions synced from the active firewall did not retain the rule information and after failover, GPRS tunneling protocol (GTP) inspection did not work.
|
||||||
|
|
||||||
|
## PAN-139391
|
||||||
|
|
||||||
|
Fixed an issue where unique GlobalProtect portal profiles were not selected in the correct order.
|
||||||
|
|
||||||
|
## PAN-139371
|
||||||
|
|
||||||
|
Fixed an issue where a commit failed with the following error message: destination is invalid when using objects from static routes.
|
||||||
|
|
||||||
|
## PAN-138870
|
||||||
|
|
||||||
|
Fixed an issue where a process (configd) restarted and administrators received one of the following error messages: Timed out while getting config lock. Please try again or Please wait while the server reboots... due to a database error.
|
||||||
|
|
||||||
|
## PAN-138813
|
||||||
|
|
||||||
|
Fixed a performance drop issue seen when using API to configure larger sets of objects (more than 25 objects).
|
||||||
|
|
||||||
|
## PAN-138739
|
||||||
|
|
||||||
|
Fixed an issue where, in an HA active/active configuration in a virtual wire deployment with asymmetric traffic, decryption did not work for some sites.
|
||||||
|
|
||||||
|
## PAN-138674
|
||||||
|
|
||||||
|
Fixed an issue where custom role-based admins were able to reset the rule hit counter for disabled device groups.
|
||||||
|
|
||||||
|
## PAN-138648
|
||||||
|
|
||||||
|
Fixed an issue with internal buffer and file sizes where logs were discarded due to slow log purging when the incoming log rate was high.
|
||||||
|
|
||||||
|
## PAN-138476
|
||||||
|
|
||||||
|
Fixed an intermittent issue where logs were delayed or missing when querying for logs by applying filters. To leverage this fix, you must upgrade Panorama to 9.0.9 and the Cloud Services plugin to 1.6.0-h1.
|
||||||
|
|
||||||
|
## PAN-138213
|
||||||
|
|
||||||
|
Fixed an issue where a Panorama **Custom Report** based on the **Detailed Logs > Panorama Data > Traffic** database was not able to report on decrypted sessions.
|
||||||
|
|
||||||
|
## PAN-138037
|
||||||
|
|
||||||
|
Fixed an issue where the host information profile (HIP) match message was automatically enabled when modifying the GlobalProtect Agent settings.
|
||||||
|
|
||||||
|
## PAN-138034
|
||||||
|
|
||||||
|
Fixed an issue where virtual machine (VM) information source Dynamic Address Groups overrode static address groups, which caused traffic to hit the wrong Security policy rule.
|
||||||
|
|
||||||
|
## PAN-137902
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where hot swapping a PA-7000 100G NPC with a PA-7000 20G NPC caused packet buffer leak and slot restarts.
|
||||||
|
|
||||||
|
## PAN-137885
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls in Microsoft Azure environment only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where a firewall with accelerated networking enabled was unable to process packets efficiently because of underlying Microsoft drivers. To leverage this fix, you must upgrade to VM-Series Plugin 1.0.12.
|
||||||
|
|
||||||
|
## PAN-137867
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls only, running with both a PA-7000 100G NPC and a PA-7000 20G NPC
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where IPSec traffic caused dataplane restarts.
|
||||||
|
|
||||||
|
## PAN-137777
|
||||||
|
|
||||||
|
Fixed an issue where GlobalProtect logs failed to send to syslog servers over a TCP connection.
|
||||||
|
|
||||||
|
## PAN-137716
|
||||||
|
|
||||||
|
Fixed an issue where, for users with admin roles, logs for only one device group were displayed due to a query string with multiple device groups.
|
||||||
|
|
||||||
|
## PAN-137673
|
||||||
|
|
||||||
|
Fixed an issue where a memory leak associated with a process (devsrvr) caused an out-of-memory (OOM) condition on the firewall.
|
||||||
|
|
||||||
|
## PAN-137656
|
||||||
|
|
||||||
|
Fixed an issue where the show config diff CLI command did not work correctly and produced unexpected output.
|
||||||
|
|
||||||
|
## PAN-137401
|
||||||
|
|
||||||
|
Fixed an issue where the authentication policy did not redirect users for Captive Portal authentication if the attached authentication profile did not have **Enable Additional Authentication Factors** selected.
|
||||||
|
|
||||||
|
## PAN-137387
|
||||||
|
|
||||||
|
Fixed an issue where URL filtering used the IP address instead of the hostname, which led to incorrect URL categorization.
|
||||||
|
|
||||||
|
## PAN-137251
|
||||||
|
|
||||||
|
Fixed an issue where a Panorama appliance running PAN-OS 9.1.0 was unable to export address objects and displayed the following error message: Error while exporting.
|
||||||
|
|
||||||
|
## PAN-137152
|
||||||
|
|
||||||
|
Fixed an issue where SSL decrypted traffic was dropped due to a certificate status error during session resumption.
|
||||||
|
|
||||||
|
## PAN-136957
|
||||||
|
|
||||||
|
Fixed an issue where access was denied if a password contained more than 63 characters.
|
||||||
|
|
||||||
|
## PAN-136950
|
||||||
|
|
||||||
|
Fixed an issue where, on a firewall managed by Panorama, the XML API based IP tags were lost after a firewall reboot or process (**useridd**) restart.
|
||||||
|
|
||||||
|
## PAN-136791
|
||||||
|
|
||||||
|
Fixed an issue where, in a particular scenario, the first response to a SIP INVITE message created incorrect appinfo2ip entries and caused Via header translation failure.
|
||||||
|
|
||||||
|
## PAN-136765
|
||||||
|
|
||||||
|
Fixed an issue where an FQDN update that resolved to the same IP address of another FQDN across different policies caused the other FQDN to be deleted due to missing FQDN aggregation.
|
||||||
|
|
||||||
|
## PAN-136726
|
||||||
|
|
||||||
|
Fixed an issue on the firewall where the dataplane pan-task process (all_pktproc) stopped responding while inspecting Server Message Block (SMB) traffic.
|
||||||
|
|
||||||
|
## PAN-136716
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama virtual appliances only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where SNMP monitoring of ifSpeed reported the interface speed as 0 for interfaces other than eth0.
|
||||||
|
|
||||||
|
## PAN-136703
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3000 Series and PA-800 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue with insufficient memory allocation for configurations to accommodate the PAN-OS 9.0 Dynamic Address Group feature.
|
||||||
|
|
||||||
|
## PAN-136649
|
||||||
|
|
||||||
|
Fixed an issue where PA-7000 20GXM and PA-7000 20GQXM Network Processing Cards (NPCs) failed to process some sessions for Layer 7 inspection due to internal maximum threshold value that was not set.
|
||||||
|
|
||||||
|
## PAN-136623
|
||||||
|
|
||||||
|
Fixed an issue where a process (useridd) failed due to internal user groups that were loading from the disk taking over the lock.
|
||||||
|
|
||||||
|
## PAN-136612
|
||||||
|
|
||||||
|
Fixed an issue where fragmented packets leaked, which caused the depletion of Work Query Entry (WQE) pools.
|
||||||
|
|
||||||
|
## PAN-136582
|
||||||
|
|
||||||
|
Fixed an issue where, when the app-version from the request header was long, the converted XML was truncated, which caused parsing to fail by a process (rasmgr) due to a limitation on the buffer length.
|
||||||
|
|
||||||
|
## PAN-136470
|
||||||
|
|
||||||
|
Fixed an issue where a process (all_pktproc) restarted while processing packets with 0.0.0.0 and destination protocol 251 that internally mapped to GTP-C traffic, which caused the dataplane to restart.
|
||||||
|
|
||||||
|
## PAN-136173
|
||||||
|
|
||||||
|
Fixed an issue where dataplane interfaces remained down after active firewall bootup or a high availability (HA) failover.
|
||||||
|
|
||||||
|
## PAN-136007
|
||||||
|
|
||||||
|
Fixed an issue where generating subordinate ECDSA Certificate Authority (CA) certificates from the web interface failed if the **Common Name** field contained a space.
|
||||||
|
|
||||||
|
## PAN-135946
|
||||||
|
|
||||||
|
Fixed an intermittent issue where Panorama was unable to query logs from the log collector due to large file sizes in es_cache_cron.log.
|
||||||
|
|
||||||
|
## PAN-135865
|
||||||
|
|
||||||
|
Fixed an issue that prevented Panorama from being switched out of management-only mode when deployed in Amazon Web Services (AWS) instance types M5 and C5.
|
||||||
|
|
||||||
|
## PAN-135844
|
||||||
|
|
||||||
|
Fixed an issue where a commit job failed due to a process (mgmtsrvr) exiting.
|
||||||
|
|
||||||
|
## PAN-135796
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped DNS requests for root servers when the action of the DNS security signature was set to **alert** or **sinkhole** in an **Anti-Spyware** Security profile.
|
||||||
|
|
||||||
|
## PAN-135684
|
||||||
|
|
||||||
|
Fixed an issue with log collectors on Panorama where large index sizes caused higher CPU usage than expected when disk space usage was high.
|
||||||
|
|
||||||
|
## PAN-135547
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where administrators were unable to delete a shared address object even when it was not referenced in the configuration.
|
||||||
|
|
||||||
|
## PAN-135504
|
||||||
|
|
||||||
|
Fixed an issue where the GlobalProtect client used IPv6 during gateway login but used IPv4 during IPsec tunnel creation, which caused it to fallback to SSL.
|
||||||
|
|
||||||
|
## PAN-135418
|
||||||
|
|
||||||
|
Fixed an issue on the firewall where configuring uppercase **User Domain** values in authentication profiles led to a failure in GlobalProtect Agent configuration selection based on the domain user match condition.
|
||||||
|
|
||||||
|
## PAN-135356
|
||||||
|
|
||||||
|
Fixed an issue where policies that contained objects did not display correctly when exported to CSV or PDF format.
|
||||||
|
|
||||||
|
## PAN-135321
|
||||||
|
|
||||||
|
Fixed an issue where all NAT rules using the same FQDN entries as translated IP addresses were not updated when the IP addresses changed for those FQDNs.
|
||||||
|
|
||||||
|
## PAN-135314
|
||||||
|
|
||||||
|
Fixed an issue where, with a new Panorama appliance running PAN-OS 9.1.0 and a firewall running an earlier version, the following error message displayed: interface sdwan is not a valid reference.
|
||||||
|
|
||||||
|
## PAN-135262
|
||||||
|
|
||||||
|
A fix was made to address a vulnerability involving information exposure through log files where an administrator's password or other sensitive information was logged in cleartext while using the CLI in PAN-OS software. The opcmdhistory.log file was introduced to track operational command (op-command) usage but did not mask all sensitive information ([CVE-2020-2044](https://security.paloaltonetworks.com/CVE-2020-2044)).
|
||||||
|
|
||||||
|
## PAN-135158
|
||||||
|
|
||||||
|
Fixed an issue where setting an IPv6 destination filter for the packet-diag option returned an error regarding a character limit.
|
||||||
|
|
||||||
|
## PAN-134979
|
||||||
|
|
||||||
|
Fixed an issue where TMP files were not deleted, which caused the root partition to run out of disk space and caused issues with accessing the firewall.
|
||||||
|
|
||||||
|
## PAN-134624
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the VLAN interface failed to obtain the MAC address when the interface was used as a DHCP relay agent.
|
||||||
|
|
||||||
|
## PAN-134431
|
||||||
|
|
||||||
|
Fixed an issue with Security Assertion Markup Language (SAML) authentication where the firewall used old authd_id values, which resulted in failed authentication.
|
||||||
|
|
||||||
|
## PAN-133885
|
||||||
|
|
||||||
|
Fixed an issue where DNS proxy failed due to incorrect mapping of the DNS transaction ID.
|
||||||
|
|
||||||
|
## PAN-133727
|
||||||
|
|
||||||
|
Fixed an issue where Session Initiation Protocol (SIP) messages were not parsed correctly when the packet was received in separate segments, which caused the receiver to receive corrupted messages.
|
||||||
|
|
||||||
|
## PAN-133673
|
||||||
|
|
||||||
|
Fixed an issue that caused a procses (ikemgr) to exit when site-to-site VPNs experienced connectivity interruptions.
|
||||||
|
|
||||||
|
## PAN-133495
|
||||||
|
|
||||||
|
Fixed an issue where the Terminal Server (TS) Agent disconnected on the firewall after a failover or reboot.
|
||||||
|
|
||||||
|
## PAN-133285
|
||||||
|
|
||||||
|
Fixed an issue on the firewalls where configuring a default Online Certificate Status Protocol (OCSP) URL in front of an intermediate certificate authority (CA) in a certificate profile did not override the OCSP URL during the validation of client certificates issued by the intermediate CA.
|
||||||
|
|
||||||
|
## PAN-132922
|
||||||
|
|
||||||
|
Fixed an issue where service objects were unable to be deleted if they were configured to exceed firewall limits.
|
||||||
|
|
||||||
|
## PAN-131973
|
||||||
|
|
||||||
|
Fixed an issue where both firewalls in an HA active/passive configuration stopped responding at the same time.
|
||||||
|
|
||||||
|
## PAN-130562
|
||||||
|
|
||||||
|
Fixed an issue where, in VM-Series firewalls deployed using init-cfg.txt in the bootstrap process and set in an HA configuration, the configuration did not display as synchronized due to the initcfg configuration.
|
||||||
|
|
||||||
|
## PAN-130168
|
||||||
|
|
||||||
|
Fixed an issue where a process (pan_comm) stopped responding due to operation commands run during a commit.
|
||||||
|
|
||||||
|
## PAN-128761
|
||||||
|
|
||||||
|
A fix was made to address an OS command injection vulnerability in the PAN-OS management interface that allowed authenticated administrators to execute arbitrary OS commands with root privileges ([CVE-2020-2037](https://security.paloaltonetworks.com/CVE-2020-2037)).
|
||||||
|
|
||||||
|
## PAN-128078
|
||||||
|
|
||||||
|
Fixed an issue where a process (mgmtsrvr) stopped responding and was inaccessible through SSH or HTTPS until the firewall was power cycled.
|
||||||
|
|
||||||
|
## PAN-127434
|
||||||
|
|
||||||
|
Fixed an issue where reports for URLs were not generating the correct data output.
|
||||||
|
|
||||||
|
## PAN-127318
|
||||||
|
|
||||||
|
Fixed an issue where the firewall intermittently dropped DNS A or AAAA queries received over IPSec tunnels due to a session installation failure.
|
||||||
|
|
||||||
|
## PAN-126938
|
||||||
|
|
||||||
|
Fixed an issue where multiple daemons restarted due to MP ARP overflow.
|
||||||
|
|
||||||
|
## PAN-125730
|
||||||
|
|
||||||
|
Fixed an issue where packets tagged with IP protocol 252 were incorrectly treated as GPRS tunneling protocol (GTP) traffic, which caused the packet processor to terminate.
|
||||||
|
|
||||||
|
## PAN-125410
|
||||||
|
|
||||||
|
Fixed an issue where a new GPRS tunneling protocol version 2 control plane (GTPv2-C) session reused GTP-C tunnel parameters within two seconds after deleting the old GTP-C session, which caused a session conflict on the firewall.
|
||||||
|
|
||||||
|
## PAN-121598
|
||||||
|
|
||||||
|
Fixed an issue where the PAN-OS XML API packet capture (pcap) export failed with the following error message: Missing value for parameter device_name. Now, device_name and sessionid are no longer required parameters.
|
||||||
|
|
||||||
|
## PAN-119118
|
||||||
|
|
||||||
|
Fixed an issue where license and content error files received from the update and license servers were not saved to disk.
|
||||||
|
|
||||||
|
## PAN-118468
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls on VMware ESXi only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where the firewall stays in a boot loop and enters maintenance mode after adding a 60GB disk.
|
||||||
|
|
||||||
|
## PAN-116843
|
||||||
|
|
||||||
|
Fixed an issue on Panorama where, when navigating through **Policies**, the following error message displayed: show rule hit count op-command failed.
|
||||||
|
|
||||||
|
## PAN-115093
|
||||||
|
|
||||||
|
Fixed an issue where the firewall generated excessive logs for content decoder (CTD) errors.
|
||||||
|
|
||||||
|
## PAN-114540
|
||||||
|
|
||||||
|
Fixed an issue where renaming a template stack did not change the value and reset to the original value after you commit the change.
|
||||||
|
|
||||||
|
## PAN-114427
|
||||||
|
|
||||||
|
Fixed an issue where an empty host name in the HTTP header caused a web server process (*websrvr*) to stop responding when you accessed the captive portal redirect page.
|
||||||
|
|
||||||
|
## PAN-112988
|
||||||
|
|
||||||
|
Fixed an issue where a process (*useridd*) leaked memory, which caused the firewall to drop traffic and display the following error message: Out-of-memory condition detected, kill process.
|
||||||
|
|
||||||
|
## PAN-112539
|
||||||
|
|
||||||
|
Fixed an issue where the firewall stopped forwarding logs to the log collector from the Log Processing Card (LPC) after a commit push from Panorama due to a race condition.
|
||||||
|
|
||||||
|
## PAN-112120
|
||||||
|
|
||||||
|
Fixed an issue where threat **Name** field of a threat **Custom Report** displayed the threat ID instead of the threat name.
|
||||||
|
|
||||||
|
## PAN-111614
|
||||||
|
|
||||||
|
Fixed an issue with summary reports where displayed dates were incorrect due to the date range calculation not considering the change in year.
|
||||||
|
|
||||||
|
## PAN-102202
|
||||||
|
|
||||||
|
Fixed an issue where the OSPF summary Link State Advertisement (LSA) for the default 0.0.0.0/0 route were not advertised by the Area Border Router (ABR).
|
||||||
|
|
||||||
|
## PAN-98803
|
||||||
|
|
||||||
|
Fixed an issue where the IP address-to-tag mappings for Dynamic Address Groups did not display as expected on Panorama after you configured the Panorama plugin to monitor virtual machines or endpoints in your AWS, Azure, or Cisco ACI environment without installing the NSX plugin.
|
||||||
|
|
||||||
|
## PAN-98694
|
||||||
|
|
||||||
|
Fixed an issue on a PA-5200 Series firewall in a high availability (HA) active/passive configuration where the firewall dropped TCP-FIN packets after a failover.
|
||||||
@@ -0,0 +1,261 @@
|
|||||||
|
---
|
||||||
|
type: Addressed
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.7
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## PAN-158691
|
||||||
|
|
||||||
|
Fixed an issue with GPRS tunneling protocol (GTP) event packet capture (pcap) where enabling **Packet Capture** did not work.
|
||||||
|
|
||||||
|
## PAN-156375
|
||||||
|
|
||||||
|
Fixed an issue where multiple all_pktoproc daemons restarted while processing HTTP/2 traffic in sw_offload.
|
||||||
|
|
||||||
|
## PAN-156017
|
||||||
|
|
||||||
|
Fixed an issue where a host information profile (HIP) report XML buffer caused a memory leak.
|
||||||
|
|
||||||
|
## PAN-155517
|
||||||
|
|
||||||
|
Fixed an issue where a sudden increase in URL-cloud data challenged the cache capacity of the device.
|
||||||
|
|
||||||
|
## PAN-155453
|
||||||
|
|
||||||
|
Fixed an issue in the configuration logs where the destination zone was masked by asterisks.
|
||||||
|
|
||||||
|
## PAN-155053
|
||||||
|
|
||||||
|
Fixed an issue where user information in the Clientless VPN wasn't handled properly in high availability (HA) configurations, which resulted in the firewall being unable to create more user sessions.
|
||||||
|
|
||||||
|
## PAN-154323
|
||||||
|
|
||||||
|
Fixed an issue in Panorama where frequent API requests caused the Panorama web interface to become unresponsive. This issue occurred because the web interface automatically refreshed after each request.
|
||||||
|
|
||||||
|
## PAN-154016
|
||||||
|
|
||||||
|
Fixed an issue where auto-commits failed for VM-Series firewalls bootstrapped with new content installation during bootstrap. The firewalls displayed the following error message: Details:Error: Undefined application <application-name>.
|
||||||
|
|
||||||
|
## PAN-153791
|
||||||
|
|
||||||
|
Fixed an issue in dpdk code that cause a system restart on a process (brdagent).
|
||||||
|
|
||||||
|
## PAN-153526
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls with 100G NPC (Network Processing Cards) only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where multicast groups were not set correctly, which caused ARP entries to display as incomplete and not update to correct values.
|
||||||
|
|
||||||
|
## PAN-153207
|
||||||
|
|
||||||
|
Fixed an issue for VM-Series firewalls deployed on Azure where a process (pan_comm) restarted if DPDK was on.
|
||||||
|
|
||||||
|
## PAN-153174
|
||||||
|
|
||||||
|
Fixed an issue where using XML API to download pcap did not work if the pcap file was larger than 8MB.
|
||||||
|
|
||||||
|
## PAN-153107
|
||||||
|
|
||||||
|
Fixed an issue where a dataplane process stopped responding while processing fragmented traffic on GTP-U tunnels.
|
||||||
|
|
||||||
|
## PAN-152912
|
||||||
|
|
||||||
|
Fixed an issue where a content update caused the Panorama XML cache build to fail. This resulted references of the used objects on Panorama being removed, which caused commits on the managed firewalls to fail.
|
||||||
|
|
||||||
|
## PAN-152762
|
||||||
|
|
||||||
|
Fixed an issue where role-based administrators were unable to import certificate key pairs onto firewalls.
|
||||||
|
|
||||||
|
## PAN-152746
|
||||||
|
|
||||||
|
Fixed an issue where the firewall dropped GTPv2-x Create Session Response packets with the following error message: bad port 84b.
|
||||||
|
|
||||||
|
## PAN-152743
|
||||||
|
|
||||||
|
Fixed an issue where, when initial flows from both directions reached the firewall at the same time, a race condition occurred, which caused the firewall to display the following error message: Duplicate flows detected while inserting <number>, flow <number> with the same key. The flow keys were identical due to the flows having the same SRC and DST ports.
|
||||||
|
|
||||||
|
## PAN-152098
|
||||||
|
|
||||||
|
Fixed an issue where the Policy Optimizer for some device groups showed incorrect data with a - character in the rule usage column.
|
||||||
|
|
||||||
|
## PAN-151872
|
||||||
|
|
||||||
|
Fixed an issue where MAC addresses containing certain characters in sequential order caused an issue with TCP connections
|
||||||
|
|
||||||
|
## PAN-151691
|
||||||
|
|
||||||
|
Fixed an issue where the number of items under **Add match criteria** for Dynamic Address Groups did not update after setting a search filter string.
|
||||||
|
|
||||||
|
## PAN-151584
|
||||||
|
|
||||||
|
Fixed an issue where the firewall changed the TTL (time-to-live) value in DNS responses to 0 when the firewall failed to resolve the DNS Security service, which caused a large amount of DNS requests to be sent to the DNS server.
|
||||||
|
|
||||||
|
## PAN-151486
|
||||||
|
|
||||||
|
Fixed an issue where user activity reports failed to run when the firewall was in FIPS mode.
|
||||||
|
|
||||||
|
## PAN-151483
|
||||||
|
|
||||||
|
Fixed an issue where, when an out-of-order stream of TCP packets was subjected to HTTP header insertion, the packets were duplicated.
|
||||||
|
|
||||||
|
## PAN-151458
|
||||||
|
|
||||||
|
Fixed an issue on firewalls with HA active/active configurations where GlobalProtect gateways timed out on-demand connections. This occurred because the **Inactivity Logout** timer did not reset.
|
||||||
|
|
||||||
|
## PAN-151214
|
||||||
|
|
||||||
|
Fixed an issue where an XML API call to display configuration logs truncated the change-preview field of the logs if the entry had more than 64 characters.
|
||||||
|
|
||||||
|
## PAN-151210
|
||||||
|
|
||||||
|
Fixed an issue where the dynamic address group learned in the parent dynamic group was not pushed to the child dynamic address group if the child dynamic address group was not configured with notify groups under the respective plugin.
|
||||||
|
|
||||||
|
When using the CLI command debug dau settings device-group recursive yes/no, clear previous dynamic address group entries from the Panorama database using the CLI command debug dau clear database device-group <dynamic address group name> for all dynamic address groups under the hierarchy for the dynamic address group configured in the monitoring definition. Also, do a full sync from the plugins configured using the command request plugins <plugin-name> sync.
|
||||||
|
|
||||||
|
## PAN-150968
|
||||||
|
|
||||||
|
Fixed a rare issue with HTTP/2 decryption that caused packet header bytes to be corrupted, which caused packet drops.
|
||||||
|
|
||||||
|
## PAN-150852
|
||||||
|
|
||||||
|
Fixed an issue with SMTP that occurred when attachment file names were longer than the allocated buffer. If the file name was longer than the buffer and Layer 7 inspection was enabled, the file was dropped, which caused session errors and an email to not be sent.
|
||||||
|
|
||||||
|
## PAN-150247
|
||||||
|
|
||||||
|
Fixed an issue on the firewall where GlobalProtect Clientless VPN portal landing page customization for the navbar_bg_color variable did not take effect.
|
||||||
|
|
||||||
|
## PAN-149915
|
||||||
|
|
||||||
|
Fixed an issue where a Panorama virtual appliance was unable to manage more than 2,500 firewalls when 28 or more CPU cores were available.
|
||||||
|
|
||||||
|
## PAN-149645
|
||||||
|
|
||||||
|
Fixed an issue in a virtual wire deployment configured with **Link State Pass Through** enabled where, when one member port went down, the peer port took longer than expected to change the status to **Down**.
|
||||||
|
|
||||||
|
## PAN-149641
|
||||||
|
|
||||||
|
Fixed an issue where firewalls stopped refreshing IP tag information when configured with the **VM Information Sources** feature with a VMWare vCenter Server.
|
||||||
|
|
||||||
|
## PAN-149547
|
||||||
|
|
||||||
|
Fixed an issue where, after a change in Security policies, traffic logs for inner GTP-U sessions did not show IMSI or IMEI fields following a commit.
|
||||||
|
|
||||||
|
## PAN-149339
|
||||||
|
|
||||||
|
Fixed an issue where, when an ECMP route changed, the flow table in the offload engine was not updated.
|
||||||
|
|
||||||
|
## PAN-149327
|
||||||
|
|
||||||
|
Fixed an issue where the show gtp info CLI command returned an error.
|
||||||
|
|
||||||
|
## PAN-149297
|
||||||
|
|
||||||
|
Fixed a buffer overflow issue on the management server, which forced the administrator to log out on the web interface.
|
||||||
|
|
||||||
|
## PAN-149207
|
||||||
|
|
||||||
|
Fixed an issue where the clear log acc CLI command did not remove URL summary logs.
|
||||||
|
|
||||||
|
## PAN-149101
|
||||||
|
|
||||||
|
Fixed an issue where the first SYN message of an FTP-DATA connection was dropped on non-session-owner appliances in an HA active/active configuration.
|
||||||
|
|
||||||
|
## PAN-148818
|
||||||
|
|
||||||
|
Fixed an issue where the decryption profile was configured without the **Block sessions with expired certificates** option, but the firewall still blocked websites that were signed by an Expired AddTrust Root CA (certificate authority).
|
||||||
|
|
||||||
|
## PAN-148767
|
||||||
|
|
||||||
|
Fixed an issue where the firewall incorrectly created GTP-U sessions from Create Session Request and Create Session Response packets.
|
||||||
|
|
||||||
|
## PAN-147959
|
||||||
|
|
||||||
|
Fixed an issue where the last commit state did not change to config sent to device when pushing a device group configuration in the **Managed Device > Summary** page on Panorama.
|
||||||
|
|
||||||
|
## PAN-147720
|
||||||
|
|
||||||
|
Fixed an issue where the firewall management server crashed when a report with a duration of 7 or more days was run.
|
||||||
|
|
||||||
|
## PAN-147385
|
||||||
|
|
||||||
|
Fixed an issue where firewall buffers were depleted with GTP traffic due to the mishandling of conflicting sessions.
|
||||||
|
|
||||||
|
## PAN-146373
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
VM-Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where a memory leak occurred on a process (vm_agent) due to host synchronization check.
|
||||||
|
|
||||||
|
## PAN-146236
|
||||||
|
|
||||||
|
Fixed an issue where the firewall was unable to properly create stream control transmission protocol (SCTP) sessions for multi-homed environments when multiple endpoints on the same SCTP associations sent INIT/INIT-ACK chunks during handshakes.
|
||||||
|
|
||||||
|
## PAN-144376
|
||||||
|
|
||||||
|
Fixed an issue in a multi-vsys environment where the firewall dropped RTP predict sessions and was unable to match them to their parent sessions due to a zone change.
|
||||||
|
|
||||||
|
## PAN-142604
|
||||||
|
|
||||||
|
Fixed an issue where virtual memory of a process (configd) continuously increased until it stopped responding.
|
||||||
|
|
||||||
|
## PAN-142548
|
||||||
|
|
||||||
|
Fixed an memory leak issue in a process (configd) that caused the firewall to be inaccessible.
|
||||||
|
|
||||||
|
## PAN-142103
|
||||||
|
|
||||||
|
Fixed an issue where administrators were logged out of the web interface while making changes.
|
||||||
|
|
||||||
|
## PAN-141719
|
||||||
|
|
||||||
|
Fixed an issue where the **before-change-preview** and **after-change-preview** filters were usable even though they did not return configuration logs.
|
||||||
|
|
||||||
|
## PAN-141255
|
||||||
|
|
||||||
|
Removed the fields **device SN** and **device name** on Panorama from the predefined filter used in **Log Forwarding** and **Log Settings**.
|
||||||
|
|
||||||
|
## PAN-140985
|
||||||
|
|
||||||
|
Fixed an issue where Cortex Data Lake traffic was identified as ssl instead of paloalto-logging-service.
|
||||||
|
|
||||||
|
## PAN-140222
|
||||||
|
|
||||||
|
Fixed an issue where logs were not forwarded to the syslog server with the following error message: profile: Syslog (1) is duplicated.
|
||||||
|
|
||||||
|
## PAN-137233
|
||||||
|
|
||||||
|
Fixed an issue where authenticating to GlobalProtect via expired SAML requests (waiting more than 10 minutes) still sent authentication to the SAML server. This invalidated the previously connected gateway and connected users to the second best gateway.
|
||||||
|
|
||||||
|
## PAN-129314
|
||||||
|
|
||||||
|
Fixed an issue where the internal SQLite3 database was locked, which caused a process (useridd) to stop responding and group mapping retrieval to fail. This issue also caused the group mapping list to not display from the CLI.
|
||||||
|
|
||||||
|
## PAN-124579
|
||||||
|
|
||||||
|
Fixed an issue where a process (all_task_3) restarted, which caused the tunnels to reset.
|
||||||
|
|
||||||
|
## PAN-119161
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Fixed an issue where firewalls were unable to start up a Network Processing Card (NCP) due to a process (brdagent) restarting repeatedly.
|
||||||
|
|
||||||
|
## PAN-110720
|
||||||
|
|
||||||
|
Fixed an issue where a high volume of traffic over SSL VPN caused a process (all_pktproc) to unexpectedly stop responding.
|
||||||
|
|
||||||
|
## PAN-100489
|
||||||
|
|
||||||
|
Fixed an issue where the **Group found** flag was set to **NO** on User-ID logs on the web interface, even when the user belonged to a group retrieved from the Active Directory (AD) server.
|
||||||
|
|
||||||
|
## PAN-79640
|
||||||
|
|
||||||
|
Fixed an issue where the firewall intermittently logged incorrect actions for WildFire submissions and reports.
|
||||||
@@ -6,6 +6,42 @@ source: common-crawl
|
|||||||
crawl: CC-MAIN-2026-12
|
crawl: CC-MAIN-2026-12
|
||||||
---
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
If you use Panorama to retrieve logs from Cortex Data Lake (CDL), new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
|
||||||
|
|
||||||
|
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to CDL and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading a PA-220 firewall takes up to an hour or more.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
PA-220 firewalls are experiencing slower web interface and CLI performance times.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## APPORTAL-3313
|
||||||
|
|
||||||
|
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
|
||||||
|
|
||||||
|
## APPORTAL-3309
|
||||||
|
|
||||||
|
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
|
||||||
|
|
||||||
|
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
|
||||||
|
|
||||||
## APL-8269
|
## APL-8269
|
||||||
|
|
||||||
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
|
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
|
||||||
|
|||||||
@@ -6,6 +6,50 @@ source: common-crawl
|
|||||||
crawl: CC-MAIN-2026-12
|
crawl: CC-MAIN-2026-12
|
||||||
---
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Not all screenshots are updated in the documentation for 10.0.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
New features for PAN-OS 10.0.2 are not included in on-device help. Refer to [docs.paloaltonetworks.com](https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-web-interface-help.html) for the latest version.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
If you use Panorama to retrieve logs from Cortex Data Lake (CDL), new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
|
||||||
|
|
||||||
|
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to CDL and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading a PA-220 firewall takes up to an hour or more.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
PA-220 firewalls are experiencing slower web interface and CLI performance times.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## APPORTAL-3313
|
||||||
|
|
||||||
|
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
|
||||||
|
|
||||||
|
## APPORTAL-3309
|
||||||
|
|
||||||
|
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
|
||||||
|
|
||||||
|
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
|
||||||
|
|
||||||
## APL-8269
|
## APL-8269
|
||||||
|
|
||||||
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
|
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
|
||||||
|
|||||||
@@ -6,6 +6,42 @@ source: common-crawl
|
|||||||
crawl: CC-MAIN-2026-12
|
crawl: CC-MAIN-2026-12
|
||||||
---
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
If you use Panorama to retrieve logs from Cortex Data Lake (CDL), new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
|
||||||
|
|
||||||
|
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to CDL and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading a PA-220 firewall takes up to an hour or more.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
PA-220 firewalls are experiencing slower web interface and CLI performance times.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## APPORTAL-3313
|
||||||
|
|
||||||
|
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
|
||||||
|
|
||||||
|
## APPORTAL-3309
|
||||||
|
|
||||||
|
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
|
||||||
|
|
||||||
|
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
|
||||||
|
|
||||||
## APL-8269
|
## APL-8269
|
||||||
|
|
||||||
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
|
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
|
||||||
|
|||||||
@@ -6,6 +6,42 @@ source: common-crawl
|
|||||||
crawl: CC-MAIN-2026-12
|
crawl: CC-MAIN-2026-12
|
||||||
---
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
If you use Panorama to retrieve logs from Cortex Data Lake (CDL), new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
|
||||||
|
|
||||||
|
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to CDL and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading a PA-220 firewall takes up to an hour or more.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
PA-220 firewalls are experiencing slower web interface and CLI performance times.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## APPORTAL-3313
|
||||||
|
|
||||||
|
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
|
||||||
|
|
||||||
|
## APPORTAL-3309
|
||||||
|
|
||||||
|
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
|
||||||
|
|
||||||
|
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
|
||||||
|
|
||||||
## APL-8269
|
## APL-8269
|
||||||
|
|
||||||
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
|
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
|
||||||
|
|||||||
@@ -6,6 +6,42 @@ source: common-crawl
|
|||||||
crawl: CC-MAIN-2026-12
|
crawl: CC-MAIN-2026-12
|
||||||
---
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
If you use Panorama to retrieve logs from Cortex Data Lake (CDL), new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
|
||||||
|
|
||||||
|
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to CDL and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading a PA-220 firewall takes up to an hour or more.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
PA-220 firewalls are experiencing slower web interface and CLI performance times.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## APPORTAL-3313
|
||||||
|
|
||||||
|
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
|
||||||
|
|
||||||
|
## APPORTAL-3309
|
||||||
|
|
||||||
|
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
|
||||||
|
|
||||||
|
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
|
||||||
|
|
||||||
## APL-8269
|
## APL-8269
|
||||||
|
|
||||||
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
|
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
|
||||||
|
|||||||
@@ -6,6 +6,42 @@ source: common-crawl
|
|||||||
crawl: CC-MAIN-2026-12
|
crawl: CC-MAIN-2026-12
|
||||||
---
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
If you use Panorama to retrieve logs from Cortex Data Lake (CDL), new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
|
||||||
|
|
||||||
|
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to CDL and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading a PA-220 firewall takes up to an hour or more.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
PA-220 firewalls are experiencing slower web interface and CLI performance times.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## APPORTAL-3313
|
||||||
|
|
||||||
|
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
|
||||||
|
|
||||||
|
## APPORTAL-3309
|
||||||
|
|
||||||
|
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
|
||||||
|
|
||||||
|
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
|
||||||
|
|
||||||
## APL-8269
|
## APL-8269
|
||||||
|
|
||||||
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
|
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
|
||||||
|
|||||||
@@ -6,6 +6,42 @@ source: common-crawl
|
|||||||
crawl: CC-MAIN-2026-12
|
crawl: CC-MAIN-2026-12
|
||||||
---
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
If you use Panorama to retrieve logs from Cortex Data Lake (CDL), new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
|
||||||
|
|
||||||
|
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to CDL and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading a PA-220 firewall takes up to an hour or more.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
PA-220 firewalls are experiencing slower web interface and CLI performance times.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## APPORTAL-3313
|
||||||
|
|
||||||
|
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
|
||||||
|
|
||||||
|
## APPORTAL-3309
|
||||||
|
|
||||||
|
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
|
||||||
|
|
||||||
|
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
|
||||||
|
|
||||||
## APL-8269
|
## APL-8269
|
||||||
|
|
||||||
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
|
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
|
||||||
|
|||||||
@@ -6,6 +6,42 @@ source: common-crawl
|
|||||||
crawl: CC-MAIN-2026-12
|
crawl: CC-MAIN-2026-12
|
||||||
---
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
If you use Panorama to retrieve logs from Strata Logging Service, new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
|
||||||
|
|
||||||
|
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to Strata Logging Service and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading a PA-220 firewall takes up to an hour or more.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
PA-220 firewalls are experiencing slower web interface and CLI performance times.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## APPORTAL-3313
|
||||||
|
|
||||||
|
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
|
||||||
|
|
||||||
|
## APPORTAL-3309
|
||||||
|
|
||||||
|
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
|
||||||
|
|
||||||
|
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
|
||||||
|
|
||||||
## APL-15000
|
## APL-15000
|
||||||
|
|
||||||
When you move a firewall from one Strata Logging Service instance to another, it can take up to an hour for the firewall to begin sending logs to the new instance.
|
When you move a firewall from one Strata Logging Service instance to another, it can take up to an hour for the firewall to begin sending logs to the new instance.
|
||||||
|
|||||||
@@ -6,6 +6,42 @@ source: common-crawl
|
|||||||
crawl: CC-MAIN-2026-12
|
crawl: CC-MAIN-2026-12
|
||||||
---
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
If you use Panorama to retrieve logs from Strata Logging Service, new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
|
||||||
|
|
||||||
|
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to Strata Logging Service and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading a PA-220 firewall takes up to an hour or more.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
PA-220 firewalls are experiencing slower web interface and CLI performance times.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less than the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## APPORTAL-3313
|
||||||
|
|
||||||
|
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
|
||||||
|
|
||||||
|
## APPORTAL-3309
|
||||||
|
|
||||||
|
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
|
||||||
|
|
||||||
|
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
|
||||||
|
|
||||||
## APL-15000
|
## APL-15000
|
||||||
|
|
||||||
When you move a firewall from one Strata Logging Service instance to another, it can take up to an hour for the firewall to begin sending logs to the new instance.
|
When you move a firewall from one Strata Logging Service instance to another, it can take up to an hour for the firewall to begin sending logs to the new instance.
|
||||||
|
|||||||
@@ -6,6 +6,42 @@ source: common-crawl
|
|||||||
crawl: CC-MAIN-2026-12
|
crawl: CC-MAIN-2026-12
|
||||||
---
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
If you use Panorama to retrieve logs from Strata Logging Service, new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
|
||||||
|
|
||||||
|
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to Strata Logging Service and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading a PA-220 firewall takes up to an hour or more.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
PA-220 firewalls are experiencing slower web interface and CLI performance times.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less than the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## APPORTAL-3313
|
||||||
|
|
||||||
|
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
|
||||||
|
|
||||||
|
## APPORTAL-3309
|
||||||
|
|
||||||
|
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
|
||||||
|
|
||||||
|
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
|
||||||
|
|
||||||
## APL-15000
|
## APL-15000
|
||||||
|
|
||||||
When you move a firewall from one Strata Logging Service instance to another, it can take up to an hour for the firewall to begin sending logs to the new instance.
|
When you move a firewall from one Strata Logging Service instance to another, it can take up to an hour for the firewall to begin sending logs to the new instance.
|
||||||
|
|||||||
@@ -6,6 +6,42 @@ source: common-crawl
|
|||||||
crawl: CC-MAIN-2026-12
|
crawl: CC-MAIN-2026-12
|
||||||
---
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
If you use Panorama to retrieve logs from Strata Logging Service, new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
|
||||||
|
|
||||||
|
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to Strata Logging Service and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading a PA-220 firewall takes up to an hour or more.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
PA-220 firewalls are experiencing slower web interface and CLI performance times.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less than the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## APPORTAL-3313
|
||||||
|
|
||||||
|
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
|
||||||
|
|
||||||
|
## APPORTAL-3309
|
||||||
|
|
||||||
|
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
|
||||||
|
|
||||||
|
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
|
||||||
|
|
||||||
## APL-15000
|
## APL-15000
|
||||||
|
|
||||||
When you move a firewall from one Strata Logging Service instance to another, it can take up to an hour for the firewall to begin sending logs to the new instance.
|
When you move a firewall from one Strata Logging Service instance to another, it can take up to an hour for the firewall to begin sending logs to the new instance.
|
||||||
|
|||||||
@@ -6,6 +6,42 @@ source: common-crawl
|
|||||||
crawl: CC-MAIN-2026-12
|
crawl: CC-MAIN-2026-12
|
||||||
---
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
If you use Panorama to retrieve logs from Strata Logging Service, new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
|
||||||
|
|
||||||
|
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to Strata Logging Service and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading a PA-220 firewall takes up to an hour or more.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
PA-220 firewalls are experiencing slower web interface and CLI performance times.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less than the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## APPORTAL-3313
|
||||||
|
|
||||||
|
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
|
||||||
|
|
||||||
|
## APPORTAL-3309
|
||||||
|
|
||||||
|
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
|
||||||
|
|
||||||
|
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
|
||||||
|
|
||||||
## APL-15000
|
## APL-15000
|
||||||
|
|
||||||
When you move a firewall from one Strata Logging Service instance to another, it can take up to an hour for the firewall to begin sending logs to the new instance.
|
When you move a firewall from one Strata Logging Service instance to another, it can take up to an hour for the firewall to begin sending logs to the new instance.
|
||||||
|
|||||||
@@ -6,6 +6,42 @@ source: common-crawl
|
|||||||
crawl: CC-MAIN-2026-12
|
crawl: CC-MAIN-2026-12
|
||||||
---
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
If you use Panorama to retrieve logs from Strata Logging Service, new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
|
||||||
|
|
||||||
|
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to Strata Logging Service and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading a PA-220 firewall takes up to an hour or more.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
PA-220 firewalls are experiencing slower web interface and CLI performance times.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less than the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## APPORTAL-3313
|
||||||
|
|
||||||
|
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
|
||||||
|
|
||||||
|
## APPORTAL-3309
|
||||||
|
|
||||||
|
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
|
||||||
|
|
||||||
|
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
|
||||||
|
|
||||||
## APL-15000
|
## APL-15000
|
||||||
|
|
||||||
When you move a firewall from one Strata Logging Service instance to another, it can take up to an hour for the firewall to begin sending logs to the new instance.
|
When you move a firewall from one Strata Logging Service instance to another, it can take up to an hour for the firewall to begin sending logs to the new instance.
|
||||||
|
|||||||
@@ -6,6 +6,42 @@ source: common-crawl
|
|||||||
crawl: CC-MAIN-2026-12
|
crawl: CC-MAIN-2026-12
|
||||||
---
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
If you use Panorama to retrieve logs from Strata Logging Service, new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
|
||||||
|
|
||||||
|
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to Strata Logging Service and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading a PA-220 firewall takes up to an hour or more.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
PA-220 firewalls are experiencing slower web interface and CLI performance times.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less than the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## APPORTAL-3313
|
||||||
|
|
||||||
|
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
|
||||||
|
|
||||||
|
## APPORTAL-3309
|
||||||
|
|
||||||
|
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
|
||||||
|
|
||||||
|
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
|
||||||
|
|
||||||
## APL-15000
|
## APL-15000
|
||||||
|
|
||||||
When you move a firewall from one Strata Logging Service instance to another, it can take up to an hour for the firewall to begin sending logs to the new instance.
|
When you move a firewall from one Strata Logging Service instance to another, it can take up to an hour for the firewall to begin sending logs to the new instance.
|
||||||
|
|||||||
@@ -6,6 +6,42 @@ source: common-crawl
|
|||||||
crawl: CC-MAIN-2026-12
|
crawl: CC-MAIN-2026-12
|
||||||
---
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
If you use Panorama to retrieve logs from Strata Logging Service, new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
|
||||||
|
|
||||||
|
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to Strata Logging Service and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading a PA-220 firewall takes up to an hour or more.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
PA-220 firewalls are experiencing slower web interface and CLI performance times.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less than the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## APPORTAL-3313
|
||||||
|
|
||||||
|
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
|
||||||
|
|
||||||
|
## APPORTAL-3309
|
||||||
|
|
||||||
|
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
|
||||||
|
|
||||||
|
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
|
||||||
|
|
||||||
## APL-15000
|
## APL-15000
|
||||||
|
|
||||||
When you move a firewall from one Strata Logging Service instance to another, it can take up to an hour for the firewall to begin sending logs to the new instance.
|
When you move a firewall from one Strata Logging Service instance to another, it can take up to an hour for the firewall to begin sending logs to the new instance.
|
||||||
|
|||||||
@@ -6,6 +6,42 @@ source: common-crawl
|
|||||||
crawl: CC-MAIN-2026-12
|
crawl: CC-MAIN-2026-12
|
||||||
---
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
If you use Panorama to retrieve logs from Strata Logging Service, new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
|
||||||
|
|
||||||
|
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to Strata Logging Service and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading a PA-220 firewall takes up to an hour or more.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
PA-220 firewalls are experiencing slower web interface and CLI performance times.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less than the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## APPORTAL-3313
|
||||||
|
|
||||||
|
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
|
||||||
|
|
||||||
|
## APPORTAL-3309
|
||||||
|
|
||||||
|
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
|
||||||
|
|
||||||
|
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
|
||||||
|
|
||||||
## APL-15000
|
## APL-15000
|
||||||
|
|
||||||
When you move a firewall from one Strata Logging Service instance to another, it can take up to an hour for the firewall to begin sending logs to the new instance.
|
When you move a firewall from one Strata Logging Service instance to another, it can take up to an hour for the firewall to begin sending logs to the new instance.
|
||||||
|
|||||||
@@ -0,0 +1,484 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.10
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## PLUG-380
|
||||||
|
|
||||||
|
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||||
|
|
||||||
|
## PAN-223365
|
||||||
|
|
||||||
|
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
|
||||||
|
|
||||||
|
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
|
||||||
|
|
||||||
|
`admin``request restart system`
|
||||||
|
|
||||||
|
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
|
||||||
|
|
||||||
|
## PAN-199557
|
||||||
|
|
||||||
|
On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Manually reboot the `Active` Panorama HA peer.
|
||||||
|
|
||||||
|
## PAN-197341
|
||||||
|
|
||||||
|
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
|
||||||
|
|
||||||
|
For example:
|
||||||
|
|
||||||
|
1. You create a parent device group `DG-A` and a child device group `DG-B`.
|
||||||
|
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
|
||||||
|
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
|
||||||
|
|
||||||
|
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
|
||||||
|
|
||||||
|
## PAN-178194
|
||||||
|
|
||||||
|
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
|
||||||
|
|
||||||
|
## PAN-154266
|
||||||
|
|
||||||
|
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
|
||||||
|
|
||||||
|
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
|
||||||
|
|
||||||
|
## PAN-154247
|
||||||
|
|
||||||
|
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
|
||||||
|
|
||||||
|
**Workaround:** Log out and back in to the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-153803
|
||||||
|
|
||||||
|
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
|
||||||
|
|
||||||
|
## PAN-146573
|
||||||
|
|
||||||
|
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||||
|
|
||||||
|
## PAN-146485
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
|
||||||
|
|
||||||
|
## PAN-144889
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 9.1.2-h1 and later releases only
|
||||||
|
```
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
|
||||||
|
|
||||||
|
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
|
||||||
|
|
||||||
|
## PAN-140959
|
||||||
|
|
||||||
|
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
|
||||||
|
|
||||||
|
## PAN-134456
|
||||||
|
|
||||||
|
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
|
||||||
|
|
||||||
|
**Workaround:** Use a destination-based service route for the SNMP trap server.
|
||||||
|
|
||||||
|
## PAN-134053
|
||||||
|
|
||||||
|
ACC does not filter WildFire logs from Dynamic User Groups.
|
||||||
|
|
||||||
|
## PAN-130550
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
|
||||||
|
|
||||||
|
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
|
||||||
|
|
||||||
|
## PAN-127813
|
||||||
|
|
||||||
|
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches don’t communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
|
||||||
|
|
||||||
|
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
|
||||||
|
|
||||||
|
## PAN-127550
|
||||||
|
|
||||||
|
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
|
||||||
|
|
||||||
|
## PAN-127474
|
||||||
|
|
||||||
|
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
|
||||||
|
|
||||||
|
## PAN-127206
|
||||||
|
|
||||||
|
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
|
||||||
|
|
||||||
|
## PAN-124956
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.11 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an issue where VM-Series firewalls do not support packet buffer protection.
|
||||||
|
|
||||||
|
## PAN-123277
|
||||||
|
|
||||||
|
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-123040
|
||||||
|
|
||||||
|
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules don’t display. A workaround exists for this issue. Please contact Support for information about the workaround.
|
||||||
|
|
||||||
|
## PAN-120440
|
||||||
|
|
||||||
|
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||||
|
|
||||||
|
## PAN-120303
|
||||||
|
|
||||||
|
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||||
|
|
||||||
|
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||||
|
|
||||||
|
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||||
|
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||||
|
2. **Commit** your changes.
|
||||||
|
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||||
|
4. **Commit** your changes.
|
||||||
|
- Restart the firewall (devsrvr) process.
|
||||||
|
1. Log in to the firewall CLI.
|
||||||
|
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||||
|
|
||||||
|
## PAN-118065
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
M-Series Panorama management servers in Management Only mode
|
||||||
|
```
|
||||||
|
|
||||||
|
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
|
||||||
|
|
||||||
|
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
|
||||||
|
|
||||||
|
## PAN-116017
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Google Cloud Platform (GCP) only
|
||||||
|
```
|
||||||
|
|
||||||
|
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||||
|
|
||||||
|
## PAN-115816
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Microsoft Azure only
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-114495
|
||||||
|
|
||||||
|
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||||
|
|
||||||
|
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||||
|
|
||||||
|
## PAN-112694
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls with multiple virtual systems only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||||
|
|
||||||
|
## PAN-112456
|
||||||
|
|
||||||
|
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
|
||||||
|
|
||||||
|
## PAN-111928
|
||||||
|
|
||||||
|
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||||
|
|
||||||
|
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||||
|
|
||||||
|
## PAN-111866
|
||||||
|
|
||||||
|
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||||
|
|
||||||
|
**Workaround:** Perform one of the following tasks.
|
||||||
|
|
||||||
|
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||||
|
- Manually select the devices that belong to the modified device group and template configurations.
|
||||||
|
|
||||||
|
## PAN-111729
|
||||||
|
|
||||||
|
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-111670
|
||||||
|
|
||||||
|
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||||
|
|
||||||
|
## PAN-111251
|
||||||
|
|
||||||
|
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
|
||||||
|
|
||||||
|
## PAN-110794
|
||||||
|
|
||||||
|
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||||
|
|
||||||
|
## PAN-109759
|
||||||
|
|
||||||
|
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
|
||||||
|
|
||||||
|
## PAN-109526
|
||||||
|
|
||||||
|
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||||
|
|
||||||
|
## PAN-106675
|
||||||
|
|
||||||
|
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||||
|
|
||||||
|
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||||
|
|
||||||
|
## PAN-104780
|
||||||
|
|
||||||
|
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||||
|
|
||||||
|
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||||
|
|
||||||
|
## PAN-103276
|
||||||
|
|
||||||
|
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||||
|
|
||||||
|
## PAN-101688
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama plugins
|
||||||
|
```
|
||||||
|
|
||||||
|
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||||
|
|
||||||
|
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||||
|
|
||||||
|
## PAN-101537
|
||||||
|
|
||||||
|
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||||
|
|
||||||
|
**Workaround:** Specify the vsys in the query string:
|
||||||
|
|
||||||
|
`admin>` `set system target-vsys <vsys-name>`
|
||||||
|
|
||||||
|
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||||
|
|
||||||
|
## PAN-98520
|
||||||
|
|
||||||
|
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||||
|
|
||||||
|
## PAN-97757
|
||||||
|
|
||||||
|
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||||
|
|
||||||
|
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||||
|
|
||||||
|
## PAN-97524
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama management server only
|
||||||
|
```
|
||||||
|
|
||||||
|
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||||
|
|
||||||
|
## PAN-96985
|
||||||
|
|
||||||
|
The `request shutdown system` command does not shut down the Panorama management server.
|
||||||
|
|
||||||
|
## PAN-96960
|
||||||
|
|
||||||
|
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
|
||||||
|
|
||||||
|
## PAN-96446
|
||||||
|
|
||||||
|
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||||
|
|
||||||
|
## PAN-95773
|
||||||
|
|
||||||
|
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||||
|
|
||||||
|
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||||
|
|
||||||
|
## PAN-95511
|
||||||
|
|
||||||
|
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||||
|
|
||||||
|
## PAN-95028
|
||||||
|
|
||||||
|
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||||
|
|
||||||
|
## PAN-94846
|
||||||
|
|
||||||
|
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||||
|
|
||||||
|
## PAN-94093
|
||||||
|
|
||||||
|
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||||
|
|
||||||
|
## PAN-93968
|
||||||
|
|
||||||
|
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||||
|
|
||||||
|
## PAN-93607
|
||||||
|
|
||||||
|
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||||
|
|
||||||
|
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||||
|
|
||||||
|
## PAN-93532
|
||||||
|
|
||||||
|
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||||
|
|
||||||
|
## PAN-93193
|
||||||
|
|
||||||
|
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||||
|
|
||||||
|
- Switch to the firewall **Context** on the Panorama management server.
|
||||||
|
- Commit changes when a dynamic update is being installed.
|
||||||
|
- Generate a custom report when a dynamic update is being installed.
|
||||||
|
- Generate custom reports during a commit.
|
||||||
|
|
||||||
|
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||||
|
|
||||||
|
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||||
|
|
||||||
|
## PAN-91802
|
||||||
|
|
||||||
|
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||||
|
|
||||||
|
## PAN-83610
|
||||||
|
|
||||||
|
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||||
|
|
||||||
|
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-83236
|
||||||
|
|
||||||
|
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||||
|
|
||||||
|
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||||
|
|
||||||
|
## PAN-83215
|
||||||
|
|
||||||
|
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||||
|
|
||||||
|
## PAN-81521
|
||||||
|
|
||||||
|
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||||
|
|
||||||
|
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||||
|
|
||||||
|
## PAN-77125
|
||||||
|
|
||||||
|
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||||
|
|
||||||
|
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-75457
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||||
|
|
||||||
|
## PAN-73530
|
||||||
|
|
||||||
|
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||||
|
|
||||||
|
## PAN-73401
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||||
|
|
||||||
|
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||||
|
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||||
|
|
||||||
|
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||||
|
|
||||||
|
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||||
|
- Configure a worker list on the cluster controller:
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||||
|
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||||
|
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||||
|
or
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||||
|
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||||
|
|
||||||
|
## PAN-71329
|
||||||
|
|
||||||
|
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
|
||||||
|
|
||||||
|
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
|
||||||
|
|
||||||
|
## PAN-70906
|
||||||
|
|
||||||
|
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||||
|
|
||||||
|
## PAN-69505
|
||||||
|
|
||||||
|
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||||
|
|
||||||
|
## PAN-41558
|
||||||
|
|
||||||
|
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||||
|
|
||||||
|
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||||
|
|
||||||
|
## PAN-40079
|
||||||
|
|
||||||
|
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||||
|
|
||||||
|
## PAN-39636
|
||||||
|
|
||||||
|
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||||
|
|
||||||
|
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||||
|
|
||||||
|
## PAN-38255
|
||||||
|
|
||||||
|
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||||
|
|
||||||
|
## PAN-31832
|
||||||
|
|
||||||
|
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||||
|
|
||||||
|
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||||
|
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||||
@@ -0,0 +1,476 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.11
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## PLUG-380
|
||||||
|
|
||||||
|
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||||
|
|
||||||
|
## PAN-223365
|
||||||
|
|
||||||
|
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
|
||||||
|
|
||||||
|
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
|
||||||
|
|
||||||
|
`admin``request restart system`
|
||||||
|
|
||||||
|
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
|
||||||
|
|
||||||
|
## PAN-199557
|
||||||
|
|
||||||
|
On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Manually reboot the `Active` Panorama HA peer.
|
||||||
|
|
||||||
|
## PAN-197341
|
||||||
|
|
||||||
|
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
|
||||||
|
|
||||||
|
For example:
|
||||||
|
|
||||||
|
1. You create a parent device group `DG-A` and a child device group `DG-B`.
|
||||||
|
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
|
||||||
|
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
|
||||||
|
|
||||||
|
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
|
||||||
|
|
||||||
|
## PAN-178194
|
||||||
|
|
||||||
|
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
|
||||||
|
|
||||||
|
## PAN-154266
|
||||||
|
|
||||||
|
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
|
||||||
|
|
||||||
|
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
|
||||||
|
|
||||||
|
## PAN-154247
|
||||||
|
|
||||||
|
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
|
||||||
|
|
||||||
|
**Workaround:** Log out and back in to the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-153803
|
||||||
|
|
||||||
|
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
|
||||||
|
|
||||||
|
## PAN-146573
|
||||||
|
|
||||||
|
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||||
|
|
||||||
|
## PAN-146485
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
|
||||||
|
|
||||||
|
## PAN-144889
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 9.1.2-h1 and later releases only
|
||||||
|
```
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
|
||||||
|
|
||||||
|
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
|
||||||
|
|
||||||
|
## PAN-140959
|
||||||
|
|
||||||
|
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
|
||||||
|
|
||||||
|
## PAN-134456
|
||||||
|
|
||||||
|
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
|
||||||
|
|
||||||
|
**Workaround:** Use a destination-based service route for the SNMP trap server.
|
||||||
|
|
||||||
|
## PAN-134053
|
||||||
|
|
||||||
|
ACC does not filter WildFire logs from Dynamic User Groups.
|
||||||
|
|
||||||
|
## PAN-130550
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
|
||||||
|
|
||||||
|
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
|
||||||
|
|
||||||
|
## PAN-127813
|
||||||
|
|
||||||
|
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches don’t communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
|
||||||
|
|
||||||
|
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
|
||||||
|
|
||||||
|
## PAN-127550
|
||||||
|
|
||||||
|
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
|
||||||
|
|
||||||
|
## PAN-127474
|
||||||
|
|
||||||
|
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
|
||||||
|
|
||||||
|
## PAN-127206
|
||||||
|
|
||||||
|
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
|
||||||
|
|
||||||
|
## PAN-123277
|
||||||
|
|
||||||
|
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-123040
|
||||||
|
|
||||||
|
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules don’t display. A workaround exists for this issue. Please contact Support for information about the workaround.
|
||||||
|
|
||||||
|
## PAN-120440
|
||||||
|
|
||||||
|
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||||
|
|
||||||
|
## PAN-120303
|
||||||
|
|
||||||
|
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||||
|
|
||||||
|
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||||
|
|
||||||
|
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||||
|
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||||
|
2. **Commit** your changes.
|
||||||
|
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||||
|
4. **Commit** your changes.
|
||||||
|
- Restart the firewall (devsrvr) process.
|
||||||
|
1. Log in to the firewall CLI.
|
||||||
|
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||||
|
|
||||||
|
## PAN-118065
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
M-Series Panorama management servers in Management Only mode
|
||||||
|
```
|
||||||
|
|
||||||
|
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
|
||||||
|
|
||||||
|
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
|
||||||
|
|
||||||
|
## PAN-116017
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Google Cloud Platform (GCP) only
|
||||||
|
```
|
||||||
|
|
||||||
|
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||||
|
|
||||||
|
## PAN-115816
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Microsoft Azure only
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-114495
|
||||||
|
|
||||||
|
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||||
|
|
||||||
|
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||||
|
|
||||||
|
## PAN-112694
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls with multiple virtual systems only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||||
|
|
||||||
|
## PAN-112456
|
||||||
|
|
||||||
|
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
|
||||||
|
|
||||||
|
## PAN-111928
|
||||||
|
|
||||||
|
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||||
|
|
||||||
|
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||||
|
|
||||||
|
## PAN-111866
|
||||||
|
|
||||||
|
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||||
|
|
||||||
|
**Workaround:** Perform one of the following tasks.
|
||||||
|
|
||||||
|
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||||
|
- Manually select the devices that belong to the modified device group and template configurations.
|
||||||
|
|
||||||
|
## PAN-111729
|
||||||
|
|
||||||
|
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-111670
|
||||||
|
|
||||||
|
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||||
|
|
||||||
|
## PAN-111251
|
||||||
|
|
||||||
|
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
|
||||||
|
|
||||||
|
## PAN-110794
|
||||||
|
|
||||||
|
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||||
|
|
||||||
|
## PAN-109759
|
||||||
|
|
||||||
|
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
|
||||||
|
|
||||||
|
## PAN-109526
|
||||||
|
|
||||||
|
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||||
|
|
||||||
|
## PAN-106675
|
||||||
|
|
||||||
|
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||||
|
|
||||||
|
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||||
|
|
||||||
|
## PAN-104780
|
||||||
|
|
||||||
|
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||||
|
|
||||||
|
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||||
|
|
||||||
|
## PAN-103276
|
||||||
|
|
||||||
|
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||||
|
|
||||||
|
## PAN-101688
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama plugins
|
||||||
|
```
|
||||||
|
|
||||||
|
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||||
|
|
||||||
|
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||||
|
|
||||||
|
## PAN-101537
|
||||||
|
|
||||||
|
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||||
|
|
||||||
|
**Workaround:** Specify the vsys in the query string:
|
||||||
|
|
||||||
|
`admin>` `set system target-vsys <vsys-name>`
|
||||||
|
|
||||||
|
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||||
|
|
||||||
|
## PAN-98520
|
||||||
|
|
||||||
|
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||||
|
|
||||||
|
## PAN-97757
|
||||||
|
|
||||||
|
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||||
|
|
||||||
|
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||||
|
|
||||||
|
## PAN-97524
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama management server only
|
||||||
|
```
|
||||||
|
|
||||||
|
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||||
|
|
||||||
|
## PAN-96985
|
||||||
|
|
||||||
|
The `request shutdown system` command does not shut down the Panorama management server.
|
||||||
|
|
||||||
|
## PAN-96960
|
||||||
|
|
||||||
|
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
|
||||||
|
|
||||||
|
## PAN-96446
|
||||||
|
|
||||||
|
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||||
|
|
||||||
|
## PAN-95773
|
||||||
|
|
||||||
|
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||||
|
|
||||||
|
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||||
|
|
||||||
|
## PAN-95511
|
||||||
|
|
||||||
|
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||||
|
|
||||||
|
## PAN-95028
|
||||||
|
|
||||||
|
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||||
|
|
||||||
|
## PAN-94846
|
||||||
|
|
||||||
|
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||||
|
|
||||||
|
## PAN-94093
|
||||||
|
|
||||||
|
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||||
|
|
||||||
|
## PAN-93968
|
||||||
|
|
||||||
|
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||||
|
|
||||||
|
## PAN-93607
|
||||||
|
|
||||||
|
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||||
|
|
||||||
|
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||||
|
|
||||||
|
## PAN-93532
|
||||||
|
|
||||||
|
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||||
|
|
||||||
|
## PAN-93193
|
||||||
|
|
||||||
|
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||||
|
|
||||||
|
- Switch to the firewall **Context** on the Panorama management server.
|
||||||
|
- Commit changes when a dynamic update is being installed.
|
||||||
|
- Generate a custom report when a dynamic update is being installed.
|
||||||
|
- Generate custom reports during a commit.
|
||||||
|
|
||||||
|
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||||
|
|
||||||
|
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||||
|
|
||||||
|
## PAN-91802
|
||||||
|
|
||||||
|
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||||
|
|
||||||
|
## PAN-83610
|
||||||
|
|
||||||
|
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||||
|
|
||||||
|
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-83236
|
||||||
|
|
||||||
|
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||||
|
|
||||||
|
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||||
|
|
||||||
|
## PAN-83215
|
||||||
|
|
||||||
|
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||||
|
|
||||||
|
## PAN-81521
|
||||||
|
|
||||||
|
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||||
|
|
||||||
|
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||||
|
|
||||||
|
## PAN-77125
|
||||||
|
|
||||||
|
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||||
|
|
||||||
|
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-75457
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||||
|
|
||||||
|
## PAN-73530
|
||||||
|
|
||||||
|
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||||
|
|
||||||
|
## PAN-73401
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||||
|
|
||||||
|
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||||
|
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||||
|
|
||||||
|
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||||
|
|
||||||
|
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||||
|
- Configure a worker list on the cluster controller:
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||||
|
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||||
|
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||||
|
or
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||||
|
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||||
|
|
||||||
|
## PAN-71329
|
||||||
|
|
||||||
|
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
|
||||||
|
|
||||||
|
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
|
||||||
|
|
||||||
|
## PAN-70906
|
||||||
|
|
||||||
|
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||||
|
|
||||||
|
## PAN-69505
|
||||||
|
|
||||||
|
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||||
|
|
||||||
|
## PAN-41558
|
||||||
|
|
||||||
|
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||||
|
|
||||||
|
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||||
|
|
||||||
|
## PAN-40079
|
||||||
|
|
||||||
|
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||||
|
|
||||||
|
## PAN-39636
|
||||||
|
|
||||||
|
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||||
|
|
||||||
|
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||||
|
|
||||||
|
## PAN-38255
|
||||||
|
|
||||||
|
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||||
|
|
||||||
|
## PAN-31832
|
||||||
|
|
||||||
|
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||||
|
|
||||||
|
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||||
|
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||||
@@ -0,0 +1,494 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.12
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## PLUG-380
|
||||||
|
|
||||||
|
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||||
|
|
||||||
|
## PAN-223365
|
||||||
|
|
||||||
|
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
|
||||||
|
|
||||||
|
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
|
||||||
|
|
||||||
|
`admin``request restart system`
|
||||||
|
|
||||||
|
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
|
||||||
|
|
||||||
|
## PAN-199557
|
||||||
|
|
||||||
|
On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Manually reboot the `Active` Panorama HA peer.
|
||||||
|
|
||||||
|
## PAN-197341
|
||||||
|
|
||||||
|
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
|
||||||
|
|
||||||
|
For example:
|
||||||
|
|
||||||
|
1. You create a parent device group `DG-A` and a child device group `DG-B`.
|
||||||
|
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
|
||||||
|
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
|
||||||
|
|
||||||
|
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
|
||||||
|
|
||||||
|
## PAN-186937
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.14 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
The firewall drops Encapsulating Security Payload (ESP) IPsec packets that originate from the same firewall. This behavior occurs when you enable **Strict IP Address Check** in the Zone Protection profile (Packet Based Attack Protection tab, IP Drop section) and the packet’s source IP address is the same as the egress interface address.
|
||||||
|
|
||||||
|
**Workaround**: Disable the **Strict IP Address Check** option in the Zone Protection profile. Alternatively, downgrade to 9.1.11 or earlier or upgrade to 10.0.0 or later if you want to enable the **Strict IP Address Check**.
|
||||||
|
|
||||||
|
## PAN-178194
|
||||||
|
|
||||||
|
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
|
||||||
|
|
||||||
|
## PAN-159295
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.13 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
Scheduled configuration export files saved in the /tmp folder are not periodically purged, which causes the root partition to fill up.
|
||||||
|
|
||||||
|
## PAN-154266
|
||||||
|
|
||||||
|
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
|
||||||
|
|
||||||
|
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
|
||||||
|
|
||||||
|
## PAN-154247
|
||||||
|
|
||||||
|
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
|
||||||
|
|
||||||
|
**Workaround:** Log out and back in to the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-153803
|
||||||
|
|
||||||
|
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
|
||||||
|
|
||||||
|
## PAN-146573
|
||||||
|
|
||||||
|
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||||
|
|
||||||
|
## PAN-146485
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
|
||||||
|
|
||||||
|
## PAN-144889
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 9.1.2-h1 and later releases only
|
||||||
|
```
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
|
||||||
|
|
||||||
|
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
|
||||||
|
|
||||||
|
## PAN-140959
|
||||||
|
|
||||||
|
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
|
||||||
|
|
||||||
|
## PAN-134456
|
||||||
|
|
||||||
|
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
|
||||||
|
|
||||||
|
**Workaround:** Use a destination-based service route for the SNMP trap server.
|
||||||
|
|
||||||
|
## PAN-134053
|
||||||
|
|
||||||
|
ACC does not filter WildFire logs from Dynamic User Groups.
|
||||||
|
|
||||||
|
## PAN-130550
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
|
||||||
|
|
||||||
|
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
|
||||||
|
|
||||||
|
## PAN-127813
|
||||||
|
|
||||||
|
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches don’t communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
|
||||||
|
|
||||||
|
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
|
||||||
|
|
||||||
|
## PAN-127550
|
||||||
|
|
||||||
|
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
|
||||||
|
|
||||||
|
## PAN-127474
|
||||||
|
|
||||||
|
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
|
||||||
|
|
||||||
|
## PAN-127206
|
||||||
|
|
||||||
|
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
|
||||||
|
|
||||||
|
## PAN-123277
|
||||||
|
|
||||||
|
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-123040
|
||||||
|
|
||||||
|
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules don’t display. A workaround exists for this issue. Please contact Support for information about the workaround.
|
||||||
|
|
||||||
|
## PAN-120440
|
||||||
|
|
||||||
|
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||||
|
|
||||||
|
## PAN-120303
|
||||||
|
|
||||||
|
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||||
|
|
||||||
|
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||||
|
|
||||||
|
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||||
|
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||||
|
2. **Commit** your changes.
|
||||||
|
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||||
|
4. **Commit** your changes.
|
||||||
|
- Restart the firewall (devsrvr) process.
|
||||||
|
1. Log in to the firewall CLI.
|
||||||
|
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||||
|
|
||||||
|
## PAN-118065
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
M-Series Panorama management servers in Management Only mode
|
||||||
|
```
|
||||||
|
|
||||||
|
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
|
||||||
|
|
||||||
|
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
|
||||||
|
|
||||||
|
## PAN-116017
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Google Cloud Platform (GCP) only
|
||||||
|
```
|
||||||
|
|
||||||
|
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||||
|
|
||||||
|
## PAN-115816
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Microsoft Azure only
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-114495
|
||||||
|
|
||||||
|
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||||
|
|
||||||
|
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||||
|
|
||||||
|
## PAN-112694
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls with multiple virtual systems only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||||
|
|
||||||
|
## PAN-112456
|
||||||
|
|
||||||
|
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
|
||||||
|
|
||||||
|
## PAN-111928
|
||||||
|
|
||||||
|
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||||
|
|
||||||
|
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||||
|
|
||||||
|
## PAN-111866
|
||||||
|
|
||||||
|
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||||
|
|
||||||
|
**Workaround:** Perform one of the following tasks.
|
||||||
|
|
||||||
|
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||||
|
- Manually select the devices that belong to the modified device group and template configurations.
|
||||||
|
|
||||||
|
## PAN-111729
|
||||||
|
|
||||||
|
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-111670
|
||||||
|
|
||||||
|
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||||
|
|
||||||
|
## PAN-111251
|
||||||
|
|
||||||
|
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
|
||||||
|
|
||||||
|
## PAN-110794
|
||||||
|
|
||||||
|
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||||
|
|
||||||
|
## PAN-109759
|
||||||
|
|
||||||
|
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
|
||||||
|
|
||||||
|
## PAN-109526
|
||||||
|
|
||||||
|
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||||
|
|
||||||
|
## PAN-106675
|
||||||
|
|
||||||
|
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||||
|
|
||||||
|
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||||
|
|
||||||
|
## PAN-104780
|
||||||
|
|
||||||
|
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||||
|
|
||||||
|
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||||
|
|
||||||
|
## PAN-103276
|
||||||
|
|
||||||
|
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||||
|
|
||||||
|
## PAN-101688
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama plugins
|
||||||
|
```
|
||||||
|
|
||||||
|
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||||
|
|
||||||
|
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||||
|
|
||||||
|
## PAN-101537
|
||||||
|
|
||||||
|
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||||
|
|
||||||
|
**Workaround:** Specify the vsys in the query string:
|
||||||
|
|
||||||
|
`admin>` `set system target-vsys <vsys-name>`
|
||||||
|
|
||||||
|
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||||
|
|
||||||
|
## PAN-98520
|
||||||
|
|
||||||
|
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||||
|
|
||||||
|
## PAN-97757
|
||||||
|
|
||||||
|
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||||
|
|
||||||
|
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||||
|
|
||||||
|
## PAN-97524
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama management server only
|
||||||
|
```
|
||||||
|
|
||||||
|
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||||
|
|
||||||
|
## PAN-96985
|
||||||
|
|
||||||
|
The `request shutdown system` command does not shut down the Panorama management server.
|
||||||
|
|
||||||
|
## PAN-96960
|
||||||
|
|
||||||
|
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
|
||||||
|
|
||||||
|
## PAN-96446
|
||||||
|
|
||||||
|
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||||
|
|
||||||
|
## PAN-95773
|
||||||
|
|
||||||
|
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||||
|
|
||||||
|
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||||
|
|
||||||
|
## PAN-95511
|
||||||
|
|
||||||
|
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||||
|
|
||||||
|
## PAN-95028
|
||||||
|
|
||||||
|
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||||
|
|
||||||
|
## PAN-94846
|
||||||
|
|
||||||
|
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||||
|
|
||||||
|
## PAN-94093
|
||||||
|
|
||||||
|
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||||
|
|
||||||
|
## PAN-93968
|
||||||
|
|
||||||
|
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||||
|
|
||||||
|
## PAN-93607
|
||||||
|
|
||||||
|
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||||
|
|
||||||
|
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||||
|
|
||||||
|
## PAN-93532
|
||||||
|
|
||||||
|
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||||
|
|
||||||
|
## PAN-93193
|
||||||
|
|
||||||
|
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||||
|
|
||||||
|
- Switch to the firewall **Context** on the Panorama management server.
|
||||||
|
- Commit changes when a dynamic update is being installed.
|
||||||
|
- Generate a custom report when a dynamic update is being installed.
|
||||||
|
- Generate custom reports during a commit.
|
||||||
|
|
||||||
|
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||||
|
|
||||||
|
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||||
|
|
||||||
|
## PAN-91802
|
||||||
|
|
||||||
|
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||||
|
|
||||||
|
## PAN-83610
|
||||||
|
|
||||||
|
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||||
|
|
||||||
|
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-83236
|
||||||
|
|
||||||
|
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||||
|
|
||||||
|
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||||
|
|
||||||
|
## PAN-83215
|
||||||
|
|
||||||
|
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||||
|
|
||||||
|
## PAN-81521
|
||||||
|
|
||||||
|
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||||
|
|
||||||
|
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||||
|
|
||||||
|
## PAN-77125
|
||||||
|
|
||||||
|
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||||
|
|
||||||
|
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-75457
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||||
|
|
||||||
|
## PAN-73530
|
||||||
|
|
||||||
|
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||||
|
|
||||||
|
## PAN-73401
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||||
|
|
||||||
|
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||||
|
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||||
|
|
||||||
|
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||||
|
|
||||||
|
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||||
|
- Configure a worker list on the cluster controller:
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||||
|
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||||
|
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||||
|
or
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||||
|
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||||
|
|
||||||
|
## PAN-71329
|
||||||
|
|
||||||
|
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
|
||||||
|
|
||||||
|
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
|
||||||
|
|
||||||
|
## PAN-70906
|
||||||
|
|
||||||
|
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||||
|
|
||||||
|
## PAN-69505
|
||||||
|
|
||||||
|
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||||
|
|
||||||
|
## PAN-41558
|
||||||
|
|
||||||
|
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||||
|
|
||||||
|
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||||
|
|
||||||
|
## PAN-40079
|
||||||
|
|
||||||
|
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||||
|
|
||||||
|
## PAN-39636
|
||||||
|
|
||||||
|
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||||
|
|
||||||
|
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||||
|
|
||||||
|
## PAN-38255
|
||||||
|
|
||||||
|
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||||
|
|
||||||
|
## PAN-31832
|
||||||
|
|
||||||
|
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||||
|
|
||||||
|
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||||
|
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||||
@@ -0,0 +1,498 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.15
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## PLUG-380
|
||||||
|
|
||||||
|
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||||
|
|
||||||
|
## PAN-223365
|
||||||
|
|
||||||
|
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
|
||||||
|
|
||||||
|
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
|
||||||
|
|
||||||
|
`admin``request restart system`
|
||||||
|
|
||||||
|
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
|
||||||
|
|
||||||
|
## PAN-221015
|
||||||
|
|
||||||
|
On M-600 appliances in Panorama or Log Collector mode, the `es-1` and `es-2` ElasticSearch processes fail to restart when the M-600 appliance is rebooted. The results in the Managed Collector `ES` health status (**Panorama** > **Managed Collectors** > **Health Status**) to be degraded.
|
||||||
|
|
||||||
|
**Workaround:** [Log in to the Panorama or Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) experiencing degraded ElasticSearch health and restart all ElasticSearch processes.
|
||||||
|
|
||||||
|
`admin>``debug elasticsearch es-restart optional all`
|
||||||
|
|
||||||
|
## PAN-199557
|
||||||
|
|
||||||
|
On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Manually reboot the `Active` Panorama HA peer.
|
||||||
|
|
||||||
|
## PAN-197919
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.16 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
When path monitoring for a static route is configured with a new Ping Interval value, that value does not get used as intended.
|
||||||
|
|
||||||
|
**Workaround**: Disable and re-enable path monitoring for that static route to change that Ping Interval value.
|
||||||
|
|
||||||
|
## PAN-197859
|
||||||
|
|
||||||
|
On firewalls running LSVPN with tunnel monitoring enabled, upgrades to 9.1.14 or later cause the LSVPN tunnels to flap.
|
||||||
|
|
||||||
|
## PAN-197341
|
||||||
|
|
||||||
|
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
|
||||||
|
|
||||||
|
For example:
|
||||||
|
|
||||||
|
1. You create a parent device group `DG-A` and a child device group `DG-B`.
|
||||||
|
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
|
||||||
|
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
|
||||||
|
|
||||||
|
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
|
||||||
|
|
||||||
|
## PAN-178194
|
||||||
|
|
||||||
|
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
|
||||||
|
|
||||||
|
## PAN-154266
|
||||||
|
|
||||||
|
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
|
||||||
|
|
||||||
|
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
|
||||||
|
|
||||||
|
## PAN-154247
|
||||||
|
|
||||||
|
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
|
||||||
|
|
||||||
|
**Workaround:** Log out and back in to the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-153803
|
||||||
|
|
||||||
|
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
|
||||||
|
|
||||||
|
## PAN-146573
|
||||||
|
|
||||||
|
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||||
|
|
||||||
|
## PAN-146485
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
|
||||||
|
|
||||||
|
## PAN-144889
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 9.1.2-h1 and later releases only
|
||||||
|
```
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
|
||||||
|
|
||||||
|
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
|
||||||
|
|
||||||
|
## PAN-140959
|
||||||
|
|
||||||
|
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
|
||||||
|
|
||||||
|
## PAN-134456
|
||||||
|
|
||||||
|
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
|
||||||
|
|
||||||
|
**Workaround:** Use a destination-based service route for the SNMP trap server.
|
||||||
|
|
||||||
|
## PAN-134053
|
||||||
|
|
||||||
|
ACC does not filter WildFire logs from Dynamic User Groups.
|
||||||
|
|
||||||
|
## PAN-130550
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
|
||||||
|
|
||||||
|
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
|
||||||
|
|
||||||
|
## PAN-127813
|
||||||
|
|
||||||
|
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches don’t communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
|
||||||
|
|
||||||
|
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
|
||||||
|
|
||||||
|
## PAN-127550
|
||||||
|
|
||||||
|
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
|
||||||
|
|
||||||
|
## PAN-127474
|
||||||
|
|
||||||
|
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
|
||||||
|
|
||||||
|
## PAN-127206
|
||||||
|
|
||||||
|
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
|
||||||
|
|
||||||
|
## PAN-123277
|
||||||
|
|
||||||
|
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-123040
|
||||||
|
|
||||||
|
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules don’t display. A workaround exists for this issue. Please contact Support for information about the workaround.
|
||||||
|
|
||||||
|
## PAN-120440
|
||||||
|
|
||||||
|
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||||
|
|
||||||
|
## PAN-120303
|
||||||
|
|
||||||
|
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||||
|
|
||||||
|
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||||
|
|
||||||
|
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||||
|
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||||
|
2. **Commit** your changes.
|
||||||
|
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||||
|
4. **Commit** your changes.
|
||||||
|
- Restart the firewall (devsrvr) process.
|
||||||
|
1. Log in to the firewall CLI.
|
||||||
|
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||||
|
|
||||||
|
## PAN-118065
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
M-Series Panorama management servers in Management Only mode
|
||||||
|
```
|
||||||
|
|
||||||
|
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
|
||||||
|
|
||||||
|
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
|
||||||
|
|
||||||
|
## PAN-116017
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Google Cloud Platform (GCP) only
|
||||||
|
```
|
||||||
|
|
||||||
|
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||||
|
|
||||||
|
## PAN-115816
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Microsoft Azure only
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-114495
|
||||||
|
|
||||||
|
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||||
|
|
||||||
|
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||||
|
|
||||||
|
## PAN-112694
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls with multiple virtual systems only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||||
|
|
||||||
|
## PAN-112456
|
||||||
|
|
||||||
|
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
|
||||||
|
|
||||||
|
## PAN-111928
|
||||||
|
|
||||||
|
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||||
|
|
||||||
|
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||||
|
|
||||||
|
## PAN-111866
|
||||||
|
|
||||||
|
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||||
|
|
||||||
|
**Workaround:** Perform one of the following tasks.
|
||||||
|
|
||||||
|
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||||
|
- Manually select the devices that belong to the modified device group and template configurations.
|
||||||
|
|
||||||
|
## PAN-111729
|
||||||
|
|
||||||
|
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-111670
|
||||||
|
|
||||||
|
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||||
|
|
||||||
|
## PAN-111251
|
||||||
|
|
||||||
|
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
|
||||||
|
|
||||||
|
## PAN-110794
|
||||||
|
|
||||||
|
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||||
|
|
||||||
|
## PAN-109759
|
||||||
|
|
||||||
|
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
|
||||||
|
|
||||||
|
## PAN-109526
|
||||||
|
|
||||||
|
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||||
|
|
||||||
|
## PAN-106675
|
||||||
|
|
||||||
|
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||||
|
|
||||||
|
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||||
|
|
||||||
|
## PAN-104780
|
||||||
|
|
||||||
|
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||||
|
|
||||||
|
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||||
|
|
||||||
|
## PAN-103276
|
||||||
|
|
||||||
|
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||||
|
|
||||||
|
## PAN-101688
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama plugins
|
||||||
|
```
|
||||||
|
|
||||||
|
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||||
|
|
||||||
|
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||||
|
|
||||||
|
## PAN-101537
|
||||||
|
|
||||||
|
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||||
|
|
||||||
|
**Workaround:** Specify the vsys in the query string:
|
||||||
|
|
||||||
|
`admin>` `set system target-vsys <vsys-name>`
|
||||||
|
|
||||||
|
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||||
|
|
||||||
|
## PAN-98520
|
||||||
|
|
||||||
|
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||||
|
|
||||||
|
## PAN-97757
|
||||||
|
|
||||||
|
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||||
|
|
||||||
|
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||||
|
|
||||||
|
## PAN-97524
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama management server only
|
||||||
|
```
|
||||||
|
|
||||||
|
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||||
|
|
||||||
|
## PAN-96985
|
||||||
|
|
||||||
|
The `request shutdown system` command does not shut down the Panorama management server.
|
||||||
|
|
||||||
|
## PAN-96960
|
||||||
|
|
||||||
|
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
|
||||||
|
|
||||||
|
## PAN-96446
|
||||||
|
|
||||||
|
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||||
|
|
||||||
|
## PAN-95773
|
||||||
|
|
||||||
|
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||||
|
|
||||||
|
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||||
|
|
||||||
|
## PAN-95511
|
||||||
|
|
||||||
|
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||||
|
|
||||||
|
## PAN-95028
|
||||||
|
|
||||||
|
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||||
|
|
||||||
|
## PAN-94846
|
||||||
|
|
||||||
|
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||||
|
|
||||||
|
## PAN-94093
|
||||||
|
|
||||||
|
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||||
|
|
||||||
|
## PAN-93968
|
||||||
|
|
||||||
|
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||||
|
|
||||||
|
## PAN-93607
|
||||||
|
|
||||||
|
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||||
|
|
||||||
|
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||||
|
|
||||||
|
## PAN-93532
|
||||||
|
|
||||||
|
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||||
|
|
||||||
|
## PAN-93193
|
||||||
|
|
||||||
|
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||||
|
|
||||||
|
- Switch to the firewall **Context** on the Panorama management server.
|
||||||
|
- Commit changes when a dynamic update is being installed.
|
||||||
|
- Generate a custom report when a dynamic update is being installed.
|
||||||
|
- Generate custom reports during a commit.
|
||||||
|
|
||||||
|
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||||
|
|
||||||
|
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||||
|
|
||||||
|
## PAN-91802
|
||||||
|
|
||||||
|
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||||
|
|
||||||
|
## PAN-83610
|
||||||
|
|
||||||
|
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||||
|
|
||||||
|
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-83236
|
||||||
|
|
||||||
|
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||||
|
|
||||||
|
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||||
|
|
||||||
|
## PAN-83215
|
||||||
|
|
||||||
|
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||||
|
|
||||||
|
## PAN-81521
|
||||||
|
|
||||||
|
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||||
|
|
||||||
|
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||||
|
|
||||||
|
## PAN-77125
|
||||||
|
|
||||||
|
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||||
|
|
||||||
|
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-75457
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||||
|
|
||||||
|
## PAN-73530
|
||||||
|
|
||||||
|
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||||
|
|
||||||
|
## PAN-73401
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||||
|
|
||||||
|
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||||
|
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||||
|
|
||||||
|
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||||
|
|
||||||
|
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||||
|
- Configure a worker list on the cluster controller:
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||||
|
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||||
|
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||||
|
or
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||||
|
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||||
|
|
||||||
|
## PAN-71329
|
||||||
|
|
||||||
|
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
|
||||||
|
|
||||||
|
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
|
||||||
|
|
||||||
|
## PAN-70906
|
||||||
|
|
||||||
|
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||||
|
|
||||||
|
## PAN-69505
|
||||||
|
|
||||||
|
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||||
|
|
||||||
|
## PAN-41558
|
||||||
|
|
||||||
|
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||||
|
|
||||||
|
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||||
|
|
||||||
|
## PAN-40079
|
||||||
|
|
||||||
|
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||||
|
|
||||||
|
## PAN-39636
|
||||||
|
|
||||||
|
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||||
|
|
||||||
|
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||||
|
|
||||||
|
## PAN-38255
|
||||||
|
|
||||||
|
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||||
|
|
||||||
|
## PAN-31832
|
||||||
|
|
||||||
|
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||||
|
|
||||||
|
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||||
|
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||||
@@ -0,0 +1,482 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.16
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## PLUG-380
|
||||||
|
|
||||||
|
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||||
|
|
||||||
|
## PAN-223365
|
||||||
|
|
||||||
|
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
|
||||||
|
|
||||||
|
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
|
||||||
|
|
||||||
|
`admin``request restart system`
|
||||||
|
|
||||||
|
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
|
||||||
|
|
||||||
|
## PAN-221015
|
||||||
|
|
||||||
|
On M-600 appliances in Panorama or Log Collector mode, the `es-1` and `es-2` ElasticSearch processes fail to restart when the M-600 appliance is rebooted. The results in the Managed Collector `ES` health status (**Panorama** > **Managed Collectors** > **Health Status**) to be degraded.
|
||||||
|
|
||||||
|
**Workaround:** [Log in to the Panorama or Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) experiencing degraded ElasticSearch health and restart all ElasticSearch processes.
|
||||||
|
|
||||||
|
`admin>``debug elasticsearch es-restart optional all`
|
||||||
|
|
||||||
|
## PAN-197859
|
||||||
|
|
||||||
|
On firewalls running LSVPN with tunnel monitoring enabled, upgrades to 9.1.14 or later cause the LSVPN tunnels to flap.
|
||||||
|
|
||||||
|
## PAN-197341
|
||||||
|
|
||||||
|
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
|
||||||
|
|
||||||
|
For example:
|
||||||
|
|
||||||
|
1. You create a parent device group `DG-A` and a child device group `DG-B`.
|
||||||
|
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
|
||||||
|
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
|
||||||
|
|
||||||
|
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
|
||||||
|
|
||||||
|
## PAN-178194
|
||||||
|
|
||||||
|
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
|
||||||
|
|
||||||
|
## PAN-154266
|
||||||
|
|
||||||
|
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
|
||||||
|
|
||||||
|
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
|
||||||
|
|
||||||
|
## PAN-154247
|
||||||
|
|
||||||
|
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
|
||||||
|
|
||||||
|
**Workaround:** Log out and back in to the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-153803
|
||||||
|
|
||||||
|
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
|
||||||
|
|
||||||
|
## PAN-146573
|
||||||
|
|
||||||
|
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||||
|
|
||||||
|
## PAN-146485
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
|
||||||
|
|
||||||
|
## PAN-144889
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 9.1.2-h1 and later releases only
|
||||||
|
```
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
|
||||||
|
|
||||||
|
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
|
||||||
|
|
||||||
|
## PAN-140959
|
||||||
|
|
||||||
|
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
|
||||||
|
|
||||||
|
## PAN-134456
|
||||||
|
|
||||||
|
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
|
||||||
|
|
||||||
|
**Workaround:** Use a destination-based service route for the SNMP trap server.
|
||||||
|
|
||||||
|
## PAN-134053
|
||||||
|
|
||||||
|
ACC does not filter WildFire logs from Dynamic User Groups.
|
||||||
|
|
||||||
|
## PAN-130550
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
|
||||||
|
|
||||||
|
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
|
||||||
|
|
||||||
|
## PAN-127813
|
||||||
|
|
||||||
|
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches don’t communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
|
||||||
|
|
||||||
|
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
|
||||||
|
|
||||||
|
## PAN-127550
|
||||||
|
|
||||||
|
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
|
||||||
|
|
||||||
|
## PAN-127474
|
||||||
|
|
||||||
|
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
|
||||||
|
|
||||||
|
## PAN-127206
|
||||||
|
|
||||||
|
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
|
||||||
|
|
||||||
|
## PAN-123277
|
||||||
|
|
||||||
|
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-123040
|
||||||
|
|
||||||
|
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules don’t display. A workaround exists for this issue. Please contact Support for information about the workaround.
|
||||||
|
|
||||||
|
## PAN-120440
|
||||||
|
|
||||||
|
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||||
|
|
||||||
|
## PAN-120303
|
||||||
|
|
||||||
|
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||||
|
|
||||||
|
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||||
|
|
||||||
|
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||||
|
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||||
|
2. **Commit** your changes.
|
||||||
|
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||||
|
4. **Commit** your changes.
|
||||||
|
- Restart the firewall (devsrvr) process.
|
||||||
|
1. Log in to the firewall CLI.
|
||||||
|
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||||
|
|
||||||
|
## PAN-118065
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
M-Series Panorama management servers in Management Only mode
|
||||||
|
```
|
||||||
|
|
||||||
|
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
|
||||||
|
|
||||||
|
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
|
||||||
|
|
||||||
|
## PAN-116017
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Google Cloud Platform (GCP) only
|
||||||
|
```
|
||||||
|
|
||||||
|
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||||
|
|
||||||
|
## PAN-115816
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Microsoft Azure only
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-114495
|
||||||
|
|
||||||
|
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||||
|
|
||||||
|
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||||
|
|
||||||
|
## PAN-112694
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls with multiple virtual systems only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||||
|
|
||||||
|
## PAN-112456
|
||||||
|
|
||||||
|
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
|
||||||
|
|
||||||
|
## PAN-111928
|
||||||
|
|
||||||
|
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||||
|
|
||||||
|
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||||
|
|
||||||
|
## PAN-111866
|
||||||
|
|
||||||
|
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||||
|
|
||||||
|
**Workaround:** Perform one of the following tasks.
|
||||||
|
|
||||||
|
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||||
|
- Manually select the devices that belong to the modified device group and template configurations.
|
||||||
|
|
||||||
|
## PAN-111729
|
||||||
|
|
||||||
|
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-111670
|
||||||
|
|
||||||
|
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||||
|
|
||||||
|
## PAN-111251
|
||||||
|
|
||||||
|
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
|
||||||
|
|
||||||
|
## PAN-110794
|
||||||
|
|
||||||
|
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||||
|
|
||||||
|
## PAN-109759
|
||||||
|
|
||||||
|
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
|
||||||
|
|
||||||
|
## PAN-109526
|
||||||
|
|
||||||
|
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||||
|
|
||||||
|
## PAN-106675
|
||||||
|
|
||||||
|
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||||
|
|
||||||
|
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||||
|
|
||||||
|
## PAN-104780
|
||||||
|
|
||||||
|
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||||
|
|
||||||
|
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||||
|
|
||||||
|
## PAN-103276
|
||||||
|
|
||||||
|
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||||
|
|
||||||
|
## PAN-101688
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama plugins
|
||||||
|
```
|
||||||
|
|
||||||
|
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||||
|
|
||||||
|
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||||
|
|
||||||
|
## PAN-101537
|
||||||
|
|
||||||
|
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||||
|
|
||||||
|
**Workaround:** Specify the vsys in the query string:
|
||||||
|
|
||||||
|
`admin>` `set system target-vsys <vsys-name>`
|
||||||
|
|
||||||
|
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||||
|
|
||||||
|
## PAN-98520
|
||||||
|
|
||||||
|
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||||
|
|
||||||
|
## PAN-97757
|
||||||
|
|
||||||
|
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||||
|
|
||||||
|
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||||
|
|
||||||
|
## PAN-97524
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama management server only
|
||||||
|
```
|
||||||
|
|
||||||
|
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||||
|
|
||||||
|
## PAN-96985
|
||||||
|
|
||||||
|
The `request shutdown system` command does not shut down the Panorama management server.
|
||||||
|
|
||||||
|
## PAN-96960
|
||||||
|
|
||||||
|
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
|
||||||
|
|
||||||
|
## PAN-96446
|
||||||
|
|
||||||
|
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||||
|
|
||||||
|
## PAN-95773
|
||||||
|
|
||||||
|
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||||
|
|
||||||
|
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||||
|
|
||||||
|
## PAN-95511
|
||||||
|
|
||||||
|
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||||
|
|
||||||
|
## PAN-95028
|
||||||
|
|
||||||
|
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||||
|
|
||||||
|
## PAN-94846
|
||||||
|
|
||||||
|
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||||
|
|
||||||
|
## PAN-94093
|
||||||
|
|
||||||
|
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||||
|
|
||||||
|
## PAN-93968
|
||||||
|
|
||||||
|
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||||
|
|
||||||
|
## PAN-93607
|
||||||
|
|
||||||
|
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||||
|
|
||||||
|
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||||
|
|
||||||
|
## PAN-93532
|
||||||
|
|
||||||
|
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||||
|
|
||||||
|
## PAN-93193
|
||||||
|
|
||||||
|
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||||
|
|
||||||
|
- Switch to the firewall **Context** on the Panorama management server.
|
||||||
|
- Commit changes when a dynamic update is being installed.
|
||||||
|
- Generate a custom report when a dynamic update is being installed.
|
||||||
|
- Generate custom reports during a commit.
|
||||||
|
|
||||||
|
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||||
|
|
||||||
|
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||||
|
|
||||||
|
## PAN-91802
|
||||||
|
|
||||||
|
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||||
|
|
||||||
|
## PAN-83610
|
||||||
|
|
||||||
|
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||||
|
|
||||||
|
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-83236
|
||||||
|
|
||||||
|
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||||
|
|
||||||
|
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||||
|
|
||||||
|
## PAN-83215
|
||||||
|
|
||||||
|
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||||
|
|
||||||
|
## PAN-81521
|
||||||
|
|
||||||
|
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||||
|
|
||||||
|
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||||
|
|
||||||
|
## PAN-77125
|
||||||
|
|
||||||
|
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||||
|
|
||||||
|
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-75457
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||||
|
|
||||||
|
## PAN-73530
|
||||||
|
|
||||||
|
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||||
|
|
||||||
|
## PAN-73401
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||||
|
|
||||||
|
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||||
|
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||||
|
|
||||||
|
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||||
|
|
||||||
|
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||||
|
- Configure a worker list on the cluster controller:
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||||
|
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||||
|
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||||
|
or
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||||
|
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||||
|
|
||||||
|
## PAN-71329
|
||||||
|
|
||||||
|
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
|
||||||
|
|
||||||
|
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
|
||||||
|
|
||||||
|
## PAN-70906
|
||||||
|
|
||||||
|
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||||
|
|
||||||
|
## PAN-69505
|
||||||
|
|
||||||
|
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||||
|
|
||||||
|
## PAN-41558
|
||||||
|
|
||||||
|
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||||
|
|
||||||
|
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||||
|
|
||||||
|
## PAN-40079
|
||||||
|
|
||||||
|
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||||
|
|
||||||
|
## PAN-39636
|
||||||
|
|
||||||
|
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||||
|
|
||||||
|
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||||
|
|
||||||
|
## PAN-38255
|
||||||
|
|
||||||
|
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||||
|
|
||||||
|
## PAN-31832
|
||||||
|
|
||||||
|
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||||
|
|
||||||
|
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||||
|
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||||
@@ -0,0 +1,492 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.17
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## PLUG-380
|
||||||
|
|
||||||
|
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||||
|
|
||||||
|
## PAN-242561
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.18 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
GlobalProtect tunnel might disconnect shortly after being established when SSL is used as a transport protocol.
|
||||||
|
|
||||||
|
**Workaround**: Disable Internet Protocol version 6 (TCP/IPv6) on the PANGP Virtual Network Adapter.
|
||||||
|
|
||||||
|
## PAN-223365
|
||||||
|
|
||||||
|
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
|
||||||
|
|
||||||
|
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
|
||||||
|
|
||||||
|
`admin``request restart system`
|
||||||
|
|
||||||
|
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
|
||||||
|
|
||||||
|
## PAN-221015
|
||||||
|
|
||||||
|
On M-600 appliances in Panorama or Log Collector mode, the `es-1` and `es-2` ElasticSearch processes fail to restart when the M-600 appliance is rebooted. The results in the Managed Collector `ES` health status (**Panorama** > **Managed Collectors** > **Health Status**) to be degraded.
|
||||||
|
|
||||||
|
**Workaround:** [Log in to the Panorama or Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) experiencing degraded ElasticSearch health and restart all ElasticSearch processes.
|
||||||
|
|
||||||
|
`admin>``debug elasticsearch es-restart optional all`
|
||||||
|
|
||||||
|
## PAN-197859
|
||||||
|
|
||||||
|
On firewalls running LSVPN with tunnel monitoring enabled, upgrades to 9.1.14 or later cause the LSVPN tunnels to flap.
|
||||||
|
|
||||||
|
## PAN-197341
|
||||||
|
|
||||||
|
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
|
||||||
|
|
||||||
|
For example:
|
||||||
|
|
||||||
|
1. You create a parent device group `DG-A` and a child device group `DG-B`.
|
||||||
|
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
|
||||||
|
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
|
||||||
|
|
||||||
|
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
|
||||||
|
|
||||||
|
## PAN-178194
|
||||||
|
|
||||||
|
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
|
||||||
|
|
||||||
|
## PAN-154266
|
||||||
|
|
||||||
|
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
|
||||||
|
|
||||||
|
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
|
||||||
|
|
||||||
|
## PAN-154247
|
||||||
|
|
||||||
|
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
|
||||||
|
|
||||||
|
**Workaround:** Log out and back in to the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-153803
|
||||||
|
|
||||||
|
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
|
||||||
|
|
||||||
|
## PAN-146573
|
||||||
|
|
||||||
|
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||||
|
|
||||||
|
## PAN-146485
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
|
||||||
|
|
||||||
|
## PAN-144889
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 9.1.2-h1 and later releases only
|
||||||
|
```
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
|
||||||
|
|
||||||
|
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
|
||||||
|
|
||||||
|
## PAN-140959
|
||||||
|
|
||||||
|
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
|
||||||
|
|
||||||
|
## PAN-134456
|
||||||
|
|
||||||
|
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
|
||||||
|
|
||||||
|
**Workaround:** Use a destination-based service route for the SNMP trap server.
|
||||||
|
|
||||||
|
## PAN-134053
|
||||||
|
|
||||||
|
ACC does not filter WildFire logs from Dynamic User Groups.
|
||||||
|
|
||||||
|
## PAN-130550
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
|
||||||
|
|
||||||
|
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
|
||||||
|
|
||||||
|
## PAN-127813
|
||||||
|
|
||||||
|
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches don’t communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
|
||||||
|
|
||||||
|
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
|
||||||
|
|
||||||
|
## PAN-127550
|
||||||
|
|
||||||
|
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
|
||||||
|
|
||||||
|
## PAN-127474
|
||||||
|
|
||||||
|
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
|
||||||
|
|
||||||
|
## PAN-127206
|
||||||
|
|
||||||
|
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
|
||||||
|
|
||||||
|
## PAN-123277
|
||||||
|
|
||||||
|
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-123040
|
||||||
|
|
||||||
|
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules don’t display. A workaround exists for this issue. Please contact Support for information about the workaround.
|
||||||
|
|
||||||
|
## PAN-120440
|
||||||
|
|
||||||
|
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||||
|
|
||||||
|
## PAN-120303
|
||||||
|
|
||||||
|
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||||
|
|
||||||
|
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||||
|
|
||||||
|
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||||
|
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||||
|
2. **Commit** your changes.
|
||||||
|
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||||
|
4. **Commit** your changes.
|
||||||
|
- Restart the firewall (devsrvr) process.
|
||||||
|
1. Log in to the firewall CLI.
|
||||||
|
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||||
|
|
||||||
|
## PAN-118065
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
M-Series Panorama management servers in Management Only mode
|
||||||
|
```
|
||||||
|
|
||||||
|
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
|
||||||
|
|
||||||
|
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
|
||||||
|
|
||||||
|
## PAN-116017
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Google Cloud Platform (GCP) only
|
||||||
|
```
|
||||||
|
|
||||||
|
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||||
|
|
||||||
|
## PAN-115816
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Microsoft Azure only
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-114495
|
||||||
|
|
||||||
|
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||||
|
|
||||||
|
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||||
|
|
||||||
|
## PAN-112694
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls with multiple virtual systems only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||||
|
|
||||||
|
## PAN-112456
|
||||||
|
|
||||||
|
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
|
||||||
|
|
||||||
|
## PAN-111928
|
||||||
|
|
||||||
|
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||||
|
|
||||||
|
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||||
|
|
||||||
|
## PAN-111866
|
||||||
|
|
||||||
|
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||||
|
|
||||||
|
**Workaround:** Perform one of the following tasks.
|
||||||
|
|
||||||
|
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||||
|
- Manually select the devices that belong to the modified device group and template configurations.
|
||||||
|
|
||||||
|
## PAN-111729
|
||||||
|
|
||||||
|
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-111670
|
||||||
|
|
||||||
|
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||||
|
|
||||||
|
## PAN-111251
|
||||||
|
|
||||||
|
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
|
||||||
|
|
||||||
|
## PAN-110794
|
||||||
|
|
||||||
|
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||||
|
|
||||||
|
## PAN-109759
|
||||||
|
|
||||||
|
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
|
||||||
|
|
||||||
|
## PAN-109526
|
||||||
|
|
||||||
|
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||||
|
|
||||||
|
## PAN-106675
|
||||||
|
|
||||||
|
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||||
|
|
||||||
|
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||||
|
|
||||||
|
## PAN-104780
|
||||||
|
|
||||||
|
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||||
|
|
||||||
|
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||||
|
|
||||||
|
## PAN-103276
|
||||||
|
|
||||||
|
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||||
|
|
||||||
|
## PAN-101688
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama plugins
|
||||||
|
```
|
||||||
|
|
||||||
|
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||||
|
|
||||||
|
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||||
|
|
||||||
|
## PAN-101537
|
||||||
|
|
||||||
|
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||||
|
|
||||||
|
**Workaround:** Specify the vsys in the query string:
|
||||||
|
|
||||||
|
`admin>` `set system target-vsys <vsys-name>`
|
||||||
|
|
||||||
|
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||||
|
|
||||||
|
## PAN-98520
|
||||||
|
|
||||||
|
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||||
|
|
||||||
|
## PAN-97757
|
||||||
|
|
||||||
|
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||||
|
|
||||||
|
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||||
|
|
||||||
|
## PAN-97524
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama management server only
|
||||||
|
```
|
||||||
|
|
||||||
|
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||||
|
|
||||||
|
## PAN-96985
|
||||||
|
|
||||||
|
The `request shutdown system` command does not shut down the Panorama management server.
|
||||||
|
|
||||||
|
## PAN-96960
|
||||||
|
|
||||||
|
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
|
||||||
|
|
||||||
|
## PAN-96446
|
||||||
|
|
||||||
|
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||||
|
|
||||||
|
## PAN-95773
|
||||||
|
|
||||||
|
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||||
|
|
||||||
|
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||||
|
|
||||||
|
## PAN-95511
|
||||||
|
|
||||||
|
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||||
|
|
||||||
|
## PAN-95028
|
||||||
|
|
||||||
|
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||||
|
|
||||||
|
## PAN-94846
|
||||||
|
|
||||||
|
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||||
|
|
||||||
|
## PAN-94093
|
||||||
|
|
||||||
|
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||||
|
|
||||||
|
## PAN-93968
|
||||||
|
|
||||||
|
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||||
|
|
||||||
|
## PAN-93607
|
||||||
|
|
||||||
|
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||||
|
|
||||||
|
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||||
|
|
||||||
|
## PAN-93532
|
||||||
|
|
||||||
|
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||||
|
|
||||||
|
## PAN-93193
|
||||||
|
|
||||||
|
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||||
|
|
||||||
|
- Switch to the firewall **Context** on the Panorama management server.
|
||||||
|
- Commit changes when a dynamic update is being installed.
|
||||||
|
- Generate a custom report when a dynamic update is being installed.
|
||||||
|
- Generate custom reports during a commit.
|
||||||
|
|
||||||
|
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||||
|
|
||||||
|
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||||
|
|
||||||
|
## PAN-91802
|
||||||
|
|
||||||
|
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||||
|
|
||||||
|
## PAN-83610
|
||||||
|
|
||||||
|
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||||
|
|
||||||
|
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-83236
|
||||||
|
|
||||||
|
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||||
|
|
||||||
|
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||||
|
|
||||||
|
## PAN-83215
|
||||||
|
|
||||||
|
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||||
|
|
||||||
|
## PAN-81521
|
||||||
|
|
||||||
|
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||||
|
|
||||||
|
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||||
|
|
||||||
|
## PAN-77125
|
||||||
|
|
||||||
|
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||||
|
|
||||||
|
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-75457
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||||
|
|
||||||
|
## PAN-73530
|
||||||
|
|
||||||
|
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||||
|
|
||||||
|
## PAN-73401
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||||
|
|
||||||
|
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||||
|
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||||
|
|
||||||
|
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||||
|
|
||||||
|
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||||
|
- Configure a worker list on the cluster controller:
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||||
|
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||||
|
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||||
|
or
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||||
|
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||||
|
|
||||||
|
## PAN-71329
|
||||||
|
|
||||||
|
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
|
||||||
|
|
||||||
|
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
|
||||||
|
|
||||||
|
## PAN-70906
|
||||||
|
|
||||||
|
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||||
|
|
||||||
|
## PAN-69505
|
||||||
|
|
||||||
|
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||||
|
|
||||||
|
## PAN-41558
|
||||||
|
|
||||||
|
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||||
|
|
||||||
|
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||||
|
|
||||||
|
## PAN-40079
|
||||||
|
|
||||||
|
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||||
|
|
||||||
|
## PAN-39636
|
||||||
|
|
||||||
|
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||||
|
|
||||||
|
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||||
|
|
||||||
|
## PAN-38255
|
||||||
|
|
||||||
|
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||||
|
|
||||||
|
## PAN-31832
|
||||||
|
|
||||||
|
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||||
|
|
||||||
|
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||||
|
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||||
@@ -0,0 +1,482 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.18
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## PLUG-380
|
||||||
|
|
||||||
|
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||||
|
|
||||||
|
## PAN-223365
|
||||||
|
|
||||||
|
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
|
||||||
|
|
||||||
|
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
|
||||||
|
|
||||||
|
`admin``request restart system`
|
||||||
|
|
||||||
|
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
|
||||||
|
|
||||||
|
## PAN-221015
|
||||||
|
|
||||||
|
On M-600 appliances in Panorama or Log Collector mode, the `es-1` and `es-2` ElasticSearch processes fail to restart when the M-600 appliance is rebooted. The results in the Managed Collector `ES` health status (**Panorama** > **Managed Collectors** > **Health Status**) to be degraded.
|
||||||
|
|
||||||
|
**Workaround:** [Log in to the Panorama or Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) experiencing degraded ElasticSearch health and restart all ElasticSearch processes.
|
||||||
|
|
||||||
|
`admin>``debug elasticsearch es-restart optional all`
|
||||||
|
|
||||||
|
## PAN-197859
|
||||||
|
|
||||||
|
On firewalls running LSVPN with tunnel monitoring enabled, upgrades to 9.1.14 or later cause the LSVPN tunnels to flap.
|
||||||
|
|
||||||
|
## PAN-197341
|
||||||
|
|
||||||
|
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
|
||||||
|
|
||||||
|
For example:
|
||||||
|
|
||||||
|
1. You create a parent device group `DG-A` and a child device group `DG-B`.
|
||||||
|
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
|
||||||
|
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
|
||||||
|
|
||||||
|
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
|
||||||
|
|
||||||
|
## PAN-178194
|
||||||
|
|
||||||
|
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
|
||||||
|
|
||||||
|
## PAN-154266
|
||||||
|
|
||||||
|
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
|
||||||
|
|
||||||
|
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
|
||||||
|
|
||||||
|
## PAN-154247
|
||||||
|
|
||||||
|
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
|
||||||
|
|
||||||
|
**Workaround:** Log out and back in to the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-153803
|
||||||
|
|
||||||
|
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
|
||||||
|
|
||||||
|
## PAN-146573
|
||||||
|
|
||||||
|
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||||
|
|
||||||
|
## PAN-146485
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
|
||||||
|
|
||||||
|
## PAN-144889
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 9.1.2-h1 and later releases only
|
||||||
|
```
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
|
||||||
|
|
||||||
|
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
|
||||||
|
|
||||||
|
## PAN-140959
|
||||||
|
|
||||||
|
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
|
||||||
|
|
||||||
|
## PAN-134456
|
||||||
|
|
||||||
|
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
|
||||||
|
|
||||||
|
**Workaround:** Use a destination-based service route for the SNMP trap server.
|
||||||
|
|
||||||
|
## PAN-134053
|
||||||
|
|
||||||
|
ACC does not filter WildFire logs from Dynamic User Groups.
|
||||||
|
|
||||||
|
## PAN-130550
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
|
||||||
|
|
||||||
|
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
|
||||||
|
|
||||||
|
## PAN-127813
|
||||||
|
|
||||||
|
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches don’t communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
|
||||||
|
|
||||||
|
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
|
||||||
|
|
||||||
|
## PAN-127550
|
||||||
|
|
||||||
|
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
|
||||||
|
|
||||||
|
## PAN-127474
|
||||||
|
|
||||||
|
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
|
||||||
|
|
||||||
|
## PAN-127206
|
||||||
|
|
||||||
|
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
|
||||||
|
|
||||||
|
## PAN-123277
|
||||||
|
|
||||||
|
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-123040
|
||||||
|
|
||||||
|
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules don’t display. A workaround exists for this issue. Please contact Support for information about the workaround.
|
||||||
|
|
||||||
|
## PAN-120440
|
||||||
|
|
||||||
|
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||||
|
|
||||||
|
## PAN-120303
|
||||||
|
|
||||||
|
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||||
|
|
||||||
|
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||||
|
|
||||||
|
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||||
|
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||||
|
2. **Commit** your changes.
|
||||||
|
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||||
|
4. **Commit** your changes.
|
||||||
|
- Restart the firewall (devsrvr) process.
|
||||||
|
1. Log in to the firewall CLI.
|
||||||
|
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||||
|
|
||||||
|
## PAN-118065
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
M-Series Panorama management servers in Management Only mode
|
||||||
|
```
|
||||||
|
|
||||||
|
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
|
||||||
|
|
||||||
|
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
|
||||||
|
|
||||||
|
## PAN-116017
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Google Cloud Platform (GCP) only
|
||||||
|
```
|
||||||
|
|
||||||
|
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||||
|
|
||||||
|
## PAN-115816
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Microsoft Azure only
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-114495
|
||||||
|
|
||||||
|
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||||
|
|
||||||
|
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||||
|
|
||||||
|
## PAN-112694
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls with multiple virtual systems only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||||
|
|
||||||
|
## PAN-112456
|
||||||
|
|
||||||
|
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
|
||||||
|
|
||||||
|
## PAN-111928
|
||||||
|
|
||||||
|
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||||
|
|
||||||
|
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||||
|
|
||||||
|
## PAN-111866
|
||||||
|
|
||||||
|
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||||
|
|
||||||
|
**Workaround:** Perform one of the following tasks.
|
||||||
|
|
||||||
|
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||||
|
- Manually select the devices that belong to the modified device group and template configurations.
|
||||||
|
|
||||||
|
## PAN-111729
|
||||||
|
|
||||||
|
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-111670
|
||||||
|
|
||||||
|
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||||
|
|
||||||
|
## PAN-111251
|
||||||
|
|
||||||
|
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
|
||||||
|
|
||||||
|
## PAN-110794
|
||||||
|
|
||||||
|
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||||
|
|
||||||
|
## PAN-109759
|
||||||
|
|
||||||
|
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
|
||||||
|
|
||||||
|
## PAN-109526
|
||||||
|
|
||||||
|
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||||
|
|
||||||
|
## PAN-106675
|
||||||
|
|
||||||
|
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||||
|
|
||||||
|
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||||
|
|
||||||
|
## PAN-104780
|
||||||
|
|
||||||
|
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||||
|
|
||||||
|
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||||
|
|
||||||
|
## PAN-103276
|
||||||
|
|
||||||
|
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||||
|
|
||||||
|
## PAN-101688
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama plugins
|
||||||
|
```
|
||||||
|
|
||||||
|
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||||
|
|
||||||
|
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||||
|
|
||||||
|
## PAN-101537
|
||||||
|
|
||||||
|
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||||
|
|
||||||
|
**Workaround:** Specify the vsys in the query string:
|
||||||
|
|
||||||
|
`admin>` `set system target-vsys <vsys-name>`
|
||||||
|
|
||||||
|
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||||
|
|
||||||
|
## PAN-98520
|
||||||
|
|
||||||
|
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||||
|
|
||||||
|
## PAN-97757
|
||||||
|
|
||||||
|
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||||
|
|
||||||
|
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||||
|
|
||||||
|
## PAN-97524
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama management server only
|
||||||
|
```
|
||||||
|
|
||||||
|
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||||
|
|
||||||
|
## PAN-96985
|
||||||
|
|
||||||
|
The `request shutdown system` command does not shut down the Panorama management server.
|
||||||
|
|
||||||
|
## PAN-96960
|
||||||
|
|
||||||
|
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
|
||||||
|
|
||||||
|
## PAN-96446
|
||||||
|
|
||||||
|
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||||
|
|
||||||
|
## PAN-95773
|
||||||
|
|
||||||
|
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||||
|
|
||||||
|
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||||
|
|
||||||
|
## PAN-95511
|
||||||
|
|
||||||
|
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||||
|
|
||||||
|
## PAN-95028
|
||||||
|
|
||||||
|
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||||
|
|
||||||
|
## PAN-94846
|
||||||
|
|
||||||
|
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||||
|
|
||||||
|
## PAN-94093
|
||||||
|
|
||||||
|
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||||
|
|
||||||
|
## PAN-93968
|
||||||
|
|
||||||
|
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||||
|
|
||||||
|
## PAN-93607
|
||||||
|
|
||||||
|
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||||
|
|
||||||
|
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||||
|
|
||||||
|
## PAN-93532
|
||||||
|
|
||||||
|
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||||
|
|
||||||
|
## PAN-93193
|
||||||
|
|
||||||
|
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||||
|
|
||||||
|
- Switch to the firewall **Context** on the Panorama management server.
|
||||||
|
- Commit changes when a dynamic update is being installed.
|
||||||
|
- Generate a custom report when a dynamic update is being installed.
|
||||||
|
- Generate custom reports during a commit.
|
||||||
|
|
||||||
|
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||||
|
|
||||||
|
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||||
|
|
||||||
|
## PAN-91802
|
||||||
|
|
||||||
|
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||||
|
|
||||||
|
## PAN-83610
|
||||||
|
|
||||||
|
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||||
|
|
||||||
|
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-83236
|
||||||
|
|
||||||
|
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||||
|
|
||||||
|
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||||
|
|
||||||
|
## PAN-83215
|
||||||
|
|
||||||
|
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||||
|
|
||||||
|
## PAN-81521
|
||||||
|
|
||||||
|
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||||
|
|
||||||
|
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||||
|
|
||||||
|
## PAN-77125
|
||||||
|
|
||||||
|
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||||
|
|
||||||
|
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-75457
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||||
|
|
||||||
|
## PAN-73530
|
||||||
|
|
||||||
|
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||||
|
|
||||||
|
## PAN-73401
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||||
|
|
||||||
|
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||||
|
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||||
|
|
||||||
|
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||||
|
|
||||||
|
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||||
|
- Configure a worker list on the cluster controller:
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||||
|
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||||
|
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||||
|
or
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||||
|
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||||
|
|
||||||
|
## PAN-71329
|
||||||
|
|
||||||
|
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
|
||||||
|
|
||||||
|
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
|
||||||
|
|
||||||
|
## PAN-70906
|
||||||
|
|
||||||
|
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||||
|
|
||||||
|
## PAN-69505
|
||||||
|
|
||||||
|
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||||
|
|
||||||
|
## PAN-41558
|
||||||
|
|
||||||
|
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||||
|
|
||||||
|
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||||
|
|
||||||
|
## PAN-40079
|
||||||
|
|
||||||
|
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||||
|
|
||||||
|
## PAN-39636
|
||||||
|
|
||||||
|
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||||
|
|
||||||
|
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||||
|
|
||||||
|
## PAN-38255
|
||||||
|
|
||||||
|
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||||
|
|
||||||
|
## PAN-31832
|
||||||
|
|
||||||
|
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||||
|
|
||||||
|
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||||
|
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||||
@@ -0,0 +1,517 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.1
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## PLUG-380
|
||||||
|
|
||||||
|
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||||
|
|
||||||
|
## PAN-223365
|
||||||
|
|
||||||
|
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
|
||||||
|
|
||||||
|
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
|
||||||
|
|
||||||
|
`admin``request restart system`
|
||||||
|
|
||||||
|
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
|
||||||
|
|
||||||
|
## PAN-199557
|
||||||
|
|
||||||
|
On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Manually reboot the `Active` Panorama HA peer.
|
||||||
|
|
||||||
|
## PAN-197341
|
||||||
|
|
||||||
|
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
|
||||||
|
|
||||||
|
For example:
|
||||||
|
|
||||||
|
1. You create a parent device group `DG-A` and a child device group `DG-B`.
|
||||||
|
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
|
||||||
|
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
|
||||||
|
|
||||||
|
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
|
||||||
|
|
||||||
|
## PAN-178194
|
||||||
|
|
||||||
|
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
|
||||||
|
|
||||||
|
## PAN-157240
|
||||||
|
|
||||||
|
When a firewall has hardware offloading turned on and OSPF enabled, if ECMP is enabled or disabled for a virtual router during a configuration commit, OSPF sessions may get stuck in Exchange Start state.
|
||||||
|
|
||||||
|
**Workaround:** Disable OSPF when enabling or disabling ECMP, and then re-enable OSPF in the next commit.
|
||||||
|
|
||||||
|
## PAN-154247
|
||||||
|
|
||||||
|
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
|
||||||
|
|
||||||
|
**Workaround:** Log out and back in to the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-153803
|
||||||
|
|
||||||
|
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
|
||||||
|
|
||||||
|
## PAN-151198
|
||||||
|
|
||||||
|
On the Panorama management server, read-only Panorama administrators (**Panorama** > **Administrators**) can load managed firewall configuration Backups (**Panorama** > **Managed Devices** > **Summary**).
|
||||||
|
|
||||||
|
## PAN-146573
|
||||||
|
|
||||||
|
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||||
|
|
||||||
|
## PAN-140084
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.5 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an issue where the default Dynamic IP and Port (DIPP) NAT oversubscription rate is set to 2.
|
||||||
|
|
||||||
|
## PAN-136763
|
||||||
|
|
||||||
|
On the Panorama management server, managed firewalls display as `disconnected` when installing a PAN-OS software update (**Panorama** > **Device Deployment** > **Software**) but display as `connected` when you view your managed firewalls Summary (**Panorama** > **Managed Devices** > **Summary**) and from the CLI.
|
||||||
|
|
||||||
|
**Workaround:** Log out and log back in to the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-136701
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000b Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Packets for new sessions drop when handling predict sessions.
|
||||||
|
|
||||||
|
**Workaround:** (PAN-OS 9.1.3 and later versions only) Use the following CLi commands to bypass this issue:
|
||||||
|
|
||||||
|
- `set session hwpredict disable yes`
|
||||||
|
- `show session hwpredict status`
|
||||||
|
|
||||||
|
## PAN-135260
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an intermittent issue where the dataplane process (all_pktproc_X) on a Network Processing Card (NPC) restarts unexpectedly when processing IPSec tunnel traffic. This issue can occur on any NPC card in any slot.
|
||||||
|
|
||||||
|
## PAN-134456
|
||||||
|
|
||||||
|
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
|
||||||
|
|
||||||
|
**Workaround:** Use a destination-based service route for the SNMP trap server.
|
||||||
|
|
||||||
|
## PAN-134053
|
||||||
|
|
||||||
|
ACC does not filter WildFire logs from Dynamic User Groups.
|
||||||
|
|
||||||
|
## PAN-130550
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
|
||||||
|
|
||||||
|
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
|
||||||
|
|
||||||
|
## PAN-127813
|
||||||
|
|
||||||
|
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches don’t communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
|
||||||
|
|
||||||
|
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
|
||||||
|
|
||||||
|
## PAN-127550
|
||||||
|
|
||||||
|
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
|
||||||
|
|
||||||
|
## PAN-127474
|
||||||
|
|
||||||
|
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
|
||||||
|
|
||||||
|
## PAN-127206
|
||||||
|
|
||||||
|
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
|
||||||
|
|
||||||
|
## PAN-124956
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.11 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an issue where VM-Series firewalls do not support packet buffer protection.
|
||||||
|
|
||||||
|
## PAN-123277
|
||||||
|
|
||||||
|
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-123040
|
||||||
|
|
||||||
|
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules don’t display. A workaround exists for this issue. Please contact Support for information about the workaround.
|
||||||
|
|
||||||
|
## PAN-120440
|
||||||
|
|
||||||
|
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||||
|
|
||||||
|
## PAN-120423
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.9 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
PAN-OS 9.1.0 does not support the XML API for GlobalProtect logs.
|
||||||
|
|
||||||
|
## PAN-120303
|
||||||
|
|
||||||
|
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||||
|
|
||||||
|
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||||
|
|
||||||
|
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||||
|
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||||
|
2. **Commit** your changes.
|
||||||
|
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||||
|
4. **Commit** your changes.
|
||||||
|
- Restart the firewall (devsrvr) process.
|
||||||
|
1. Log in to the firewall CLI.
|
||||||
|
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||||
|
|
||||||
|
## PAN-118065
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
M-Series Panorama management servers in Management Only mode
|
||||||
|
```
|
||||||
|
|
||||||
|
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
|
||||||
|
|
||||||
|
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
|
||||||
|
|
||||||
|
## PAN-116017
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Google Cloud Platform (GCP) only
|
||||||
|
```
|
||||||
|
|
||||||
|
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||||
|
|
||||||
|
## PAN-115816
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Microsoft Azure only
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-114495
|
||||||
|
|
||||||
|
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||||
|
|
||||||
|
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||||
|
|
||||||
|
## PAN-112694
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls with multiple virtual systems only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||||
|
|
||||||
|
## PAN-112456
|
||||||
|
|
||||||
|
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
|
||||||
|
|
||||||
|
## PAN-111928
|
||||||
|
|
||||||
|
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||||
|
|
||||||
|
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||||
|
|
||||||
|
## PAN-111866
|
||||||
|
|
||||||
|
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||||
|
|
||||||
|
**Workaround:** Perform one of the following tasks.
|
||||||
|
|
||||||
|
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||||
|
- Manually select the devices that belong to the modified device group and template configurations.
|
||||||
|
|
||||||
|
## PAN-111729
|
||||||
|
|
||||||
|
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-111670
|
||||||
|
|
||||||
|
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||||
|
|
||||||
|
## PAN-111251
|
||||||
|
|
||||||
|
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
|
||||||
|
|
||||||
|
## PAN-110794
|
||||||
|
|
||||||
|
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||||
|
|
||||||
|
## PAN-109759
|
||||||
|
|
||||||
|
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
|
||||||
|
|
||||||
|
## PAN-109526
|
||||||
|
|
||||||
|
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||||
|
|
||||||
|
## PAN-106675
|
||||||
|
|
||||||
|
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||||
|
|
||||||
|
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||||
|
|
||||||
|
## PAN-104780
|
||||||
|
|
||||||
|
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||||
|
|
||||||
|
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||||
|
|
||||||
|
## PAN-103276
|
||||||
|
|
||||||
|
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||||
|
|
||||||
|
## PAN-103018
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama plugins
|
||||||
|
```
|
||||||
|
|
||||||
|
When you use the AND/OR boolean operators to define the match criteria for Dynamic Address Groups on Panorama, the boolean operators do not function properly. The member IP addresses are not included in the address group as expected.
|
||||||
|
|
||||||
|
## PAN-101688
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama plugins
|
||||||
|
```
|
||||||
|
|
||||||
|
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||||
|
|
||||||
|
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||||
|
|
||||||
|
## PAN-101537
|
||||||
|
|
||||||
|
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||||
|
|
||||||
|
**Workaround:** Specify the vsys in the query string:
|
||||||
|
|
||||||
|
`admin>` `set system target-vsys <vsys-name>`
|
||||||
|
|
||||||
|
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||||
|
|
||||||
|
## PAN-98520
|
||||||
|
|
||||||
|
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||||
|
|
||||||
|
## PAN-97757
|
||||||
|
|
||||||
|
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||||
|
|
||||||
|
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||||
|
|
||||||
|
## PAN-97524
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama management server only
|
||||||
|
```
|
||||||
|
|
||||||
|
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||||
|
|
||||||
|
## PAN-96985
|
||||||
|
|
||||||
|
The `request shutdown system` command does not shut down the Panorama management server.
|
||||||
|
|
||||||
|
## PAN-96960
|
||||||
|
|
||||||
|
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
|
||||||
|
|
||||||
|
## PAN-96446
|
||||||
|
|
||||||
|
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||||
|
|
||||||
|
## PAN-95773
|
||||||
|
|
||||||
|
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||||
|
|
||||||
|
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||||
|
|
||||||
|
## PAN-95511
|
||||||
|
|
||||||
|
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||||
|
|
||||||
|
## PAN-95028
|
||||||
|
|
||||||
|
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||||
|
|
||||||
|
## PAN-94846
|
||||||
|
|
||||||
|
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||||
|
|
||||||
|
## PAN-94093
|
||||||
|
|
||||||
|
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||||
|
|
||||||
|
## PAN-93968
|
||||||
|
|
||||||
|
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||||
|
|
||||||
|
## PAN-93607
|
||||||
|
|
||||||
|
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||||
|
|
||||||
|
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||||
|
|
||||||
|
## PAN-93532
|
||||||
|
|
||||||
|
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||||
|
|
||||||
|
## PAN-93193
|
||||||
|
|
||||||
|
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||||
|
|
||||||
|
- Switch to the firewall **Context** on the Panorama management server.
|
||||||
|
- Commit changes when a dynamic update is being installed.
|
||||||
|
- Generate a custom report when a dynamic update is being installed.
|
||||||
|
- Generate custom reports during a commit.
|
||||||
|
|
||||||
|
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||||
|
|
||||||
|
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||||
|
|
||||||
|
## PAN-91802
|
||||||
|
|
||||||
|
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||||
|
|
||||||
|
## PAN-83610
|
||||||
|
|
||||||
|
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||||
|
|
||||||
|
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-83236
|
||||||
|
|
||||||
|
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||||
|
|
||||||
|
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||||
|
|
||||||
|
## PAN-83215
|
||||||
|
|
||||||
|
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||||
|
|
||||||
|
## PAN-81521
|
||||||
|
|
||||||
|
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||||
|
|
||||||
|
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||||
|
|
||||||
|
## PAN-77125
|
||||||
|
|
||||||
|
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||||
|
|
||||||
|
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-75457
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||||
|
|
||||||
|
## PAN-73530
|
||||||
|
|
||||||
|
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||||
|
|
||||||
|
## PAN-73401
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||||
|
|
||||||
|
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||||
|
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||||
|
|
||||||
|
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||||
|
|
||||||
|
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||||
|
- Configure a worker list on the cluster controller:
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||||
|
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||||
|
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||||
|
or
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||||
|
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||||
|
|
||||||
|
## PAN-71329
|
||||||
|
|
||||||
|
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
|
||||||
|
|
||||||
|
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
|
||||||
|
|
||||||
|
## PAN-70906
|
||||||
|
|
||||||
|
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||||
|
|
||||||
|
## PAN-69505
|
||||||
|
|
||||||
|
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||||
|
|
||||||
|
## PAN-41558
|
||||||
|
|
||||||
|
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||||
|
|
||||||
|
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||||
|
|
||||||
|
## PAN-40079
|
||||||
|
|
||||||
|
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||||
|
|
||||||
|
## PAN-39636
|
||||||
|
|
||||||
|
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||||
|
|
||||||
|
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||||
|
|
||||||
|
## PAN-38255
|
||||||
|
|
||||||
|
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||||
|
|
||||||
|
## PAN-31832
|
||||||
|
|
||||||
|
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||||
|
|
||||||
|
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||||
|
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||||
@@ -0,0 +1,515 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.2
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## PLUG-380
|
||||||
|
|
||||||
|
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||||
|
|
||||||
|
## PAN-223365
|
||||||
|
|
||||||
|
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
|
||||||
|
|
||||||
|
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
|
||||||
|
|
||||||
|
`admin``request restart system`
|
||||||
|
|
||||||
|
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
|
||||||
|
|
||||||
|
## PAN-199557
|
||||||
|
|
||||||
|
On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Manually reboot the `Active` Panorama HA peer.
|
||||||
|
|
||||||
|
## PAN-197341
|
||||||
|
|
||||||
|
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
|
||||||
|
|
||||||
|
For example:
|
||||||
|
|
||||||
|
1. You create a parent device group `DG-A` and a child device group `DG-B`.
|
||||||
|
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
|
||||||
|
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
|
||||||
|
|
||||||
|
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
|
||||||
|
|
||||||
|
## PAN-178194
|
||||||
|
|
||||||
|
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
|
||||||
|
|
||||||
|
## PAN-154247
|
||||||
|
|
||||||
|
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
|
||||||
|
|
||||||
|
**Workaround:** Log out and back in to the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-153803
|
||||||
|
|
||||||
|
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
|
||||||
|
|
||||||
|
## PAN-151909
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.10 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
On the Panorama management server, Preview Changes (**Commit** > **Commit to Panorama**) incorrectly displays an existing route as Added and the new route as an existing route in the Candidate Configuration when you configure a new virtual router route (**Network** > **Virtual Router**).
|
||||||
|
|
||||||
|
## PAN-146573
|
||||||
|
|
||||||
|
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||||
|
|
||||||
|
## PAN-144889
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 9.1.2-h1 and later releases only
|
||||||
|
```
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
|
||||||
|
|
||||||
|
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
|
||||||
|
|
||||||
|
## PAN-144073
|
||||||
|
|
||||||
|
On the Panorama management server, hub and branch firewall latency, jitter, and packet loss data is not updated when monitoring SD-WAN link performance (**Panorama** > **SD-WAN** > **Monitoring**).
|
||||||
|
|
||||||
|
## PAN-140084
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.5 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an issue where the default Dynamic IP and Port (DIPP) NAT oversubscription rate is set to 2.
|
||||||
|
|
||||||
|
## PAN-136701
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000b Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Packets for new sessions drop when handling predict sessions.
|
||||||
|
|
||||||
|
**Workaround:** (PAN-OS 9.1.3 and later versions only) Use the following CLi commands to bypass this issue:
|
||||||
|
|
||||||
|
- `set session hwpredict disable yes`
|
||||||
|
- `show session hwpredict status`
|
||||||
|
|
||||||
|
## PAN-134456
|
||||||
|
|
||||||
|
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
|
||||||
|
|
||||||
|
**Workaround:** Use a destination-based service route for the SNMP trap server.
|
||||||
|
|
||||||
|
## PAN-134053
|
||||||
|
|
||||||
|
ACC does not filter WildFire logs from Dynamic User Groups.
|
||||||
|
|
||||||
|
## PAN-130550
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
|
||||||
|
|
||||||
|
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
|
||||||
|
|
||||||
|
## PAN-127813
|
||||||
|
|
||||||
|
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches don’t communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
|
||||||
|
|
||||||
|
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
|
||||||
|
|
||||||
|
## PAN-127550
|
||||||
|
|
||||||
|
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
|
||||||
|
|
||||||
|
## PAN-127474
|
||||||
|
|
||||||
|
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
|
||||||
|
|
||||||
|
## PAN-127206
|
||||||
|
|
||||||
|
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
|
||||||
|
|
||||||
|
## PAN-124956
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.11 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an issue where VM-Series firewalls do not support packet buffer protection.
|
||||||
|
|
||||||
|
## PAN-123277
|
||||||
|
|
||||||
|
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-123040
|
||||||
|
|
||||||
|
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules don’t display. A workaround exists for this issue. Please contact Support for information about the workaround.
|
||||||
|
|
||||||
|
## PAN-120440
|
||||||
|
|
||||||
|
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||||
|
|
||||||
|
## PAN-120423
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.9 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
PAN-OS 9.1.0 does not support the XML API for GlobalProtect logs.
|
||||||
|
|
||||||
|
## PAN-120303
|
||||||
|
|
||||||
|
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||||
|
|
||||||
|
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||||
|
|
||||||
|
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||||
|
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||||
|
2. **Commit** your changes.
|
||||||
|
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||||
|
4. **Commit** your changes.
|
||||||
|
- Restart the firewall (devsrvr) process.
|
||||||
|
1. Log in to the firewall CLI.
|
||||||
|
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||||
|
|
||||||
|
## PAN-118065
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
M-Series Panorama management servers in Management Only mode
|
||||||
|
```
|
||||||
|
|
||||||
|
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
|
||||||
|
|
||||||
|
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
|
||||||
|
|
||||||
|
## PAN-116017
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Google Cloud Platform (GCP) only
|
||||||
|
```
|
||||||
|
|
||||||
|
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||||
|
|
||||||
|
## PAN-115816
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Microsoft Azure only
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-114495
|
||||||
|
|
||||||
|
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||||
|
|
||||||
|
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||||
|
|
||||||
|
## PAN-112694
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls with multiple virtual systems only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||||
|
|
||||||
|
## PAN-112456
|
||||||
|
|
||||||
|
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
|
||||||
|
|
||||||
|
## PAN-111928
|
||||||
|
|
||||||
|
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||||
|
|
||||||
|
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||||
|
|
||||||
|
## PAN-111866
|
||||||
|
|
||||||
|
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||||
|
|
||||||
|
**Workaround:** Perform one of the following tasks.
|
||||||
|
|
||||||
|
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||||
|
- Manually select the devices that belong to the modified device group and template configurations.
|
||||||
|
|
||||||
|
## PAN-111729
|
||||||
|
|
||||||
|
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-111670
|
||||||
|
|
||||||
|
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||||
|
|
||||||
|
## PAN-111251
|
||||||
|
|
||||||
|
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
|
||||||
|
|
||||||
|
## PAN-110794
|
||||||
|
|
||||||
|
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||||
|
|
||||||
|
## PAN-109759
|
||||||
|
|
||||||
|
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
|
||||||
|
|
||||||
|
## PAN-109526
|
||||||
|
|
||||||
|
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||||
|
|
||||||
|
## PAN-106675
|
||||||
|
|
||||||
|
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||||
|
|
||||||
|
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||||
|
|
||||||
|
## PAN-104780
|
||||||
|
|
||||||
|
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||||
|
|
||||||
|
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||||
|
|
||||||
|
## PAN-103276
|
||||||
|
|
||||||
|
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||||
|
|
||||||
|
## PAN-103018
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama plugins
|
||||||
|
```
|
||||||
|
|
||||||
|
When you use the AND/OR boolean operators to define the match criteria for Dynamic Address Groups on Panorama, the boolean operators do not function properly. The member IP addresses are not included in the address group as expected.
|
||||||
|
|
||||||
|
## PAN-101688
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama plugins
|
||||||
|
```
|
||||||
|
|
||||||
|
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||||
|
|
||||||
|
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||||
|
|
||||||
|
## PAN-101537
|
||||||
|
|
||||||
|
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||||
|
|
||||||
|
**Workaround:** Specify the vsys in the query string:
|
||||||
|
|
||||||
|
`admin>` `set system target-vsys <vsys-name>`
|
||||||
|
|
||||||
|
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||||
|
|
||||||
|
## PAN-98520
|
||||||
|
|
||||||
|
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||||
|
|
||||||
|
## PAN-97757
|
||||||
|
|
||||||
|
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||||
|
|
||||||
|
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||||
|
|
||||||
|
## PAN-97524
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama management server only
|
||||||
|
```
|
||||||
|
|
||||||
|
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||||
|
|
||||||
|
## PAN-96985
|
||||||
|
|
||||||
|
The `request shutdown system` command does not shut down the Panorama management server.
|
||||||
|
|
||||||
|
## PAN-96960
|
||||||
|
|
||||||
|
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
|
||||||
|
|
||||||
|
## PAN-96446
|
||||||
|
|
||||||
|
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||||
|
|
||||||
|
## PAN-95773
|
||||||
|
|
||||||
|
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||||
|
|
||||||
|
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||||
|
|
||||||
|
## PAN-95511
|
||||||
|
|
||||||
|
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||||
|
|
||||||
|
## PAN-95028
|
||||||
|
|
||||||
|
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||||
|
|
||||||
|
## PAN-94846
|
||||||
|
|
||||||
|
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||||
|
|
||||||
|
## PAN-94093
|
||||||
|
|
||||||
|
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||||
|
|
||||||
|
## PAN-93968
|
||||||
|
|
||||||
|
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||||
|
|
||||||
|
## PAN-93607
|
||||||
|
|
||||||
|
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||||
|
|
||||||
|
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||||
|
|
||||||
|
## PAN-93532
|
||||||
|
|
||||||
|
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||||
|
|
||||||
|
## PAN-93193
|
||||||
|
|
||||||
|
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||||
|
|
||||||
|
- Switch to the firewall **Context** on the Panorama management server.
|
||||||
|
- Commit changes when a dynamic update is being installed.
|
||||||
|
- Generate a custom report when a dynamic update is being installed.
|
||||||
|
- Generate custom reports during a commit.
|
||||||
|
|
||||||
|
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||||
|
|
||||||
|
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||||
|
|
||||||
|
## PAN-91802
|
||||||
|
|
||||||
|
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||||
|
|
||||||
|
## PAN-83610
|
||||||
|
|
||||||
|
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||||
|
|
||||||
|
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-83236
|
||||||
|
|
||||||
|
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||||
|
|
||||||
|
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||||
|
|
||||||
|
## PAN-83215
|
||||||
|
|
||||||
|
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||||
|
|
||||||
|
## PAN-81521
|
||||||
|
|
||||||
|
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||||
|
|
||||||
|
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||||
|
|
||||||
|
## PAN-77125
|
||||||
|
|
||||||
|
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||||
|
|
||||||
|
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-75457
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||||
|
|
||||||
|
## PAN-73530
|
||||||
|
|
||||||
|
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||||
|
|
||||||
|
## PAN-73401
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||||
|
|
||||||
|
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||||
|
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||||
|
|
||||||
|
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||||
|
|
||||||
|
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||||
|
- Configure a worker list on the cluster controller:
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||||
|
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||||
|
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||||
|
or
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||||
|
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||||
|
|
||||||
|
## PAN-71329
|
||||||
|
|
||||||
|
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
|
||||||
|
|
||||||
|
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
|
||||||
|
|
||||||
|
## PAN-70906
|
||||||
|
|
||||||
|
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||||
|
|
||||||
|
## PAN-69505
|
||||||
|
|
||||||
|
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||||
|
|
||||||
|
## PAN-41558
|
||||||
|
|
||||||
|
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||||
|
|
||||||
|
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||||
|
|
||||||
|
## PAN-40079
|
||||||
|
|
||||||
|
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||||
|
|
||||||
|
## PAN-39636
|
||||||
|
|
||||||
|
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||||
|
|
||||||
|
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||||
|
|
||||||
|
## PAN-38255
|
||||||
|
|
||||||
|
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||||
|
|
||||||
|
## PAN-31832
|
||||||
|
|
||||||
|
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||||
|
|
||||||
|
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||||
|
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||||
@@ -0,0 +1,551 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.3
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## PLUG-380
|
||||||
|
|
||||||
|
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||||
|
|
||||||
|
## PAN-223365
|
||||||
|
|
||||||
|
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
|
||||||
|
|
||||||
|
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
|
||||||
|
|
||||||
|
`admin``request restart system`
|
||||||
|
|
||||||
|
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
|
||||||
|
|
||||||
|
## PAN-199557
|
||||||
|
|
||||||
|
On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Manually reboot the `Active` Panorama HA peer.
|
||||||
|
|
||||||
|
## PAN-197341
|
||||||
|
|
||||||
|
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
|
||||||
|
|
||||||
|
For example:
|
||||||
|
|
||||||
|
1. You create a parent device group `DG-A` and a child device group `DG-B`.
|
||||||
|
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
|
||||||
|
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
|
||||||
|
|
||||||
|
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
|
||||||
|
|
||||||
|
## PAN-178194
|
||||||
|
|
||||||
|
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
|
||||||
|
|
||||||
|
## PAN-154266
|
||||||
|
|
||||||
|
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
|
||||||
|
|
||||||
|
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
|
||||||
|
|
||||||
|
## PAN-154247
|
||||||
|
|
||||||
|
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
|
||||||
|
|
||||||
|
**Workaround:** Log out and back in to the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-153803
|
||||||
|
|
||||||
|
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
|
||||||
|
|
||||||
|
## PAN-151909
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.10 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
On the Panorama management server, Preview Changes (**Commit** > **Commit to Panorama**) incorrectly displays an existing route as Added and the new route as an existing route in the Candidate Configuration when you configure a new virtual router route (**Network** > **Virtual Router**).
|
||||||
|
|
||||||
|
## PAN-150172
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.3-h1 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
Dataplane processes restart when attempting to access websites that have the `NotBefore` attribute less than or equal to Unix Epoch Time in the server certificate with forward proxy enabled.
|
||||||
|
|
||||||
|
## PAN-149913
|
||||||
|
|
||||||
|
On the firewall CLI, the `show system info` command displays the management IP address of the firewall as the Ethernet1/1 interface IP address.
|
||||||
|
|
||||||
|
On the Panorama management server, the IPv4 address (**Panorama** > **Managed Devices** > **Summary**) displays the Ethernet1/1 interface IP address.
|
||||||
|
|
||||||
|
## PAN-146573
|
||||||
|
|
||||||
|
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||||
|
|
||||||
|
## PAN-146485
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
|
||||||
|
|
||||||
|
## PAN-144889
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 9.1.2-h1 and later releases only
|
||||||
|
```
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
|
||||||
|
|
||||||
|
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
|
||||||
|
|
||||||
|
## PAN-140959
|
||||||
|
|
||||||
|
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
|
||||||
|
|
||||||
|
## PAN-140084
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.5 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an issue where the default Dynamic IP and Port (DIPP) NAT oversubscription rate is set to 2.
|
||||||
|
|
||||||
|
## PAN-136701
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000b Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Packets for new sessions drop when handling predict sessions.
|
||||||
|
|
||||||
|
**Workaround:** Use the following CLi commands to bypass this issue:
|
||||||
|
|
||||||
|
- `set session hwpredict disable yes`
|
||||||
|
- `show session hwpredict status`
|
||||||
|
|
||||||
|
## PAN-134456
|
||||||
|
|
||||||
|
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
|
||||||
|
|
||||||
|
**Workaround:** Use a destination-based service route for the SNMP trap server.
|
||||||
|
|
||||||
|
## PAN-134053
|
||||||
|
|
||||||
|
ACC does not filter WildFire logs from Dynamic User Groups.
|
||||||
|
|
||||||
|
## PAN-130550
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
|
||||||
|
|
||||||
|
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
|
||||||
|
|
||||||
|
## PAN-127813
|
||||||
|
|
||||||
|
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches don’t communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
|
||||||
|
|
||||||
|
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
|
||||||
|
|
||||||
|
## PAN-127550
|
||||||
|
|
||||||
|
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
|
||||||
|
|
||||||
|
## PAN-127474
|
||||||
|
|
||||||
|
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
|
||||||
|
|
||||||
|
## PAN-127206
|
||||||
|
|
||||||
|
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
|
||||||
|
|
||||||
|
## PAN-124956
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.11 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an issue where VM-Series firewalls do not support packet buffer protection.
|
||||||
|
|
||||||
|
## PAN-123277
|
||||||
|
|
||||||
|
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-123040
|
||||||
|
|
||||||
|
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules don’t display. A workaround exists for this issue. Please contact Support for information about the workaround.
|
||||||
|
|
||||||
|
## PAN-121484
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.6 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
The dataplane sends positive acknowledgments to predict-status checks from FPP when the corresponding predict is deleted, which causes SIP and RTSP applications to perform less than the expected achievable performance.
|
||||||
|
|
||||||
|
## PAN-120440
|
||||||
|
|
||||||
|
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||||
|
|
||||||
|
## PAN-120423
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.9 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
PAN-OS 9.1.0 does not support the XML API for GlobalProtect logs.
|
||||||
|
|
||||||
|
## PAN-120303
|
||||||
|
|
||||||
|
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||||
|
|
||||||
|
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||||
|
|
||||||
|
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||||
|
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||||
|
2. **Commit** your changes.
|
||||||
|
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||||
|
4. **Commit** your changes.
|
||||||
|
- Restart the firewall (devsrvr) process.
|
||||||
|
1. Log in to the firewall CLI.
|
||||||
|
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||||
|
|
||||||
|
## PAN-118065
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
M-Series Panorama management servers in Management Only mode
|
||||||
|
```
|
||||||
|
|
||||||
|
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
|
||||||
|
|
||||||
|
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
|
||||||
|
|
||||||
|
## PAN-116017
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Google Cloud Platform (GCP) only
|
||||||
|
```
|
||||||
|
|
||||||
|
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||||
|
|
||||||
|
## PAN-115816
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Microsoft Azure only
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-114495
|
||||||
|
|
||||||
|
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||||
|
|
||||||
|
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||||
|
|
||||||
|
## PAN-112694
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls with multiple virtual systems only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||||
|
|
||||||
|
## PAN-112456
|
||||||
|
|
||||||
|
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
|
||||||
|
|
||||||
|
## PAN-111928
|
||||||
|
|
||||||
|
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||||
|
|
||||||
|
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||||
|
|
||||||
|
## PAN-111866
|
||||||
|
|
||||||
|
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||||
|
|
||||||
|
**Workaround:** Perform one of the following tasks.
|
||||||
|
|
||||||
|
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||||
|
- Manually select the devices that belong to the modified device group and template configurations.
|
||||||
|
|
||||||
|
## PAN-111729
|
||||||
|
|
||||||
|
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-111670
|
||||||
|
|
||||||
|
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||||
|
|
||||||
|
## PAN-111251
|
||||||
|
|
||||||
|
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
|
||||||
|
|
||||||
|
## PAN-110794
|
||||||
|
|
||||||
|
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||||
|
|
||||||
|
## PAN-109759
|
||||||
|
|
||||||
|
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
|
||||||
|
|
||||||
|
## PAN-109526
|
||||||
|
|
||||||
|
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||||
|
|
||||||
|
## PAN-106675
|
||||||
|
|
||||||
|
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||||
|
|
||||||
|
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||||
|
|
||||||
|
## PAN-104780
|
||||||
|
|
||||||
|
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||||
|
|
||||||
|
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||||
|
|
||||||
|
## PAN-103276
|
||||||
|
|
||||||
|
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||||
|
|
||||||
|
## PAN-103018
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama plugins
|
||||||
|
```
|
||||||
|
|
||||||
|
When you use the AND/OR boolean operators to define the match criteria for Dynamic Address Groups on Panorama, the boolean operators do not function properly. The member IP addresses are not included in the address group as expected.
|
||||||
|
|
||||||
|
## PAN-101688
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama plugins
|
||||||
|
```
|
||||||
|
|
||||||
|
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||||
|
|
||||||
|
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||||
|
|
||||||
|
## PAN-101537
|
||||||
|
|
||||||
|
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||||
|
|
||||||
|
**Workaround:** Specify the vsys in the query string:
|
||||||
|
|
||||||
|
`admin>` `set system target-vsys <vsys-name>`
|
||||||
|
|
||||||
|
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||||
|
|
||||||
|
## PAN-98520
|
||||||
|
|
||||||
|
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||||
|
|
||||||
|
## PAN-97757
|
||||||
|
|
||||||
|
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||||
|
|
||||||
|
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||||
|
|
||||||
|
## PAN-97524
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama management server only
|
||||||
|
```
|
||||||
|
|
||||||
|
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||||
|
|
||||||
|
## PAN-96985
|
||||||
|
|
||||||
|
The `request shutdown system` command does not shut down the Panorama management server.
|
||||||
|
|
||||||
|
## PAN-96960
|
||||||
|
|
||||||
|
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
|
||||||
|
|
||||||
|
## PAN-96446
|
||||||
|
|
||||||
|
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||||
|
|
||||||
|
## PAN-95773
|
||||||
|
|
||||||
|
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||||
|
|
||||||
|
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||||
|
|
||||||
|
## PAN-95511
|
||||||
|
|
||||||
|
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||||
|
|
||||||
|
## PAN-95028
|
||||||
|
|
||||||
|
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||||
|
|
||||||
|
## PAN-94846
|
||||||
|
|
||||||
|
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||||
|
|
||||||
|
## PAN-94093
|
||||||
|
|
||||||
|
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||||
|
|
||||||
|
## PAN-93968
|
||||||
|
|
||||||
|
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||||
|
|
||||||
|
## PAN-93607
|
||||||
|
|
||||||
|
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||||
|
|
||||||
|
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||||
|
|
||||||
|
## PAN-93532
|
||||||
|
|
||||||
|
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||||
|
|
||||||
|
## PAN-93193
|
||||||
|
|
||||||
|
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||||
|
|
||||||
|
- Switch to the firewall **Context** on the Panorama management server.
|
||||||
|
- Commit changes when a dynamic update is being installed.
|
||||||
|
- Generate a custom report when a dynamic update is being installed.
|
||||||
|
- Generate custom reports during a commit.
|
||||||
|
|
||||||
|
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||||
|
|
||||||
|
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||||
|
|
||||||
|
## PAN-91802
|
||||||
|
|
||||||
|
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||||
|
|
||||||
|
## PAN-83610
|
||||||
|
|
||||||
|
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||||
|
|
||||||
|
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-83236
|
||||||
|
|
||||||
|
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||||
|
|
||||||
|
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||||
|
|
||||||
|
## PAN-83215
|
||||||
|
|
||||||
|
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||||
|
|
||||||
|
## PAN-81521
|
||||||
|
|
||||||
|
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||||
|
|
||||||
|
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||||
|
|
||||||
|
## PAN-77125
|
||||||
|
|
||||||
|
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||||
|
|
||||||
|
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-75457
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||||
|
|
||||||
|
## PAN-73530
|
||||||
|
|
||||||
|
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||||
|
|
||||||
|
## PAN-73401
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||||
|
|
||||||
|
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||||
|
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||||
|
|
||||||
|
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||||
|
|
||||||
|
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||||
|
- Configure a worker list on the cluster controller:
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||||
|
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||||
|
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||||
|
or
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||||
|
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||||
|
|
||||||
|
## PAN-71329
|
||||||
|
|
||||||
|
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
|
||||||
|
|
||||||
|
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
|
||||||
|
|
||||||
|
## PAN-70906
|
||||||
|
|
||||||
|
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||||
|
|
||||||
|
## PAN-69505
|
||||||
|
|
||||||
|
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||||
|
|
||||||
|
## PAN-41558
|
||||||
|
|
||||||
|
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||||
|
|
||||||
|
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||||
|
|
||||||
|
## PAN-40079
|
||||||
|
|
||||||
|
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||||
|
|
||||||
|
## PAN-39636
|
||||||
|
|
||||||
|
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||||
|
|
||||||
|
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||||
|
|
||||||
|
## PAN-38255
|
||||||
|
|
||||||
|
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||||
|
|
||||||
|
## PAN-31832
|
||||||
|
|
||||||
|
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||||
|
|
||||||
|
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||||
|
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||||
@@ -0,0 +1,529 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.5
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## PLUG-380
|
||||||
|
|
||||||
|
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||||
|
|
||||||
|
## PAN-223365
|
||||||
|
|
||||||
|
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
|
||||||
|
|
||||||
|
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
|
||||||
|
|
||||||
|
`admin``request restart system`
|
||||||
|
|
||||||
|
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
|
||||||
|
|
||||||
|
## PAN-199557
|
||||||
|
|
||||||
|
On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Manually reboot the `Active` Panorama HA peer.
|
||||||
|
|
||||||
|
## PAN-197341
|
||||||
|
|
||||||
|
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
|
||||||
|
|
||||||
|
For example:
|
||||||
|
|
||||||
|
1. You create a parent device group `DG-A` and a child device group `DG-B`.
|
||||||
|
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
|
||||||
|
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
|
||||||
|
|
||||||
|
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
|
||||||
|
|
||||||
|
## PAN-178194
|
||||||
|
|
||||||
|
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
|
||||||
|
|
||||||
|
## PAN-154266
|
||||||
|
|
||||||
|
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
|
||||||
|
|
||||||
|
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
|
||||||
|
|
||||||
|
## PAN-154247
|
||||||
|
|
||||||
|
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
|
||||||
|
|
||||||
|
**Workaround:** Log out and back in to the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-153803
|
||||||
|
|
||||||
|
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
|
||||||
|
|
||||||
|
## PAN-151909
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.10 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
On the Panorama management server, Preview Changes (**Commit** > **Commit to Panorama**) incorrectly displays an existing route as Added and the new route as an existing route in the Candidate Configuration when you configure a new virtual router route (**Network** > **Virtual Router**).
|
||||||
|
|
||||||
|
## PAN-148359
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.8 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
SD-WAN server-to-client symmetric return does not function correctly under certain circumstances, and the issue can also affect path selection of parent/child applications, such as FTP.
|
||||||
|
|
||||||
|
## PAN-146573
|
||||||
|
|
||||||
|
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||||
|
|
||||||
|
## PAN-146485
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
|
||||||
|
|
||||||
|
## PAN-144889
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 9.1.2-h1 and later releases only
|
||||||
|
```
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
|
||||||
|
|
||||||
|
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
|
||||||
|
|
||||||
|
## PAN-140959
|
||||||
|
|
||||||
|
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
|
||||||
|
|
||||||
|
## PAN-136701
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000b Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Packets for new sessions drop when handling predict sessions.
|
||||||
|
|
||||||
|
**Workaround:** Use the following CLi commands to bypass this issue:
|
||||||
|
|
||||||
|
- `set session hwpredict disable yes`
|
||||||
|
- `show session hwpredict status`
|
||||||
|
|
||||||
|
## PAN-134456
|
||||||
|
|
||||||
|
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
|
||||||
|
|
||||||
|
**Workaround:** Use a destination-based service route for the SNMP trap server.
|
||||||
|
|
||||||
|
## PAN-134053
|
||||||
|
|
||||||
|
ACC does not filter WildFire logs from Dynamic User Groups.
|
||||||
|
|
||||||
|
## PAN-130550
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
|
||||||
|
|
||||||
|
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
|
||||||
|
|
||||||
|
## PAN-127813
|
||||||
|
|
||||||
|
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches don’t communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
|
||||||
|
|
||||||
|
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
|
||||||
|
|
||||||
|
## PAN-127550
|
||||||
|
|
||||||
|
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
|
||||||
|
|
||||||
|
## PAN-127474
|
||||||
|
|
||||||
|
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
|
||||||
|
|
||||||
|
## PAN-127206
|
||||||
|
|
||||||
|
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
|
||||||
|
|
||||||
|
## PAN-124956
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.11 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an issue where VM-Series firewalls do not support packet buffer protection.
|
||||||
|
|
||||||
|
## PAN-123277
|
||||||
|
|
||||||
|
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-123040
|
||||||
|
|
||||||
|
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules don’t display. A workaround exists for this issue. Please contact Support for information about the workaround.
|
||||||
|
|
||||||
|
## PAN-121484
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.6 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
The dataplane sends positive acknowledgments to predict-status checks from FPP when the corresponding predict is deleted, which causes SIP and RTSP applications to perform less than the expected achievable performance.
|
||||||
|
|
||||||
|
## PAN-120440
|
||||||
|
|
||||||
|
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||||
|
|
||||||
|
## PAN-120423
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.9 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
PAN-OS 9.1.0 does not support the XML API for GlobalProtect logs.
|
||||||
|
|
||||||
|
## PAN-120303
|
||||||
|
|
||||||
|
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||||
|
|
||||||
|
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||||
|
|
||||||
|
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||||
|
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||||
|
2. **Commit** your changes.
|
||||||
|
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||||
|
4. **Commit** your changes.
|
||||||
|
- Restart the firewall (devsrvr) process.
|
||||||
|
1. Log in to the firewall CLI.
|
||||||
|
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||||
|
|
||||||
|
## PAN-118065
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
M-Series Panorama management servers in Management Only mode
|
||||||
|
```
|
||||||
|
|
||||||
|
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
|
||||||
|
|
||||||
|
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
|
||||||
|
|
||||||
|
## PAN-116017
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Google Cloud Platform (GCP) only
|
||||||
|
```
|
||||||
|
|
||||||
|
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||||
|
|
||||||
|
## PAN-115816
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Microsoft Azure only
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-114495
|
||||||
|
|
||||||
|
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||||
|
|
||||||
|
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||||
|
|
||||||
|
## PAN-112694
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls with multiple virtual systems only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||||
|
|
||||||
|
## PAN-112456
|
||||||
|
|
||||||
|
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
|
||||||
|
|
||||||
|
## PAN-111928
|
||||||
|
|
||||||
|
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||||
|
|
||||||
|
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||||
|
|
||||||
|
## PAN-111866
|
||||||
|
|
||||||
|
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||||
|
|
||||||
|
**Workaround:** Perform one of the following tasks.
|
||||||
|
|
||||||
|
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||||
|
- Manually select the devices that belong to the modified device group and template configurations.
|
||||||
|
|
||||||
|
## PAN-111729
|
||||||
|
|
||||||
|
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-111670
|
||||||
|
|
||||||
|
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||||
|
|
||||||
|
## PAN-111251
|
||||||
|
|
||||||
|
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
|
||||||
|
|
||||||
|
## PAN-110794
|
||||||
|
|
||||||
|
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||||
|
|
||||||
|
## PAN-109759
|
||||||
|
|
||||||
|
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
|
||||||
|
|
||||||
|
## PAN-109526
|
||||||
|
|
||||||
|
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||||
|
|
||||||
|
## PAN-106675
|
||||||
|
|
||||||
|
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||||
|
|
||||||
|
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||||
|
|
||||||
|
## PAN-104780
|
||||||
|
|
||||||
|
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||||
|
|
||||||
|
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||||
|
|
||||||
|
## PAN-103276
|
||||||
|
|
||||||
|
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||||
|
|
||||||
|
## PAN-101688
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama plugins
|
||||||
|
```
|
||||||
|
|
||||||
|
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||||
|
|
||||||
|
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||||
|
|
||||||
|
## PAN-101537
|
||||||
|
|
||||||
|
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||||
|
|
||||||
|
**Workaround:** Specify the vsys in the query string:
|
||||||
|
|
||||||
|
`admin>` `set system target-vsys <vsys-name>`
|
||||||
|
|
||||||
|
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||||
|
|
||||||
|
## PAN-98520
|
||||||
|
|
||||||
|
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||||
|
|
||||||
|
## PAN-97757
|
||||||
|
|
||||||
|
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||||
|
|
||||||
|
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||||
|
|
||||||
|
## PAN-97524
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama management server only
|
||||||
|
```
|
||||||
|
|
||||||
|
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||||
|
|
||||||
|
## PAN-96985
|
||||||
|
|
||||||
|
The `request shutdown system` command does not shut down the Panorama management server.
|
||||||
|
|
||||||
|
## PAN-96960
|
||||||
|
|
||||||
|
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
|
||||||
|
|
||||||
|
## PAN-96446
|
||||||
|
|
||||||
|
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||||
|
|
||||||
|
## PAN-95773
|
||||||
|
|
||||||
|
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||||
|
|
||||||
|
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||||
|
|
||||||
|
## PAN-95511
|
||||||
|
|
||||||
|
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||||
|
|
||||||
|
## PAN-95028
|
||||||
|
|
||||||
|
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||||
|
|
||||||
|
## PAN-94846
|
||||||
|
|
||||||
|
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||||
|
|
||||||
|
## PAN-94093
|
||||||
|
|
||||||
|
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||||
|
|
||||||
|
## PAN-93968
|
||||||
|
|
||||||
|
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||||
|
|
||||||
|
## PAN-93607
|
||||||
|
|
||||||
|
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||||
|
|
||||||
|
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||||
|
|
||||||
|
## PAN-93532
|
||||||
|
|
||||||
|
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||||
|
|
||||||
|
## PAN-93193
|
||||||
|
|
||||||
|
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||||
|
|
||||||
|
- Switch to the firewall **Context** on the Panorama management server.
|
||||||
|
- Commit changes when a dynamic update is being installed.
|
||||||
|
- Generate a custom report when a dynamic update is being installed.
|
||||||
|
- Generate custom reports during a commit.
|
||||||
|
|
||||||
|
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||||
|
|
||||||
|
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||||
|
|
||||||
|
## PAN-91802
|
||||||
|
|
||||||
|
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||||
|
|
||||||
|
## PAN-83610
|
||||||
|
|
||||||
|
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||||
|
|
||||||
|
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-83236
|
||||||
|
|
||||||
|
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||||
|
|
||||||
|
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||||
|
|
||||||
|
## PAN-83215
|
||||||
|
|
||||||
|
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||||
|
|
||||||
|
## PAN-81521
|
||||||
|
|
||||||
|
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||||
|
|
||||||
|
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||||
|
|
||||||
|
## PAN-77125
|
||||||
|
|
||||||
|
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||||
|
|
||||||
|
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-75457
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||||
|
|
||||||
|
## PAN-73530
|
||||||
|
|
||||||
|
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||||
|
|
||||||
|
## PAN-73401
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||||
|
|
||||||
|
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||||
|
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||||
|
|
||||||
|
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||||
|
|
||||||
|
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||||
|
- Configure a worker list on the cluster controller:
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||||
|
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||||
|
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||||
|
or
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||||
|
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||||
|
|
||||||
|
## PAN-71329
|
||||||
|
|
||||||
|
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
|
||||||
|
|
||||||
|
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
|
||||||
|
|
||||||
|
## PAN-70906
|
||||||
|
|
||||||
|
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||||
|
|
||||||
|
## PAN-69505
|
||||||
|
|
||||||
|
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||||
|
|
||||||
|
## PAN-41558
|
||||||
|
|
||||||
|
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||||
|
|
||||||
|
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||||
|
|
||||||
|
## PAN-40079
|
||||||
|
|
||||||
|
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||||
|
|
||||||
|
## PAN-39636
|
||||||
|
|
||||||
|
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||||
|
|
||||||
|
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||||
|
|
||||||
|
## PAN-38255
|
||||||
|
|
||||||
|
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||||
|
|
||||||
|
## PAN-31832
|
||||||
|
|
||||||
|
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||||
|
|
||||||
|
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||||
|
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||||
@@ -0,0 +1,537 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.6
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## PLUG-380
|
||||||
|
|
||||||
|
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||||
|
|
||||||
|
## PAN-223365
|
||||||
|
|
||||||
|
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
|
||||||
|
|
||||||
|
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
|
||||||
|
|
||||||
|
`admin``request restart system`
|
||||||
|
|
||||||
|
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
|
||||||
|
|
||||||
|
## PAN-199557
|
||||||
|
|
||||||
|
On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Manually reboot the `Active` Panorama HA peer.
|
||||||
|
|
||||||
|
## PAN-197341
|
||||||
|
|
||||||
|
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
|
||||||
|
|
||||||
|
For example:
|
||||||
|
|
||||||
|
1. You create a parent device group `DG-A` and a child device group `DG-B`.
|
||||||
|
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
|
||||||
|
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
|
||||||
|
|
||||||
|
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
|
||||||
|
|
||||||
|
## PAN-178194
|
||||||
|
|
||||||
|
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
|
||||||
|
|
||||||
|
## PAN-162748
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.9 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
GlobalProtect clients in systems with umlaut diacritics in the serial number are unable to log in to the GlobalProtect gateway.
|
||||||
|
|
||||||
|
## PAN-160633
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
The dataplane restarts repeatedly due to internal path monitoring failures until a power cycle.
|
||||||
|
|
||||||
|
## PAN-154266
|
||||||
|
|
||||||
|
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
|
||||||
|
|
||||||
|
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
|
||||||
|
|
||||||
|
## PAN-154247
|
||||||
|
|
||||||
|
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
|
||||||
|
|
||||||
|
**Workaround:** Log out and back in to the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-153803
|
||||||
|
|
||||||
|
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
|
||||||
|
|
||||||
|
## PAN-151909
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.10 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
On the Panorama management server, Preview Changes (**Commit** > **Commit to Panorama**) incorrectly displays an existing route as Added and the new route as an existing route in the Candidate Configuration when you configure a new virtual router route (**Network** > **Virtual Router**).
|
||||||
|
|
||||||
|
## PAN-148359
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.8 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
SD-WAN server-to-client symmetric return does not function correctly under certain circumstances, and the issue can also affect path selection of parent/child applications, such as FTP.
|
||||||
|
|
||||||
|
## PAN-146573
|
||||||
|
|
||||||
|
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||||
|
|
||||||
|
## PAN-146485
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
|
||||||
|
|
||||||
|
## PAN-144889
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 9.1.2-h1 and later releases only
|
||||||
|
```
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
|
||||||
|
|
||||||
|
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
|
||||||
|
|
||||||
|
## PAN-140959
|
||||||
|
|
||||||
|
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
|
||||||
|
|
||||||
|
## PAN-136701
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000b Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Packets for new sessions drop when handling predict sessions.
|
||||||
|
|
||||||
|
**Workaround:** Use the following CLi commands to bypass this issue:
|
||||||
|
|
||||||
|
- `set session hwpredict disable yes`
|
||||||
|
- `show session hwpredict status`
|
||||||
|
|
||||||
|
## PAN-134456
|
||||||
|
|
||||||
|
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
|
||||||
|
|
||||||
|
**Workaround:** Use a destination-based service route for the SNMP trap server.
|
||||||
|
|
||||||
|
## PAN-134053
|
||||||
|
|
||||||
|
ACC does not filter WildFire logs from Dynamic User Groups.
|
||||||
|
|
||||||
|
## PAN-130550
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
|
||||||
|
|
||||||
|
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
|
||||||
|
|
||||||
|
## PAN-127813
|
||||||
|
|
||||||
|
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches don’t communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
|
||||||
|
|
||||||
|
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
|
||||||
|
|
||||||
|
## PAN-127550
|
||||||
|
|
||||||
|
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
|
||||||
|
|
||||||
|
## PAN-127474
|
||||||
|
|
||||||
|
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
|
||||||
|
|
||||||
|
## PAN-127206
|
||||||
|
|
||||||
|
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
|
||||||
|
|
||||||
|
## PAN-124956
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.11 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an issue where VM-Series firewalls do not support packet buffer protection.
|
||||||
|
|
||||||
|
## PAN-123277
|
||||||
|
|
||||||
|
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-123040
|
||||||
|
|
||||||
|
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules don’t display. A workaround exists for this issue. Please contact Support for information about the workaround.
|
||||||
|
|
||||||
|
## PAN-120440
|
||||||
|
|
||||||
|
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||||
|
|
||||||
|
## PAN-120423
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.9 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
PAN-OS 9.1.0 does not support the XML API for GlobalProtect logs.
|
||||||
|
|
||||||
|
## PAN-120303
|
||||||
|
|
||||||
|
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||||
|
|
||||||
|
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||||
|
|
||||||
|
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||||
|
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||||
|
2. **Commit** your changes.
|
||||||
|
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||||
|
4. **Commit** your changes.
|
||||||
|
- Restart the firewall (devsrvr) process.
|
||||||
|
1. Log in to the firewall CLI.
|
||||||
|
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||||
|
|
||||||
|
## PAN-118065
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
M-Series Panorama management servers in Management Only mode
|
||||||
|
```
|
||||||
|
|
||||||
|
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
|
||||||
|
|
||||||
|
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
|
||||||
|
|
||||||
|
## PAN-116017
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Google Cloud Platform (GCP) only
|
||||||
|
```
|
||||||
|
|
||||||
|
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||||
|
|
||||||
|
## PAN-115816
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Microsoft Azure only
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-114495
|
||||||
|
|
||||||
|
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||||
|
|
||||||
|
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||||
|
|
||||||
|
## PAN-112694
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls with multiple virtual systems only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||||
|
|
||||||
|
## PAN-112456
|
||||||
|
|
||||||
|
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
|
||||||
|
|
||||||
|
## PAN-111928
|
||||||
|
|
||||||
|
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||||
|
|
||||||
|
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||||
|
|
||||||
|
## PAN-111866
|
||||||
|
|
||||||
|
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||||
|
|
||||||
|
**Workaround:** Perform one of the following tasks.
|
||||||
|
|
||||||
|
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||||
|
- Manually select the devices that belong to the modified device group and template configurations.
|
||||||
|
|
||||||
|
## PAN-111729
|
||||||
|
|
||||||
|
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-111670
|
||||||
|
|
||||||
|
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||||
|
|
||||||
|
## PAN-111251
|
||||||
|
|
||||||
|
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
|
||||||
|
|
||||||
|
## PAN-110794
|
||||||
|
|
||||||
|
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||||
|
|
||||||
|
## PAN-109759
|
||||||
|
|
||||||
|
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
|
||||||
|
|
||||||
|
## PAN-109526
|
||||||
|
|
||||||
|
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||||
|
|
||||||
|
## PAN-106675
|
||||||
|
|
||||||
|
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||||
|
|
||||||
|
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||||
|
|
||||||
|
## PAN-104780
|
||||||
|
|
||||||
|
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||||
|
|
||||||
|
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||||
|
|
||||||
|
## PAN-103276
|
||||||
|
|
||||||
|
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||||
|
|
||||||
|
## PAN-101688
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama plugins
|
||||||
|
```
|
||||||
|
|
||||||
|
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||||
|
|
||||||
|
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||||
|
|
||||||
|
## PAN-101537
|
||||||
|
|
||||||
|
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||||
|
|
||||||
|
**Workaround:** Specify the vsys in the query string:
|
||||||
|
|
||||||
|
`admin>` `set system target-vsys <vsys-name>`
|
||||||
|
|
||||||
|
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||||
|
|
||||||
|
## PAN-98520
|
||||||
|
|
||||||
|
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||||
|
|
||||||
|
## PAN-97757
|
||||||
|
|
||||||
|
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||||
|
|
||||||
|
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||||
|
|
||||||
|
## PAN-97524
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama management server only
|
||||||
|
```
|
||||||
|
|
||||||
|
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||||
|
|
||||||
|
## PAN-96985
|
||||||
|
|
||||||
|
The `request shutdown system` command does not shut down the Panorama management server.
|
||||||
|
|
||||||
|
## PAN-96960
|
||||||
|
|
||||||
|
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
|
||||||
|
|
||||||
|
## PAN-96446
|
||||||
|
|
||||||
|
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||||
|
|
||||||
|
## PAN-95773
|
||||||
|
|
||||||
|
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||||
|
|
||||||
|
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||||
|
|
||||||
|
## PAN-95511
|
||||||
|
|
||||||
|
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||||
|
|
||||||
|
## PAN-95028
|
||||||
|
|
||||||
|
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||||
|
|
||||||
|
## PAN-94846
|
||||||
|
|
||||||
|
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||||
|
|
||||||
|
## PAN-94093
|
||||||
|
|
||||||
|
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||||
|
|
||||||
|
## PAN-93968
|
||||||
|
|
||||||
|
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||||
|
|
||||||
|
## PAN-93607
|
||||||
|
|
||||||
|
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||||
|
|
||||||
|
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||||
|
|
||||||
|
## PAN-93532
|
||||||
|
|
||||||
|
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||||
|
|
||||||
|
## PAN-93193
|
||||||
|
|
||||||
|
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||||
|
|
||||||
|
- Switch to the firewall **Context** on the Panorama management server.
|
||||||
|
- Commit changes when a dynamic update is being installed.
|
||||||
|
- Generate a custom report when a dynamic update is being installed.
|
||||||
|
- Generate custom reports during a commit.
|
||||||
|
|
||||||
|
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||||
|
|
||||||
|
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||||
|
|
||||||
|
## PAN-91802
|
||||||
|
|
||||||
|
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||||
|
|
||||||
|
## PAN-83610
|
||||||
|
|
||||||
|
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||||
|
|
||||||
|
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-83236
|
||||||
|
|
||||||
|
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||||
|
|
||||||
|
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||||
|
|
||||||
|
## PAN-83215
|
||||||
|
|
||||||
|
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||||
|
|
||||||
|
## PAN-81521
|
||||||
|
|
||||||
|
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||||
|
|
||||||
|
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||||
|
|
||||||
|
## PAN-77125
|
||||||
|
|
||||||
|
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||||
|
|
||||||
|
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-75457
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||||
|
|
||||||
|
## PAN-73530
|
||||||
|
|
||||||
|
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||||
|
|
||||||
|
## PAN-73401
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||||
|
|
||||||
|
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||||
|
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||||
|
|
||||||
|
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||||
|
|
||||||
|
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||||
|
- Configure a worker list on the cluster controller:
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||||
|
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||||
|
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||||
|
or
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||||
|
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||||
|
|
||||||
|
## PAN-71329
|
||||||
|
|
||||||
|
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
|
||||||
|
|
||||||
|
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
|
||||||
|
|
||||||
|
## PAN-70906
|
||||||
|
|
||||||
|
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||||
|
|
||||||
|
## PAN-69505
|
||||||
|
|
||||||
|
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||||
|
|
||||||
|
## PAN-41558
|
||||||
|
|
||||||
|
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||||
|
|
||||||
|
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||||
|
|
||||||
|
## PAN-40079
|
||||||
|
|
||||||
|
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||||
|
|
||||||
|
## PAN-39636
|
||||||
|
|
||||||
|
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||||
|
|
||||||
|
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||||
|
|
||||||
|
## PAN-38255
|
||||||
|
|
||||||
|
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||||
|
|
||||||
|
## PAN-31832
|
||||||
|
|
||||||
|
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||||
|
|
||||||
|
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||||
|
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||||
@@ -0,0 +1,541 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.7
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## PLUG-380
|
||||||
|
|
||||||
|
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||||
|
|
||||||
|
## PAN-223365
|
||||||
|
|
||||||
|
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
|
||||||
|
|
||||||
|
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
|
||||||
|
|
||||||
|
`admin``request restart system`
|
||||||
|
|
||||||
|
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
|
||||||
|
|
||||||
|
## PAN-199557
|
||||||
|
|
||||||
|
On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Manually reboot the `Active` Panorama HA peer.
|
||||||
|
|
||||||
|
## PAN-197341
|
||||||
|
|
||||||
|
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
|
||||||
|
|
||||||
|
For example:
|
||||||
|
|
||||||
|
1. You create a parent device group `DG-A` and a child device group `DG-B`.
|
||||||
|
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
|
||||||
|
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
|
||||||
|
|
||||||
|
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
|
||||||
|
|
||||||
|
## PAN-178194
|
||||||
|
|
||||||
|
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
|
||||||
|
|
||||||
|
## PAN-162748
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.9 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
GlobalProtect clients in systems with umlaut diacritics in the serial number are unable to log in to the GlobalProtect gateway.
|
||||||
|
|
||||||
|
## PAN-161121
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.8 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
On the Panorama management server, invalid reference errors occur when attempting to delete an address object (**Objects** > **Addresses**) after removing the address object reference from an address group (**Objects** > **Address Groups**) resulting in you being unable commit and push the configuration to managed firewalls.
|
||||||
|
|
||||||
|
**Workaround:** Log in to the [Panorama CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli.html) and restart `configd`.
|
||||||
|
|
||||||
|
`admin>``debug software restart process configd`
|
||||||
|
|
||||||
|
## PAN-154266
|
||||||
|
|
||||||
|
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
|
||||||
|
|
||||||
|
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
|
||||||
|
|
||||||
|
## PAN-154247
|
||||||
|
|
||||||
|
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
|
||||||
|
|
||||||
|
**Workaround:** Log out and back in to the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-153803
|
||||||
|
|
||||||
|
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
|
||||||
|
|
||||||
|
## PAN-151909
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.10 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
On the Panorama management server, Preview Changes (**Commit** > **Commit to Panorama**) incorrectly displays an existing route as Added and the new route as an existing route in the Candidate Configuration when you configure a new virtual router route (**Network** > **Virtual Router**).
|
||||||
|
|
||||||
|
## PAN-148359
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.8 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
SD-WAN server-to-client symmetric return does not function correctly under certain circumstances, and the issue can also affect path selection of parent/child applications, such as FTP.
|
||||||
|
|
||||||
|
## PAN-146573
|
||||||
|
|
||||||
|
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||||
|
|
||||||
|
## PAN-146485
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
|
||||||
|
|
||||||
|
## PAN-144889
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 9.1.2-h1 and later releases only
|
||||||
|
```
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
|
||||||
|
|
||||||
|
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
|
||||||
|
|
||||||
|
## PAN-140959
|
||||||
|
|
||||||
|
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
|
||||||
|
|
||||||
|
## PAN-136701
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000b Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Packets for new sessions drop when handling predict sessions.
|
||||||
|
|
||||||
|
**Workaround:** Use the following CLi commands to bypass this issue:
|
||||||
|
|
||||||
|
- `set session hwpredict disable yes`
|
||||||
|
- `show session hwpredict status`
|
||||||
|
|
||||||
|
## PAN-134456
|
||||||
|
|
||||||
|
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
|
||||||
|
|
||||||
|
**Workaround:** Use a destination-based service route for the SNMP trap server.
|
||||||
|
|
||||||
|
## PAN-134053
|
||||||
|
|
||||||
|
ACC does not filter WildFire logs from Dynamic User Groups.
|
||||||
|
|
||||||
|
## PAN-130550
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
|
||||||
|
|
||||||
|
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
|
||||||
|
|
||||||
|
## PAN-127813
|
||||||
|
|
||||||
|
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches don’t communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
|
||||||
|
|
||||||
|
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
|
||||||
|
|
||||||
|
## PAN-127550
|
||||||
|
|
||||||
|
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
|
||||||
|
|
||||||
|
## PAN-127474
|
||||||
|
|
||||||
|
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
|
||||||
|
|
||||||
|
## PAN-127206
|
||||||
|
|
||||||
|
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
|
||||||
|
|
||||||
|
## PAN-124956
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.11 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an issue where VM-Series firewalls do not support packet buffer protection.
|
||||||
|
|
||||||
|
## PAN-123277
|
||||||
|
|
||||||
|
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-123040
|
||||||
|
|
||||||
|
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules don’t display. A workaround exists for this issue. Please contact Support for information about the workaround.
|
||||||
|
|
||||||
|
## PAN-120440
|
||||||
|
|
||||||
|
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||||
|
|
||||||
|
## PAN-120423
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.9 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
PAN-OS 9.1.0 does not support the XML API for GlobalProtect logs.
|
||||||
|
|
||||||
|
## PAN-120303
|
||||||
|
|
||||||
|
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||||
|
|
||||||
|
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||||
|
|
||||||
|
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||||
|
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||||
|
2. **Commit** your changes.
|
||||||
|
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||||
|
4. **Commit** your changes.
|
||||||
|
- Restart the firewall (devsrvr) process.
|
||||||
|
1. Log in to the firewall CLI.
|
||||||
|
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||||
|
|
||||||
|
## PAN-118065
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
M-Series Panorama management servers in Management Only mode
|
||||||
|
```
|
||||||
|
|
||||||
|
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
|
||||||
|
|
||||||
|
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
|
||||||
|
|
||||||
|
## PAN-116017
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Google Cloud Platform (GCP) only
|
||||||
|
```
|
||||||
|
|
||||||
|
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||||
|
|
||||||
|
## PAN-115816
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Microsoft Azure only
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-114495
|
||||||
|
|
||||||
|
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||||
|
|
||||||
|
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||||
|
|
||||||
|
## PAN-112694
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls with multiple virtual systems only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||||
|
|
||||||
|
## PAN-112456
|
||||||
|
|
||||||
|
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
|
||||||
|
|
||||||
|
## PAN-111928
|
||||||
|
|
||||||
|
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||||
|
|
||||||
|
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||||
|
|
||||||
|
## PAN-111866
|
||||||
|
|
||||||
|
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||||
|
|
||||||
|
**Workaround:** Perform one of the following tasks.
|
||||||
|
|
||||||
|
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||||
|
- Manually select the devices that belong to the modified device group and template configurations.
|
||||||
|
|
||||||
|
## PAN-111729
|
||||||
|
|
||||||
|
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-111670
|
||||||
|
|
||||||
|
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||||
|
|
||||||
|
## PAN-111251
|
||||||
|
|
||||||
|
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
|
||||||
|
|
||||||
|
## PAN-110794
|
||||||
|
|
||||||
|
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||||
|
|
||||||
|
## PAN-109759
|
||||||
|
|
||||||
|
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
|
||||||
|
|
||||||
|
## PAN-109526
|
||||||
|
|
||||||
|
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||||
|
|
||||||
|
## PAN-106675
|
||||||
|
|
||||||
|
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||||
|
|
||||||
|
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||||
|
|
||||||
|
## PAN-104780
|
||||||
|
|
||||||
|
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||||
|
|
||||||
|
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||||
|
|
||||||
|
## PAN-103276
|
||||||
|
|
||||||
|
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||||
|
|
||||||
|
## PAN-101688
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama plugins
|
||||||
|
```
|
||||||
|
|
||||||
|
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||||
|
|
||||||
|
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||||
|
|
||||||
|
## PAN-101537
|
||||||
|
|
||||||
|
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||||
|
|
||||||
|
**Workaround:** Specify the vsys in the query string:
|
||||||
|
|
||||||
|
`admin>` `set system target-vsys <vsys-name>`
|
||||||
|
|
||||||
|
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||||
|
|
||||||
|
## PAN-98520
|
||||||
|
|
||||||
|
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||||
|
|
||||||
|
## PAN-97757
|
||||||
|
|
||||||
|
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||||
|
|
||||||
|
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||||
|
|
||||||
|
## PAN-97524
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama management server only
|
||||||
|
```
|
||||||
|
|
||||||
|
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||||
|
|
||||||
|
## PAN-96985
|
||||||
|
|
||||||
|
The `request shutdown system` command does not shut down the Panorama management server.
|
||||||
|
|
||||||
|
## PAN-96960
|
||||||
|
|
||||||
|
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
|
||||||
|
|
||||||
|
## PAN-96446
|
||||||
|
|
||||||
|
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||||
|
|
||||||
|
## PAN-95773
|
||||||
|
|
||||||
|
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||||
|
|
||||||
|
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||||
|
|
||||||
|
## PAN-95511
|
||||||
|
|
||||||
|
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||||
|
|
||||||
|
## PAN-95028
|
||||||
|
|
||||||
|
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||||
|
|
||||||
|
## PAN-94846
|
||||||
|
|
||||||
|
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||||
|
|
||||||
|
## PAN-94093
|
||||||
|
|
||||||
|
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||||
|
|
||||||
|
## PAN-93968
|
||||||
|
|
||||||
|
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||||
|
|
||||||
|
## PAN-93607
|
||||||
|
|
||||||
|
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||||
|
|
||||||
|
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||||
|
|
||||||
|
## PAN-93532
|
||||||
|
|
||||||
|
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||||
|
|
||||||
|
## PAN-93193
|
||||||
|
|
||||||
|
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||||
|
|
||||||
|
- Switch to the firewall **Context** on the Panorama management server.
|
||||||
|
- Commit changes when a dynamic update is being installed.
|
||||||
|
- Generate a custom report when a dynamic update is being installed.
|
||||||
|
- Generate custom reports during a commit.
|
||||||
|
|
||||||
|
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||||
|
|
||||||
|
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||||
|
|
||||||
|
## PAN-91802
|
||||||
|
|
||||||
|
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||||
|
|
||||||
|
## PAN-83610
|
||||||
|
|
||||||
|
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||||
|
|
||||||
|
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-83236
|
||||||
|
|
||||||
|
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||||
|
|
||||||
|
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||||
|
|
||||||
|
## PAN-83215
|
||||||
|
|
||||||
|
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||||
|
|
||||||
|
## PAN-81521
|
||||||
|
|
||||||
|
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||||
|
|
||||||
|
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||||
|
|
||||||
|
## PAN-77125
|
||||||
|
|
||||||
|
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||||
|
|
||||||
|
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-75457
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||||
|
|
||||||
|
## PAN-73530
|
||||||
|
|
||||||
|
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||||
|
|
||||||
|
## PAN-73401
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||||
|
|
||||||
|
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||||
|
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||||
|
|
||||||
|
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||||
|
|
||||||
|
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||||
|
- Configure a worker list on the cluster controller:
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||||
|
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||||
|
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||||
|
or
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||||
|
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||||
|
|
||||||
|
## PAN-71329
|
||||||
|
|
||||||
|
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
|
||||||
|
|
||||||
|
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
|
||||||
|
|
||||||
|
## PAN-70906
|
||||||
|
|
||||||
|
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||||
|
|
||||||
|
## PAN-69505
|
||||||
|
|
||||||
|
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||||
|
|
||||||
|
## PAN-41558
|
||||||
|
|
||||||
|
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||||
|
|
||||||
|
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||||
|
|
||||||
|
## PAN-40079
|
||||||
|
|
||||||
|
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||||
|
|
||||||
|
## PAN-39636
|
||||||
|
|
||||||
|
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||||
|
|
||||||
|
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||||
|
|
||||||
|
## PAN-38255
|
||||||
|
|
||||||
|
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||||
|
|
||||||
|
## PAN-31832
|
||||||
|
|
||||||
|
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||||
|
|
||||||
|
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||||
|
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||||
@@ -0,0 +1,521 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.8
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## PLUG-380
|
||||||
|
|
||||||
|
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||||
|
|
||||||
|
## PAN-223365
|
||||||
|
|
||||||
|
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
|
||||||
|
|
||||||
|
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
|
||||||
|
|
||||||
|
`admin``request restart system`
|
||||||
|
|
||||||
|
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
|
||||||
|
|
||||||
|
## PAN-199557
|
||||||
|
|
||||||
|
On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Manually reboot the `Active` Panorama HA peer.
|
||||||
|
|
||||||
|
## PAN-197341
|
||||||
|
|
||||||
|
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
|
||||||
|
|
||||||
|
For example:
|
||||||
|
|
||||||
|
1. You create a parent device group `DG-A` and a child device group `DG-B`.
|
||||||
|
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
|
||||||
|
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
|
||||||
|
|
||||||
|
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
|
||||||
|
|
||||||
|
## PAN-178194
|
||||||
|
|
||||||
|
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
|
||||||
|
|
||||||
|
## PAN-162748
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.9 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
GlobalProtect clients in systems with umlaut diacritics in the serial number are unable to log in to the GlobalProtect gateway.
|
||||||
|
|
||||||
|
## PAN-154266
|
||||||
|
|
||||||
|
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
|
||||||
|
|
||||||
|
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
|
||||||
|
|
||||||
|
## PAN-154247
|
||||||
|
|
||||||
|
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
|
||||||
|
|
||||||
|
**Workaround:** Log out and back in to the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-153803
|
||||||
|
|
||||||
|
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
|
||||||
|
|
||||||
|
## PAN-151909
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.10 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
On the Panorama management server, Preview Changes (**Commit** > **Commit to Panorama**) incorrectly displays an existing route as Added and the new route as an existing route in the Candidate Configuration when you configure a new virtual router route (**Network** > **Virtual Router**).
|
||||||
|
|
||||||
|
## PAN-146573
|
||||||
|
|
||||||
|
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||||
|
|
||||||
|
## PAN-146485
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
|
||||||
|
|
||||||
|
## PAN-144889
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 9.1.2-h1 and later releases only
|
||||||
|
```
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
|
||||||
|
|
||||||
|
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
|
||||||
|
|
||||||
|
## PAN-140959
|
||||||
|
|
||||||
|
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
|
||||||
|
|
||||||
|
## PAN-136701
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000b Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Packets for new sessions drop when handling predict sessions.
|
||||||
|
|
||||||
|
**Workaround:** Use the following CLi commands to bypass this issue:
|
||||||
|
|
||||||
|
- `set session hwpredict disable yes`
|
||||||
|
- `show session hwpredict status`
|
||||||
|
|
||||||
|
## PAN-134456
|
||||||
|
|
||||||
|
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
|
||||||
|
|
||||||
|
**Workaround:** Use a destination-based service route for the SNMP trap server.
|
||||||
|
|
||||||
|
## PAN-134053
|
||||||
|
|
||||||
|
ACC does not filter WildFire logs from Dynamic User Groups.
|
||||||
|
|
||||||
|
## PAN-130550
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
|
||||||
|
|
||||||
|
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
|
||||||
|
|
||||||
|
## PAN-127813
|
||||||
|
|
||||||
|
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches don’t communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
|
||||||
|
|
||||||
|
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
|
||||||
|
|
||||||
|
## PAN-127550
|
||||||
|
|
||||||
|
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
|
||||||
|
|
||||||
|
## PAN-127474
|
||||||
|
|
||||||
|
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
|
||||||
|
|
||||||
|
## PAN-127206
|
||||||
|
|
||||||
|
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
|
||||||
|
|
||||||
|
## PAN-124956
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.11 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an issue where VM-Series firewalls do not support packet buffer protection.
|
||||||
|
|
||||||
|
## PAN-123277
|
||||||
|
|
||||||
|
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-123040
|
||||||
|
|
||||||
|
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules don’t display. A workaround exists for this issue. Please contact Support for information about the workaround.
|
||||||
|
|
||||||
|
## PAN-120440
|
||||||
|
|
||||||
|
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||||
|
|
||||||
|
## PAN-120423
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.9 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
PAN-OS 9.1.0 does not support the XML API for GlobalProtect logs.
|
||||||
|
|
||||||
|
## PAN-120303
|
||||||
|
|
||||||
|
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||||
|
|
||||||
|
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||||
|
|
||||||
|
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||||
|
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||||
|
2. **Commit** your changes.
|
||||||
|
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||||
|
4. **Commit** your changes.
|
||||||
|
- Restart the firewall (devsrvr) process.
|
||||||
|
1. Log in to the firewall CLI.
|
||||||
|
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||||
|
|
||||||
|
## PAN-118065
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
M-Series Panorama management servers in Management Only mode
|
||||||
|
```
|
||||||
|
|
||||||
|
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
|
||||||
|
|
||||||
|
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
|
||||||
|
|
||||||
|
## PAN-116017
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Google Cloud Platform (GCP) only
|
||||||
|
```
|
||||||
|
|
||||||
|
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||||
|
|
||||||
|
## PAN-115816
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Microsoft Azure only
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-114495
|
||||||
|
|
||||||
|
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||||
|
|
||||||
|
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||||
|
|
||||||
|
## PAN-112694
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls with multiple virtual systems only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||||
|
|
||||||
|
## PAN-112456
|
||||||
|
|
||||||
|
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
|
||||||
|
|
||||||
|
## PAN-111928
|
||||||
|
|
||||||
|
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||||
|
|
||||||
|
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||||
|
|
||||||
|
## PAN-111866
|
||||||
|
|
||||||
|
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||||
|
|
||||||
|
**Workaround:** Perform one of the following tasks.
|
||||||
|
|
||||||
|
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||||
|
- Manually select the devices that belong to the modified device group and template configurations.
|
||||||
|
|
||||||
|
## PAN-111729
|
||||||
|
|
||||||
|
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-111670
|
||||||
|
|
||||||
|
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||||
|
|
||||||
|
## PAN-111251
|
||||||
|
|
||||||
|
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
|
||||||
|
|
||||||
|
## PAN-110794
|
||||||
|
|
||||||
|
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||||
|
|
||||||
|
## PAN-109759
|
||||||
|
|
||||||
|
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
|
||||||
|
|
||||||
|
## PAN-109526
|
||||||
|
|
||||||
|
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||||
|
|
||||||
|
## PAN-106675
|
||||||
|
|
||||||
|
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||||
|
|
||||||
|
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||||
|
|
||||||
|
## PAN-104780
|
||||||
|
|
||||||
|
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||||
|
|
||||||
|
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||||
|
|
||||||
|
## PAN-103276
|
||||||
|
|
||||||
|
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||||
|
|
||||||
|
## PAN-101688
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama plugins
|
||||||
|
```
|
||||||
|
|
||||||
|
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||||
|
|
||||||
|
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||||
|
|
||||||
|
## PAN-101537
|
||||||
|
|
||||||
|
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||||
|
|
||||||
|
**Workaround:** Specify the vsys in the query string:
|
||||||
|
|
||||||
|
`admin>` `set system target-vsys <vsys-name>`
|
||||||
|
|
||||||
|
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||||
|
|
||||||
|
## PAN-98520
|
||||||
|
|
||||||
|
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||||
|
|
||||||
|
## PAN-97757
|
||||||
|
|
||||||
|
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||||
|
|
||||||
|
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||||
|
|
||||||
|
## PAN-97524
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama management server only
|
||||||
|
```
|
||||||
|
|
||||||
|
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||||
|
|
||||||
|
## PAN-96985
|
||||||
|
|
||||||
|
The `request shutdown system` command does not shut down the Panorama management server.
|
||||||
|
|
||||||
|
## PAN-96960
|
||||||
|
|
||||||
|
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
|
||||||
|
|
||||||
|
## PAN-96446
|
||||||
|
|
||||||
|
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||||
|
|
||||||
|
## PAN-95773
|
||||||
|
|
||||||
|
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||||
|
|
||||||
|
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||||
|
|
||||||
|
## PAN-95511
|
||||||
|
|
||||||
|
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||||
|
|
||||||
|
## PAN-95028
|
||||||
|
|
||||||
|
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||||
|
|
||||||
|
## PAN-94846
|
||||||
|
|
||||||
|
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||||
|
|
||||||
|
## PAN-94093
|
||||||
|
|
||||||
|
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||||
|
|
||||||
|
## PAN-93968
|
||||||
|
|
||||||
|
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||||
|
|
||||||
|
## PAN-93607
|
||||||
|
|
||||||
|
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||||
|
|
||||||
|
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||||
|
|
||||||
|
## PAN-93532
|
||||||
|
|
||||||
|
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||||
|
|
||||||
|
## PAN-93193
|
||||||
|
|
||||||
|
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||||
|
|
||||||
|
- Switch to the firewall **Context** on the Panorama management server.
|
||||||
|
- Commit changes when a dynamic update is being installed.
|
||||||
|
- Generate a custom report when a dynamic update is being installed.
|
||||||
|
- Generate custom reports during a commit.
|
||||||
|
|
||||||
|
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||||
|
|
||||||
|
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||||
|
|
||||||
|
## PAN-91802
|
||||||
|
|
||||||
|
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||||
|
|
||||||
|
## PAN-83610
|
||||||
|
|
||||||
|
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||||
|
|
||||||
|
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-83236
|
||||||
|
|
||||||
|
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||||
|
|
||||||
|
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||||
|
|
||||||
|
## PAN-83215
|
||||||
|
|
||||||
|
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||||
|
|
||||||
|
## PAN-81521
|
||||||
|
|
||||||
|
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||||
|
|
||||||
|
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||||
|
|
||||||
|
## PAN-77125
|
||||||
|
|
||||||
|
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||||
|
|
||||||
|
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-75457
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||||
|
|
||||||
|
## PAN-73530
|
||||||
|
|
||||||
|
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||||
|
|
||||||
|
## PAN-73401
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||||
|
|
||||||
|
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||||
|
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||||
|
|
||||||
|
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||||
|
|
||||||
|
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||||
|
- Configure a worker list on the cluster controller:
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||||
|
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||||
|
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||||
|
or
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||||
|
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||||
|
|
||||||
|
## PAN-71329
|
||||||
|
|
||||||
|
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
|
||||||
|
|
||||||
|
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
|
||||||
|
|
||||||
|
## PAN-70906
|
||||||
|
|
||||||
|
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||||
|
|
||||||
|
## PAN-69505
|
||||||
|
|
||||||
|
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||||
|
|
||||||
|
## PAN-41558
|
||||||
|
|
||||||
|
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||||
|
|
||||||
|
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||||
|
|
||||||
|
## PAN-40079
|
||||||
|
|
||||||
|
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||||
|
|
||||||
|
## PAN-39636
|
||||||
|
|
||||||
|
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||||
|
|
||||||
|
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||||
|
|
||||||
|
## PAN-38255
|
||||||
|
|
||||||
|
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||||
|
|
||||||
|
## PAN-31832
|
||||||
|
|
||||||
|
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||||
|
|
||||||
|
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||||
|
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||||
@@ -0,0 +1,513 @@
|
|||||||
|
---
|
||||||
|
type: Known
|
||||||
|
product: PAN-OS
|
||||||
|
version: 9.1.9
|
||||||
|
source: common-crawl
|
||||||
|
crawl: CC-MAIN-2026-12
|
||||||
|
---
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
|
||||||
|
|
||||||
|
## BLANK-000000
|
||||||
|
|
||||||
|
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
|
||||||
|
|
||||||
|
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
|
||||||
|
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
|
||||||
|
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
|
||||||
|
|
||||||
|
## PLUG-380
|
||||||
|
|
||||||
|
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
|
||||||
|
|
||||||
|
## PAN-223365
|
||||||
|
|
||||||
|
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
|
||||||
|
|
||||||
|
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
|
||||||
|
|
||||||
|
`admin``request restart system`
|
||||||
|
|
||||||
|
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
|
||||||
|
|
||||||
|
## PAN-199557
|
||||||
|
|
||||||
|
On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Manually reboot the `Active` Panorama HA peer.
|
||||||
|
|
||||||
|
## PAN-197341
|
||||||
|
|
||||||
|
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
|
||||||
|
|
||||||
|
For example:
|
||||||
|
|
||||||
|
1. You create a parent device group `DG-A` and a child device group `DG-B`.
|
||||||
|
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
|
||||||
|
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
|
||||||
|
|
||||||
|
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
|
||||||
|
|
||||||
|
## PAN-178194
|
||||||
|
|
||||||
|
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
|
||||||
|
|
||||||
|
## PAN-162748
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.9 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
GlobalProtect clients in systems with umlaut diacritics in the serial number are unable to log in to the GlobalProtect gateway.
|
||||||
|
|
||||||
|
## PAN-154266
|
||||||
|
|
||||||
|
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
|
||||||
|
|
||||||
|
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
|
||||||
|
|
||||||
|
## PAN-154247
|
||||||
|
|
||||||
|
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
|
||||||
|
|
||||||
|
**Workaround:** Log out and back in to the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-153803
|
||||||
|
|
||||||
|
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
|
||||||
|
|
||||||
|
## PAN-151909
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.10 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
On the Panorama management server, Preview Changes (**Commit** > **Commit to Panorama**) incorrectly displays an existing route as Added and the new route as an existing route in the Candidate Configuration when you configure a new virtual router route (**Network** > **Virtual Router**).
|
||||||
|
|
||||||
|
## PAN-146573
|
||||||
|
|
||||||
|
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
|
||||||
|
|
||||||
|
## PAN-146485
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
|
||||||
|
|
||||||
|
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
|
||||||
|
|
||||||
|
## PAN-144889
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 9.1.2-h1 and later releases only
|
||||||
|
```
|
||||||
|
|
||||||
|
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
|
||||||
|
|
||||||
|
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
|
||||||
|
|
||||||
|
## PAN-136701
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-7000b Series firewalls only
|
||||||
|
```
|
||||||
|
|
||||||
|
Packets for new sessions drop when handling predict sessions.
|
||||||
|
|
||||||
|
**Workaround:** Use the following CLi commands to bypass this issue:
|
||||||
|
|
||||||
|
- `set session hwpredict disable yes`
|
||||||
|
- `show session hwpredict status`
|
||||||
|
|
||||||
|
## PAN-140959
|
||||||
|
|
||||||
|
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
|
||||||
|
|
||||||
|
## PAN-134456
|
||||||
|
|
||||||
|
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
|
||||||
|
|
||||||
|
**Workaround:** Use a destination-based service route for the SNMP trap server.
|
||||||
|
|
||||||
|
## PAN-134053
|
||||||
|
|
||||||
|
ACC does not filter WildFire logs from Dynamic User Groups.
|
||||||
|
|
||||||
|
## PAN-130550
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
|
||||||
|
```
|
||||||
|
|
||||||
|
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
|
||||||
|
|
||||||
|
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
|
||||||
|
|
||||||
|
## PAN-127813
|
||||||
|
|
||||||
|
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches don’t communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
|
||||||
|
|
||||||
|
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
|
||||||
|
|
||||||
|
## PAN-127550
|
||||||
|
|
||||||
|
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
|
||||||
|
|
||||||
|
## PAN-127474
|
||||||
|
|
||||||
|
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
|
||||||
|
|
||||||
|
## PAN-127206
|
||||||
|
|
||||||
|
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
|
||||||
|
|
||||||
|
## PAN-124956
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
This issue is now resolved. See PAN-OS 9.1.11 Addressed Issues.
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an issue where VM-Series firewalls do not support packet buffer protection.
|
||||||
|
|
||||||
|
## PAN-123277
|
||||||
|
|
||||||
|
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
|
||||||
|
|
||||||
|
## PAN-123040
|
||||||
|
|
||||||
|
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules don’t display. A workaround exists for this issue. Please contact Support for information about the workaround.
|
||||||
|
|
||||||
|
## PAN-120440
|
||||||
|
|
||||||
|
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
|
||||||
|
|
||||||
|
## PAN-120303
|
||||||
|
|
||||||
|
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
|
||||||
|
|
||||||
|
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
|
||||||
|
|
||||||
|
- Modify the PAN-DB Server IP address on the managed firewall.
|
||||||
|
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
|
||||||
|
2. **Commit** your changes.
|
||||||
|
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
|
||||||
|
4. **Commit** your changes.
|
||||||
|
- Restart the firewall (devsrvr) process.
|
||||||
|
1. Log in to the firewall CLI.
|
||||||
|
2. Restart the devsrvr process: `debug software restart process device-server`
|
||||||
|
|
||||||
|
## PAN-118065
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
M-Series Panorama management servers in Management Only mode
|
||||||
|
```
|
||||||
|
|
||||||
|
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
|
||||||
|
|
||||||
|
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
|
||||||
|
|
||||||
|
## PAN-116017
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Google Cloud Platform (GCP) only
|
||||||
|
```
|
||||||
|
|
||||||
|
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
|
||||||
|
|
||||||
|
## PAN-115816
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Microsoft Azure only
|
||||||
|
```
|
||||||
|
|
||||||
|
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
|
||||||
|
|
||||||
|
**Workaround:** Reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-114495
|
||||||
|
|
||||||
|
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
|
||||||
|
|
||||||
|
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
|
||||||
|
|
||||||
|
## PAN-112694
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Firewalls with multiple virtual systems only
|
||||||
|
```
|
||||||
|
|
||||||
|
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
|
||||||
|
|
||||||
|
## PAN-112456
|
||||||
|
|
||||||
|
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
|
||||||
|
|
||||||
|
## PAN-111928
|
||||||
|
|
||||||
|
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
|
||||||
|
|
||||||
|
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
|
||||||
|
|
||||||
|
## PAN-111866
|
||||||
|
|
||||||
|
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
|
||||||
|
|
||||||
|
**Workaround:** Perform one of the following tasks.
|
||||||
|
|
||||||
|
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
|
||||||
|
- Manually select the devices that belong to the modified device group and template configurations.
|
||||||
|
|
||||||
|
## PAN-111729
|
||||||
|
|
||||||
|
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
|
||||||
|
|
||||||
|
## PAN-111670
|
||||||
|
|
||||||
|
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
|
||||||
|
|
||||||
|
## PAN-111251
|
||||||
|
|
||||||
|
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
|
||||||
|
|
||||||
|
## PAN-110794
|
||||||
|
|
||||||
|
DGA-based threats shown in the firewall threat log display the same name for all such instances.
|
||||||
|
|
||||||
|
## PAN-109759
|
||||||
|
|
||||||
|
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
|
||||||
|
|
||||||
|
## PAN-109526
|
||||||
|
|
||||||
|
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
|
||||||
|
|
||||||
|
## PAN-106675
|
||||||
|
|
||||||
|
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
|
||||||
|
|
||||||
|
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
|
||||||
|
|
||||||
|
## PAN-104780
|
||||||
|
|
||||||
|
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
|
||||||
|
|
||||||
|
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
|
||||||
|
|
||||||
|
## PAN-103276
|
||||||
|
|
||||||
|
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
|
||||||
|
|
||||||
|
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
|
||||||
|
|
||||||
|
## PAN-101688
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama plugins
|
||||||
|
```
|
||||||
|
|
||||||
|
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
|
||||||
|
|
||||||
|
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
|
||||||
|
|
||||||
|
## PAN-101537
|
||||||
|
|
||||||
|
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
|
||||||
|
|
||||||
|
**Workaround:** Specify the vsys in the query string:
|
||||||
|
|
||||||
|
`admin>` `set system target-vsys <vsys-name>`
|
||||||
|
|
||||||
|
`admin>` `show log <log-type> direction equal <direction> query equal ‘vsys eq <vsys-name>’ <dst> | <src> in <object-name>`
|
||||||
|
|
||||||
|
## PAN-98520
|
||||||
|
|
||||||
|
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
|
||||||
|
|
||||||
|
## PAN-97757
|
||||||
|
|
||||||
|
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
|
||||||
|
|
||||||
|
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
|
||||||
|
|
||||||
|
## PAN-97524
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
Panorama management server only
|
||||||
|
```
|
||||||
|
|
||||||
|
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
|
||||||
|
|
||||||
|
## PAN-96985
|
||||||
|
|
||||||
|
The `request shutdown system` command does not shut down the Panorama management server.
|
||||||
|
|
||||||
|
## PAN-96960
|
||||||
|
|
||||||
|
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
|
||||||
|
|
||||||
|
## PAN-96446
|
||||||
|
|
||||||
|
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
|
||||||
|
|
||||||
|
## PAN-95773
|
||||||
|
|
||||||
|
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
|
||||||
|
|
||||||
|
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
|
||||||
|
|
||||||
|
## PAN-95511
|
||||||
|
|
||||||
|
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
|
||||||
|
|
||||||
|
## PAN-95028
|
||||||
|
|
||||||
|
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
|
||||||
|
|
||||||
|
## PAN-94846
|
||||||
|
|
||||||
|
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
|
||||||
|
|
||||||
|
## PAN-94093
|
||||||
|
|
||||||
|
HTTP Header Insertion does not work when jumbo frames are received out of order.
|
||||||
|
|
||||||
|
## PAN-93968
|
||||||
|
|
||||||
|
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
|
||||||
|
|
||||||
|
## PAN-93607
|
||||||
|
|
||||||
|
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesn’t list the SCTP Protection profile in its drop-down list of available profiles.
|
||||||
|
|
||||||
|
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
|
||||||
|
|
||||||
|
## PAN-93532
|
||||||
|
|
||||||
|
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
|
||||||
|
|
||||||
|
## PAN-93193
|
||||||
|
|
||||||
|
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
|
||||||
|
|
||||||
|
- Switch to the firewall **Context** on the Panorama management server.
|
||||||
|
- Commit changes when a dynamic update is being installed.
|
||||||
|
- Generate a custom report when a dynamic update is being installed.
|
||||||
|
- Generate custom reports during a commit.
|
||||||
|
|
||||||
|
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
|
||||||
|
|
||||||
|
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
|
||||||
|
|
||||||
|
## PAN-91802
|
||||||
|
|
||||||
|
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
|
||||||
|
|
||||||
|
## PAN-83610
|
||||||
|
|
||||||
|
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
|
||||||
|
|
||||||
|
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-83236
|
||||||
|
|
||||||
|
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
|
||||||
|
|
||||||
|
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
|
||||||
|
|
||||||
|
## PAN-83215
|
||||||
|
|
||||||
|
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
|
||||||
|
|
||||||
|
## PAN-81521
|
||||||
|
|
||||||
|
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
|
||||||
|
|
||||||
|
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
|
||||||
|
|
||||||
|
## PAN-77125
|
||||||
|
|
||||||
|
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode don’t close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
|
||||||
|
|
||||||
|
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
|
||||||
|
|
||||||
|
## PAN-75457
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
|
||||||
|
|
||||||
|
## PAN-73530
|
||||||
|
|
||||||
|
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
|
||||||
|
|
||||||
|
## PAN-73401
|
||||||
|
|
||||||
|
```caveat
|
||||||
|
PAN-OS 8.0.1 and later releases
|
||||||
|
```
|
||||||
|
|
||||||
|
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
|
||||||
|
|
||||||
|
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
|
||||||
|
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
|
||||||
|
|
||||||
|
**Workaround:** There are three possible workarounds to sync the controller nodes:
|
||||||
|
|
||||||
|
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
|
||||||
|
- Configure a worker list on the cluster controller:
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
|
||||||
|
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
|
||||||
|
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
|
||||||
|
or
|
||||||
|
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
|
||||||
|
Both commands result in Panorama reporting that the controller nodes are in sync.
|
||||||
|
|
||||||
|
## PAN-71329
|
||||||
|
|
||||||
|
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
|
||||||
|
|
||||||
|
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
|
||||||
|
|
||||||
|
## PAN-70906
|
||||||
|
|
||||||
|
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
|
||||||
|
|
||||||
|
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
|
||||||
|
|
||||||
|
## PAN-69505
|
||||||
|
|
||||||
|
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
|
||||||
|
|
||||||
|
## PAN-41558
|
||||||
|
|
||||||
|
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
|
||||||
|
|
||||||
|
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
|
||||||
|
|
||||||
|
## PAN-40079
|
||||||
|
|
||||||
|
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
|
||||||
|
|
||||||
|
## PAN-39636
|
||||||
|
|
||||||
|
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
|
||||||
|
|
||||||
|
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
|
||||||
|
|
||||||
|
## PAN-38255
|
||||||
|
|
||||||
|
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
|
||||||
|
|
||||||
|
## PAN-31832
|
||||||
|
|
||||||
|
The following issues apply when configuring a firewall to use a hardware security module (HSM):
|
||||||
|
|
||||||
|
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
|
||||||
|
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
|
||||||
+51
-2
@@ -392,15 +392,64 @@
|
|||||||
"10.0.8_2026-03-16.md",
|
"10.0.8_2026-03-16.md",
|
||||||
"10.0.9_2026-03-16.md"
|
"10.0.9_2026-03-16.md"
|
||||||
]
|
]
|
||||||
|
}
|
||||||
},
|
},
|
||||||
|
"9": {
|
||||||
"9.1": {
|
"9.1": {
|
||||||
"addressed": [],
|
"addressed": [
|
||||||
"known": []
|
"9.1.0_2026-03-16.md",
|
||||||
|
"9.1.1_2026-03-16.md",
|
||||||
|
"9.1.2_2026-03-16.md",
|
||||||
|
"9.1.3_2026-03-16.md",
|
||||||
|
"9.1.7_2026-03-16.md",
|
||||||
|
"9.1.10_2026-03-16.md",
|
||||||
|
"9.1.11_2026-03-16.md",
|
||||||
|
"9.1.11-h2_2026-03-16.md",
|
||||||
|
"9.1.11-h3_2026-03-16.md",
|
||||||
|
"9.1.11-h4_2026-03-16.md",
|
||||||
|
"9.1.11-h5_2026-03-16.md",
|
||||||
|
"9.1.12_2026-03-16.md",
|
||||||
|
"9.1.12-h3_2026-03-16.md",
|
||||||
|
"9.1.12-h4_2026-03-16.md",
|
||||||
|
"9.1.12-h7_2026-03-16.md",
|
||||||
|
"9.1.13-h1_2026-03-16.md",
|
||||||
|
"9.1.13-h3_2026-03-16.md",
|
||||||
|
"9.1.13-h4_2026-03-16.md",
|
||||||
|
"9.1.14_2026-03-16.md",
|
||||||
|
"9.1.14-h1_2026-03-16.md",
|
||||||
|
"9.1.14-h4_2026-03-16.md",
|
||||||
|
"9.1.14-h7_2026-03-16.md",
|
||||||
|
"9.1.14-h8_2026-03-16.md",
|
||||||
|
"9.1.15_2026-03-16.md",
|
||||||
|
"9.1.16_2026-03-16.md",
|
||||||
|
"9.1.16-h3_2026-03-16.md",
|
||||||
|
"9.1.16-h5_2026-03-16.md",
|
||||||
|
"9.1.17_2026-03-16.md"
|
||||||
|
],
|
||||||
|
"known": [
|
||||||
|
"9.1.1_2026-03-16.md",
|
||||||
|
"9.1.2_2026-03-16.md",
|
||||||
|
"9.1.3_2026-03-16.md",
|
||||||
|
"9.1.5_2026-03-16.md",
|
||||||
|
"9.1.6_2026-03-16.md",
|
||||||
|
"9.1.7_2026-03-16.md",
|
||||||
|
"9.1.8_2026-03-16.md",
|
||||||
|
"9.1.9_2026-03-16.md",
|
||||||
|
"9.1.10_2026-03-16.md",
|
||||||
|
"9.1.11_2026-03-16.md",
|
||||||
|
"9.1.12_2026-03-16.md",
|
||||||
|
"9.1.15_2026-03-16.md",
|
||||||
|
"9.1.16_2026-03-16.md",
|
||||||
|
"9.1.17_2026-03-16.md",
|
||||||
|
"9.1.18_2026-03-16.md"
|
||||||
|
]
|
||||||
},
|
},
|
||||||
"9.0": {
|
"9.0": {
|
||||||
"addressed": [],
|
"addressed": [],
|
||||||
"known": []
|
"known": []
|
||||||
|
}
|
||||||
},
|
},
|
||||||
|
"8": {
|
||||||
"8.1": {
|
"8.1": {
|
||||||
"addressed": [],
|
"addressed": [],
|
||||||
"known": []
|
"known": []
|
||||||
|
|||||||
Reference in New Issue
Block a user