diff --git a/reference/PAN-OS/addressed/11.1.0-h1.html b/reference/PAN-OS/addressed/11.1.0-h1.html new file mode 100644 index 0000000..aea4660 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.0-h1.html @@ -0,0 +1,36 @@ +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-237871
+ |
+
+
+ (WF-500 appliances and PAN-DB private cloud deployments only) Fixed an issue where the
+ root-cert was set to expire on
+ December 31, 2023. With this fix, the expiration date has been
+ extended.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-238792
+ |
+
+
+ Fixed the following device certificate issues:
+
+
|
+
|
+ PAN-237876
+ |
+
+
+ Extended the firewall Panorama root CA certificate which was
+ previously set to expire on April 7th, 2024.
+
+ |
+
|
+ PAN-231771
+ |
+
+
+ Fixed an issue where the firewall issued /box/getserv/ requests with
+ PAN-OS 7.1.0 and did not take device certificates.
+
+ |
+
|
+ PAN-227568
+ |
+
+
+ When a device certificate is installed, renewed, or removed, the
+ firewall will reconnect to the WildFire cloud to use the newest
+ certificate.
+
+ |
+
|
+ PAN-215576
+ |
+
+
+ Fixed an issue where the
+ userID-Agent and
+ TS-Agent certificates were set to
+ expire on November 18, 2024. With this fix, the expiration date has
+ been extended to January 2032.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-252214
+ |
+
+
+ A fix was made to address
+ CVE-2024-3400.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-272809
+ |
+ + + | +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-233557
+ |
+
+
+ Fixed an issue where, after using Panorama to configure per policy
+ persistent DIPP, downgrading the firewall using Panorama and then
+ upgrading the firewall back to a later PAN-OS release, the global DIPP
+ configuration was not successfully converted b ack to the per policy
+ persistent DIPP rules.
+
+ |
+
|
+ PAN-230359
+ |
+
+
+ Fixed an issue where SAML authentication failed with the error message
+ Failed to verify signature against certificate
+ when ds:KeyName was in the IdP
+ metadata.
+
+ |
+
|
+ PAN-227639
+ |
+
+
+ Fixed an issue where the
+ ACC displayed an incorrect DNS-base
+ application traffic byte count.
+
+ |
+
|
+ PAN-227376
+ |
+
+
+ Fixed an issue where a memory overrun caused the
+ all_task
+ process to stop responding.
+
+ |
+
|
+ PAN-227368
+ |
+
+
+ Fixed an issue where GlobalProtect users could not connect the app to
+ a portal or gateway and GlobalProtect Clientless VPN users were unable
+ to access applications when authentication took longer than 20
+ seconds.
+
+ |
+
|
+ PAN-226418
+ |
+
+
+ A CLI command was added to address an issue where long-lived sessions
+ aged out even when there was ongoing traffic.
+
+ |
+
|
+ PAN-226198
+ |
+
+
+ Fixed an issue on Panorama where the
+ configd
+ process repeatedly restarted when attempting to make configuration
+ changes.
+
+ |
+
|
+ PAN-225920
+ |
+
+
+ Fixed an issue where duplicate predict sessions didn't release NAT
+ resources.
+
+ |
+
|
+ PAN-225886
+ |
+
+
+ Fixed an issue where if you enabled explicit proxy mode for the web
+ proxy, intermittent errors and unexpected TCP reconnections may have
+ occurred.
+
+ |
+
|
+ PAN-225169
+ |
+
+
+ Added a CLI command to view
+ Strata Logging Service queue usage.
+
+ |
+
|
+ PAN-224772
+ |
+
+
+ Fixed a high memory usage issue with the
+ mongodb
+ process that caused an OOM condition.
+
+ |
+
|
+ PAN-224145
+ |
+
+
+ Fixed an issue in multi-vsys environments where, when Panorama was on
+ a PAN-OS 10.2 release and the firewall was on a PAN-OS 10.1 release,
+ commits failed on the firewall when inbound inspection mode was
+ configured in the decryption policy rule.
+
+ |
+
|
+ PAN-223457
+ |
+
+
+ Fixed an issue where, if the number of group queries exceeded the Okta
+ rate limit threshold, the firewall cleared the cache for the groups.
+
+ |
+
|
+ PAN-221126
+ |
+
+
+ Fixed an issue where email server profiles (Device > Server Profiles > Email and Panorama > Server
+ Profiles > Email) to forward logs as email notifications were not forwarded in a
+ readable format.
+
+ |
+
|
+ PAN-218555
+ |
+
+
+ Fixed an issue where the firewall did not receive dynamic address
+ updates pushed from Panorama during initial registration to Panorama.
+
+ |
+
|
+ PAN-213931
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process cache was not in sync with the mapping on the firewall.
+
+ |
+
|
+ PAN-206913
+ |
+ + Fixed an issue where, when DHCPv6 client was configured on firewalls in + active/passive HA configurations, releasing the IPv6 address from the + client released the IPv6 address from only the active firewall. + | +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-252214
+ |
+
+
+ A fix was made to address
+ CVE-2024-3400.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-272809
+ |
+ + + | +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-239241
+ |
+ + Extended the root certificate for WildFire appliances to December 31, + 2032. + | +
|
+ PAN-238792
+ |
+
+
+ Fixed the following device certificate issues:
+
+
|
+
|
+ PAN-237935
+ |
+
+
+ Extended the offline PAN-DB, Panorama, and WildFire certificates which
+ were previously set to expire on September 2, 2024.
+
+ |
+
|
+ PAN-237876
+ |
+ + Extended the firewall Panorama root CA certificate which was previously + set to expire on April 7th, 2024. + | +
|
+ PAN-236605
+ |
+
+
+ Fixed an issue where the
+ configd
+ process stopped responding due to a deadlock related to
+ rule-hit-count.
+
+ |
+
|
+ PAN-235385
+ |
+
+ Enhanced wifclient cloud connectivity redundancy.
+ |
+
|
+ PAN-234929
+ |
+
+
+ Fixed an issue where tabs in the
+ ACC such as
+ Network Activity
+ Threat Activity and
+ Blocked Activity did not display
+ data when you applied a Time filter
+ of Last 15 Minutes,
+ Last Hour,
+ Last 6 Hours, or
+ Last 12 Hours, and the data that was
+ displayed with the
+ Last 24 Hours filter was not
+ accurate. Reports that were run against summary logs also did not
+ display accurate results.
+
+ |
+
|
+ PAN-233957
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ the NAT private pool was not used properly when enabling slot 6 DPC.
+
+ |
+
|
+ PAN-233191
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ the Data Processing Card (DPC) restarted due to path monitor failure
+ after QSFP28 disconnected from the Network Processing Card (NPC).
+
+ |
+
|
+ PAN-232358
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ the interface on QSFP28 ports did not go down when the Tx cable was
+ removed from the QSFP28 module.
+
+ |
+
|
+ PAN-231771
+ |
+
+
+ Fixed an issue where the firewall issued /box/getserv/ requests with
+ PAN-OS 7.1.0 and did not take device certificates.
+
+ |
+
|
+ PAN-231658
+ |
+
+
+ Fixed an issue where DNS resolution failed when interfaces were
+ configured as DHCP and a DNS server was provided via DHCP while also
+ statically configured with DNS servers.
+
+ |
+
|
+ PAN-231194
+ |
+
+
+ Fixed an issue where the firewall was unable to clear hints from the
+ disk.
+
+ |
+
|
+ PAN-227568
+ |
+
+
+ When a device certificate is installed, renewed, or removed, the
+ firewall will reconnect to the WildFire cloud to use the newest
+ certificate.
+
+ |
+
|
+ PAN-215576
+ |
+
+
+ Fixed an issue where the
+ userID-Agent and
+ TS-Agent certificates were set to
+ expire on November 18, 2024. With this fix, the expiration date has
+ been extended to January 2032.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-242879
+ |
+
+
+ Fixed an issue where the dataplane restarted when advanced features
+ such as Advanced Threat Protection, Advanced WildFire, and Advanced
+ URL Filtering hit max latency under inline mode.
+
+ |
+
|
+ PAN-242634
+ |
+
+
+ (PA-1400 Series, PA-3400 Series, and PA-5400 Series firewalls
+ only) Fixed an issue where a large packet burst from the dataplane to the
+ management plane caused the DPDK kernel network interface to become
+ unresponsive.
+
+ |
+
|
+ PAN-240166
+ |
+
+
+ Fixed an issue where, when explicit proxy was configured on the
+ firewall, websites loaded more slowly than expected or did not load
+ due to DNS using TCP.
+
+ |
+
|
+ PAN-239279
+ |
+
+
+ Fixed an issue where the proxy did not accept new connections.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-264421
+ |
+
+
+ Fixed an issue on Panorama where
+ Push Scope did not populate
+ automatically after changing the device group configuration.
+
+ |
+
|
+ PAN-263226
+ |
+
+
+ Fixed an issue where decryption based traffic failed on Explicit Proxy
+ nodes.
+
+ |
+
|
+ PAN-262831
+ |
+
+
+ (PA-5450 firewalls only) Fixed an intermittent
+ issue where the
+ all_task
+ process stopped responding, which caused the firewall to restart.
+
+ |
+
|
+ PAN-262593
+ |
+
+
+ Fixed an issue where traffic to websites failed on the Google Chrome
+ web browser on Secure Web Gateway (SWG) nodes.
+
+ |
+
|
+ PAN-261991
+ |
+
+
+ Fixed an issue where traffic that did not match a decryption policy
+ rule, or matched a no-decrypt policy rule, failed when accumulation
+ proxy was enabled and a Zone Protection profile was configured with
+ syn-cookies enabled.
+
+ |
+
|
+ PAN-261917
+ |
+
+
+ Fixed an issue where websites with a no-decrypt policy rule were
+ decrypted in traffic log when using a Google Chrome browser with PQC
+ enabled.
+
+ |
+
|
+ PAN-259769
+ |
+
+
+ Fixed an issue where the GlobalProtect portal was not accessible via a
+ web browser and displayed the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-258736
+ |
+
+
+ Fixed an issue where policy rule configurations pushed from Panorama
+ were not reflected on the firewall if the rule had 63 characters.
+
+ |
+
|
+ PAN-253213
+ |
+
+
+ Fixed an issue where the firewall sent HIP notifications every time it
+ received a HIP report instead of every two hours.
+
+ |
+
|
+ PAN-252300
+ |
+
+
+ Fixed an issue where you were unable to select device groups in the
+ push scope for user accounts.
+
+ |
+
|
+ PAN-245690
+ |
+
+
+ Fixed an issue where the
+ Managed Collectors health status on
+ Panorama displayed as empty.
+
+ |
+
|
+ PAN-209574
+ |
+
+
+ Fixed an issue with HTTP/2 traffic where downloading large files did
+ not work when decryption was enabled.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
| PAN-262287 | +
+
+ Fixed an issue where dereferencing a NULL pointer that occurred caused
+ pan_task
+ processes to stop responding.
+
+ |
+
|
+ PAN-261673
+ |
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where, when Accelerated Networking was enabled,
+ traffic was dropped because of the
+ flow_parse_ip_hdr
+ counter related to an Nvidia driver issue.
+
+ |
+
|
+ PAN-259151
+ |
+
+
+ Fixed an issue where unused objects were pushed to the firewall, which
+ caused configuration pushes to fail with the error
+ Number of address groups exceed platform capacity.
+
+ |
+
|
+ PAN-259002
+ |
+
+
+ Fixed an issue where frequent external dynamic list updates caused the
+ configd
+ process to restart.
+
+ |
+
|
+ PAN-257601
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ Networking Cards (NC) experienced an internal link fault which caused
+ path monitoring failure on the Dataplane Processing Card (DPC).
+
+ |
+
|
+ PAN-257327
+ |
+
+
+ Fixed an issue where a failover event occurred unexpectedly on the
+ firewall.
+
+ |
+
|
+ PAN-253626
+ |
+
+
+ Fixed an issue on Panorama where unused objects were pushed to the
+ firewall, which caused the push operations to intermittently fail.
+
+ |
+
|
+ PAN-236191
+ |
+
+
+ Fixed an issue where the web interface performance was slower than
+ expected.
+
+ |
+
|
+ PAN-222542
+ |
+
+
+ (PA-7000 Series firewalls only) Fixed an issue
+ where Log Forward Cards (LFC) were incorrectly identified as
+ distribution policies, which caused packet loss due to traffic, BFD,
+ and other control packets being forwarded to the LFC.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-272809
+ |
+ + + | +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-272809
+ |
+ + + | +
|
+ PAN-269000
+ |
+
+
+ Fixed an issue where the firewall stopped responding due to a NULL
+ pointer dereference when path monitoring failed.
+
+ |
+
|
+ PAN-265785
+ |
+
+
+ Fixed an issue where the firewall rebooted due to a
+ sysd
+ variable being modified before it was created.
+
+ |
+
|
+ PAN-265179
+ |
+
+
+ Fixed an issue where a kernel race condition caused the firewall to
+ reboot with a kernel panic.
+
+ |
+
|
+ PAN-263973
+ |
+
+
+ Fixed an issue where log collectors had a low incoming log rate.
+
+ |
+
|
+ PAN-263208
+ |
+
+
+ (PA-5440 and PA-5445 firewalls only) Fixed an
+ issue where interrupts were generated at a certain packet rate, and
+ dataplane processes missed heartbeats, which caused the dataplane to
+ go down.
+
+ |
+
|
+ PAN-259881
+ |
+
+
+ Fixed an issue on Panorama where traffic log details were not
+ displayed under detailed log view.
+
+ |
+
|
+ PAN-259351
+ |
+
+
+ A fix was made to address
+ CVE-2024-3393.
+
+ |
+
|
+ PAN-256223
+ |
+
+
+ Fixed an issue where device telemetry log collection filled the root
+ partition.
+
+ |
+
|
+ PAN-255747
+ |
+
+
+ Fixed an issue on the firewall where CLI commands returned
+ Server error: op command for client dagger timed out as client is
+ not available.
+
+ |
+
|
+ PAN-253485
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where dataplane packet capture filter configuration
+ failed on the active firewall with the error
+ op command for client dagger timed out as client is not
+ available.
+
+ |
+
|
+ PAN-249300
+ |
+
+
+ Fixed an issue where, when CUID was enabled, the CUID firewall pub
+ node was slower than expected when processing incoming traffic and
+ User-ID mapping redistribution between PAN-OS nodes was impacted.
+
+ |
+
|
+ PAN-219805
+ |
+
+
+ Fixed an issue where the
+ reportd
+ process stopped responding due to a race condition.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-279604
+ |
+
+
+ Fixed an issue where scheduled SaaS application usage reports were
+ generated incorrectly, and the login page was displayed instead of the
+ report content.
+
+ |
+
|
+ PAN-273085
+ |
+
+
+ Fixed an issue on the web interface where you were unable to edit or
+ create policy rules.
+
+ |
+
|
+ PAN-272006
+ |
+
+
+ Fixed an issue where the firewall did not trigger a kernel core dump
+ as a large core when the CPLD (Complex Programmable Logic Device) sent
+ a Non-Maskable Interrupt (NMI) to the CPU.
+
+ |
+
|
+ PAN-271926
+ |
+
+
+ Fixed an issue where TLS 1.3 decryption failed with a bad record MAC
+ error when the firewall was configured to decrypt and inspect TLS
+ traffic.
+
+ |
+
|
+ PAN-270549
+ |
+
+
+ Fixed an issue where some TLS connections were not handled correctly,
+ which led to instability in the dataplane.
+
+ |
+
|
+ PAN-268727
+ |
+
+
+ Fixed an issue where traffic was dropped when the accumulation proxy
+ was enabled and header insertion modified packets.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-252214
+ |
+
+
+ A fix was made to address
+ CVE-2024-3400.
+
+ |
+
|
+ PAN-246949
+ |
+
+
+ Fixed an issue where custom admin users were not able to click
+ OK in the push scope selection
+ window when device group or template were disabled under commit in the
+ admin roles.
+
+ |
+
|
+ PAN-244013
+ |
+
+
+ Fixed an issue on the Panorama web interface where, when a new content
+ package was installed, new
+ Anti-Spyware Signatures and new
+ Vulnerability Signatures were not
+ visible in their respective profiles.
+
+ |
+
|
+ PAN-243951
+ |
+
+
+ Fixed an issue on Panorama appliances in active/passive HA
+ configurations where managed devices displayed as out-of-sync on the
+ passive appliance when peer configuration changes were made to the
+ SD-WAN configuration on the active peer.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-252214
+ |
+
+
+ A fix was made to address
+ CVE-2024-3400.
+
+ |
+
|
+ PAN-251013
+ |
+
+
+ Fixed an issue on the web interface where the
+ Virtual Router and
+ Virtual System
+ configurations for the template incorrectly showed as
+ none.
+
+ |
+
|
+ PAN-250686
+ |
+
+
+ Fixed an issue where selective push operations did not work when more
+ than one admin user simultaneously performed changes and partial
+ commits on Panorama.
+
+ |
+
|
+ PAN-249931
+ |
+
+
+ Fixed an issue where configuration pushes from Panorama on PAN-OS
+ 11.1.1 to a firewall on a PAN-OS 10.2 release failed.
+
+ |
+
|
+ PAN-249808
+ |
+
+
+ Fixed an issue where the
+ configd
+ process stopped responding when performing multi-device group pushes
+ via XML API.
+
+ |
+
|
+ PAN-247403
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the push scope CLI command took longer than expected, which caused the
+ web interface to be slow.
+
+ |
+
| PAN-246960 | +
+
+ Fixed an issue where firewalls failed to fetch content updates from
+ the Wildfire Private Cloud due to an
+ Unsupported protocol error.
+
+ |
+
|
+ PAN-244894
+ |
+
+
+ Fixed an issue where turning off
+ mprelay
+ logging caused *mprelay* heartbeat failure.
+
+ |
+
|
+ PAN-244622
+ |
+
+
+ Fixed an issue where FIB re-push did not work with Advanced Routing
+ enabled.
+
+ |
+
|
+ PAN-244227
+ |
+
+
+ Fixed an issue where inconsistent FIB entries across the dataplane
+ were not detected.
+
+ |
+
|
+ PAN-242309
+ |
+
+
+ Fixed an issue where a higher byte count (s2c) was observed for
+ DNS-Base application.
+
+ |
+
|
+ PAN-242027
+ |
+
+
+ Fixed an issue where the
+ all-task
+ process repeatedly restarted during memory allocation failures.
+
+ |
+
|
+ PAN-241141
+ |
+
+
+ Fixed an issue where creating more than one address object in the same
+ XML API request resulted in a commit error.
+
+ |
+
|
+ PAN-240477
+ |
+
+
+ Fixed a temporary hardware issue that caused PAN-SFP-PLUS-CU-5M to not
+ be able to link up on PA-3400 and PA-1400 Series firewalls.
+
+ |
+
|
+ PAN-240308
+ |
+
+
+ Fixed an issue where ElasticSearch did not work as expected when
+ raid-mounts were not fully ready after a reboot.
+
+ |
+
|
+ PAN-239367
+ |
+
+
+ Fixed an issue on the firewall where a memory leak associated with the
+ logrcvr
+ process occurred.
+
+ |
+
|
+ PAN-239354
+ |
+
+
+ Fixed an issue where DNS resolution was delayed when an Antispyware
+ policy rule was applied to both client to firewall and firewall to
+ internal DNS server legs of a connection.
+
+ |
+
|
+ PAN-238643
+ |
+ + Fixed an issue where a memory leak caused multiple processes to stop + responding when VM Information Sources was configured + | +
|
+ PAN-237537
+ |
+
+
+ Fixed an issue where, when deleting CTD entries, the
+ all_pktproc
+ process stopped responding which resulted in dataplane failure.
+
+ |
+
|
+ PAN-237208
+ |
+
+
+ Fixed an issue where the
+ reportd
+ process stopped and the firewall rebooted.
+
+ |
+
|
+ PAN-233789
+ |
+
+
+ Fixed an issue with push and commit and push operations where the user
+ was not correctly bound to the scope, which caused all device groups
+ to be selected for a selective push.
+
+ |
+
|
+ PAN-233692
+ |
+
+
+ Fixed an issue on Panorama where the
+ configd
+ process stopped, which caused performance issues.
+
+ |
+
|
+ PAN-233684
+ |
+ + Fixed an issue on Panorama where + Push to Devices or + Commit and Push operations took longer + than expected on the web interface. + | +
|
+ PAN-231148
+ |
+
+
+ Fixed an issue where no DHCP option list was defined when using
+ GlobalProtect.
+
+ |
+
|
+ PAN-230746
+ |
+
+
+ Fixed an issue on the web interface where device groups with a large
+ number of managed firewalls displayed the
+ Policy page more slowly than
+ expected.
+
+ |
+
|
+ PAN-205482
+ |
+
+
+ Fixed an issue related to the
+ configd
+ process where Panorama displayed the error
+ Server not responding when editing
+ policies.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-258225
+ |
+
+
+ Fixed an issue on the Panorama web interface where Security policy
+ rules loaded more slowly than expected.
+
+ |
+
|
+ PAN-257615
+ |
+
+
+ Fixed an issue on Panorama where logs did not display or displayed
+ intermittently on the web interface.
+
+ |
+
|
+ PAN-256725
+ |
+
+
+ Fixed an issue on the Panorama interface where
+ Traffic and
+ Unified event details loaded more
+ slowly than expected.
+
+ |
+
|
+ PAN-255868
+ |
+
+
+ (PA-3400 Series firewalls only) Fixed an issue
+ where the firewall entered maintenance mode after enabling kernel data
+ collection during the silent reboot.
+
+ |
+
|
+ PAN-255266
+ |
+
+
+ Fixed an issue where you were unable to clone a template stack with
+ the Pre-Shared Key variable.
+
+ |
+
|
+ PAN-254411
+ |
+
+
+ Fixed an issue where the
+ configd
+ process stopped responding, which caused
+ RR_CONNECTION_REFUSED error messages
+ to be displayed in admin sessions.
+
+ |
+
|
+ PAN-253546
+ |
+
+
+ Fixed an issue where a TLS client hello was split into multiple
+ packets and arrived out of order, so the packets were dropped and the
+ session terminated.
+
+ |
+
|
+ PAN-251563
+ |
+
+
+ Added CPLD enhancement to capture external power issues.
+
+ |
+
|
+ PAN-247099
+ |
+
+
+ Fixed an issue where the firewall decrypted traffic unexpectedly when
+ the client hello was spread across multiple packets.
+
+ |
+
|
+ PAN-246772
+ |
+
+
+ Fixed an issue on the firewall where the dataplane went down due to a
+ path monitor failure caused by an OOM condition related to the
+ pan_task
+ process.
+
+ |
+
|
+ PAN-246059
+ |
+
+
+ Fixed an issue where forwarded logs were not visible on Panorama due
+ to the Elasticsearch service not starting when it encountered old and
+ unsupported indices.
+
+ |
+
|
+ PAN-245428
+ |
+
+
+ Fixed an issue where FIB entries aged out and were incorrectly removed
+ after an HA failover event.
+
+ |
+
|
+ PAN-244548
+ |
+
+
+ Fixed an issue where ECMP sessions changed destination MAC addresses
+ mid-session, which caused connections to be reset.
+
+ |
+
|
+ PAN-243098
+ |
+
+
+ Fixed an issue with corrupted images when SSL decryption and Security
+ profiles were configured.
+
+ |
+
|
+ PAN-240739
+ |
+
+
+ Fixed an issue where the ECMP FIB update on the dataplane didn't clear
+ the pending change flag, which caused the next non-ECMP FIB update to
+ miss the latest generation ID and age out after 5 minutes.
+
+ |
+
|
+ PAN-240612
+ |
+
+ Fixed a kernel panic caused by a third-party issue.
+ |
+
|
+ PAN-240596
+ |
+
+
+ Fixed an issue where the
+ all_task
+ process stopped responding due to an invalid memory address.
+
+ |
+
|
+ PAN-236133
+ |
+
+
+ Fixed an issue where SSL traffic was impacted when
+ SSL Command and Control detector for
+ Incline Cloud Analysis was set to
+ reset-both, reset-client,
+ reset-server, or
+ drop.
+
+ |
+
|
+ PAN-234560
+ |
+
+
+ Fixed an issue where the daily summary report displayed IPv6 addresses
+ instead of IPv4 addresses.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-242627
+ |
+
+ Fixed an issue where selective push did not work.
+ |
+
|
+ PAN-242561
+ |
+
+
+ Fixed an issue where GlobalProtect tunnels disconnected shortly after
+ being established when SSL was used as the transfer protocol.
+
+ |
+
|
+ PAN-242519
+ |
+
+
+ Fixed an issue where scheduled email reports failed if the
+ @
+ symbol before the mail client was missing.
+
+ |
+
|
+ PAN-241504
+ |
+
+
+ Fixed an issue on the web interface where filtering logs under the
+ Monitor tab was slower than
+ expected.
+
+ |
+
|
+ PAN-239769
+ |
+
+
+ Fixed an issue where object references in a rule were renamed, and a
+ selective revert of the changes with
+ Commit changes by me caused a
+ reference error.
+
+ |
+
|
+ PAN-238769
+ |
+
+
+ (VM-Series firewalls in FIPS-CC mode only)
+ Fixed an issue where upgrading Panorama caused all locally created
+ Security policy rule actions to Deny.
+
+ |
+
|
+ PAN-238586
+ |
+
+
+ Fixed an issue where DNS resolution failure from the LFC resulted in
+ WildFire public cloud connectivity failure.
+
+ |
+
|
+ PAN-236120
+ |
+
+
+ Fixed an issue where the /opt/panlogs partition reached capacity due
+ to the logdb-quota for the User-ID log folder not being matched.
+
+ |
+
|
+ PAN-235840
+ |
+
+
+ Fixed an issue where, after a configuration push from Panorama to
+ managed firewalls, the status displayed as
+ None and the push took longer than
+ expected.
+
+ |
+
|
+ PAN-235585
+ |
+
+
+ Fixed an issue where, when custom signatures and predefined signatures
+ shared the same literal pattern part, the custom signature caused an
+ incorrect calculation for the length of the predefined signature,
+ which resulted in App-ID not detecting correctly.
+
+ |
+
|
+ PAN-234279
+ |
+
+
+ Fixed an issue where the
+ ikemgr
+ process crashed due to an IKEv1 timing issue, which caused commits to
+ fail with the following error message:
+ Client ikemgr requesting last config in the middle of a
+ commit/validate, aborting current commit.
+
+ |
+
|
+ PAN-230106
+ |
+
+
+ Fixed an issue where the firewall was unable to retrieve the most
+ current external dynamic list information from the server due to
+ hostname resolution failure.
+
+ |
+
|
+ PAN-227397
+ |
+
+
+ Fixed an issue where selective pushes on Panorama removed a previously
+ pushed configuration from the firewalls.
+
+ |
+
|
+ PAN-226785
+ |
+
+
+ Fixed an issue where accessing websites with HTTP to HTTPS redirect
+ failed via explicit proxy.
+
+ |
+
|
+ PAN-225337
+ |
+
+
+ Fixed an issue on Panorama related to Shared configuration objects
+ where configuration pushes to multi-vsys firewalls failed.
+
+ |
+
|
+ PAN-225203
+ |
+
+
+ Fixed an issue where the Log Forwarding Card (LFC) did not honor the
+ negotiated MSS on the logging connection.
+
+ |
+
|
+ PAN-224954
+ |
+
+
+ Fixed an issue where, after upgrading and rebooting a Panorama
+ appliance in Panorama or Log Collector mode, managed firewalls
+ continuously disconnected.
+
+ |
+
|
+ PAN-223259
+ |
+
+
+ Fixed an issue where selective pushes failed with the error message
+ Failed to generate selective push configuration. Unable to retrieve
+ last in-sync configuration for the device, either a push was never
+ done or version is too old. Please try a full push.
+
+ |
+
|
+ PAN-216941
+ |
+
+
+ (Panorama appliances in Log Collector mode only) Fixed an issue where Panorama stopped processing and saving logs.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-256765
+ |
+
+
+ Fixed an issue where you were unable to push variables from Panorama
+ in service routes for non-cluster templates.
+
+ |
+
|
+ PAN-255868
+ |
+
+
+ (PA-3400 Series firewalls only) Fixed an issue
+ where the firewall entered maintenance mode after enabling kernel data
+ collection during the silent reboot.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-265336
+ |
+
+
+ (PA-800 Series, PA-3200 Series, PA-5200 Series, and PA-5450
+ firewalls only) Fixed an issue where the copper ports flapped when generating a
+ technical support file or executing telemetry.
+
+ |
+
|
+ PAN-265287
+ |
+
+
+ Fixed an issue where the firewall experienced a packet buffer leak in
+ the dataplane of the network processing card (NPC) when processing
+ certain net messages.
+
+ |
+
|
+ PAN-265287
+ |
+
+
+ Fixed an issue where the firewall experienced a packet buffer leak in
+ the dataplane of the NPC when processing certain net messages.
+
+ |
+
|
+ PAN-263973
+ |
+
+
+ Fixed an issue where log collectors had a low incoming log rate.
+
+ |
+
|
+ PAN-262287
+ |
+
+
+ Fixed an issue where dereferencing a NULL pointer that occurred caused
+ pan_task
+ processes to stop responding.
+
+ |
+
|
+ PAN-261485
+ |
+
+
+ Fixed an issue where the firewall dropped the Real Time Transport
+ Protocol (RTP) session for the second SIP call on Persistent-DIPP
+ connections when the source port of the client device was reset.
+
+ |
+
|
+ PAN-259733
+ |
+
+
+ Fixed an issue where a custom report was not deleted on Panorama when
+ expected.
+
+ |
+
|
+ PAN-259151
+ |
+
+
+ Fixed an issue where unused objects were pushed to the firewall, which
+ caused configuration pushes to fail with the error
+ Number of address groups exceed platform capacity.
+
+ |
+
|
+ PAN-257912
+ |
+
+
+ Fixed an issue where the firewall stopped responding when it received
+ RADIUS traffic and user equipment (UE) traffic at the same time on an
+ NPC.
+
+ |
+
|
+ PAN-257615
+ |
+
+
+ Fixed an issue on Panorama where logs did not display or displayed
+ intermittently on the web interface.
+
+ |
+
|
+ PAN-257601
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ Networking Cards (NC) experienced an internal link fault which caused
+ path monitoring failure on the Dataplane Processing Card (DPC).
+
+ |
+
|
+ PAN-257327
+ |
+
+
+ (PA-5440 firewalls only) Fixed an issue where a
+ failover event occurred unexpectedly on the firewall.
+
+ |
+
|
+ PAN-256725
+ |
+
+
+ Fixed an issue on the Panorama interface where
+ Traffic and
+ Unified event details loaded more
+ slowly than expected.
+
+ |
+
|
+ PAN-254794
+ |
+
+
+ Fixed an issue where the Panorama management server stopped
+ responding.
+
+ |
+
|
+ PAN-253626
+ |
+
+
+ Fixed an issue on Panorama where unused objects were pushed to the
+ firewall, which caused the push operations to intermittently fail.
+
+ |
+
|
+ PAN-250394
+ |
+
+
+ Fixed an issue where a large amount of group data caused serialization
+ errors and prevented synchronization.
+
+ |
+
|
+ PAN-246708
+ |
+
+
+ Fixed an issue where the firewall stopped responding when the
+ all_pktproc
+ repeatedly restarted.
+
+ |
+
|
+ PAN-243098
+ |
+
+
+ Fixed an issue with corrupted images when SSL decryption and Security
+ profiles were configured.
+
+ |
+
|
+ PAN-222542
+ |
+
+
+ (PA-7000 Series firewalls only) Fixed an issue
+ where Log Forward Cards (LFC) were incorrectly identified as
+ distribution policies, which caused packet loss due to traffic, BFD,
+ and other control packets being forwarded to the LFC.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-272809
+ |
+ + + | +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-272809
+ |
+ + + | +
|
+ PAN-269000
+ |
+
+
+ Fixed an issue where the firewall stopped responding due to a NULL
+ pointer dereference when path monitoring failed.
+
+ |
+
|
+ PAN-265785
+ |
+
+
+ Fixed an issue where the firewall rebooted due to a
+ sysd
+ variable being modified before it was created.
+
+ |
+
|
+ PAN-263208
+ |
+
+
+ (PA-5440 and PA-5445 firewalls only) Fixed an
+ issue where interrupts were generated at a certain packet rate, and
+ dataplane processes missed heartbeats, which caused the dataplane to
+ go down.
+
+ |
+
|
+ PAN-260604
+ |
+
+
+ Fixed an issue where the firewall displayed inaccurate throughput
+ utilization stats in NetFlow analyzer tools.
+
+ |
+
|
+ PAN-259881
+ |
+
+
+ Fixed an issue on Panorama where traffic log details were not
+ displayed under detailed log view.
+
+ |
+
|
+ PAN-259351
+ |
+
+
+ A fix was made to address
+ CVE-2024-3393.
+
+ |
+
|
+ PAN-258799
+ |
+
+
+ Fixed an issue where, when updating a Security Policy
+ Policy Optimizer, the web interface
+ stopped responding.
+
+ |
+
|
+ PAN-256223
+ |
+
+
+ Fixed an issue where device telemetry log collection filled the root
+ partition.
+
+ |
+
|
+ PAN-255915
+ |
+
+
+ Fixed an issue where a memory leak in the
+ sslmgr
+ process caused the firewall to restart.
+
+ |
+
|
+ PAN-254826
+ |
+
+
+ Fixed an issue where the firewall stopped responding when processing
+ traffic.
+
+ |
+
|
+ PAN-254794
+ |
+
+
+ Fixed an issue where the Panorama management server stopped
+ responding.
+
+ |
+
|
+ PAN-254577
+ |
+
+
+ Fixed an issue where a core file was created on the Log Forwarding
+ Card (LFC) due to a third-party software issue.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-259733
+ |
+
+
+ Fixed an issue where a custom report was not deleted on Panorama when
+ expected.
+
+ |
+
|
+ PAN-259473
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ the chassis shut down when FAN1 was removed.
+
+ |
+
|
+ PAN-254411
+ |
+
+
+ Fixed an issue where the
+ configd
+ process stopped responding, which caused
+ ERR_CONNECTION_REFUSED error messages to be
+ displayed in admin sessions.
+
+ |
+
|
+ PAN-253546
+ |
+
+
+ Fixed an issue where a TLS client hello was split into multiple
+ packets and arrived out of order, so the packets were dropped and the
+ session terminated.
+
+ |
+
|
+ PAN-249814
+ |
+
+
+ Fixed an issue where multiple
+ all_task
+ processes stopped responding, which caused the dataplane to fail.
+
+ |
+
|
+ PAN-247099
+ |
+
+
+ Fixed an issue where the firewall decrypted traffic unexpectedly when
+ the client hello was spread across multiple packets.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-259480
+ |
+
+
+ Fixed an issue where the
+ varrcvr
+ process stopped responding after running out of memory due to how the
+ process queued and dequeued files for WildFire file forwarding when a
+ WildFire Analysis Security profile was enabled.
+
+ |
+
|
+ PAN-257925
+ |
+
+
+ (CN-Series firewalls only) Fixed an issue where
+ the CLI command
+ show system setting ctd state did
+ not work as expected.
+
+ |
+
|
+ PAN-257615
+ |
+
+
+ Fixed an issue on Panorama where logs did not display or displayed
+ intermittently on the web interface.
+
+ |
+
|
+ PAN-257462
+ |
+
+
+ Fixed an issue related to the
+ varrcvr
+ process where the management plane CPU was higher than expected during
+ WildFire updates.
+
+ |
+
|
+ PAN-256385
+ |
+
+
+ (CN-Series firewalls only) Fixed an issue where
+ communication was broken between the management plane and the
+ dataplane when anti-spyware profiles were configured in a Security
+ policy rule.
+
+ |
+
|
+ PAN-254373
+ |
+
+
+ Fixed an issue where the firewall did not handle error code 500
+ responses from the WildFire cloud correctly.
+
+ |
+
|
+ PAN-251639
+ |
+
+
+ Fixed an issue where an out-of-memory condition occurred due to a
+ memory leak related to the
+ varrvcr
+ process when a WildFire Analysis security profile was enabled.
+
+ |
+
|
+ PAN-248148
+ |
+
+ Jumbo frame feature support is enabled.
+ |
+
|
+ PAN-225213
+ |
+
+
+ Fixed an issue where
+ Push All Changes displayed changes
+ that were already committed in the push scope for another device group
+ after performing a selective commit and selective push to the first
+ device group.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-263226
+ |
+
+
+ Fixed an issue where decryption based traffic failed on Explicit Proxy
+ nodes.
+
+ |
+
|
+ PAN-262593
+ |
+
+
+ Fixed an issue where traffic to websites failed on the Google Chrome
+ web browser on Secure Web Gateway (SWG) nodes.
+
+ |
+
|
+ PAN-261991
+ |
+
+
+ Fixed an issue where traffic that did not match a decryption policy
+ rule, or matched a no-decrypt policy rule, failed when accumulation
+ proxy was enabled and a Zone Protection profile was configured with
+ syn-cookies enabled.
+
+ |
+
|
+ PAN-261917
+ |
+
+
+ Fixed an issue where websites with a no-decrypt policy rule were
+ decrypted in traffic log when using a Google Chrome browser with PQC
+ enabled.
+
+ |
+
|
+ PAN-259769
+ |
+
+
+ Fixed an issue where the GlobalProtect portal was not accessible via a
+ web browser and displayed the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-257957
+ |
+
+
+ (Firewalls and Panorama appliances in FIPS-CC mode only) Fixed an issue where the
+ authd
+ process restarted if RADIUS PAP/CHAP authentication was used.
+
+ |
+
|
+ PAN-242331
+ |
+
+
+ Fixed an issue where Prisma Access remote network firewalls
+ intermittently created incorrect user-to-IP-address mappings.
+
+ |
+
|
+ PAN-232214
+ |
+
+
+ Fixed an issue where GlobalProtect clients remained in the connecting
+ state during portal pre-login when Kerberos single sign-on (SSO) was
+ enabled.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-251013
+ |
+
+
+ Fixed an issue on the web interface where the
+ Virtual Router and
+ Virtual System
+ configurations for the template incorrectly showed as
+ none.
+
+ |
+
|
+ PAN-250686
+ |
+
+
+ Fixed an issue where selective push operations did not work when more
+ than one admin user simultaneously performed changes and partial
+ commits on Panorama.
+
+ |
+
|
+ PAN-249808
+ |
+
+
+ Fixed an issue where the
+ configd
+ process stopped responding when performing multi-device group pushes
+ via XML API.
+
+ |
+
|
+ PAN-249597
+ |
+
+
+ Fixed an issue where the Policy page
+ on the Panorama web interface was slower than expected when a device
+ group had a large number of managed devices.
+
+ |
+
|
+ PAN-249019
+ |
+
+
+ Fixed an issue where the
+ all_pktproc
+ process stopped responding, which caused the firewall to become
+ unresponsive.
+
+ |
+
|
+ PAN-248748
+ |
+
+
+ Fixed an issue that caused the dataplane to stop responding when
+ running a packet diagnostic with Jumbo frames enabled.
+
+ |
+
|
+ PAN-248105
+ |
+
+
+ Fixed an issue where the GlobalProtect SSL VPN tunnel immediately
+ disconnected due to a keep-alive timeout.
+
+ |
+
|
+ PAN-247403
+ |
+
+
+ (Panorama virtual appliances only) Fixed an
+ issue where the push scope CLI command took longer than expected,
+ which caused the web interface to be slow.
+
+ |
+
|
+ PAN-246707
+ |
+
+
+ Fixed an issue where failover was not triggered when multiple
+ processes stopped responding.
+
+ |
+
|
+ PAN-246420
+ |
+
+
+ (PA-5450 Series firewalls only) Fixed an issue
+ where the firewall rebooted unexpectedly during an upgrade.
+
+ |
+
|
+ PAN-246215
+ |
+
+
+ Fixed an issue where the sleep time for a suspended
+ pan_task
+ process caused configuration and policy updates to be blocked.
+
+ |
+
|
+ PAN-245701
+ |
+
+
+ Fixed an issue where the returned values to SNMP requests for data
+ port statistics were incorrect.
+
+ |
+
|
+ PAN-245690
+ |
+
+
+ Fixed an issue where the Managed Collectors health status on Panorama
+ displayed as empty.
+
+ |
+
|
+ PAN-245428
+ |
+
+
+ Fixed an issue where FIB entries aged out and were incorrectly removed
+ after an HA failover event.
+
+ |
+
|
+ PAN-245387
+ |
+
+
+ Fixed an issue where selective push failed intermittently due to
+ schema validation or bad encryption errors.
+
+ |
+
|
+ PAN-245041
+ |
+
+
+ Fixed an issue where the WF-500 appliance returned an error verdict
+ for every sample in FIPS mode.
+
+ |
+
|
+ PAN-244907
+ |
+
+
+ (PA-3400, PA-5400, and PA-1400 Series firewalls only) Fixed an issue where virtual wire ports did not go down when moving
+ from an active state to a suspended state.
+
+ |
+
|
+ PAN-244894
+ |
+ + + | +
|
+ PAN-244836
+ |
+
+
+ A knob was introduced to toggle the default behavior of BGP in the
+ Advanced Routing stack to not suppress duplicate updates. By default,
+ the prefix updates are suppressed for optimization.
+
+ |
+
|
+ PAN-244648
+ |
+
+
+ Fixed an issue where, when FIPS was enabled in maintenance mode, the
+ firewall rebooted and returned to maintenance mode.
+
+ |
+
|
+ PAN-244625
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ incorrect virtual MAC addresses were used in interfaces.
+
+ |
+
|
+ PAN-244622
+ |
+
+
+ Fixed an issue where FIB re-push did not work with Advanced Routing
+ enabled.
+
+ |
+
|
+ PAN-244548
+ |
+
+
+ Fixed an issue where ECMP sessions changed destination MAC addresses
+ mid-session, which caused connections to be reset.
+
+ |
+
|
+ PAN-244493
+ |
+
+
+ Fixed a memory limitation with mapping subinterfaces to VPCE endpoints
+ for GCP IPS, Amazon Web Services (AWS) integration with GWLB, and NSX
+ service chain mapping.
+
+ |
+
|
+ PAN-244227
+ |
+
+
+ Fixed an issue where inconsistent FIB entries across the dataplane
+ were not detected.
+
+ |
+
|
+ PAN-244013
+ |
+
+
+ Fixed an issue where the web interface did not display newly added
+ Anti-Spyware signatures or Vulnerability Signatures.
+
+ |
+
|
+ PAN-243463
+ |
+
+
+ Fixed an issue where high Enhanced Application Log traffic used excess
+ system resources and caused processes to not work.
+
+ |
+
|
+ PAN-242027
+ |
+
+
+ Fixed an issue where the
+ all-task
+ process repeatedly restarted during memory allocation failures.
+
+ |
+
|
+ PAN-241548
+ |
+
+
+ Fixed an issue where the firewall stopped responding when switching
+ from endpoint authentication bypass to endpoint Kerberos
+ authentication with SWG-proxy traffic.
+
+ |
+
|
+ PAN-241230
+ |
+
+
+ Fixed an issue where the SNMP get request status value for Panorama
+ connections was incorrect.
+
+ |
+
|
+ PAN-241164
+ |
+
+
+ (PA-410 firewalls only) Fixed an issue where
+ system and configuration logs sent from the firewall to Panorama
+ contained the serial number field instead of the firewall device name.
+
+ |
+
|
+ PAN-241141
+ |
+
+
+ Fixed an issue where creating more than one address object in the same
+ XML API request resulted in a commit error.
+
+ |
+
|
+ PAN-241041
+ |
+
+
+ Fixed an issue where, after upgrading to 11.1.0, exporting CSV files
+ for template stack variables or template variables resulted in an
+ empty file.
+
+ |
+
|
+ PAN-241018
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed a Dataplane Development Kit (DPDK) issue where interfaces
+ remained in a link-down stage after an Azure hot plug event.
+
+ |
+
|
+ PAN-240993
+ |
+
+
+ Fixed an issue where you were unable to revert a sort in task manager
+ in the admin column.
+
+ |
+
|
+ PAN-240786
+ |
+
+
+ Fixed an issue on firewalls in HA configurations where VXLAN sessions
+ were allocated, but not installed or freed, which resulted in a
+ constant high session table usage that was not synced between the
+ firewalls. This resulted in a session count mismatch.
+
+ |
+
|
+ PAN-240618
+ |
+
+
+ Fixed an issue where configuration commits were successful even when
+ dynamic peer IKE gateways configured on the same interface and IP
+ address that did not have the same IKE crypto profile.
+
+ |
+
|
+ PAN-240612
+ |
+
+ Fixed a kernel panic caused by a third-party issue
+ |
+
|
+ PAN-240596
+ |
+
+
+ Fixed an issue where
+ all_task
+ stopped responding due to an invalid memory address.
+
+ |
+
|
+ PAN-240477
+ |
+
+
+ Fixed a temporary hardware issue that caused PAN-SFP-PLUS-CU-5M to not
+ be able to link up on PA-3400 and PA-1400 Series firewalls.
+
+ |
+
|
+ PAN-240368
+ |
+
+
+ Fixed an issue where authentication portal redirection for HTTPS
+ websites did not work when
+ Enhanced Handling of SSL/TLS Handshakes for Decrypted Traffic
+ was enabled.
+
+ |
+
|
+ PAN-240347
+ |
+
+
+ Fixed an issue with the web interface where the
+ Dashboard and a
+ Device Group policy rule took longer
+ than expected to load.
+
+ |
+
|
+ PAN-240308
+ |
+
+
+ Fixed an issue where ElasticSearch did not work as expected when
+ raid-mounts were not fully ready after a reboot.
+
+ |
+
|
+ PAN-240251
+ |
+
+
+ Fixed an issue where the
+ vldmgr
+ process incorrectly restarted during an Elasticsearch restart.
+
+ |
+
|
+ PAN-239776
+ |
+
+
+ Fixed an issue where Panorama went into maintenance mode due to a
+ GlobalProtect quota configuration that was under the minimum required
+ quota.
+
+ |
+
|
+ PAN-239722
+ |
+
+
+ Fixed an issue where SNMP scans to the firewall took longer than
+ expected and intermittently timed out.
+
+ |
+
|
+ PAN-239662
+ |
+
+
+ Fixed an issue where the NSSA default route from the firewall was not
+ generated to advertise even though the backbone area default route was
+ advertised during a graceful restart.
+
+ |
+
|
+ PAN-239367
+ |
+
+
+ Fixed an issue on the firewall where a memory leak associated with the
+ logrcvr
+ process occurred.
+
+ |
+
|
+ PAN-239354
+ |
+
+
+ Fixed an issue where DNS resolution was delayed when an antispyware
+ policy rule was applied to both client to firewall and firewall to
+ internal DNS server legs of a connection.
+
+ |
+
|
+ PAN-239337
+ |
+
+
+ Fixed an issue where the log_index was suspended and corrupted BDX
+ files flooded the index_log.
+
+ |
+
|
+ PAN-239256
+ |
+
+
+ Fixed an issue where ARP entries were unable to be completed for
+ subinterfaces with SNAT configured.
+
+ |
+
|
+ PAN-239255
+ |
+
+
+ Fixed an issue where the firewall did not update the ARP cache timeout
+ value after modifying the
+ arp-cache-timeout setting.
+
+ |
+
|
+ PAN-238996
+ |
+
+
+ Fixed an issue where commits did not complete and remained in a
+ pending state due to a race condition. With this fix, the commit will
+ fail after 60 seconds and not remain in a pending state.
+
+ |
+
|
+ PAN-238643
+ |
+
+
+ Fixed an issue where a memory leak caused multiple processes to stop
+ responding when VM Information Sources was configured.
+
+ |
+
|
+ PAN-238625
+ |
+
+
+ Fixed an issue where, when the physical interface went down, the
+ SD-WAN Ethernet connection state still showed
+ UP/path-monitor due to the Active
+ URL SaaS monitor connection state remaining UP/path-monitor.
+
+ |
+
|
+ PAN-238621
+ |
+
+
+ Fixed an issue where the HA3 link status remained down when updating
+ the HA3 interface configuration when the AE interface was up.
+
+ |
+
|
+ PAN-238562
+ |
+
+
+ Fixed an issue where log collectors stopped responding when gathering
+ reports from Panorama.
+
+ |
+
|
+ PAN-238508
+ |
+
+
+ Fixed an issue where the
+ routed
+ process created excessive logs in the log file.
+
+ |
+
|
+ PAN-237678
+ |
+
+
+ Fixed an issue with firewalls in active/passive HA configurations
+ where the passive firewall displayed the error message
+ Unable to read QSFP Module ID
+ when the passive link state was set to shutdown.
+
+ |
+
|
+ PAN-237537
+ |
+
+
+ Fixed an issue where, when deleting CTD entries, the
+ all_pktproc
+ process stopped responding which resulted in dataplane failure.
+
+ |
+
|
+ PAN-237478
+ |
+
+
+ Fixed an issue where the traffic log displayed 0 bytes for denied
+ sessions.
+
+ |
+
|
+ PAN-237454
+ |
+
+
+ Fixed an issue where Panorama stopped redistributing IP
+ address-to-username mappings when packet loss occurred between the
+ distributor and the client.
+
+ |
+
|
+ PAN-237369
+ |
+
+
+ (PA-1420 firewalls only) Fixed an issue where
+ the
+ all_task
+ process stopped responding, which caused the firewall to become
+ unresponsive.
+
+ |
+
|
+ PAN-237246
+ |
+
+
+ Fixed an issue where the
+ all_pktproc
+ process repeatedly restarted, which caused the firewall to go into a
+ nonfunctional state.
+
+ |
+
|
+ PAN-236802
+ |
+
+
+ Fixed an issue on firewalls in HA configurations where unexpected
+ failovers occurred.
+
+ |
+
|
+ PAN-236261
+ |
+
+
+ Fixed an issue where a proxy server was used for External Dynamic List
+ communication even when the dataplane interface was configured through
+ service routes.
+
+ |
+
|
+ PAN-236244
+ |
+
+
+ Fixed an issue where you were unable to select Authentication Profiles
+ via the web interface.
+
+ |
+
|
+ PAN-236233
+ |
+
+
+ Fixed an issue where SNMP reports displayed incorrect values for SSL
+ Proxy sessions and SSL Proxy utilization.
+
+ |
+
|
+ PAN-235737
+ |
+
+
+ Fixed an issue where the
+ brdagent
+ process stopped responding due to a sudden increase in logging to the
+ bcm.log.
+
+ |
+
|
+ PAN-235628
+ |
+
+
+ Fixed an issue where you were not prompted for login credentials when
+ you disconnected and connected back to the GlobalProtect portal when
+ SAML authentication was selected along with Single Sign-On (SSO) and
+ Single Log Out (SLO).
+
+ |
+
|
+ PAN-235557
+ |
+
+
+ Fixed an issue where uploads from tunnels, including GlobalProtect,
+ were slower than expected when the inner and outer sessions were on
+ different dataplanes.
+
+ |
+
|
+ PAN-235476
+ |
+
+
+ Fixed an issue where threat logs from different Security zones were
+ aggregated into one log.
+
+ |
+
|
+ PAN-235168
+ |
+
+
+ Fixed an issue where disk space became full even after clearing old
+ logs and content images.
+
+ |
+
|
+ PAN-235081
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the firewall sent packets to its own interface after configuring
+ NAT64.
+
+ |
+
|
+ PAN-234596
+ |
+
+
+ Fixed an issue on firewalls in active/passive HA configurations where
+ the passive firewall incorrectly became active after a reboot.
+
+ |
+
|
+ PAN-234459
+ |
+
+
+ Fixed an issue with the firewall web interface where local SSL
+ decryption exclusion cache entries were not visible.
+
+ |
+
|
+ PAN-234290
+ |
+
+
+ Fixed an issue where the firewall displayed incorrect interface
+ transfer rates when running the CLI command
+ show system state filter-pretty sys.s1.px
+ with a filter.
+
+ |
+
|
+ PAN-234169
+ |
+
+
+ Fixed an issue where downloading files failed or was slower than
+ expected due to malware scanning even when the session was matched to
+ a Security policy rule with no Anti-Virus profile attached.
+
+ |
+
|
+ PAN-234031
+ |
+
+
+ Fixed an issue on multi-core firewalls where the firewall displayed
+ packets out of order when capturing packets on the transmit stage.
+
+ |
+
|
+ PAN-233833
+ |
+
+
+ Fixed an issue where enabling Jumbo frames resulted in software packet
+ buffer depletion.
+
+ |
+
|
+ PAN-233789
+ |
+
+
+ Fixed an issue with Push and
+ Commit and Push operations where the
+ user was not correctly bound to the scope, which caused all device
+ groups to be selected for a selective push.
+
+ |
+
|
+ PAN-233692
+ |
+
+
+ Fixed an issue on Panorama where the
+ configd
+ process stopped, which caused performance issues.
+
+ |
+
|
+ PAN-233684
+ |
+
+
+ Fixed an issue on Panorama where
+ Push to Devices or
+ Commit and Push operations took
+ longer than expected on the web interface.
+
+ |
+
|
+ PAN-233603
+ |
+
+
+ (CN-Series firewalls only) Fixed an issue where
+ slot information was not correct after a
+ slotd
+ process restart on the management pod.
+
+ |
+
|
+ PAN-233541
+ |
+
+
+ Fixed an issue where device group and template administrators with
+ access to a specific virtual system were able to see logs for all
+ virtual systems via Context Switch.
+
+ |
+
|
+ PAN-233517
+ |
+
+
+ Fixed an issue on Panorama where managed device templates and device
+ groups took longer than expected to display in the
+ Push to Devices window.
+
+ |
+
|
+ PAN-233463
+ |
+
+
+ Fixed an issue where the X-Forwarded-For (XFF) IP addressed value was
+ not displayed in traffic logs.
+
+ |
+
|
+ PAN-233207
+ |
+
+
+ Fixed an issue where the
+ configd
+ process stopped responding when a partial configuration revert
+ operation was performed.
+
+ |
+
|
+ PAN-233039
+ |
+
+
+ Fixed an issue where GENEVE encapsulated packets coming from a GFE
+ Proxy mapped to an incorrect Security policy rule.
+
+ |
+
|
+ PAN-232953
+ |
+
+
+ Fixed an issue where you were able to cancel the same commit
+ repeatedly, which displayed the error message
+ Cannot stop job <job> at this time.
+
+ |
+
|
+ PAN-232368
+ |
+
+
+ Fixed an issue where commits failed with the error message
+ Error: Max. user groups used in policy 1389 exceed capacity
+ (1000).
+
+ |
+
|
+ PAN-232250
+ |
+
+
+ Fixed an issue where, when SSH service profiles for management access
+ were set to None, the reported
+ output was incorrect.
+
+ |
+
|
+ PAN-231802
+ |
+
+
+ Fixed an issue where an Advanced Routing BGP session flapped with
+ commits when BGP peer authentication was enabled.
+
+ |
+
|
+ PAN-231552
+ |
+
+
+ Fixed an issue where traffic returning from a third-party Security
+ chain was dropped.
+
+ |
+
|
+ PAN-231507
+ |
+
+
+ (PA-1400 Series firewalls only) Fixed an issue
+ where, when an HSCI interface was used as an HA2 interface, HA2
+ packets were intermittently dropped on the passive firewall, which
+ caused the HA2 connection to flap due to missing HA2 keepalive
+ messages.
+
+ |
+
|
+ PAN-231480
+ |
+
+
+ Fixed an issue where the firewall CLI output for GlobalProtect log
+ quota settings did not match the settings configured on the Panorama
+ web interface.
+
+ |
+
|
+ PAN-231439
+ |
+
+
+ Fixed an issue where, when a VoIP call using dynamic IP and NAT was
+ put on hold, the audio became one-way due to early termination of NAT
+ ports.
+
+ |
+
|
+ PAN-231395
+ |
+
+
+ Fixed an intermittent issue where the OCSP query failed.
+
+ |
+
|
+ PAN-231148
+ |
+
+
+ Fixed an issue where no DHCP option list was defined when using
+ GlobalProtect.
+
+ |
+
|
+ PAN-230813
+ |
+
+
+ Fixed an issue where flex memory leak caused decryption failure and
+ commit failure with the error message
+ Error preparing global objects failed to handle
+ CONFIG_UPDATE_START.
+
+ |
+
|
+ PAN-230746
+ |
+
+
+ Fixed an issue on the web interface where device groups with a large
+ number of managed firewalls displayed the
+ Policy page more slowly than
+ expected.
+
+ |
+
|
+ PAN-230656
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where a split brain condition occurred on both firewalls after
+ booting up any firewall, and an HA switchover occurred after booting
+ up a firewall with a higher HA priority even when no preemptive option
+ was enabled on the firewall.
+
+ |
+
|
+ PAN-230377
+ |
+
+
+ Fixed an issue where FEC support was not enabled by default for
+ PAN-25G-SFP28-LR modules.
+
+ |
+
|
+ PAN-230372
+ |
+
+
+ Fixed an issue where OCSP queries did not work after upgrading to a
+ PAN-OS 11.0 release.
+
+ |
+
|
+ PAN-230039
+ |
+
+
+ Fixed an issue where migrating from an Enterprise License Agreement
+ (ELA) to a Flexible VM-Series License failed with a deactivation error
+ message.
+
+ |
+
|
+ PAN-229985
+ |
+
+
+ (VM-Series firewalls in Amazon Web Services (AWS) only) Fixed an issue where, when Gateway Load Balancer (GWLB) overlay
+ routing was enabled, GWLB packets re-encapsulated with the incorrect
+ flow cookie in the GENEVE header when transmitting the response back
+ to GWLB.
+
+ |
+
|
+ PAN-229874
+ |
+
+
+ Fixed an issue where the firewall was unable to form OSPFv3 adjacency
+ when using an ESP authentication profile.
+
+ |
+
|
+ PAN-229873
+ |
+
+
+ (PA-7050 firewalls only) Fixed an issue related
+ to
+ brdagent
+ process errors.
+
+ |
+
|
+ PAN-229315
+ |
+
+
+ Fixed an issue where Octets in NetFlow records were always reported to
+ be 0 despite having a non-zero packet count.
+
+ |
+
|
+ PAN-229069
+ |
+
+
+ Fixed an issue where clientless VPN portal users were unable to access
+ clientless applications due to an SSL renegotiation being triggered.
+
+ |
+
|
+ PAN-228457
+ |
+
+
+ (PA-7000 firewalls only) Fixed an issue where
+ the GTP logs forwarded from the firewall to the log collector did not
+ include the pcap.
+
+ |
+
|
+ PAN-228442
+ |
+
+
+ Fixed an issue on firewalls in active/passive HA configurations where
+ sessions did not fail over from the active firewall to the passive
+ firewall when upgrading PAN-OS.
+
+ |
+
|
+ PAN-228323
+ |
+
+
+ Fixed an issue where a large number of Panorama management server
+ cookies were created in the Redis database when the Cloud-Service
+ plugin sent an authentication request every second, and logging in to
+ or using Panorama was slower than expected.
+
+ |
+
|
+ PAN-227973
+ |
+
+
+ Fixed an issue where commits failed after renaming an address object
+ or object group with a selective commit.
+
+ |
+
|
+ PAN-227939
+ |
+
+
+ Fixed an issue where the
+ all_task
+ process stopped responding due to high wifclient memory usage, which
+ caused the firewall to reboot.
+
+ |
+
|
+ PAN-227887
+ |
+
+
+ Fixed an issue where IP address checksums were calculated incorrectly.
+
+ |
+
|
+ PAN-227510
+ |
+
+
+ Fixed an issue where the error message
+ Failed to establish GRPC connection to UrlCat service: failed to
+ start grpc connection
+ was displayed in the system log when the Advanced URL Filtering
+ license was applied but not configured.
+
+ |
+
|
+ PAN-227064
+ |
+
+
+ Fixed an issue with high availability (HA) sync failure when
+ performing a partial commit after creating a Security policy via REST
+ API.
+
+ |
+
|
+ PAN-226489
+ |
+
+
+ Fixed an issue where Panorama was unable to push scheduled dynamic
+ updates to firewalls with the error message
+ Failed to add deploy job. Too many (30) deploy jobs pending for
+ device.
+
+ |
+
|
+ PAN-225090
+ |
+
+
+ Fixed an issue on Panorama where
+ Commit and Push was grayed out when
+ making changes to a template or device group.
+
+ |
+
|
+ PAN-225064
+ |
+
+
+ Fixed an issue where Panorama stopped responding and entered a
+ non-functional state after moving multiple Security policy rules at
+ the same time from one device group to another device group.
+
+ |
+
|
+ PAN-224938
+ |
+
+
+ Fixed an issue where the CLI command settings for
+ set system setting logging max-log-rate
+ did not persist after a
+ mgmtsrvr
+ process restart.
+
+ |
+
|
+ PAN-224584
+ |
+ + Fixed an issue on Panorama where generating UAR reports for 30 days or + more was slower than expected, and reports showed the same logs + repeatedly in a loop. + | +
|
+ PAN-224424
+ |
+
+
+ (PA-3440 firewalls only) Fixed an issue where
+ you were unable to set the link speed as 25Gbps from the drop-down in
+ the template for Ethernet ports 1/23 through 1/26.
+
+ |
+
|
+ PAN-224060
+ |
+
+
+ (PA-220 Series firewalls only) Fixed an issue
+ where multiple dataplane processes stopped responding after an
+ upgrade.
+
+ |
+
|
+ PAN-223365
+ |
+
+
+ Fixed an issue where Panorama was unable to query any logs if the
+ Elasticsearch health status for any log collector was degraded.
+
+ |
+
|
+ PAN-223172
+ |
+
+
+ Fixed an issue on Panorama where host IDs manually added to the device
+ quarantine list were unexpectedly removed.
+
+ |
+
|
+ PAN-222188
+ |
+
+
+ A CLI command was introduced to address an issue where SNMP monitoring
+ performance was slower than expected, which resulted in
+ snmpwalk timeouts.
+
+ |
+
|
+ PAN-222002
+ |
+
+
+ Fixed an issue where content updates failed with the error message
+ Unable to get key pancontent-8.0.pass from cryptod. Error -9.
+
+ |
+
|
+ PAN-220931
+ |
+
+
+ (Panorama appliances in FIPS-CC mode only)
+ Fixed an issue where scheduled email reports did not contain PDF
+ attachments.
+
+ |
+
|
+ PAN-219805
+ |
+
+
+ Fixed an issue where the
+ reportd
+ process stopped responding due to a race condition.
+
+ |
+
|
+ PAN-219113
+ |
+
+
+ Fixed an issue where, when a port on the NPC was configured for log
+ forwarding, the ingress traffic on the card was sent for processing to
+ the LPC, and the LPC card was reloaded when the ingress volume of
+ traffic was high.
+
+ |
+
|
+ PAN-217619
+ |
+
+
+ Fixed an issue where supported Bi-DI transceivers were not recognized
+ which caused ports to not come up.
+
+ |
+
|
+ PAN-217307
+ |
+
+
+ Fixed an issue where the
+ log-start and
+ log-end policy rule filters did
+ not return reliable results when set to
+ no or
+ yes.
+
+ |
+
|
+ PAN-217241
+ |
+
+
+ Fixed an issue where predict session conversion failed for RTP and
+ RTCP traffic.
+
+ |
+
|
+ PAN-209574
+ |
+
+
+ Fixed an issue with HTTP/2 traffic where downloading large files did
+ not work when decryption was enabled.
+
+ |
+
|
+ PAN-205482
+ |
+
+
+ Fixed an issue related to the
+ configd
+ process where Panorama displayed the error
+ Server not responding when editing
+ policies.
+
+ |
+
|
+ PAN-199141
+ |
+
+
+ Fixed an issue where renaming a device group and then performing a
+ partial commit led to the device group hierarchy being incorrectly
+ changed.
+
+ |
+
|
+ PAN-196395
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ the firewall accepted 12 aggregate ethernet interfaces, but you were
+ unable to configure interfaces 9-12 via the web interface.
+
+ |
+
|
+ PAN-174454
+ |
+
+
+ Fixed an issue where the firewall did not fetch group and user
+ membership due to the Okta sync domain not matching the active Cloud
+ Identity Engine domain.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-245690
+ |
+
+
+ Fixed an issue where the
+ Managed Collectors health status on
+ Panorama displayed as empty.
+
+ |
+
|
+ PAN-259733
+ |
+
+
+ Fixed an issue where a custom report was not deleted on Panorama when
+ expected.
+
+ |
+
|
+ PAN-259480
+ |
+
+
+ Fixed an issue where the
+ varrcvr
+ process stopped responding after running out of memory due to how the
+ process queued and dequeued files for WildFire file forwarding when a
+ WildFire Analysis Security profile was enabled.
+
+ |
+
|
+ PAN-257615
+ |
+
+
+ Fixed an issue on Panorama where logs did not display or displayed
+ intermittently on the web interface.
+
+ |
+
|
+ PAN-257462
+ |
+
+
+ Fixed an issue related to the
+ varrcvr
+ process where the management plane CPU was higher than expected during
+ WildFire updates.
+
+ |
+
|
+ PAN-257028
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where firewalls entered a non-functional state and
+ displayed the error message
+ Dataplane down: path monitor failure during the fail-over.
+
+ |
+
|
+ PAN-255711
+ |
+
+
+ Fixed an issue where the firewall displayed a malformed request error
+ when selecting a custom format and clicking
+ OK on the configuration window due
+ to the log type
+ Correlation incorrectly being
+ displayed (Device > Log Setting - Correlation > Syslog Server Profile
+ > Custom Log Format > Correlation).
+
+ |
+
|
+ PAN-254373
+ |
+
+
+ Fixed an issue where the firewall did not handle error code 500
+ responses from the WildFire cloud correctly.
+
+ |
+
|
+ PAN-225213
+ |
+
+
+ Fixed an issue where
+ Push All Changes displayed changes
+ that were already committed in the push scope for another device group
+ after performing a selective commit and selective push to the first
+ device group.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-279604
+ |
+
+
+ Fixed an issue where scheduled SaaS application usage reports were
+ generated incorrectly, and the login page was displayed instead of the
+ report content.
+
+ |
+
|
+ PAN-278088
+ |
+
+
+ Fixed an issue where the
+ show system resources follow CLI
+ command was not available.
+
+ |
+
|
+ PAN-274791
+ |
+
+
+ Fixed an issue where the firewall rebooted when Shared Pool Type 32
+ was depleted and traffic matched advanced features.
+
+ |
+
|
+ PAN-274592
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where the firewall did not fail over when the active firewall
+ experienced data plane issues.
+
+ |
+
|
+ PAN-273994
+ |
+
+
+ A fix was made to address
+ CVE-2025-0111.
+
+ |
+
|
+ PAN-273971
+ |
+ + A fix was made to address + CVE-2025-0108. + | +
|
+ PAN-273278
+ |
+ + A fix was made to address + CVE-2025-0109. + | +
|
+ PAN-273129
+ |
+
+
+ Fixed an issue on the web interface where the
+ negate option was visible when you
+ clicked on the rule name, but not when you viewed the target options
+ from the rulebase attribute.
+
+ |
+
|
+ PAN-273085
+ |
+
+
+ Fixed an issue on the web interface where you were unable to edit or
+ create policy rules.
+
+ |
+
|
+ PAN-273026
+ |
+
+
+ Fixed an issue where traffic logs did not display correctly when
+ filters were applied.
+
+ |
+
|
+ PAN-273019
+ |
+
+
+ Fixed an intermittent issue where SSL decryption failed.
+
+ |
+
|
+ PAN-272959
+ |
+
+
+ Fixed an issue where the firewall generated BGP update packets larger
+ than 1500 bytes when the interface MTU was 1500 bytes and jumbo frames
+ were enabled globally.
+
+ |
+
|
+ PAN-272006
+ |
+
+
+ Fixed an issue where the firewall did not trigger a kernel core dump
+ as a large core when the CPLD (Complex Programmable Logic Device) sent
+ a Non-Maskable Interrupt (NMI) to the CPU.
+
+ |
+
|
+ PAN-271937
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ the
+ logrcvr
+ process stopped responding when processing logs from a large number of
+ sources.
+
+ |
+
|
+ PAN-271926
+ |
+
+
+ Fixed an issue where TLS 1.3 decryption failed with a bad record MAC
+ error when the firewall was configured to decrypt and inspect TLS
+ traffic.
+
+ |
+
|
+ PAN-270549
+ |
+
+
+ Fixed an issue where some TLS connections were not handled correctly,
+ which led to instability in the dataplane.
+
+ |
+
|
+ PAN-270471
+ |
+
+
+ (Firewalls in active/active configurations only) Fixed an issue where the firewall did not detect configuration
+ changes when only the interface of an IKE gateway was changed, which
+ caused IPSec tunnels to not come up after migrating the IKE gateway IP
+ address from a subinterface to a physical interface.
+
+ |
+
|
+ PAN-270077
+ |
+
+
+ (VM-Series firewalls in Amazon Web Services (AWS) environments
+ only) Fixed an issue template values were missing in newly spun firewalls
+ in auto scale deployments without an explicit push with forced
+ template values from Panorama.
+
+ |
+
|
+ PAN-269731
+ |
+
+
+ Fixed an issue where Panorama did not display logs from firewalls
+ after upgrading to PAN-OS 10.2.11 on devices due to Elasticsearch (ES)
+ getting restarted continuously.
+
+ |
+
|
+ PAN-269539
+ |
+
+
+ Fixed an issue where whitespace was added before the timestamp in
+ syslog logs forwarded from Panorama.
+
+ |
+
|
+ PAN-269499
+ |
+
+
+ Fixed an issue where the firewall stopped responding when receiving a
+ high number of logs.
+
+ |
+
|
+ PAN-269106
+ |
+
+
+ Fixed issue where the
+ wifclient restarted and multiple
+ processes stopped responding.
+
+ |
+
|
+ PAN-268909
+ |
+
+
+ Fixed an issue where IP address tags were removed from firewalls after
+ a management server or
+ useridd
+ process restart. This occurred when a Panorama serial-number based
+ configuration was used for User-ID redistribution.
+
+ |
+
|
+ PAN-268815
+ |
+
+
+ Fixed an issue where the firewall entered a non-functional state due
+ to duplicate entries in the shared memory.
+
+ |
+
|
+ PAN-268727
+ |
+
+
+ Fixed an issue where traffic was dropped when the accumulation proxy
+ was enabled and header insertion modified packets.
+
+ |
+
|
+ PAN-267781
+ |
+
+
+ Fixed an issue where Panorama did not display the Source Dynamic
+ Address Group.
+
+ |
+
|
+ PAN-267762
+ |
+
+
+ (Panorama virtual appliances in Management-Only mode) Fixed a issue where the maximum configuration size was lower than
+ expected.
+
+ |
+
|
+ PAN-267671
+ |
+ + Fixed an issue where the firewall rebooted unexpectedly due to the + all_task + process restarting with an OOM condition due to a memory leak on the + reportd + process. + | +
|
+ PAN-267430
+ |
+
+
+ Fixed an issue where Panorama was unable to return logs for queries
+ that were longer than 64,000 characters.
+
+ |
+
|
+ PAN-267097
+ |
+
+
+ Fixed an issue where the replay database size increased significantly
+ due to local and special configurations not being purged after
+ commits.
+
+ |
+
|
+ PAN-266581
+ |
+
+
+ Fixed an issue where a failed SSL connection to a syslog server
+ resulted in a
+ /tmp/srvr.crt.xxxxxx file not
+ being removed, which caused index node (inode) exhaustion.
+
+ |
+
|
+ PAN-266559
+ |
+
+
+ Fixed an issue where partial commits failed when objects that were
+ referenced in a high number of Security policy rules were renamed.
+
+ |
+
|
+ PAN-266354
+ |
+
+
+ Fixed an issue where Hybrid-SWG explicit proxy connections failed when
+ the number of destination domains exceeded 1024.
+
+ |
+
|
+ PAN-265745
+ |
+
+
+ Fixed an issue where the firewall displayed incorrect MAC receive
+ error counters for VMWare devices hosted in ESXi.
+
+ |
+
|
+ PAN-265179
+ |
+
+
+ Fixed an issue where a kernel race condition caused the firewall to
+ reboot with a kernel panic.
+
+ |
+
|
+ PAN-265160
+ |
+
+
+ Fixed an issue where the firewall created multiple connections to a
+ syslog server and remained in the FINWAIT1 state, which caused logs to
+ drop while being forwarded to the syslog server.
+
+ |
+
|
+ PAN-264369
+ |
+
+
+ Fixed an issue where the
+ 7 Day Threat Report was empty in the
+ scheduled reports sent via email.
+
+ |
+
|
+ PAN-263291
+ |
+
+
+ Fixed an issue where Microsoft Outlook did not work as expected when
+ the GlobalProtect clientless VPN was configured.
+
+ |
+
|
+ PAN-262627
+ |
+
+
+ Fixed an issue where the firewall rebooted into maintenance mode due
+ to a service failure in the
+ configd
+ process.
+
+ |
+
|
+ PAN-262383
+ |
+
+
+ Fixed an issue where the firewall was unable to decompress the HTTP2
+ header, which caused the session to be classified as unknown-tcp
+ instead of web-browsing.
+
+ |
+
|
+ PAN-262254
+ |
+
+
+ Fixed an issue where the firewall experienced an OOM condition and the
+ useridd
+ process stopped responding, which caused the firewall to drop
+ interfaces from their respective aggregate groups.
+
+ |
+
|
+ PAN-261998
+ |
+
+
+ Fixed an issue where the firewall configuration process restarted
+ during an External Dynamic List refresh or a commit and push
+ operation.
+
+ |
+
|
+ PAN-260290
+ |
+
+
+ Fixed an issue for fixed model licenses to support new content size
+ requirements by reducing the total sessions supported to be equivalent
+ to their flex memory counterpart
+
+ |
+
|
+ PAN-260149
+ |
+
+
+ Fixed an issue where the management plane DNS cache size was lower
+ than expected.
+
+ |
+
|
+ PAN-259055
+ |
+
+
+ Fixed an issue where the firewall stopped responding when receiving
+ SNMPv3 traps.
+
+ |
+
|
+ PAN-258996
+ |
+
+
+ Fixed an issue where the firewall displayed the SFP ports as
+ PowerDown when the SFP
+ transceiver was removed and reinserted or the port was shut down and
+ brought back up on the peer device.
+
+ |
+
|
+ PAN-257390
+ |
+
+
+ (PA-5250 firewalls only) Fixed an issue where
+ the
+ logrcvr
+ process stopped responding due to a segmentation fault.
+
+ |
+
|
+ PAN-256669
+ |
+
+
+ Fixed an issue where the memory usage reported by SNMP did not match
+ the memory usage reported by the top command.
+
+ |
+
|
+ PAN-255773
+ |
+
+
+ Fixed an issue where errors related to applications in
+ Content-preview caused commit
+ failures.
+
+ |
+
|
+ PAN-255747
+ |
+
+
+ Fixed an issue on the firewall where CLI commands returned
+ Server error: op command for client dagger timed out as client is
+ not available.
+
+ |
+
|
+ PAN-255653
+ |
+
+
+ Fixed an HA failover issue where, when Management Processing Card
+ (MPC) or Base Card (BC) failures occurred, the HA link went down,
+ which caused fpp-down events on one firewall.
+
+ |
+
|
+ PAN-253485
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where dataplane packet capture filter configuration
+ failed on the active firewall with the error
+ op command for client dagger timed out as client is not
+ available.
+
+ |
+
|
+ PAN-252669
+ |
+
+
+ Fixed an issue where the
+ ikemgr
+ process stopped responding with a SIGSEGV error.
+
+ |
+
|
+ PAN-252036
+ |
+
+
+ Fixed an issue where, when the GlobalProtect portal was not
+ configured, accessing the GlobalProtect gateway still loaded a portal
+ malformed page.
+
+ |
+
|
+ PAN-252224
+ |
+
+
+ Fixed an issue where Panorama did not forward logs to a syslog server
+ over an SSL connection using CRL as a revocation verification method.
+
+ |
+
|
+ PAN-250585
+ |
+
+
+ Fixed an issue where the firewall CPU use increased after upgrading
+ from PAN-OS 10.2.4-h4 to PAN-OS 10.2.8 due to a change in system
+ resource reporting by the REST API.
+
+ |
+
|
+ PAN-246209
+ |
+
+
+ Fixed an issue where IPSec VPN tunnels went down after receiving a
+ DHCP server message that the DHCP client cleared the IP address on the
+ interface.
+
+ |
+
|
+ PAN-242739
+ |
+
+
+ Fixed an issue on the firewall where the dataplane repeatedly
+ restarted.
+
+ |
+
|
+ PAN-240225
+ |
+
+
+ Fixed an issue where authentication failed on web-based GlobalProtect
+ portal.
+
+ |
+
|
+ PAN-238594
+ |
+
+
+ Fixed an issue where the firewall rebooted when a QSFP28 cable was
+ removed from the port while the port was passing traffic.
+
+ |
+
|
+ PAN-232833
+ |
+
+
+ Fixed an issue where the following error message displayed for IoT
+ trial licenses:
+ IoT Security license is required for the feature to function.
+
+ |
+
|
+ PAN-232550
+ |
+
+
+ Fixed an issue where SNMPv3 authentication failed when using SHA-512
+ Auth protocol.
+
+ |
+
|
+ PAN-225228
+ |
+
+
+ Fixed an issue where filtering threat logs using any value under
+ THREAT ID/NAME displayed the error
+ Invalid term.
+
+ |
+
|
+ PAN-218873
+ |
+
+
+ Fixed an issue where a HIP mask was reused when an existing IP address
+ user mapping was updated by a new IP address user mapping that had a
+ different username but the same IP address.
+
+ |
+
|
+ PAN-216054
+ |
+
+
+ Fixed an issue that caused the firewall's fan speed to increase while
+ it was idle.
+
+ |
+
|
+ PAN-214430
+ |
+
+
+ Fixed an issue where some commands did not have executable
+ permissions.
+
+ |
+
|
+ PAN-212197
+ |
+
+
+ Fixed an issue where you were able to create local administrator
+ usernames that contained only numbers.
+
+ |
+
|
+ PAN-207972
+ |
+
+
+ Fixed an issue on the web interface where the BGP routing table did
+ not display advertised routes.
+
+ |
+
|
+ PAN-193285
+ |
+
+
+ Fixed an issue where the policy optimizer feature did not add entries
+ back to the mongodb database
+ after removing them during an upgrade or downgrade.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-282236
+ |
+ + Fixed an issue where large IPv6 packets were reassembled on the firewall + when the packets arrived fragmented over an IPv4 tunnel. + | +
|
+ PAN-280471
+ |
+
+
+ Fixed an issue where navigating
+
+ was slower than expected.
+
+ |
+
|
+ PAN-279746
+ |
+
+
+ Fixed an issue where SMTP packets were not sent out when the Client
+ Hello arrived at the firewall in multiple out-of-order segments and
+ the traffic was not subject to SSL decryption.
+
+ |
+
|
+ PAN-279191
+ |
+
+
+ Fixed an issue where a GlobalProtect gateway stopped responding when
+ handling HTTP/1.1 traffic with web inspection enabled.
+
+ |
+
|
+ PAN-278684
+ |
+
+
+ (PA-445 firewalls only) Fixed an issue where
+ the firewall did not properly power cycle during a reboot.
+
+ |
+
|
+ PAN-275905
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected and Elasticsearch CPU usage was high.
+
+ |
+
|
+ PAN-275032
+ |
+
+
+ Fixed an issue where the Elasticsearch cluster certificate (CC) status
+ displayed with a past expiration date, which caused all shards to be
+ unassigned.
+
+ |
+
|
+ PAN-273141
+ |
+
+
+ Fixed an issue where GlobalProtect clients experienced slow file
+ transfer download throughput when passing through an IPSec tunnel.
+
+ |
+
|
+ PAN-272085
+ |
+
+
+ Fixed an issue where the firewall might crash and reboot when DoH is
+ enabled for DNS Security and multiple DoH transactions are sent in a
+ single HTTP/1 connection.
+
+ |
+
|
+ PAN-270744
+ |
+
+
+ Fixed an issue where API calls to Panorama failed with the error
+ Server error : Timed out while getting config lock. Please try
+ again.
+
+ |
+
|
+ PAN-268279
+ |
+
+
+ Fixed an issue where autocommits failed if the management IPv6 gateway
+ was the same as the dataplane interface IP address.
+
+ |
+
|
+ PAN-242130
+ |
+
+
+ Fixed an issue where the firewall displayed the speed and duplex of
+ its dataplane interfaces as
+ Unknown even though the link was up.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-282022
+ |
+
+
+ Fixed the support limitation for the Panorama M-600 and M-700
+ appliances.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-282022
+ |
+
+
+ Fixed the support limitation for the Panorama M-600 and M-700
+ appliances.
+
+ |
+
|
+ PAN-281885
+ |
+
+
+ Fixed an issue where, when exporting and importing CSV files, the hash
+ values of pre-shared key variables set at template and template stack
+ levels changed inconsistently, which resulted in both variables
+ displaying the same hash value.
+
+ |
+
|
+ PAN-280505
+ |
+
+
+ Fixed an issue where the web interface did not display a message to
+ commit prior changes before attempting a partial configuration load.
+
+ |
+
|
+ PAN-280243
+ |
+
+
+ Fixed an issue where the firewall lost the pre-shared key
+ configuration assigned from a PSK variable when an unrelated device
+ group configuration was loaded.
+
+ |
+
|
+ PAN-279336
+ |
+
+
+ Fixed an issue where the CLI did not display a message to commit prior
+ changes before loading a partial configuration.
+
+ |
+
|
+ PAN-279176
+ |
+
+
+ Fixed an issue where the configuration audit displayed inaccurate
+ information after partially loading the configuration via the CLI,
+ which caused the audit to flag the configuration as deleted or
+ changed.
+
+ |
+
|
+ PAN-277762
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ unexpected failovers occurred on firewalls running PAN-OS 11.2.2-h2.
+
+ |
+
|
+ PAN-275713
+ |
+
+
+ Fixed an issue where the
+ dscd
+ process stopped responding when
+ Endpoint Serial Number was enabled,
+ which resulted in the
+ Active Directory returning a list of
+ serial numbers for a specific firewall from the Cloud Identity Engine.
+
+ |
+
|
+ PAN-275077
+ |
+
+
+ Fixed an issue where DNS Security intermittently logs malicious domain
+ URLs as Alert instead of taking a Sinkhole action, even when
+ configured to Sinkhole malicious DNS domains.
+
+ |
+
|
+ PAN-274750
+ |
+
+
+ Fixed an issue where the detailed log view in Panorama did not display
+ all packet details for traffic logs received from the cloud.
+
+ |
+
|
+ PAN-273694
+ |
+
+
+ Fixed an issue where the firewall rebooted due to an out-of-bounds
+ memory access that occurred as a result of the SIP content length
+ value being split across packets.
+
+ |
+
|
+ PAN-272538
+ |
+
+
+ Fixed an issue where the
+ configd
+ process stopped responding during a commit-all validation when there
+ were uncommitted changes and
+ share-unused-objects-with-devices
+ was set to off.
+
+ |
+
|
+ PAN-272171
+ |
+
+
+ Fixed an issue where the firewall dropped the AAAA DNS server response
+ and caused delays in traffic from Ubuntu or Linux clients when DNS
+ Security was enabled.
+
+ |
+
|
+ PAN-270607
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where OSPF failed to establish after a failover from
+ the active firewall to the passive firewall.
+
+ |
+
|
+ PAN-271351
+ |
+
+
+ A fix was made to address
+ CVE-2025-0116.
+
+ |
+
|
+ PAN-267091
+ |
+
+
+ Fixed an issue on Panorama where Elasticsearch repeatedly restarted.
+
+ |
+
|
+ PAN-264678
+ |
+
+
+ Fixed an issue where
+ Preview Changes did not display
+ configuration changes in
+ Commit and push > Push Scope.
+
+ |
+
|
+ PAN-262511
+ |
+
+
+ Fixed an issue on firewalls in HA configurations where OSPF neighbors
+ were not established after an HA failover.
+
+ |
+
|
+ PAN-261825
+ |
+
+
+ Fixed an issue where traffic was dropped when Data Loss Prevention or
+ Advanced URL Filtering were enabled. This occurred when the payload
+ size was greater than 3.5 KB.
+
+ |
+
|
+ PAN-259706
+ |
+
+
+ Fixed an issue on Panorama where the web interface was slower than
+ expected or unresponsive when monitoring definitions were added in the
+ Kubernetes plugin.
+
+ |
+
|
+ PAN-257183
+ |
+
+
+ Fixed an issue where the firewall dropped DNS traffic when using DNS
+ Security.
+
+ |
+
|
+ PAN-254174
+ |
+
+
+ A fix was made to address
+ CVE-2025-0115.
+
+ |
+
|
+ PAN-248762
+ |
+
+
+ Fixed an issue where, when the Advanced Routing Engine was configured
+ with OSPF, the firewall stopped responding when attempting to connect
+ to the neighbor while exchanging route maps.
+
+ |
+
|
+ PAN-239201
+ |
+
+
+ Fixed an issue where partial commit or partial validation operations
+ failed for non-super user administrators with the error
+ <device-group-name> is invalid. meta data not found for dg
+ <device-group-name>.
+
+ |
+
|
+ PAN-235733
+ |
+
+
+ Fixed an issue where the displayed NTP information was incorrect if
+ the DNS servers timed out.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-286255
+ |
+
+
+ Fixed an issue where, when the firewall received an unexpected
+ termination request for SSL sessions, the dataplane experienced a slow
+ buffer resource leak.
+
+ |
+
|
+ PAN-282069
+ |
+
+
+ Fixed an issue on Panorama where Security policy rules were removed
+ from device groups when you cloned or edited Security policy rules
+ that used more than 63 characters.
+
+ |
+
|
+ PAN-280942
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process stopped responding.
+
+ |
+
|
+ PAN-273949
+ |
+
+
+ Fixed an issue where the firewall generated the following error
+ message in the
+ snmpd
+ logs:
+ pan_get_keystr_from_cryptod(pan_snmpinterface.c:181): Key
+ X2F1dGhfa2V5 import from cryptod failed.
+
+ |
+
|
+ PAN-271273
+ |
+
+
+ Fixed an issue where dynamic update downloads failed when
+ IPv6 firewalling was enabled on the
+ firewall and both IPv4 and IPv6 were configured on the management
+ interface.
+
+ |
+
|
+ PAN-270193
+ |
+
+
+ Fixed an issue where the Panorama management server changed its
+ certificate authority (CA) unexpectedly, which caused managed
+ firewalls to disconnect.
+
+ |
+
|
+ PAN-268614
+ |
+
+
+ Fixed an issue on the web interface where, when all rules were
+ highlighted when a read-only admin user clicked the
+ Highlight Unused Rules checkbox.
+
+ |
+
|
+ PAN-265621
+ |
+
+
+ Fixed an issue where the
+ restart option for IPSec tunnels was
+ greyed out when you attempted to restart the tunnel from
+ .
+
+ |
+
|
+ PAN-260300
+ |
+
+
+ (PA-5410, PA-5420, PA-5430, PA-5440 and PA-5445 firewalls only) Fixed an issue related to the
+ all_pktproc
+ process where DPC slot 3 stopped responding.
+
+ |
+
|
+ PAN-259535
+ |
+
+
+ Fixed an issue where the firewall failed to boot up after running
+ power cycle tests due to
+ ehmon
+ process heartbeat failures.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-292261
+ |
+
+
+ Fixed an issue where the firewall repeatedly reported an unreachable
+ syslog server as back online when
+ the server remained unavailable. This resulted in misleading
+ alternating connection status messages in the system logs.
+
+ |
+
|
+ PAN-287423
+ |
+
+
+ Fixed an issue where content loading issues occurred on IPv6 websites
+ due to the firewall incorrectly setting the IPv6 header flow label to
+ 0.
+
+ |
+
|
+ PAN-286255
+ |
+
+
+ Fixed an issue where, when the firewall received an unexpected
+ termination request for SSL sessions, the dataplane experienced a slow
+ buffer resource leak.
+
+ |
+
|
+ PAN-282069
+ |
+
+
+ Fixed an issue on Panorama where Security policy rules were removed
+ from device groups when you cloned or edited Security policy rules
+ that used more than 63 characters.
+
+ |
+
|
+ PAN-280942
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process stopped responding.
+
+ |
+
|
+ PAN-280698
+ |
+
+
+ Fixed an issue where the firewall removed the TCP timestamp from
+ client hello messages that did not fit in a single packet, which
+ resulted in connection issues.
+
+ |
+
|
+ PAN-279901
+ |
+
+
+ An issue was fixed where the firewall dropped fragmented TLS
+ ClientHello packets, which blocked access to certain websites. This
+ occurred because the packets arrived truncated, in varying sizes and
+ orders, and the firewall's heuristics failed to handle them correctly.
+
+
+ To enable this fix, run:
+ debug dataplane set ssl-decrypt accumulate-client-hello disjoined
+ yes.
+
+ |
+
|
+ PAN-273949
+ |
+
+
+ Fixed an issue where the firewall generated the following error
+ message in the
+ snmpd
+ logs:
+ pan_get_keystr_from_cryptod(pan_snmpinterface.c:181): Key
+ X2F1dGhfa2V5 import from cryptod failed.
+
+ |
+
|
+ PAN-271273
+ |
+
+
+ Fixed an issue where dynamic update downloads failed when
+ IPv6 firewalling was enabled on the
+ firewall and both IPv4 and IPv6 were configured on the management
+ interface.
+
+ |
+
|
+ PAN-270193
+ |
+
+
+ Fixed an issue where the Panorama management server changed its
+ certificate authority (CA) unexpectedly, which caused managed
+ firewalls to disconnect.
+
+ |
+
|
+ PAN-268614
+ |
+
+
+ Fixed an issue on the web interface where, when all rules were
+ highlighted when a read-only admin user clicked the
+ Highlight Unused Rules checkbox.
+
+ |
+
|
+ PAN-265621
+ |
+
+
+ Fixed an issue where the
+ restart option for IPSec tunnels was
+ greyed out when you attempted to restart the tunnel from
+ .
+
+ |
+
|
+ PAN-260300
+ |
+
+
+ (PA-5410, PA-5420, PA-5430, PA-5440 and PA-5445 firewalls only) Fixed an issue related to the
+ all_pktproc
+ process where DPC slot 3 stopped responding.
+
+ |
+
|
+ PAN-259535
+ |
+
+
+ Fixed an issue where the firewall failed to boot up after running
+ power cycle tests due to
+ ehmon
+ process heartbeat failures.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-301801
+ |
+
+
+ Fixed an issue on Log Collectors where the Elasticsearch process
+ fluctuated intermittently between green and red states, which led to
+ interruptions in log collection. This issue occurred when the number
+ of shards exceeded the cluster's maximum supported threshold of
+ greater than 1000 shards per Elasticsearch instance.
+
+ |
+
|
+ PAN-292159 and PAN-271216
+ |
+
+
+ A fix was made to address
+ CVE-2025-4615.
+
+ |
+
|
+ PAN-291661
+ |
+
+
+ Fixed an issue on Panorama appliances and Log Collectors where, after
+ an upgrade, Elasticsearch intermittently entered into a Red state
+ before automatically recovering.
+
+ |
+
|
+ PAN-286164
+ |
+
+
+ A fix was made to address
+ CVE-2025-4614.
+
+ |
+
|
+ PAN-282093
+ |
+
+
+ Enhanced the CLI command
+ request legacy reset to delete
+ the legacy certificate files that were being used to connect with the
+ secondary Panorama appliance.
+
+ |
+
|
+ PAN-278296
+ |
+
+
+ Fixed an issue where the system MAC address of the aggregate interface
+ was the same on the active firewall and the passive firewall after an
+ upgrade.
+
+ |
+
|
+ PAN-272539
+ |
+
+
+ (Panorama appliances on Microsoft Azure environments only) Fixed an issue where user to IP address mapping was missing for
+ some users connected to specific Prisma Access gateways, which caused
+ the collection layer Azure firewall to not form the mapping.
+
+ |
+
|
+ PAN-271221
+ |
+
+
+ A fix was made to address
+ CVE-2025-4615.
+
+ |
+
|
+ PAN-251715
+ |
+
+
+ Fixed an issue where the firewall closed the SSL connection to the
+ user ID agent.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-265963
+ |
+
+
+ Fixed an issue where the
+ escd
+ process caused a memory leak when session resiliency was enabled on
+ the firewall.
+
+ |
+
|
+ PAN-265349
+ |
+
+
+ Fixed an issue where multiple segments of HTTP proxy connect messages
+ were not handled correctly by proxy.
+
+ |
+
|
+ PAN-264421
+ |
+
+
+ Fixed an issue on Panorama where
+ Push Scope did not populate
+ automatically after changing the device group configuration.
+
+ |
+
|
+ PAN-263987
+ |
+
+
+ Fixed an issue on the firewall where, when a NAT transversal IPSec
+ tunnel was terminated, and the NAT rule that was applied to the NAT-T
+ IPSec tunnel was on the same firewall, traffic flowing through the
+ tunnel was not correctly translated.
+
+ |
+
|
+ PAN-263559
+ |
+
+
+ Fixed an issue where the dataplane stopped responding and the firewall
+ unexpectedly rebooted due to multiple process restarts.
+
+ |
+
|
+ PAN-263226
+ |
+
+
+ Fixed an issue where, when SSL decryption was enabled and Client Hello
+ messages spanned multiple TCP segments, some SSL decrypted sessions
+ failed.
+
+ |
+
|
+ PAN-262593
+ |
+
+
+ Fixed an issue where traffic to websites failed on the Google Chrome
+ web browser on Secure Web Gateway (SWG) nodes.
+
+ |
+
|
+ PAN-262340
+ |
+
+
+ Fixed an issue where FQDN resolution failed for address objects, and
+ all FQDN traffic was denied by the interzone-default policy rule.
+
+ |
+
|
+ PAN-262287
+ |
+
+
+ Fixed an issue where dereferencing a NULL pointer that occurred when
+ App-ID stopped responding caused the firewall to restart.
+
+ |
+
|
+ PAN-261991
+ |
+
+
+ Fixed an issue where traffic that did not match a decryption policy
+ rule, or matched a no-decrypt policy rule, failed when accumulation
+ proxy was enabled and a Zone Protection profile was configured with
+ syn-cookies enabled.
+
+ |
+
|
+ PAN-261917
+ |
+
+
+ Fixed an issue where websites with a no-decrypt policy rule were
+ decrypted in traffic log when using a Google Chrome browser with PQC
+ enabled.
+
+ |
+
|
+ PAN-261909
+ |
+
+
+ Fixed an issue where the GlobalProtect client did not display the
+ dialog box for an MFA verification code.
+
+ |
+
|
+ PAN-261489
+ |
+
+
+ Fixed an issue where an out-of-memory (OOM) condition caused a
+ firewall outage.
+
+ |
+
|
+ PAN-261484
+ |
+
+
+ Fixed an issue on the firewall where DPDK allocated twice the amount
+ of memory as requested for pre-allocation.
+
+ |
+
|
+ PAN-261001
+ |
+
+
+ Fixed an issue where GlobalProtect users were unable to switch
+ gateways after upgrading to GlobalProtect version 6.2.3.
+
+ |
+
|
+ PAN-260974
+ |
+
+
+ Fixed an issue where the Cloud Identity Engine (CIE) user context did
+ not correctly redistribute user/IP address port mapping to on-premises
+ firewalls.
+
+ |
+
|
+ PAN-259997
+ |
+
+
+ (PA-3410, PA-3420, and PA-3430 firewalls only)
+ Fixed an issue where the install failed when upgrading from PAN-OS
+ 10.2.3-h3 and later 10.2 releases to PAN-OS 10.2.10 due to the number
+ of configured vsys zones exceeding the zone limit in PAN-OS 10.2.10.
+
+ |
+
|
+ PAN-259769
+ |
+
+
+ Fixed an issue where the GlobalProtect portal was not accessible via a
+ web browser and displayed the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-259151
+ |
+
+
+ Fixed an issue where unused objects were pushed to the firewall, which
+ caused configuration pushes to fail with the error
+ Number of address groups exceed platform capacity.
+
+ |
+
|
+ PAN-258736
+ |
+
+
+ Fixed an issue where policy rule configurations pushed from Panorama
+ were not reflected on the firewall if the rule had 63 characters.
+
+ |
+
|
+ PAN-258225
+ |
+
+
+ Fixed an issue on the Panorama web interface where Security policy
+ rules loaded more slowly than expected.
+
+ |
+
|
+ PAN-257957
+ |
+
+
+ (Firewalls and Panorama appliances in FIPS-CC mode only) Fixed an issue where the authd process
+ restarted if RADIUS PAP/CHAP authentication was used.
+
+ |
+
|
+ PAN-257925
+ |
+
+
+ (CN-Series firewalls only) Fixed an issue where
+ the CLI command
+ show system setting ctd state did
+ not work as expected.
+
+ |
+
|
+ PAN-256725
+ |
+
+
+ Fixed an issue on the Panorama interface where
+ Traffic and
+ Unified event details loaded more
+ slowly than expected.
+
+ |
+
|
+ PAN-256666
+ |
+
+
+ Fixed an issue where the configdprocess stopped
+ responding when Commit and Push operations were
+ performed on multiple device groups.
+
+ |
+
|
+ PAN-256385
+ |
+
+
+ (CN-Series firewalls only) Fixed an issue where
+ communication was broken between the management plane and the
+ dataplane when anti-spyware profiles were configured in a Security
+ policy rule.
+
+ |
+
|
+ PAN-256350
+ |
+
+
+ Fixed an issue where, when you cloned an admin role or an LDAP server
+ profile and then changed the name of the clone, the configuration
+ change was not reflected on the managed firewall after pushing the
+ configuration from Panorama.
+
+ |
+
|
+ PAN-256320
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where GTP sessions remained as allocated sessions on
+ the passive firewall even when there were no active sessions.
+
+ |
+
|
+ PAN-255930
+ |
+
+
+ Fixed an issue where persistent DIPP NAT entries were deleted even
+ when being used during an active session.
+
+ |
+
|
+ PAN-255266
+ |
+
+
+ Fixed an issue where you were unable to clone a template stack with
+ the Pre-Shared Key variable.
+
+ |
+
|
+ PAN-254826
+ |
+
+
+ Fixed an issue where the firewall stopped responding when processing
+ traffic.
+
+ |
+
|
+ PAN-254671
+ |
+
+
+ Fixed an issue where excessive
+ Timed out while getting config lock
+ error messages were generated when making bulk changes via XML API.
+
+ |
+
|
+ PAN-254423
+ |
+
+
+ Fixed an issue on Panorama where custom role-based admin users with
+ read only access were able to make changes to configurations.
+
+ |
+
|
+ PAN-253626
+ |
+
+
+ Fixed an issue on Panorama where unused objects were pushed to the
+ firewall, which caused the push operations to intermittently fail.
+
+ |
+
|
+ PAN-253213
+ |
+
+
+ Fixed an issue where the firewall sent HIP notifications every time it
+ received a HIP report instead of every two hours.
+
+ |
+
|
+ PAN-252300
+ |
+
+
+ Fixed an issue where you were unable to select device groups in the
+ push scope for user accounts.
+
+ |
+
|
+ PAN-251676
+ |
+
+
+ Fixed an issue on Panorama appliances in large-scale deployments where
+ configd
+ process core files consumed more space in the /opt/panlogs partition
+ than was available.
+
+ |
+
|
+ PAN-251655
+ |
+
+
+ Fixed an issue where the firewall stopped forwarding files to the
+ WildFire cloud and a restart of the
+ varrcvr
+ process was required.
+
+ |
+
|
+ PAN-250787
+ |
+
+
+ Fixed an issue where network issues between the firewall and the log
+ collector caused
+ logrcvr
+ process memory exhaustion.
+
+ |
+
|
+ PAN-250419
+ |
+
+
+ Fixed an issue where XML API explorer inserted a plus (+) character in
+ the Xpath when a space was used in the object name.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Fixed an issue where device telemetry failed after upgrading due to
+ bundle generation failure.
+
+ |
+
|
+ PAN-249266
+ |
+
+
+ Fixed an issue where the
+ config
+ process virtual memory was exceeded due to delays in post-commit
+ processing.
+
+ |
+
|
+ PAN-249011
+ |
+
+
+ Fixed an issue where the firewall became unresponsive when committing
+ a configuration change with a large number of uncommitted changes in
+ the replay database.
+
+ |
+
|
+ PAN-247099
+ |
+
+
+ Fixed an issue where the firewall decrypted traffic unexpectedly when
+ the client hello was spread across multiple packets.
+
+ |
+
|
+ PAN-246304
+ |
+
+
+ Fixed an issue on Panorama where commits failed due to a timeout in
+ the
+ sysd
+ process during decryption.
+
+ |
+
|
+ PAN-246220
+ |
+
+
+ Fixed an issue where a dynamic peer connection was rejected when using
+ an FQDN for the peer address.
+
+ |
+
|
+ PAN-244039
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ the firewall dropped packets when attempting to reuse a TCP session.
+
+ |
+
|
+ PAN-243098
+ |
+
+
+ Fixed an issue with corrupted images when SSL decryption and Security
+ profiles were configured.
+
+ |
+
|
+ PAN-241781
+ |
+
+
+ Fixed an issue where partial commit and commit-all operations took
+ more time than expected to create the job ID.
+
+ |
+
|
+ PAN-241044
+ |
+
+
+ Fixed an issue where traffic was denied by the interzone-default
+ policy rule when a Security policy rule with an FQDN destination was
+ configured.
+
+ |
+
|
+ PAN-234560
+ |
+
+
+ Fixed an issue where the daily summary report displayed IPv6 addresses
+ instead of IPv4 addresses.
+
+ |
+
|
+ PAN-233727
+ |
+
+
+ Fixed an issue on the web interface where the following error message
+ was incorrectly displayed for an IKE gateway with a valid
+ configuration:
+ ikev2->pq-ppk->negotiation-mode is invalid.
+
+ |
+
|
+ PAN-237582
+ |
+
+
+ Fixed an issue where logs were intermittently missing on the log
+ collector due to missing aliases for some indices
+
+ |
+
|
+ PAN-234094
+ |
+
+
+ Fixed an issue on Panorama where
+ Deploy Master Keyresulted in the error message
+ Failed to communicate with device due to a low connection timeout
+ value.
+
+ |
+
|
+ PAN-232214
+ |
+
+
+ Fixed an issue where GlobalProtect clients remained in the connecting
+ state during portal pre-login when Kerberos single sign-on (SSO) was
+ enabled.
+
+ |
+
|
+ PAN-230825
+ |
+
+
+ Fixed an issue where link flaps occurred on Panorama appliances in HA
+ configurations.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-272809
+ |
+ + + | +
|
+ PAN-268823
+ |
+
+
+ Fixed an issue where
+
+ did not display all logs when you applied a filter.
+
+ |
+
|
+ PAN-265785
+ |
+
+
+ Fixed an issue where the firewall rebooted due to a
+ sysd
+ variable being modified before it was created.
+
+ |
+
|
+ PAN-264883
+ |
+
+
+ (PA-7080 appliances with LPCs only) Fixed an
+ issue where syslog forwarding over TCP stopped after upgrading.
+
+ |
+
|
+ PAN-263369
+ |
+
+
+ Fixed an issue where commits from Panorama to Panorama virtual
+ appliances failed with the error message
+ Internal error during commit processing. Commit/Validate
+ failed
+ after upgrading Panorama.
+
+ |
+
|
+ PAN-261673
+ |
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where, when Accelerated Networking was enabled,
+ traffic was dropped because of the
+ flow_parse_ip_hdr counter related
+ to an Nvidia driver issue.
+
+ |
+
|
+ PAN-261371
+ |
+
+
+ (PA-5410 firewalls in active/passive high availability (HA)
+ configurations only) Fixed an issue where the
+ reportd
+ process restarted, which caused the firewall to reboot.
+
+ |
+
|
+ PAN-261209
+ |
+
+
+ (Firewalls in active/active HA configuration only) Fixed an issue where the firewall displayed the HA2 status as down
+ when the HSCI port was used for both HA2 and HA3.
+
+ |
+
|
+ PAN-260905
+ |
+
+
+ Fixed an issue where the HS: Fiber Port Eth1/2 did not come up on a
+ cold boot and remained in an incorrect state.
+
+ |
+
|
+ PAN-260316
+ |
+
+
+ Fixed an issue where the
+ all_task
+ process stopped responding and the firewall rebooted.
+
+ |
+
|
+ PAN-259351
+ |
+
+
+ A fix was made to address
+ CVE-2024-3393.
+
+ |
+
|
+ PAN-259002
+ |
+
+
+ Fixed an issue where frequent external dynamic list updates caused the
+ configd
+ process to restart.
+
+ |
+
|
+ PAN-257601
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ Networking Cards (NC) experienced an internal link fault which caused
+ path monitoring failure on the Dataplane Processing Card (DPC).
+
+ |
+
|
+ PAN-257327
+ |
+
+
+ Fixed an issue where a failover event occurred unexpectedly on the
+ firewall.
+
+ |
+
|
+ PAN-256223
+ |
+
+
+ Fixed an issue where device telemetry log collection filled the root
+ partition.
+
+ |
+
|
+ PAN-254794
+ |
+
+
+ Fixed an issue where the Panorama management server stopped
+ responding.
+
+ |
+
|
+ PAN-249384
+ |
+
+
+ Fixed an issue on Panorama where configuration locks were observed
+ during a partial rulebase commit.
+
+ |
+
|
+ PAN-243240
+ |
+
+
+ Fixed an issue where the using QoS caused packet buffer utilization to
+ increase exponentially and the
+ PKI POOL DFLT pool depleted until
+ a reboot was performed.
+
+ |
+
|
+ PAN-242479
+ |
+
+
+ Fixed an issue where a high number of packets caused high packet
+ descriptors on the firewall when handling EtherIP traffic.
+
+ |
+
|
+ PAN-230893
+ |
+
+
+ Added a CLI command to address an issue where system lock files
+ blocked authentication.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-273215
+ |
+
+
+ Fixed an issue where a syntax error in the index generation script
+ caused a high management plane CPU load after upgrading.
+
+ |
+
|
+ PAN-271912
+ |
+
+
+ Fixed an issue on Panorama where the *configd* process stopped
+ responding when filtering in the configuration audit window after
+ upgrading to PAN-OS 11.1.3.
+
+ |
+
|
+ PAN-271613
+ |
+
+
+ Fixed an issue where configuration pushes from Panorama to the
+ firewall failed due to an OOXML commit error.
+
+ |
+
|
+ PAN-271314
+ |
+
+
+ Fixed an issue where pushing changes to a prefix list used for BGP
+ from Panorama affected OSPF routes.
+
+ |
+
|
+ PAN-270224
+ |
+
+
+ Fixed an issue where indices were not opened after a query.
+
+ |
+
|
+ PAN-269956
+ |
+
+
+ Fixed an issue where the
+ all_pktproc
+ process stopped responding, which caused internal path monitor
+ failures.
+
+ |
+
|
+ PAN-269899
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected when querying for device tags.
+
+ |
+
|
+ PAN-269673
+ |
+
+
+ Fixed an issue where ElasticSearch was not set up after an upgrade.
+
+ |
+
|
+ PAN-269000
+ |
+
+
+ Fixed an issue where the firewall stopped responding due to a NULL
+ pointer dereference when path monitoring failed.
+
+ |
+
|
+ PAN-268972
+ |
+
+
+ Fixed an issue where Panorama was slower than expected when using a
+ high number of device group tags in a non-shared context.
+
+ |
+
|
+ PAN-268501
+ |
+
+
+ Fixed an issue where the firewall was unable to generate a TSF file
+ due to a full root partition.
+
+ |
+
|
+ PAN-266639
+ |
+
+
+ Fixed an issue where administrators were unable to edit or add virtual
+ router configurations when a filter was applied to the viewer.
+
+ |
+
|
+ PAN-266114
+ |
+
+
+ Fixed an issue where, when a new set of URL logs came in, the content
+ of the earlier URL and traffic logs were lost.
+
+ |
+
|
+ PAN-265973
+ |
+
+
+ Fixed an issue where administrator sessions were logged out with an
+ ERR_CONNECTION_REFUSED error on
+ the browser.
+
+ |
+
|
+ PAN-265742
+ |
+
+
+ Fixed an issue on the Panorama web interface where the
+ OK button on the GlobalProtect
+ gateway configuration dialog box was not clickable.
+
+ |
+
|
+ PAN-265219
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ GRE traffic did not work properly.
+
+ |
+
|
+ PAN-264871
+ |
+
+
+ Fixed an issue on Panorama where the
+ configd
+ process stopped responding when viewing IP addresses on dynamic
+ address groups with a large number of IP addresses.
+
+ |
+
|
+ PAN-264249
+ |
+
+
+ Fixed an issue on the firewall where SNMP queries timed out when using
+ SNMP.
+
+ |
+
|
+ PAN-263973
+ |
+
+
+ Fixed an issue where log collectors had a low incoming log rate.
+
+ |
+
|
+ PAN-263287
+ |
+
+
+ The PAN-COMMON-MIB.my file was updated to support new object
+ identifiers (OID) to poll interface use via SNMP with table
+ identifiers.
+
+ |
+
|
+ PAN-263208
+ |
+
+
+ (PA-5440 and PA-5445 firewalls only) Fixed an
+ issue where interrupts were generated at a certain packet rate, and
+ dataplane processes missed heartbeats, which caused the dataplane to
+ go down.
+
+ |
+
|
+ PAN-263017
+ |
+
+
+ Fixed an issue where the firewall was unable to mount a disk partition
+ due to a corrupted filesystem.
+
+ |
+
|
+ PAN-261485
+ |
+
+
+ Fixed an issue where the firewall dropped the Real Time Transport
+ Protocol (RTP) session for the second SIP call on Persistent-DIPP
+ connections when the source port of the client device was reset.
+
+ |
+
|
+ PAN-260604
+ |
+
+
+ Fixed an issue where the firewall displayed inaccurate throughput
+ utilization stats in NetFlow analyzer tools.
+
+ |
+
|
+ PAN-260512
+ |
+
+
+ Fixed an issue where accessing the IP address of the device address
+ group objects from the user interface caused the
+ configd
+ process to stop responding.
+
+ |
+
|
+ PAN-260461
+ |
+
+
+ Fixed an issue where traffic logs showed a non-zero destination port
+ number on ICMP echo sessions through the firewall.
+
+ |
+
|
+ PAN-260417
+ |
+
+
+ Fixed an issue on Panorama where
+ UpdateLicDB was triggered every
+ few minutes when firewalls with PAYG licenses were onboarded.
+
+ |
+
|
+ PAN-260235
+ |
+
+
+ Fixed an issue where the firewall sent Threat logs and URL logs to an
+ external syslog server without Security profile settings when Enhanced
+ Application Logging was enabled.
+
+ |
+
|
+ PAN-259910
+ |
+
+
+ Fixed an issue where the firewall reported the same value over
+ consecutive SNMP polls when asynchronous mode was enabled.
+
+ |
+
|
+ PAN-259881
+ |
+
+
+ Fixed an issue on Panorama where traffic log details were not
+ displayed under detailed log view.
+
+ |
+
|
+ PAN-259802
+ |
+
+
+ (Panorama appliances in high availability (HA) clusters only) Fixed an issue where, after replacing a secondary Panorama
+ appliance in a Panorama HA cluster, the ElasticSearch cluster was
+ unable to establish SSL tunnels due to SSLHandshakeException errors.
+
+ |
+
|
+ PAN-259078
+ |
+
+
+ Fixed an issue where WildFire Analysis reports were not generated and
+ the following error message was displayed:
+ Error 500: Internal Server Error.
+
+ |
+
|
+ PAN-258799
+ |
+
+
+ Fixed an issue where, when updating a Security Policy
+ Policy Optimizer, the web interface
+ stopped responding.
+
+ |
+
|
+ PAN-257961
+ |
+
+
+ Fixed an issue on Panorama where
+ Test Security Policy Match failed
+ when the From or
+ To zone fields were populated.
+
+ |
+
|
+ PAN-255915
+ |
+
+
+ Fixed an issue where a memory leak in the
+ sslmgr
+ process caused the firewall to restart.
+
+ |
+
|
+ PAN-254904
+ |
+
+
+ Fixed an issue on Panorama where a core file was generated by
+ /usr/local/bin/logd during a restart.
+
+ |
+
|
+ PAN-254577
+ |
+
+
+ Fixed an issue where a core file was created on the Log Forwarding
+ Card (LFC) due to a third-party software issue.
+
+ |
+
|
+ PAN-253829
+ |
+
+
+ Fixed an issue where the CLI command
+ show running security-policy
+ timed out when the Security policy was large.
+
+ |
+
|
+ PAN-252381
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected when opening interfaces, virtual routers, and zones in a
+ template or template stack.
+
+ |
+
|
+ PAN-250394
+ |
+
+
+ Fixed an issue where a large amount of group data caused serialization
+ errors and prevented synchronization.
+
+ |
+
|
+ PAN-249581
+ |
+
+
+ Fixed an issue where stale BGP routes were advertised to peers even
+ when they were not present in the local RIB table.
+
+ |
+
|
+ PAN-246699
+ |
+
+
+ Fixed an issue on Panorama where the
+ Rule Usage and
+ Apps Seen under Security policy
+ rules stopped incrementing.
+
+ |
+
|
+ PAN-246567
+ |
+
+
+ Fixed an issue where a firewall with a copper SFP transceiver
+ (PAN-SFP-CG) flapped during a commit.
+
+ |
+
|
+ PAN-242331
+ |
+
+
+ Fixed an issue where Prisma Access remote network firewalls
+ intermittently created incorrect user-to-IP-address mappings.
+
+ |
+
|
+ PAN-241004
+ |
+
+
+ Fixed an issue where DNS Proxy dropped client requests of the type
+ ns for a root domain.
+
+ |
+
|
+ PAN-235808
+ |
+
+
+ (Panorama appliances in Log Collector mode only) Fixed an issue where an unnamed core file was generated after a
+ reboot.
+
+ |
+
|
+ PAN-233197
+ |
+
+
+ Fixed an issue where the CLI command to set the FEC parameter for the
+ front panel ports was not supported on platforms supporting 25G and
+ 100G.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-256181
+ |
+
+
+ Fixed an issue where the management interface and front panel port
+ interface statistics were not populated in asynchronous mode of SNMP
+ operations.
+
+ |
+
|
+ PAN-255868
+ |
+
+
+ (PA-3400 Series firewalls only) Fixed an issue
+ where the firewall entered maintenance mode after enabling kernel data
+ collection during the silent reboot.
+
+ |
+
|
+ PAN-253317
+ |
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where you were unable to log in to the firewall
+ after a private data reset.
+
+ |
+
|
+ PAN-252517
+ |
+
+
+ Fixed an issue where SNMP failed to respond to multiple Object
+ Identifier (OID) queries in a single SNMP GET request.
+
+ |
+
|
+ PAN-251639
+ |
+
+
+ Fixed an issue where an out of memory condition might occur due to a
+ memory leak in the
+ varrcvr
+ process when a Wildfire Analysis security profile is enabled.
+
+ |
+
|
+ PAN-250597
+ |
+
+
+ Fixed an issue where Global Find for a Panorama pushed shared address
+ object displayed Others in the
+ results.
+
+ |
+
|
+ PAN-250270
+ |
+
+
+ Fixed an issue where partial commits did not merge changes when the
+ complete rule base was updated with edit operations via XML API.
+
+ |
+
|
+ PAN-249814
+ |
+
+
+ Fixed an issue where multiple
+ all_task
+ processes stopped responding, which caused the dataplane to fail.
+
+ |
+
|
+ PAN-249292
+ |
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where CPU usage was higher than expected after a
+ hotplug event when Accelerated Networking was enabled for the
+ management interface.
+
+ |
+
|
+ PAN-245157
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the firewall restarted after an HA failover
+ when DPDK was enabled.
+
+ |
+
|
+ PAN-245125
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where file descriptors were not closed due to
+ invalid configurations.
+
+ |
+
|
+ PAN-244746
+ |
+
+
+ Fixed an issue where changes committed on Panorama were not reflected
+ on the firewall after a successful push.
+
+ |
+
|
+ PAN-238183
+ |
+
+
+ Fixed an issue where Panorama displayed deviating device system logs
+ for non-connected interfaces.
+
+ |
+
|
+ PAN-236497
+ |
+
+
+ Fixed an issue where the firewall was unable to purge expired GTP-U
+ sessions that remained as allocated sessions even after the TTL was
+ expired.
+
+ |
+
|
+ PAN-234977
+ |
+
+
+ Fixed an issue where, when a Layer 2 interface that was a member of a
+ VLAN was down, all traffic transmitted over the VLAN was dropped.
+
+ |
+
|
+ PAN-231642
+ |
+
+
+ Fixed an issue on the Panorama web interface where users that were
+ logged in through multiple sessions were able to see an active lock on
+ only one session.
+
+ |
+
|
+ PAN-214773
+ |
+
+
+ Fixed an issue where RTP packets traversing inter-vsys were dropped on
+ the outgoing vsys.
+
+ |
+
|
+ PAN-202095
+ |
+
+
+ Fixed an issue on the web interface where the language setting was not
+ retained.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-272809
+ |
+ + + | +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-268823
+ |
+
+
+ Fixed an issue where
+ Monitor > Log Display did not
+ display all logs when you applied a filter.
+
+ |
+
|
+ PAN-265963
+ |
+
+
+ Fixed an issue where the
+ escd
+ process caused a memory leak when session resiliency was enabled on
+ the firewall.
+
+ |
+
|
+ PAN-265785
+ |
+
+
+ Fixed an issue where the firewall rebooted due to a
+ sysd
+ variable being modified before it was created.
+
+ |
+
|
+ PAN-265462
+ |
+
+
+ Fixed an issue where you were unable to download PDFs when connected
+ via a Clientless VPN.
+
+ |
+
|
+ PAN-265344
+ |
+
+
+ Fixed an issue where
+ Import GlobalProtect Client Package
+ did not work after clicking OK after
+ selecting a valid package under
+ Device > GlobalProtect Client > Upload).
+
+ |
+
|
+ PAN-265287
+ |
+
+
+ Fixed an issue where the firewall experienced a packet buffer leak in
+ the dataplane of the network processing card (NPC) when processing
+ certain net messages.
+
+ |
+
|
+ PAN-264806
+ |
+
+
+ (PA-3440 firewalls only) Fixed an issue where
+ the firewall was unable to validate or commit a configuration when it
+ was imported from another firewall model.
+
+ |
+
|
+ PAN-264369
+ |
+
+
+ Fixed an issue where the
+ 7 Day Threat Report was empty in the
+ scheduled reports sent via email.
+
+ |
+
|
+ PAN-264249
+ |
+
+
+ Fixed an issue on the firewall where SNMP queries timed out when using
+ SNMP.
+
+ |
+
|
+ PAN-263987
+ |
+
+
+ Fixed an issue on the firewall where, when a NAT transversal IPSec
+ tunnel was terminated, and the NAT rule that was applied to the NAT-T
+ IPSec tunnel was on the same firewall, traffic flowing through the
+ tunnel was not correctly translated.
+
+ |
+
|
+ PAN-263956
+ |
+
+
+ (PA-440 firewalls only) Fixed an issue where a
+ firewall running PAN-OS 11.1.2-h3 only displayed the
+ Auto option for the interface duplex
+ setting.
+
+ |
+
|
+ PAN-263505
+ |
+
+
+ (PA-850 firewalls only) Fixed an issue where
+ the firewall stopped responding and rebooted after upgrading to PAN-OS
+ 11.1.4.
+
+ |
+
|
+ PAN-263287
+ |
+
+
+ The PAN-COMMON-MIB.my file was updated to support new object
+ identifiers (OID) to poll interface use via SNMP with table
+ identifiers.
+
+ |
+
|
+ PAN-263278
+ |
+
+
+ Fixed an issue where the management interface flapped when IPv6 was
+ disabled and DHCPv6 was enabled.
+
+ |
+
|
+ PAN-263226
+ |
+
+
+ Fixed an issue where, when SSL decryption was enabled and Client Hello
+ messages spanned multiple TCP segments, some SSL decrypted sessions
+ failed.
+
+ |
+
|
+ PAN-263164
+ |
+
+
+ Fixed an issue where Netflow User ID information was truncated to 31
+ characters.
+
+ |
+
|
+ PAN-262902
+ |
+
+
+ Fixed an issue on the web interface where cloning region objects did
+ not work.
+
+ |
+
|
+ PAN-262593
+ |
+
+
+ Fixed an issue where traffic to websites failed on the Google Chrome
+ web browser on Secure Web Gateway (SWG) nodes.
+
+ |
+
|
+ PAN-262415
+ |
+
+
+ Fixed an issue where a partial configuration load failed for
+ configuration files that contained
+ regenerate-hostkeys.
+
+ |
+
|
+ PAN-262410
+ |
+
+
+ Fixed an issue where the
+ App Scope graph did not display for
+ all days when selecting
+ Last 60 days or
+ Last 90 days.
+
+ |
+
|
+ PAN-262340
+ |
+
+
+ Fixed an issue where FQDN resolution failed for address objects, and
+ all FQDN traffic was denied by the interzone-default policy rule.
+
+ |
+
|
+ PAN-262287
+ |
+
+
+ Fixed an issue where dereferencing a NULL pointer that occurred when
+ App-ID stopped responding caused the firewall to restart.
+
+ |
+
|
+ PAN-262254
+ |
+
+
+ Fixed an issue where the firewall experienced an OOM condition and the
+ useridd
+ process stopped responding, which caused the firewall to drop
+ interfaces from their respective aggregate groups.
+
+ |
+
|
+ PAN-261991
+ |
+
+
+ Fixed an issue where traffic that did not match a decryption policy
+ rule, or matched a no-decrypt policy rule, failed when accumulation
+ proxy was enabled and a Zone Protection profile was configured with
+ syn-cookies enabled.
+
+ |
+
|
+ PAN-261935
+ |
+
+
+ Fixed an issue where the firewall unexpectedly rebooted when replacing
+ or inserting SFPs from an old firewall into a new RMA firewall.
+
+ |
+
|
+ PAN-261831
+ |
+
+
+ (Firewalls in HA configuration only) Fixed an
+ issue where link-down events did not occur after an HA failover.
+
+ |
+
|
+ PAN-261671
+ |
+
+
+ Fixed an issue where GlobalProtect clients randomly fell back to the
+ SSL tunnel as the gateway dropped the initial three keepalive packets.
+
+ |
+
|
+ PAN-261639
+ |
+
+
+ Fixed an issue where the firewall incorrectly logged the XFF IP in
+ threat logs when a single HTTP header was used.
+
+ |
+
|
+ PAN-261489
+ |
+
+
+ Fixed an issue where an out-of-memory (OOM) condition caused a
+ firewall outage.
+
+ |
+
|
+ PAN-261485
+ |
+
+
+ Fixed an issue where the firewall dropped the Real Time Transport
+ Protocol (RTP) session for the second SIP call on Persistent-DIPP
+ connections when the source port of the client device was reset.
+
+ |
+
|
+ PAN-261484
+ |
+
+
+ Fixed an issue on the firewall where DPDK allocated twice the amount
+ of memory as requested for pre-allocation.
+
+ |
+
|
+ PAN-261371
+ |
+
+
+ (PA-5410 firewalls in active/passive HA configurations only) Fixed an issue where the
+ reportd
+ process restarted, which caused the firewall to reboot.
+
+ |
+
|
+ PAN-261209
+ |
+
+
+ (Firewalls in active/active HA configuration only) Fixed an issue where the firewall displayed the HA2 status as down
+ when the HSCI port was used for both HA2 and HA3.
+
+ |
+
|
+ PAN-261174
+ |
+
+
+ Fixed an issue on Panorama where importing a certificate for a
+ template stack configuration incorrectly prompted for a passphrase as
+ a required field.
+
+ |
+
|
+ PAN-261028
+ |
+
+
+ Fixed an issue where the firewall did not autocommit after a reboot
+ when the cellular interface was configured as a local interface for
+ the IPSec Satellite and the IP address was allocated dynamically.
+
+ |
+
|
+ PAN-261019
+ |
+
+
+ Fixed an issue where Evasive Empire C2 Traffic Detection generated
+ benign verdicts and max latency timeout logs simultaneously when the
+ MICA ATP action was configured as
+ reset-both.
+
+ |
+
|
+ PAN-260974
+ |
+
+
+ Fixed an issue where the Cloud Identity Engine (CIE) user context did
+ not correctly redistribute user/IP address port mapping to on-premises
+ firewalls.
+
+ |
+
|
+ PAN-260928
+ |
+
+
+ Fixed an issue where GlobalProtect failed to connect when using LDAP
+ authentication with machine certificates with the error message
+ You are not authorized to connect to GlobalProtect portal.
+
+ |
+
|
+ PAN-260905
+ |
+
+
+ Fixed an issue where the HS: Fiber Port Eth1/2 did not come up on a
+ cold boot and remained in an incorrect state.
+
+ |
+
|
+ PAN-260842
+ |
+
+
+ A CLI command was introduced to address an issue where TCP packets
+ were out of order.
+
+ |
+
|
+ PAN-260633
+ |
+
+
+ Fixed an issue where the firewall did not send a client certificate
+ after a TLS Certificate Request when establishing a secure syslog
+ connection.
+
+ |
+
|
+ PAN-260546
+ |
+
+
+ (PA-440 firewalls only) Fixed an issue where
+ the system clock reset to the epoch date and time after 8 to 12 weeks
+ of shelf life or no power.
+
+ |
+
|
+ PAN-260512
+ |
+
+
+ Fixed an issue where accessing the IP address of the device address
+ group objects from the user interface caused the
+ configd
+ process to stop responding.
+
+ |
+
|
+ PAN-260316
+ |
+
+
+ Fixed an issue where the
+ all_task
+ process stopped responding and the firewall rebooted.
+
+ |
+
|
+ PAN-260218
+ |
+
+
+ Fixed an issue where BGP Aggregate Advertise filters did not work as
+ expected when the summary option was enabled, and only summarized
+ routes were advertised.
+
+ |
+
|
+ PAN-260193
+ |
+
+
+ Fixed an issue where GlobalProtect on macOS clients did not connect
+ when using a client certificate and the X.509 policy was set to
+ Use System Default.
+
+ |
+
|
+ PAN-260132
+ |
+
+
+ Fixed an issue where secondary IP addresses with a /32 prefix
+ configured on Layer 3 interfaces were not reachable in FRR mode.
+
+ |
+
|
+ PAN-260114
+ |
+
+
+ Fixed an issue where the firewall generated a
+ devsrvr
+ core file when processes were restarted.
+
+ |
+
|
+ PAN-259910
+ |
+
+
+ Fixed an issue where the firewall reported the same value over
+ consecutive SNMP polls when asynchronous mode was enabled.
+
+ |
+
|
+ PAN-259883
+ |
+
+
+ Fixed an issue where the firewalls behind an Amazon Web Services (AWS)
+ Gateway Load Balancer (GWLB) stopped responding when processing GENEVE
+ packets with the reserved bit set.
+
+ |
+
|
+ PAN-259881
+ |
+
+
+ Fixed an issue on Panorama where traffic log details were not
+ displayed under detailed log view.
+
+ |
+
|
+ PAN-259802
+ |
+
+
+ (Panorama appliances in HA clusters only) Fixed
+ an issue where, after replacing a secondary Panorama appliance in a
+ Panorama HA cluster, the ElasticSearch cluster was unable to establish
+ SSL tunnels due to SSLHandshakeException errors.
+
+ |
+
|
+ PAN-259769
+ |
+
+
+ Fixed an issue where the GlobalProtect portal was not accessible via a
+ web browser and displayed the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-259706
+ |
+
+
+ Fixed an issue on Panorama where the web interface was slower than
+ expected or unresponsive when monitoring definitions were added in the
+ Kubernetes plugin.
+
+ |
+
|
+ PAN-259535
+ |
+
+
+ Fixed an issue where the firewall failed to boot up after running
+ power cycle tests due to
+ ehmon
+ process heartbeat failures.
+
+ |
+
|
+ PAN-259370
+ |
+
+
+ Fixed an issue on the web interface where
+ Correlation Log Detail > Match Evidence
+ did not populate.
+
+ |
+
|
+ PAN-259351
+ |
+
+
+ A fix was made to address
+ CVE-2024-3393.
+
+ |
+
|
+ PAN-259344
+ |
+
+
+ Fixed an issue where performing a configuration commit on a firewall
+ locally or from Panorama caused a memory leak related to the
+ configd
+ process and resulted in an OOM condition.
+
+ |
+
|
+ PAN-259200
+ |
+
+
+ Fixed an issue where the firewall displayed truncated zone names in
+ the Block IP List log when a zone
+ name contained more than 14 characters.
+
+ |
+
|
+ PAN-259151
+ |
+
+
+ Fixed an issue where unused objects were pushed to the firewall, which
+ caused configuration pushes to fail with the error
+ Number of address groups exceed platform capacity.
+
+ |
+
|
+ PAN-259002
+ |
+
+
+ Fixed an issue where frequent external dynamic list updates caused the
+ configd
+ process to restart.
+
+ |
+
|
+ PAN-258996
+ |
+
+
+ Fixed an issue where the firewall displayed the SFP ports as
+ PowerDown when the SFP
+ transceiver was removed and reinserted or the port was shut down and
+ brought back up on the peer device.
+
+ |
+
|
+ PAN-258757
+ |
+
+
+ Fixed an issue on Panorama where upgrades failed with validation
+ errors.
+
+ |
+
|
+ PAN-258734
+ |
+
+
+ Fixed an issue where virtual wire ports did not go down when moving
+ from an active state to a suspended state.
+
+ |
+
|
+ PAN-258576
+ |
+
+
+ Fixed an issue on the Panorama web interface where products in HIP
+ objects were not displayed correctly.
+
+ |
+
|
+ PAN-258442
+ |
+
+
+ Fixed an issue where changes made to the split tunnel configuration on
+ the Prisma Access gateway were not reflected on the GlobalProtect
+ client.
+
+ |
+
|
+ PAN-258240
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where HA path monitoring did not work as expected when using
+ vwire.
+
+ |
+
|
+ PAN-258225
+ |
+
+
+ Fixed an issue on the Panorama web interface where Security policy
+ rules loaded more slowly than expected.
+
+ |
+
|
+ PAN-258188
+ |
+
+
+ Fixed an issue on Panorama Template where the virtual wire
+ subinterface page did not display all fields and the
+ OK button did not work.
+
+ |
+
|
+ PAN-258166
+ |
+
+
+ (PA-220 firewalls only) Fixed an issue where
+ the root partition frequently reached 100%.
+
+ |
+
|
+ PAN-257961
+ |
+
+
+ Fixed an issue on Panorama where
+ Test Security Policy Match failed
+ when the From or
+ To zone fields were populated.
+
+ |
+
|
+ PAN-257957
+ |
+
+
+ (Firewalls and Panorama appliances in FIPS-CC mode only) Fixed an issue where the
+ authd
+ process restarted if RADIUS PAP/CHAP authentication was used.
+
+ |
+
|
+ PAN-257925
+ |
+
+
+ (CN-Series firewalls only) Fixed an issue where
+ the CLI command
+ show system setting ctd state did
+ not work as expected.
+
+ |
+
|
+ PAN-257912
+ |
+
+
+ Fixed an issue where the firewall stopped responding when it received
+ RADIUS traffic and user equipment (UE) traffic at the same time on a
+ Network Processing Card (NPC)
+
+ |
+
|
+ PAN-257747
+ |
+
+
+ Fixed an issue where the firewall incorrectly displayed the error
+ message
+ IoT Security license is required for feature to function
+ even when the firewall had a valid Enterprise IoT security license.
+
+ |
+
|
+ PAN-257660
+ |
+
+
+ Fixed an issue where show commands were hidden for superusers in
+ read-only roles.
+
+ |
+
|
+ PAN-257652
+ |
+
+
+ Fixed an issue where Internal Host Detection for IPv6 did not work
+ after upgrading to a PAN-OS 10.2 release.
+
+ |
+
|
+ PAN-257638
+ |
+
+
+ Fixed an issue where the firewall dataplane stopped responding, which
+ caused BGP flaps between hubs and branches.
+
+ |
+
|
+ PAN-257624
+ |
+
+
+ Fixed an issue where the firewall web interface was blank after
+ logging in.
+
+ |
+
|
+ PAN-257619
+ |
+
+
+ Fixed an issue on Panorama where the
+ Task Manager took longer than
+ expected to display managed FW report tasks details when its empty
+
+ |
+
|
+ PAN-257601
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ Networking Cards (NC) experienced an internal link fault which caused
+ path monitoring failure on the Dataplane Processing Card (DPC).
+
+ |
+
|
+ PAN-257600
+ |
+
+
+ Fixed an issue where the firewall returned a 404 error for all sites
+ accessed through the clientless VPN portal.
+
+ |
+
|
+ PAN-257432
+ |
+
+
+ Fixed an issue on Panorama where the
+ reportd
+ process stopped responding, which caused a log query issue.
+
+ |
+
|
+ PAN-257390
+ |
+
+
+ (PA-5250 firewalls only) Fixed an issue where
+ the
+ logrcvr
+ process stopped responding due to a segmentation fault.
+
+ |
+
|
+ PAN-257327
+ |
+
+
+ (PA-5440 firewalls only) Fixed an issue where a
+ failover event occurred unexpectedly on the firewall.
+
+ |
+
|
+ PAN-257267
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ observed warning message during commit completion & critical
+ system log when configuration size exceeded the maximum recommended
+ configuration size.
+
+ |
+
|
+ PAN-257117
+ |
+
+
+ Fixed an issue where CSV or PDF exports of zones did not contain all
+ zones.
+
+ |
+
|
+ PAN-257028
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where firewalls entered a non-functional state and
+ displayed the error message
+ Dataplane down: path monitor failure during the fail-over.
+
+ |
+
|
+ PAN-257021
+ |
+
+
+ "Fixed an issue on the web interface where
+ Match Evidence log details for
+ Monitor > Correlated events did
+ not populate."
+
+ |
+
|
+ PAN-256960
+ |
+
+
+ Fixed an issue where a custom portal login page was not displayed
+ correctly in the GlobalProtect portal when using a customized portal
+ landing page.
+
+ |
+
|
+ PAN-256939
+ |
+
+
+ Fixed an issue on the firewall where disk space was low in
+ /opt/pancfg/, which caused
+ dynamic content installation to fail.
+
+ |
+
|
+ PAN-256738
+ |
+
+
+ (VM-Series firewalls in HA configurations only)
+ Fixed an issue where BGP routes from the active firewall were lost
+ when the passive firewall was rebooted.
+
+ |
+
|
+ PAN-256725
+ |
+
+
+ Fixed an issue on the Panorama interface where
+ Traffic and
+ Unified event details loaded more
+ slowly than expected.
+
+ |
+
|
+ PAN-256669
+ |
+
+
+ Fixed an issue where the memory usage reported by SNMP did not match
+ the memory usage reported by the top command.
+
+ |
+
|
+ PAN-256666
+ |
+
+
+ Fixed an issue where the
+ configd
+ process stopped responding when
+ Commit and Push operations were
+ performed on multiple device groups.
+
+ |
+
|
+ PAN-256652
+ |
+
+
+ Fixed an issue where content updates were processed incorrectly, which
+ caused a mismatch between a Threat ID's signature and its
+ corresponding action.
+
+ |
+
|
+ PAN-256518
+ |
+
+
+ Fixed an issue where Panorama was unable to push firmware updates to a
+ VM-Series firewall with a PAYG license.
+
+ |
+
|
+ PAN-256449
+ |
+
+
+ Fixed an issue where DHCPv6 relay was not working in Advanced Routing
+ mode when the firewall was configured as a DHCP relay agent.
+
+ |
+
|
+ PAN-256385
+ |
+
+
+ (CN-Series firewalls only) Fixed an issue where
+ communication was broken between the management plane and the
+ dataplane when anti-spyware profiles were configured in a Security
+ policy rule.
+
+ |
+
|
+ PAN-256362
+ |
+
+
+ Fixed an issue in Panorama where shared address objects used in the
+ GlobalProtect configuration agents were not considered as used and not
+ pushed to Firewall that causes commit-all failure error
+
+ |
+
|
+ PAN-256350
+ |
+
+
+ Fixed an issue where, when you cloned an admin role or an LDAP server
+ profile and then changed the name of the clone, the configuration
+ change was not reflected on the managed firewall after pushing the
+ configuration from Panorama.
+
+ |
+
|
+ PAN-256327
+ |
+
+
+ (Panorama virtual appliances on Microsoft Azure environments
+ only) Fixed an issue where the
+ logd
+ process repeatedly restarted due to a buffer overflow when generating
+ a traffic summary from a traffic log.
+
+ |
+
|
+ PAN-256249
+ |
+
+
+ Fixed an issue on the web interface that occurred when changing the
+ pre-shared key to a variable (Network > Network Profiles > IKE Gateways).
+
+ |
+
|
+ PAN-256223
+ |
+
+
+ Fixed an issue where device telemetry log collection filled the root
+ partition.
+
+ |
+
|
+ PAN-256115
+ |
+
+
+ Fixed an issue where, after replacing a Panorama appliance or log
+ collector, the secondary Panorama appliance or log collector displayed
+ a disconnected status for the
+ inter-log collector connection.
+
+ |
+
|
+ PAN-256051
+ |
+
+
+ Fixed an issue on the firewall where enabling flow basic caused the
+ firewall to stop responding due to a
+ masterd
+ process restart.
+
+ |
+
|
+ PAN-255930
+ |
+
+
+ Fixed an issue where persistent DIPP NAT entries were deleted even
+ when being used during an active session.
+
+ |
+
|
+ PAN-255895
+ |
+
+
+ Fixed an issue where Panorama administrators with the
+ Panorama Administrator dynamic
+ administrator type were not able to create or modify BGP timer
+ profiles or BGP dampening profiles.
+
+ |
+
|
+ PAN-255820
+ |
+
+
+ Fixed an issue where the WildFire signature generation check box in
+ Panorama did not register a change in the configuration.
+
+ |
+
|
+ PAN-255773
+ |
+
+
+ Fixed an issue where errors related to applications in
+ Content-preview caused commit
+ failures.
+
+ |
+
|
+ PAN-255711
+ |
+
+
+ Fixed an issue where the firewall displayed a malformed request error
+ when selecting a custom format and clicking
+ OK on the configuration window due
+ to the log type
+ Correlation incorrectly being
+ displayed (Device > Log Setting - Correlation > Syslog Server Profile
+ > Custom Log Format > Correlation).
+
+ |
+
|
+ PAN-255660
+ |
+
+
+ (Firewalls in active/active HA configurations only) Fixed an issue where the path monitor displayed as up even when
+ routes to the destination IP address were removed.
+
+ |
+
|
+ PAN-255579
+ |
+
+
+ (PA-7500 Series firewalls and Panorama appliances only) Fixed an issue where dataplane logs were displayed after a delay.
+
+ |
+
|
+ PAN-255396
+ |
+
+
+ Fixed an issue where, when using serial number and IP address
+ authentication, and multiple gateways were configured, the portal
+ returned the last gateway in the list and disregarded the satellite
+ assignment by serial number.
+
+ |
+
|
+ PAN-255391
+ |
+
+
+ Fixed an issue where the firewall was unable to filter logs using the
+ ISO 8601 timestamp format after upgrading to PAN-OS 11.0.4 or a later
+ release.
+
+ |
+
|
+ PAN-255360
+ |
+
+
+ Fixed an issue where the firewall booted into maintenance mode when
+ there was no connectivity to the specified hardware security module
+ (HSM).
+
+ |
+
|
+ PAN-255285
+ |
+
+
+ Fixed an issue where, when only the HSCI-A link was connected on
+ firewall cluster nodes, and the management interface went down, a
+ split brain condition occurred.
+
+ |
+
|
+ PAN-255282
+ |
+
+
+ (PA-450 firewalls in HA configurations only)
+ Fixed an issue where the firewall remained in an active state and all
+ traffic stopped until a failover to the passive firewall was
+ performed.
+
+ |
+
|
+ PAN-255252
+ |
+
+
+ Fixed an issue where Panorama administrators with the type Dynamic
+ were unable to create, modify, or delete BGP Dampening profiles.
+
+ |
+
|
+ PAN-255163
+ |
+
+
+ (CN-Series firewalls only) Fixed an issue where
+ the system database key that stored the configuration status of the
+ dataplane pod was not updated frequently.
+
+ |
+
|
+ PAN-255116
+ |
+
+
+ Fixed an issue where, when QoS was enabled, traffic on an NGFW cluster
+ node that went from an MC-LAG interface to a destination stopped when
+ a member of the MC-LAG went down.
+
+ |
+
|
+
+ 254927
+
+ |
+
+
+ (PA-7500 Series firewalls only) Fixed an issue
+ where data packets sent to threat inspection processing on the
+ networking card caused the
+ pan_task
+ process to stop responding.
+
+ |
+
|
+ PAN-254901
+ |
+
+
+ Fixed an issue where GlobalProtect user-to-IP address mapping was
+ removed even though the tunnel for the specific user was up and
+ traffic was being passed.
+
+ |
+
|
+ PAN-254875
+ |
+
+
+ (PA-410 firewalls only) Fixed an issue where
+ the firewall rebooted unexpectedly due to multiple
+ all_task
+ process restarts.
+
+ |
+
|
+
+ PAN-254827
+
+ |
+
+
+ Fixed an issue where, when you changed an IP address on a management
+ interface on an NGFW cluster node, commit-all operations did not push
+ the updated IP address.
+
+ |
+
|
+ PAN-254826
+ |
+
+
+ Fixed an issue where the firewall stopped responding when processing
+ traffic.
+
+ |
+
|
+ PAN-254797
+ |
+
+
+ (PA-5400 Series firewalls only) Fixed an issue
+ where you were unable to use SNMP polling o monitor the status of
+ power supply units.
+
+ |
+
|
+ PAN-254704
+ |
+
+
+ (LSVPN Portal firewalls in active/passive HA configurations only) Fixed an issue where the satellite cookie key did not sync between
+ LSVPN portal HA firewalls, which resulted in re-authentication of
+ satellites with the portal during the event of HA failover.
+
+ |
+
|
+ PAN-254671
+ |
+
+
+ Fixed an issue where excessive
+ Timed out while getting config lock
+ error messages were generated when making bulk changes via XML API.
+
+ |
+
|
+ PAN-254629
+ |
+
+
+ Fixed an issue on the Management Processing Card where excessive logs
+ were generated for an error.
+
+ |
+
|
+ PAN-254577
+ |
+
+
+ Fixed an issue where a core file was created on the Log Forwarding
+ Card due to a third-party software issue.
+
+ |
+
|
+ PAN-254423
+ |
+
+
+ Fixed an issue on Panorama where custom role-based admin users with
+ read only access were able to make changes to configurations.
+
+ |
+
|
+ PAN-254422
+ |
+
+
+ Fixed an issue where the firewall required a restart when an SD-WAN
+ policy rule was pushed from Panorama.
+
+ |
+
|
+ PAN-254351
+ |
+
+
+ Fixed an issue where an NGFW cluster node remained in a suspended
+ state when GRE tunnel termination was used with keepalive enabled on
+ both ends.
+
+ |
+
|
+ PAN-254301
+ |
+
+
+ Fixed an issue where GlobalProtect logs showed the public IPv4 address
+ in the private IPv4 address field for logs generated during
+ portal/gateway negotiation.
+
+ |
+
|
+ PAN-254241
+ |
+
+
+ Fixed an issue where the firewall stopped responding due to a high
+ number of SD-WAN probes being sent.
+
+ |
+
|
+ PAN-254181
+ |
+
+
+ (CN-Series firewalls only) Fixed an issue where
+ firewall pods and application pods repeatedly restarted.
+
+ |
+
|
+ PAN-254124
+ |
+
+
+ (PA-7050 firewalls with DPC and 100G NPCs only)
+ Fixed an issue on the firewall where you were unable to change the
+ flow key type from tag to tuple.
+
+ |
+
|
+ PAN-253829
+ |
+
+
+ Fixed an issue where the CLI command
+ show running security-policy
+ timed out when the Security policy was large.
+
+ |
+
|
+ PAN-253819
+ |
+
+
+ Fixed an issue where a
+ User Activity Report was not
+ generated by Run Now or not emailed
+ through the Email Schedule when the
+ locale setting was not English.
+
+ |
+
|
+ PAN-253626
+ |
+
+
+ Fixed an issue on Panorama where unused objects were pushed to the
+ firewall, which caused the push operations to intermittently fail.
+
+ |
+
|
+ PAN-253584
+ |
+
+
+ Fixed an issue where ikemgr process unexpectedly stopped due to a
+ memory mapping in an incorrect location.
+
+ |
+
|
+ PAN-253557
+ |
+
+
+ Fixed an issue where, after a cluster manager restart on the leader
+ node of an NGFW cluster, traffic stopped due to only the state machine
+ transitioning to unknown and not the leader.
+
+ |
+
|
+ PAN-253452
+ |
+
+
+ Fixed an issue where GlobalProtect users were unable to connect to the
+ GlobalProtect gateway and received the error
+ Gateway does not exist.
+
+ |
+
|
+ PAN-253466
+ |
+
+
+ Fixed an issue where, on NFGW cluster nodes, an expected packet buffer
+ leak occurred with FTP/SIP traffic over an extended period of time.
+
+ |
+
|
+ PAN-253250
+ |
+
+
+ Fixed an issue where, when ASPath Prepend was configured, AS override
+ did not work.
+
+ |
+
|
+ PAN-253085
+ |
+
+
+ Fixed an issue where the firewall restarted when the parsing of the
+ cross-pkt http origin header failed when processing a translator
+ website.
+
+ |
+
|
+ PAN-252974
+ |
+
+
+ (PA-450 firewalls only) Fixed an issue where
+ specific routes were not advertised when BGP Aggregate was configured
+ with the advertise filter.
+
+ |
+
|
+ PAN-252867
+ |
+
+
+ Fixed an issue where an incorrect memory reference in an IoT API
+ caused the wifclient process to
+ stop responding.
+
+ |
+
|
+ PAN-252816
+ |
+
+
+ Fixed an issue where multiple SSHD process restarts triggered a
+ firewall reboot when the login banner and SSH host keys were updated
+ at the same time.
+
+ |
+
|
+ PAN-252801
+ |
+
+
+ Fixed an issue where the LSVPN tunnel monitoring status displayed as
+ No data available after re-key
+ events.
+
+ |
+
|
+ PAN-252411
+ |
+
+
+ Fixed an issue where, when log files were purged from the rollup
+ summary logs, the summary report still used the rollup summary data,
+ which resulted in the summary report displaying less data.
+
+ |
+
|
+ PAN-252370
+ |
+
+
+ Fixed an issue where services with the reserved keyword
+ application-default were allowed.
+
+ |
+
|
+ PAN-252270
+ |
+
+
+ Fixed an issue on the firewall where changes were incorrectly applied
+ after a reboot or a restart of the
+ configd
+ process.
+
+ |
+
|
+ PAN-252224
+ |
+
+
+ Fixed an issue where Panorama did not forward logs to a syslog server
+ over an SSL connection using CRL as a revocation verification method.
+
+ |
+
|
+ PAN-252161
+ |
+
+
+ Fixed an issue where the
+ gp_broker
+ process stopped responding.
+
+ |
+
|
+ PAN-252131
+ |
+
+
+ (PA-5200 Series and PA-7000 Series firewalls only) Fixed an issue where an unsupported SFP caused the firewall to
+ restart.
+
+ |
+
|
+ PAN-252036
+ |
+
+
+ Fixed an issue where, when the GlobalProtect portal was not
+ configured, accessing the GlobalProtect gateway still loaded a portal
+ malformed page.
+
+ |
+
|
+ PAN-252029
+ |
+
+
+ Fixed an issue where the firewall stopped responding when processing
+ authentication requests.
+
+ |
+
|
+ PAN-251929
+ |
+
+
+ Fixed an issue where inbound decryption did not work when FIPS self
+ tests were turned on.
+
+ |
+
|
+ PAN-251732
+ |
+
+
+ Fixed an issue where Oracle traffic over generic routing encapsulation
+ (GRE) was dropped when the traffic passed through the firewall using
+ tunnel content inspection (TCI).
+
+ |
+
|
+ PAN-251684
+ |
+
+
+ Fixed an issue where the LEDs for copper ports lighted up when SFP
+ links were up.
+
+ |
+
|
+ PAN-251676
+ |
+
+
+ Fixed an issue on Panorama appliances in large-scale deployments where
+ configd
+ process core files consumed more space in the /opt/panlogs partition
+ than was available.
+
+ |
+
|
+ PAN-251661
+ |
+
+
+ Fixed an issue where a memory overwrite occurred during HTTP/2 header
+ inflation.
+
+ |
+
|
+ PAN-251656
+ |
+
+
+ Fixed an issue where enabling lockless QoS caused traffic disruptions.
+
+ |
+
|
+ PAN-251501
+ |
+
+
+ Fixed an issue where, after a reboot, NGFW cluster nodes failed to
+ rejoin a cluster due to a timing issue.
+
+ |
+
|
+ PAN-251372
+ |
+
+
+ Fixed an issue where a policy-based forwarding (PBF) did not work for
+ a server-to-client (S-C) flow when the source port was specified.
+
+ |
+
|
+ PAN-251035
+ |
+
+
+ Fixed an issue where selective push operations did not push
+ certificate changes to the firewall.
+
+ |
+
|
+ PAN-250948
+ |
+
+
+ Fixed an issues where GlobalProtect on Microsoft Windows devices did
+ not attempt CNAME resolution for sinkhole.paloaltonetworks.com.
+
+ |
+
|
+ PAN-250909
+ |
+
+
+ Fixed an issue where, when creating a Security policy rule via the
+ CLI, validation was not implemented and the same object was able to be
+ referenced in the policy twice.
+
+ |
+
|
+ PAN-250756
+ |
+
+
+ Fixed an issue where querying threat logs using the threat name, such
+ as generic:<site> did not
+ work.
+
+ |
+
|
+ PAN-250716
+ |
+
+
+ Fixed an issue where
+ Panorama > Push to Devices
+ displayed device group and template entries that had been changed by
+ other administrators.
+
+ |
+
|
+ PAN-250703
+ |
+
+
+ Fixed an issue where the task manager failed with a 504 error when a
+ large number of previous jobs or tasks were present.
+
+ |
+
|
+ PAN-250530
+ |
+
+
+ Fixed an issue where management traffic routed via the dataplane was
+ being decrypted instead of bypassing the decryption lookup.
+
+ |
+
|
+ PAN-250462
+ |
+
+
+ Fixed an issue where the session logout time for the firewall was
+ incorrect when viewing via context switch from Panorama.
+
+ |
+
|
+ PAN-250455
+ |
+
+
+ Fixed an issue where GlobalProtect portal authentication incorrectly
+ timed out after 30 seconds when the timeout value was set to 1 minute.
+
+ |
+
|
+ PAN-250443
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ multiple processes exited due to an OOM condition and caused a network
+ outage.
+
+ |
+
|
+ PAN-250419
+ |
+
+
+ Fixed an issue where XML API explorer inserted a plus (+) character in
+ the Xpath when a space was used in the object name.
+
+ |
+
|
+ PAN-250405
+ |
+
+
+ (CN-Series firewalls only) Fixed an issue on
+ the firewall where
+ websrvr related messages
+ displayed repeatedly.
+
+ |
+
|
+ PAN-250394
+ |
+
+
+ Fixed an issue where a large amount of group data caused serialization
+ errors and prevented synchronization.
+
+ |
+
|
+ PAN-250311
+ |
+
+
+ Fixed an issue where the domain was not mapped when using certificate
+ profile authentication on GlobalProtect.
+
+ |
+
|
+ PAN-250258
+ |
+
+
+ Fixed an issue on the firewall where the Certificate Name character
+ limit was 31 characters instead of 63 characters.
+
+ |
+
|
+ PAN-250146
+ |
+
+
+ Fixed an issue on the web interface where templates incorrectly showed
+ that telemetry was enabled when it was not enabled. With this fix, the
+ telemetry setting is not displayed in the template on the web
+ interface.
+
+ |
+
|
+ PAN-250127
+ |
+
+
+ Fixed an issue where commits failed with the error message
+ set is not allowed when
+ default originate was enabled with a
+ route map that included a set action.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Fixed an issue where device telemetry failed after upgrading due to
+ bundle generation failure.
+
+ |
+
|
+ PAN-250043
+ |
+
+
+ Fixed an issue where, on an NGFW cluster node, operations failed when
+ QoS interfaces were configured with an egress max that exceeded 68,000
+ Mbps.
+
+ |
+
|
+ PAN-250021
+ |
+
+
+ Fixed an issue where
+ Change Summary and
+ Preview Changes displayed
+ inconsistent information when changing an admin user password.
+
+ |
+
|
+ PAN-250005
+ |
+
+
+ Fixed an issue where the Advanced Routing migration script did not
+ migrate BGP import policy rules correctly when the policy rule was
+ configured with an exact match condition.
+
+ |
+
|
+ PAN-249855
+ |
+
+
+ Fixed an issue where the firewall dropped the active source of the
+ Multicast source via MSDP when they were not received from the MSDP
+ peer firewall.
+
+ |
+
|
+ PAN-249727
+ |
+
+
+ Fixed an issue where, on an NGFW cluster node, the
+ Custom/Pre-defined URL category was
+ not in the session flow data, which caused it to be excluded from the
+ promoted session after a failover.
+
+ |
+
|
+ PAN-249548
+ |
+
+
+ Fixed an issue where the firewall stopped responding during a high
+ availability (HA) failover with continued traffic.
+
+ |
+
|
+ PAN-249533
+ |
+
+
+ Fixed an issue where an internal error message was displayed when you
+ selected
+ Exclude video traffic from the tunnel (Windows and macOS
+ only).
+
+ |
+
|
+ PAN-249404
+ |
+
+
+ Fixed an issue on the Panorama web interface where the commit lock for
+ a device group and template with the same name was not visible.
+
+ |
+
|
+ PAN-249266
+ |
+
+
+ Fixed an issue where the
+ config
+ process virtual memory was exceeded due to delays in post-commit
+ processing.
+
+ |
+
|
+ PAN-249194
+ |
+
+
+ Fixed an issue where SaaS quality profile probes were dropped on the
+ SD-WAN hub.
+
+ |
+
|
+ PAN-249132
+ |
+
+
+ Fixed an issue on Panorama DG where the address group object created
+ with Disable Override property in
+ Parent DG was overridden by child DG via CLI.
+
+ |
+
|
+ PAN-249072
+ |
+
+
+ Fixed an issue where content upgrade installation failed with the
+ error
+ Error: can't find cert <cert> when using cloud
+ interfaces.
+
+ |
+
|
+ PAN-248945
+ |
+
+
+ Fixed an issue where commits failed when you committed a configuration
+ to advertise the default route (0.0.0.0/0) as a BGP network statement
+ (Advanced Routing > BGP settings).
+
+ |
+
|
+ PAN-248841
+ |
+
+
+ Fixed an issue where the SSL response time was not displayed in the
+ GlobalProtect log.
+
+ |
+
|
+ PAN-248762
+ |
+
+
+ Fixed an issue where, when the Advanced Routing Engine was configured
+ with OSPF, the firewall stopped responding when attempting to connect
+ to the neighbor while exchanging route maps.
+
+ |
+
|
+ PAN-248618
+ |
+
+
+ Fixed an issue where the
+ show chassis inventory in the XML
+ API output did not include the chassis serial number.
+
+ |
+
|
+ PAN-248542
+ |
+
+
+ Fixed an issue where the NPB policy type was missing from
+ configuration policy updates, which caused error messages to
+ incorrectly display in the system logs.
+
+ |
+
|
+ PAN-248312
+ |
+
+
+ Fixed an issue where the firewall did not re-encapsulate the DNS
+ Security Sinkhole Domain Response into GENEVE when the firewall was
+ integrated with AWS Gateway Load Balancer (GWLB) and Cloud NGFW.
+
+ |
+
|
+ PAN-248285
+ |
+
+
+ Fixed an issue where the firewall went into maintenance mode or
+ stopped responding.
+
+ |
+
|
+ PAN-248211
+ |
+
+
+ Fixed an issue on Panorama where commits failed when Advanced Routing
+ was enabled.
+
+ |
+
|
+ PAN-247857
+ |
+
+
+ (PA-7050 firewalls in HA configurations only)
+ Fixed an issue on the firewall where a dataplane process restarted
+ when updating the routing table.
+
+ |
+
|
+ PAN-247754
+ |
+
+
+ Fixed an issue where successful
+ Commit and Push operations performed
+ by SAML authenticated users were not reflected on the firewall.
+
+ |
+
|
+ PAN-247230
+ |
+
+
+ Fixed an issue where the syslog forwarding configuration did not
+ include the full path for Security policy rules.
+
+ |
+
|
+ PAN-247190
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the firewall was unable to connect to Panorama after manually
+ uploading the license key.
+
+ |
+
|
+ PAN-247052
+ |
+
+
+ Fixed an intermittent issue where the OSPF ABR option was disabled
+ when a static route was added.
+
+ |
+
|
+ PAN-246803
+ |
+
+
+ Fixed an issue with failed pre-login cookies that caused GlobalProtect
+ portal configurations to show as empty.
+
+ |
+
|
+ PAN-246567
+ |
+
+
+ Fixed an issue where a firewall with a copper SFP transceiver
+ (PAN-SFP-CG) flapped during a commit.
+
+ |
+
|
+ PAN-246416
+ |
+
+
+ Fixed an issue where the firewall stopped responding when processing
+ specific HTTP response packets due to an incorrect offset calculation.
+
+ |
+
|
+ PAN-246304
+ |
+
+
+ Fixed an issue on Panorama where commits failed due to a timeout in
+ the
+ sysd
+ process during decryption.
+
+ |
+
|
+ PAN-246256
+ |
+
+
+ Fixed an issue where the firewall received the following error message
+ in the system logs after rebooting:
+ fail to read ncores: cfg.paltform.cores.
+
+ |
+
|
+ PAN-246220
+ |
+
+
+ Fixed an issue where a dynamic peer connection was rejected when using
+ an FQDN for the peer address.
+
+ |
+
|
+ PAN-246209
+ |
+
+
+ Fixed an issue where IPSec VPN tunnels went down after receiving a
+ DHCP server message that the DHCP client cleared the IP address on the
+ interface.
+
+ |
+
|
+ PAN-245993
+ |
+
+
+ Fixed an issue where API calls to move the BGP export rules failed
+ with the error
+ The request could not be handled.
+
+ |
+
|
+ PAN-245845
+ |
+
+
+ Fixed an issue where the firewall displayed a message that the license
+ was invalid even though all licenses were up to date.
+
+ |
+
|
+ PAN-245682
+ |
+
+
+ Fixed an issue on Panorama where
+ Commit and Push progress displayed
+ over 100%.
+
+ |
+
|
+ PAN-245545
+ |
+
+
+ Fixed an issue where, when you were connected to the VPN and enabled
+ the client accelerator, you were disconnected from the VPN.
+
+ |
+
|
+ PAN-245058
+ |
+
+
+ Fixed an issue on the Panorama web interface where tagging a new user
+ failed the error message
+ Tags addition failed.
+
+ |
+
|
+ PAN-244743
+ |
+
+
+ Fixed an issue where intermittent 500 errors occurred when making API
+ calls to the firewall.
+
+ |
+
|
+ PAN-244708
+ |
+
+
+ Fixed an issue where the GlobalProtect VPN connection inactivity TTL
+ value became negative, which caused the VPN to disconnect when the
+ system time was changed back to the past time.
+
+ |
+
|
+ PAN-244262
+ |
+
+
+ Fixed an issue where interface settings were not saved when the
+ template was overridden in the candidate configuration while enabling
+ DNS settings.
+
+ |
+
|
+ PAN-244035
+ |
+
+
+ (PA-5220 firewalls only) Fixed an issue on the
+ web interface where the displayed dataplane CPU usage was up to 20%
+ less than the correct CPU usage.
+
+ |
+
|
+ PAN-243969
+ |
+
+
+ Fixed an issue on Panorama managed firewalls where you were unable to
+ add a new Layer 3 interface to a template with a zone, VR, IP address,
+ and SD-WAN interface profile configured.
+
+ |
+
|
+ PAN-243968
+ |
+
+
+ Fixed an issue where the correct portal agent configuration for
+ GlobalProtect was not matched. This occurred when CRL checks failed
+ due to unavailability.
+
+ |
+
|
+ PAN-243957
+ |
+
+
+ Fixed an issue where the firewall TLS/SSL service profile exclusion
+ settings were not correctly applied on the captive portal.
+
+ |
+
|
+ PAN-243908
+ |
+
+
+ Fixed an issue where custom object import for spyware got stuck on
+ uploading page and seen uploaded successfully after refreshing GUI
+ tab.
+
+ |
+
|
+ PAN-243816
+ |
+
+
+ Fixed an issue where new users were unable to change their password
+ during the first login when the
+ Max session count was set to 1 and
+ Require Password Change on First Login
+ was enabled.
+
+ |
+
|
+ PAN-243787
+ |
+
+
+ Fixed an issue where the CLI command
+ delete user-file ssh-known-hosts
+ did not remove the SSH host keys.
+
+ |
+
|
+ PAN-243786
+ |
+
+
+ Fixed an issue on Panorama where custom GlobalProtect reports
+ displayed inaccurate values.
+
+ |
+
|
+ PAN-243773
+ |
+
+
+ Fixed an issue where the DHCP server stopped responding with the error
+ IP address is already in use.
+
+ |
+
|
+ PAN-243674
+ |
+
+
+ Fixed an issue where you were unable to configure NDP proxy with IPv6
+ address /88 on a Layer 3 interface.
+
+ |
+
|
+ PAN-243240
+ |
+
+
+ Fixed an issue where the using QoS caused packet buffer utilization to
+ increase exponentially and the
+ PKI POOL DFLT pool depleted until
+ a reboot was performed.
+
+ |
+
|
+ PAN-243223
+ |
+
+
+ Fixed an issue where authentication to the GlobalProtect gateway
+ failed due to an invalid Satellite certificate.
+
+ |
+
|
+ PAN-243190
+ |
+
+
+ Fixed an issue where the show commands for HSCI ports did not provide
+ information about optics and light levels.
+
+ |
+
|
+ PAN-243123
+ |
+
+
+ Fixed an issue where SNMPv3 traps were not sent when using FQDN server
+ addresses.
+
+ |
+
|
+ PAN-243098
+ |
+
+
+ Fixed an issue with corrupted images when SSL decryption and Security
+ profiles were configured.
+
+ |
+
|
+ PAN-242960
+ |
+
+
+ Fixed an issue where the firewall did not honor the peer
+ Desired Minimum Tx Interval when in
+ a BFD INIT state.
+
+ |
+
|
+ PAN-242958
+ |
+
+
+ Fixed an issue where the firewall intermittently logged
+ connect-agent-failure messages
+ for service connection instances due to bi-directional host ID
+ redistribution.
+
+ |
+
|
+ PAN-242957
+ |
+
+
+ Fixed an issue where the
+ Rule usage columns of overridden
+ default policy rules on the Security policy page stopped responding.
+
+ |
+
|
+ PAN-242826
+ |
+
+
+ Fixed an issue with the REST API syntax when creating a DHCP server
+ configuration for an existing subinterface.
+
+ |
+
|
+ PAN-242739
+ |
+
+
+ Fixed an issue on the firewall where the dataplane repeatedly
+ restarted.
+
+ |
+
|
+ PAN-242479
+ |
+
+
+ Fixed an issue where a high number of packets caused high packet
+ descriptors on the firewall when handling EtherIP traffic.
+
+ |
+
|
+ PAN-242431
+ |
+
+
+ Fixed an issue where the BGP timer setting was in read-only mode for
+ custom admin users when Advanced Routing was enabled.
+
+ |
+
|
+ PAN-242331
+ |
+
+
+ Fixed an issue where Prisma Access remote network firewalls
+ intermittently created incorrect user-to-IP-address mappings.
+
+ |
+
|
+ PAN-242130
+ |
+
+
+ Fixed an issue where the firewall displayed the speed and duplex of
+ its dataplane interfaces as
+ Unknown even though the link was up.
+
+ |
+
|
+ PAN-241871
+ |
+
+
+ Fixed an issue where the firewall was unable to create new IPSec
+ tunnels when the tunnel monitor flapped.
+
+ |
+
|
+ PAN-241821
+ |
+
+
+ Fixed an issue where
+ Global Search did not show results
+ past the second level.
+
+ |
+
|
+ PAN-241781
+ |
+
+
+ Fixed an issue where partial
+ commit and
+ commit-all operations took more
+ time than expected to create the job ID.
+
+ |
+
|
+ PAN-241772
+ |
+
+
+ Fixed an issue where, when TLSv1.3 was used, an incorrect error
+ message invalid padding was
+ displayed instead of the expected error message
+ Invalid server certificate.
+
+ |
+
|
+ PAN-241655
+ |
+
+
+ Fixed an issue where the firewall incorrectly categorized URLs as
+ phishing due to machine learning
+ analysis
+ MLAV
+ incorrectly marking the URLs as malicious.
+
+ |
+
|
+ PAN-241536
+ |
+
+
+ Fixed an issue on Panorama where admin users with the Custom Panorama
+ Admin role were unable to add, edit, or delete route filters under
+ Routing Profiles
+
+ |
+
|
+ PAN-241519
+ |
+
+
+ Fixed an issue where incorrect log filters were displayed under
+ unified logs.
+
+ |
+
|
+ PAN-241295
+ |
+
+
+ Fixed an issue where Panorama pushed permitted IP address lists were
+ editable on the firewall.
+
+ |
+
|
+ PAN-241044
+ |
+
+
+ Fixed an issue where traffic was denied by the interzone-default
+ policy rule when a Security policy rule with an FQDN destination was
+ configured.
+
+ |
+
|
+ PAN-241004
+ |
+
+
+ Fixed an issue where DNS Proxy dropped client requests of the type
+ ns for a root domain.
+
+ |
+
|
+ PAN-240990
+ |
+
+
+ Fixed an issue where
+ l3svc.py displayed incorrect
+ logs.
+
+ |
+
|
+ PAN-240723
+ |
+
+
+ Fixed an issue where Threat logs were logged within a 5 second
+ interval instead of the exact detection time when the logging rate was
+ low.
+
+ |
+
|
+ PAN-240225
+ |
+
+
+ Fixed an issue where authentication failed on web-based GlobalProtect
+ portal.
+
+ |
+
|
+ PAN-239952
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where HA sync messages from the active firewall took
+ longer than expected to reach the passive firewall.
+
+ |
+
|
+ PAN-239695
+ |
+
+
+ Fixed an issue where the firewall stopped responding due to an
+ internal server error when accessing certificates with the block
+ private key option enabled.
+
+ |
+
|
+ PAN-239532
+ |
+
+
+ Fixed an issue where the firewall was unable to identify the URL
+ category in the session details.
+
+ |
+
|
+ PAN-239409
+ |
+
+
+ Fixed an issue where the
+ lodash.js version installed on
+ the firewall was not accurately reflected in PanXML.
+
+ |
+
|
+ PAN-239246
+ |
+
+
+ Fixed an issue where the CLI command
+ debug user-id dump hip-based-profile-database-entry
+ returned an incorrect value in the output for the
+ total size of hip reports.
+
+ |
+
|
+ PAN-239201
+ |
+
+
+ Fixed an issue where partial commit or partial validation operations
+ failed for non-super user administrators with the error
+ <device-group-name> is invalid. meta data not found for dg
+ <device-group-name>.
+
+ |
+
|
+ PAN-239165
+ |
+
+
+ Fixed an issue where adding an interface in a route filter resulted in
+ an OSPF LSA Type-5 packet check failure, which caused redistributed
+ routes to be removed.
+
+ |
+
|
+ PAN-239143
+ |
+
+
+ Fixed an issue with accessing websites when URL filtering profiles
+ were configured with the
+ block-continue action and the server
+ used HTTP/2.
+
+ |
+
|
+ PAN-239138
+ |
+
+
+ Fixed an issue where a decryption rule with the Log Successful TLS
+ handshakes option disabled still generated successful decryption logs.
+
+ |
+
|
+ PAN-239036
+ |
+
+
+ Fixed an issue where the
+ configd
+ process stopped responding on Panorama due to an out-of-memory
+ condition.
+
+ |
+
|
+ PAN-238813
+ |
+
+
+ Fixed an issue where the DNS proxy was unable to handle UDP DNS
+ replies with a length of over 512 bytes.
+
+ |
+
|
+ PAN-238793
+ |
+
+
+ (Panorama virtual appliances in Microsoft Azure environments
+ only) Fixed an issue where a bootstrapped Panorama appliance did not
+ automatically retrieve the CDL license, which resulted in the firewall
+ not automatically sending logs to CDL.
+
+ |
+
|
+ PAN-238741
+ |
+
+
+ Fixed an issue where, after a selective push of the configuration, a
+ parent device group object with multiple child device groups was not
+ shown in the device group's push scope.
+
+ |
+
|
+ PAN-238303
+ |
+
+
+ (PA-5220 firewalls only) Fixed an issue where
+ multicast streaming did not recover when multicast traffic was
+ offloaded.
+
+ |
+
|
+ PAN-238266
+ |
+
+
+ Fixed an issue where the default
+ lag-flow-key-type was different
+ between the dataplane and the forwarding engine.
+
+ |
+
|
+ PAN-237582
+ |
+
+
+ Fixed an issue where logs were intermittently missing on the log
+ collector due to missing aliases for some indices.
+
+ |
+
|
+ PAN-237109
+ |
+
+
+ Fixed an issue where the application page was not launched directly
+ after the login page when only one application was configured.
+
+ |
+
|
+ PAN-236909
+ |
+
+
+ Fixed an issue where, when you committed the first configuration
+ change after booting up the firewall, the external dynamic list file
+ download failed until the list was refreshed. This occurred when the
+ configuration was pushed with a certificate profile.
+
+ |
+
|
+ PAN-236830
+ |
+
+
+ Fixed an issue where traffic that was correctly detected on the
+ firewall as the threat category
+ DNS was detected on Panorama as the
+ threat category N/A.
+
+ |
+
|
+ PAN-236574
+ |
+
+
+ Fixed an issue where User-ID traffic was incorrectly identified as SSL
+ application instead of
+ paloalto-userid-agent
+ application.
+
+ |
+
|
+ PAN-236447
+ |
+
+
+ Fixed an issue where the firewall rebooted and the kernel log
+ displayed the following message:
+
+ 0.000000] Linux version 4.18.0-240.1.1.27.pan.x86_64.
+
+ |
+
|
+ PAN-236182
+ |
+
+
+ Fixed an issue where, when forward message processing received an
+ invalid payload with a message length of 0 in the buffer header, the
+ firewall rebooted unexpectedly.
+
+ |
+
|
+ PAN-236059
+ |
+
+
+ Fixed an issue on firewalls in HA configuration where the IoT content
+ version was not synced from the active firewall to the passive
+ firewall.
+
+ |
+
|
+ PAN-235808
+ |
+
+
+ (Panorama appliances in Log Collector mode only) Fixed an issue where an unnamed core file was generated after a
+ reboot.
+
+ |
+
|
+ PAN-235529
+ |
+
+
+ Fixed an issue where the Active Directory IP-address-to-user mappings
+ were not updated on
+ Mappings & Tags on the Cloud
+ Identity Engine.
+
+ |
+
|
+ PAN-235110
+ |
+
+
+ (PA-220 firewalls only) Fixed an issue where
+ the web interface did not load after an upgrade.
+
+ |
+
|
+ PAN-234461
+ |
+
+
+ Fixed an issue where excess
+ distributord
+ process memory use caused processes to restart due to OOM conditions.
+
+ |
+
|
+ PAN-234272
+ |
+
+
+ Fixed an issue where scheduled device group reports included data from
+ other device groups.
+
+ |
+
|
+ PAN-234107
+ |
+
+
+ Fixed an issue where Smart Card authentication failed when the SAN
+ field contained additional details.
+
+ |
+
|
+ PAN-234082
+ |
+
+
+ (Panorama virtual appliances only) Fixed an
+ issue where Saas reports were generated with a report period of 0
+ days.
+
+ |
+
|
+ PAN-233681
+ |
+
+
+ Fixed an issue where the
+ authd
+ process on Prisma Access firewalls stopped responding after receiving
+ the SIGUSR1 signal.
+
+ |
+
|
+ PAN-232833
+ |
+
+
+ Fixed an issue where the following error message displayed for IoT
+ trial licenses:
+ IoT Security license is required for the feature to function.
+
+ |
+
|
+ PAN-232792
+ |
+
+
+ Fixed an issue on the Panorama where the web interface did not display
+ the Scheduled Config Push page.
+
+ |
+
|
+ PAN-232594
+ |
+
+
+ (Panorama managed CN-Series firewalls in HA configurations only) Fixed an issue where an error occurred while adding tags.
+
+ |
+
|
+ PAN-232550
+ |
+
+
+ Fixed an issue where SNMPv3 authentication failed when using SHA-512
+ Auth protocol.
+
+ |
+
|
+ PAN-232263
+ |
+
+
+ (Panorama virtual appliances only) Fixed an
+ issue where multiple processes stopped responding due to a traffic
+ outage, which was caused by a corrupted content file.
+
+ |
+
|
+ PAN-231065
+ |
+
+
+ Fixed an issue on Panorama where the CLI command
+ show applications list <Application-group/application
+ filters> device-group <name of device-group>
+ returned incomplete result.
+
+ |
+
|
+ PAN-230934
+ |
+
+
+ Fixed an issue where HTTP/S, SSH, and PING were enabled on the AUX
+ port by default even when these administrative management services
+ were not enabled on the interface.
+
+ |
+
|
+ PAN-230902
+ |
+
+
+ Fixed an issue on the Panorama web interface where you were unable to
+ configure L3 net-inspect rules for a template stack.
+
+ |
+
|
+ PAN-230893
+ |
+
+
+ Added a CLI command to address an issue where system lock files
+ blocked authentication.
+
+ |
+
|
+ PAN-230825
+ |
+
+
+ Fixed an issue where link flaps occurred on Panorama appliances in HA
+ configurations.
+
+ |
+
|
+ PAN-228555
+ |
+
+
+ Fixed an issue where GlobalProtect logs returned no data when using
+ the filter
+ ( private_ip eq 0.0.0.0 ).
+
+ |
+
|
+ PAN-227978
+ |
+
+
+ Fixed an issue where the web interface did not accurately list the
+ status of the port when NGFW clustering was enabled.
+
+ |
+
|
+ PAN-226789
+ |
+
+
+ (VM-Series firewalls in Amazon Web Services (AWS) environments
+ only) Fixed an issue template values were missing in newly spun firewalls
+ in auto scale deployments without an explicit push with forced
+ template values from Panorama.
+
+ |
+
|
+ PAN-226365
+ |
+
+
+ Fixed an issue with the output format of certificate issuer and
+ subject fields during certificate creation.
+
+ |
+
|
+ PAN-226280
+ |
+
+
+ Fixed an issue where the
+ ConfigPushScheduler REST API
+ failed when the target device was a firewall with a non-default
+ management profile.
+
+ |
+
|
+ PAN-226125
+ |
+
+
+ Fixed an issue where the
+ Management Interface Telnet Service
+ was disabled but the service was still allowed.
+
+ |
+
|
+ PAN-225806
+ |
+
+
+ Fixed an issue where LACP packets did not reach the dataplane, which
+ caused the firewall to stop forwarding traffic.
+
+ |
+
|
+ PAN-225228
+ |
+
+
+ Fixed an issue where filtering threat logs using any value under
+ THREAT ID/NAME displayed the error
+ Invalid term.
+
+ |
+
|
+ PAN-224729
+ |
+
+
+ Fixed an issue where you were unable to create duplicate entries in
+ Advanced Routing AS path prepend the BGP filter route map.
+
+ |
+
|
+ PAN-221096
+ |
+
+
+ Fixed an issue where IPSec transport mode failed when the firewall was
+ the initiator.
+
+ |
+
|
+ PAN-218873
+ |
+
+
+ Fixed an issue where a HIP mask was reused when an existing IP address
+ user mapping was updated by a new IP address user mapping that had a
+ different username but the same IP address.
+
+ |
+
|
+ PAN-215882
+ |
+
+
+ Fixed an issue where you were unable to connect to the GlobalProtect
+ gateway when the gateway was scaled up automatically.
+
+ |
+
|
+ PAN-214430
+ |
+
+
+ Fixed an issue where some commands did not have executable
+ permissions.
+
+ |
+
|
+ PAN-212197
+ |
+
+
+ Fixed an issue where you were able to create local administrator
+ usernames that contained only numbers.
+
+ |
+
|
+ PAN-207972
+ |
+
+
+ Fixed an issue on the web interface where the BGP routing table did
+ not display advertised routes.
+
+ |
+
|
+ PAN-202619
+ |
+
+
+ Fixed an issue where, when SPI values were different for static and
+ dynamic Satellite tunnel IP addresses during IPSec tunnel
+ renegotiation, traffic issues occurred between the satellite and the
+ gateway.
+
+ |
+
|
+ PAN-197428
+ |
+
+
+ Fixed an issue where IKE negotiation with distinguished name
+ identification did not work.
+
+ |
+
|
+ PAN-193285
+ |
+
+
+ Fixed an issue where the policy optimizer feature did not add entries
+ back to the mongodb database
+ after removing them during an upgrade or downgrade.
+
+ |
+
|
+ PAN-192176
+ |
+
+
+ Fixed an issue where the management server access log file did not
+ rotate, which caused the root partition to become full and led to
+ system instability.
+
+ |
+
|
+ PAN-164885
+ |
+
+
+ Fixed an issue on Panorama where
+ Commit and Push or
+ Push to Devices operations failed
+ when an external dynamic list was configured to check for updates
+ every 5 minutes due to the commit and external dynamic fetch processes
+ overlapping.
+
+ |
+
|
+ PAN-76904
+ |
+
+
+ (PA-5410 firewalls only) Fixed an issue where
+ the management interface went down and an error message displayed in
+ the show interface management CLI
+ command output.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-284490
+ |
+
+
+ A fix was made to address
+ CVE-2025-2182.
+
+ |
+
|
+ PAN-283493
+ |
+
+
+ Fixed an issue threat reports were empty when generated from Panorama,
+ but displayed correctly when generated from the firewall.
+
+ |
+
|
+ PAN-282236
+ |
+
+
+ Fixed an issue where large IPv6 packets were reassembled incorrectly
+ on the firewall when the packets arrived fragmented over an IPv4
+ tunnel.
+
+ |
+
|
+ PAN-281540
+ |
+
+
+ Fixed an issue where the
+ logd
+ process repeatedly restarted when the SD-WAN site name was over 31
+ characters and contained certain XML escape characters.
+
+ |
+
|
+ PAN-280505
+ |
+
+
+ Fixed an issue where the web interface did not display a message to
+ commit prior changes before attempting a partial configuration load.
+
+ |
+
|
+ PAN-280471
+ |
+
+
+ Fixed an issue where navigating
+ Panorama > Monitor > Logs was
+ slower than expected.
+
+ |
+
|
+ PAN-280243
+ |
+
+
+ Fixed an issue where the firewall lost the pre-shared key
+ configuration assigned from a PSK variable when an unrelated device
+ group configuration was loaded.
+
+ |
+
|
+ PAN-279983
+ |
+
+
+ (PA-1400 Series firewalls only) Fixed an issue
+ on the web interface where
+ Enable Bonjour Reflector was not
+ displayed (Network > Interfaces > Ethernet Interface).
+
+ |
+
|
+ PAN-279746
+ |
+
+
+ Fixed an issue where SMTP packets were not sent out when the Client
+ Hello arrived at the firewall in multiple out-of-order segments and
+ the traffic was not subject to SSL decryption.
+
+ |
+
|
+ PAN-279604
+ |
+
+
+ Fixed an issue where scheduled SaaS application usage reports were
+ generated incorrectly, and the login page was displayed instead of the
+ report content.
+
+ |
+
|
+ PAN-279336
+ |
+
+
+ Fixed an issue where the CLI did not display a message to commit prior
+ changes before loading a partial configuration.
+
+ |
+
|
+ PAN-279176
+ |
+
+
+ Fixed an issue where the configuration audit displayed inaccurate
+ information after partially loading the configuration via the CLI,
+ which caused the audit to flag the configuration as deleted or
+ changed.
+
+ |
+
|
+ PAN-278684
+ |
+
+
+ (PA-445 firewalls only) Fixed an issue where
+ the firewall did not properly power cycle during a reboot.
+
+ |
+
|
+ PAN-277751
+ |
+
+
+ Fixed an issue where a policy-based forwarding (PBF) rule with an
+ action of no-pbf and a service of
+ TCP-22 did not match traffic after upgrading to PAN-OS 11.1.5-h1. As a
+ result, traffic was matched by a lower rule with a service of
+ any and an action of
+ forward.
+
+ |
+
|
+ PAN-277631
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process discarded logs due to a full queue.
+
+ |
+
|
+ PAN-277306
+ |
+
+
+ Fixed an issue where the XML API and REST API failed to run commands
+ with an error.
+
+ |
+
|
+ PAN-276822
+ |
+
+
+ Fixed an issue where the packet buffer size increased significantly
+ when WildFire File Forwarding was continued after a threat detection
+ and then canceled.
+
+ |
+
|
+ PAN-276795
+ |
+
+
+ Fixed an issue where the GlobalProtect client displayed an error
+ message when you clicked
+ Check Now and
+ Preferred Releases and
+ Base Releases were unchecked (Device > Software).
+
+ |
+
|
+ PAN-276599
+ |
+
+
+ Fixed an issue where the password expiry prompt was not visible when
+ logging in via the web interface.
+
+ |
+
|
+ PAN-276491
+ |
+
+
+ (Panorama virtual appliances only) Fixed an
+ issue where Panorama stopped responding when running reports.
+
+ |
+
|
+ PAN-276352
+ |
+
+
+ Fixed an issue where multicast flows were dropped due to a missing
+ sysd
+ variable for maximum multicast routes.
+
+ |
+
|
+ PAN-276062
+ |
+
+
+ Fixed an issue where importing a firewall with a large number of
+ address objects into Panorama did not work and remained at 99%
+ completion.
+
+ |
+
|
+ PAN-275905
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected and Elasticsearch CPU usage was high.
+
+ |
+
|
+ PAN-275754
+ |
+
+
+ Added support for bootstrapping Panorama virtual appliances on ESXi.
+
+ |
+
|
+ PAN-275718
+ |
+
+
+ Fixed an issue where Panorama stopped forwarding logs to a Syslog
+ server after upgrading to PAN-OS 11.1.5-h1.
+
+ |
+
|
+ PAN-275653
+ |
+
+
+ Fixed an issue where the Log Collector service did not start on a new
+ Log Collector appliance added to a Log Collector group. As a result,
+ the new Log Collector appliance did not appear in the cluster and the
+ number of nodes in the cluster was incorrect.
+
+ |
+
|
+ PAN-275077
+ |
+
+
+ Fixed an issue where DNS Security intermittently logs malicious domain
+ URLs as Alert instead of taking a Sinkhole action, even when
+ configured to Sinkhole malicious DNS domains.
+
+ |
+
|
+ PAN-275032
+ |
+
+
+ (M-600 appliances only) Fixed an issue where
+ the Elasticsearch cluster certificate (CC) status displayed with a
+ past expiration date, which caused all shards to be unassigned.
+
+ |
+
|
+ PAN-274791
+ |
+
+
+ Fixed an issue where the firewall might reboot when traffic matches
+ with certain Advanced features (such as Advanced Threat Prevention and
+ Advanced URL Filtering with properly configured URL
+ Filtering/Anti-Spyware/Vulnerability security profiles) and Shared
+ Pool Type 32 becomes depleted.
+
+ |
+
|
+ PAN-274671
+ |
+
+
+ Fixed an issue where empty traffic
+ logdb folders were generated for
+ each day even when traffic logs were not received by the
+ logrcvr
+ process.
+
+ |
+
|
+ PAN-274570
+ |
+
+
+ Fixed an issue where the
+ devsrvr
+ process restarted after a failed commit due to an invalid memory
+ access.
+
+ |
+
|
+ PAN-274557
+ |
+
+
+ Fixed an issue on PA-5450 in FIPSCC mode where a firewall rebooted
+ into maintenance mode when it was manually rebooted from the web
+ interface.
+
+ |
+
|
+ PAN-274292
+ |
+
+
+ (M-600 Appliances only) Fixed an issue where
+ the web interface was slow when logging in and filtering for policies
+ due to deep search operations taking longer than expected.
+
+ |
+
|
+ PAN-274207
+ |
+
+
+ Fixed an issue where Global Search did not redirect correctly to
+ routing profiles when searching for their names.
+
+ |
+
|
+ PAN-274146
+ |
+
+
+ Fixed an issue where the firewall rebooted continuously after
+ upgrading to PAN-OS 11.1.5-h1 when a tunnel session was established in
+ a Gateway Load Balancing (GWLB) scenario and no data packet was
+ associated with the packet.
+
+ |
+
|
+ PAN-274038
+ |
+
+
+ Fixed an issue where you were unable to use the
+ s_encrypted field in custom reports
+ for the Panorama threat log database.
+
+ |
+
|
+ PAN-273991
+ |
+
+
+ Fixed an issue where the transmit power for a cable that was used on
+ port 44 displayed as N/A.
+
+ |
+
|
+ PAN-273963
+ |
+
+
+ Fixed an issue where GlobalProtect health information (HIP) did not
+ display the certificate key usage.
+
+ |
+
|
+ PAN-273949
+ |
+
+
+ Fixed an issue where the firewall generated the following error
+ message in the
+ snmpd
+ logs:
+ pan_get_keystr_from_cryptod(pan_snmpinterface.c:181): Key
+ X2F1dGhfa2V5 import from cryptod failed.
+
+ |
+
|
+ PAN-273727
+ |
+
+
+ Fixed an issue where the firewall skipped the DNS policy rule of a
+ domain external dynamic list (EDL) during an EDL refresh.
+
+ |
+
|
+ PAN-273614
+ |
+
+
+ Fixed an issue where packets were dropped initially when a SYN cookie
+ with activation threshold 0 was enabled.
+
+ |
+
|
+ PAN-273597
+ |
+
+
+ Fixed an issue where logs in the cloud database displayed in the
+ Not-Resolved category but not in the
+ local database.
+
+ |
+
|
+ PAN-273589
+ |
+
+
+ Fixed an issue where firewalls configured with a VPN tunnel stopped
+ responding when a configuration update was applied.
+
+ |
+
|
+ PAN-273453
+ |
+
+
+ Fixed an issue where restarting the firewall did not initiate an
+ autocommit job, which caused the firewall to stop responding and the
+ HA interface to go down.
+
+ |
+
|
+ PAN-273277
+ |
+
+
+ Fixed an issue where GlobalProtect clients on macOS devices were
+ prompted to enter their username and password for Kerberos SSO
+ authentication.
+
+ |
+
|
+ PAN-273153
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected due to excessive polling of the
+ MonitorDirect.getTasks API by the
+ Task Manager.
+
+ |
+
|
+ PAN-273019
+ |
+
+
+ Fixed an intermittent issue where SSL decryption failed.
+
+ |
+
|
+ PAN-272998
+ |
+
+
+ Fixed an issue where commits from Panorama to VM-Series firewalls on
+ Microsoft Azure environments failed.
+
+ |
+
|
+ PAN-272796
+ |
+
+
+ Fixed an issue where you were unable to export the GlobalProtect
+ client software version to the SCP server.
+
+ |
+
|
+ PAN-272746
+ |
+
+
+ (PA-440 firewalls only) Fixed an issue where
+ the firewall entered an unstable state after committing changes or
+ onboarding to Panorama.
+
+ |
+
|
+ PAN-272743
+ |
+
+
+ Fixed an issue where non-captive portal traffic was not visible under
+ Traffic Logs when the traffic was
+ denied by an authentication rule and the session was discarded.
+
+ |
+
|
+ PAN-272726
+ |
+
+
+ Fixed an issue on the web interface where the
+ URL Filtering change category
+ feature did not work.
+
+ |
+
|
+ PAN-272605
+ |
+
+
+ Fixed an issue where the firewall did not display VPC endpoints when
+ there was a large amount of VPC endpoints to interface mappings.
+
+ |
+
|
+ PAN-272408
+ |
+
+
+ (PA-1420 firewalls only) Fixed an issue where
+ the firewall reported unsupported SFPs when PAN-SFPPLUS10GBASE-T SFPs
+ were used on ports Ethernet 1/21 and 1/22.
+
+ |
+
|
+ PAN-272178
+ |
+
+
+ Fixed an issue where the firewall displayed packet buffers between 18
+ and 19 even when there was little or no traffic.
+
+ |
+
|
+ PAN-272172
+ |
+
+
+ Fixed an issue where
+ plugin_api_server could
+ experience a memory leak when using OpenConfig for telemetry.
+
+ |
+
|
+ PAN-272171
+ |
+
+
+ Fixed an issue where the firewall dropped the AAAA DNS server response
+ and caused delays in traffic from Ubuntu or Linux clients when DNS
+ Security was enabled.
+
+ |
+
|
+ PAN-272085
+ |
+
+
+ Fixed an issue where the firewall might crash and reboot when DoH is
+ enabled for DNS Security and multiple DoH transactions are sent in a
+ single HTTP/1 connection.
+
+ |
+
|
+ PAN-271915
+ |
+
+
+ Fixed an issue where the push scope did not populate when attempting
+ to push a policy to a device group.
+
+ |
+
|
+ PAN-271774
+ |
+
+
+ Fixed an issue where the firewall logs displayed the reason for data
+ filtering action as
+ FW Skipped: XXXX.
+
+ |
+
|
+ PAN-271700
+ |
+
+
+ Fixed an issue where User-ID connections were lost after an HA
+ failover.
+
+ |
+
|
+ PAN-271637
+ |
+
+
+ Fixed an issue where the firewall did not increase the metric of the
+ default route when redistributed into OSPF when the firewall was
+ configured as an NSSA ABR.
+
+ |
+
|
+ PAN-271636
+ |
+
+
+ (PA-1400 and PA-3400 Series firewalls only)
+ Fixed an issue where the firewall displayed the error message
+ Failed to parse pbf policy when
+ you committed a configuration that included more than 8 Policy Based
+ Forwarding (PBF) rules with symmetric return enabled.
+
+ |
+
|
+ PAN-271490
+ |
+
+
+ Fixed an issue on the firewall that caused the following error message
+ to be displayed:
+ frr_ns0: failed to stop child frr_ns0_ospf6d.
+
+ |
+
|
+ PAN-271438
+ |
+
+
+ Fixed an issue where the firewall calculated available memory
+ incorrectly on CENTOS devices, which caused the firewall to display
+ high memory usage alerts even when sufficient memory was available.
+
+ |
+
|
+ PAN-271436
+ |
+
+
+ A CLI counter was added to indicate a full suppression queue.
+
+ |
+
|
+ PAN-271184
+ |
+
+
+ Fixed an issue where Device Telemetry failed due to an issue with the
+ encoding of characters in the log file path.
+
+ |
+
|
+ PAN-271181
+ |
+
+
+ Fixed an issue where committing changes to Advanced Routing and
+ redistribution profiles failed while pushing the configuration from
+ SCM.
+
+ |
+
|
+ PAN-271152
+ |
+
+
+ (7000-Series firewalls in HA configurations only) Fixed an issue where the firewall failed over into a non-functional
+ state, and the LFC LED was blinking on the passive firewall.
+
+ |
+
|
+ PAN-270849
+ |
+
+
+ Fixed a memory leak issue related to the
+ configd
+ process that occurred when running consecutive commits for mulitple
+ days.
+
+ |
+
|
+ PAN-270747
+ |
+
+
+ Fixed an issue where the
+ show system statistics application
+ CLI command failed.
+
+ |
+
|
+ PAN-270744
+ |
+
+
+ Fixed an issue where API calls to Panorama failed with the error
+ Server error : Timed out while getting config lock. Please try
+ again.
+
+ |
+
|
+ PAN-270651
+ |
+
+
+ Fixed an issue where the firewall didn't restart after applying an
+ air-gapped license if the firewall capacity was the same as the
+ license capacity. The additional character in subscription is tracked
+ fixed as IT issue.
+
+ |
+
|
+ PAN-270569
+ |
+
+
+ Fixed an issue where the
+ userid
+ process stopped responding due to memory was being reset to NULL when
+ it was freed.
+
+ |
+
|
+ PAN-270554
+ |
+
+
+ Fixed an issue where the GlobalProtect client (UWP) or metered hotspot
+ connections triggered TLS resumption fo GlobalProtect portal
+ authentication, which caused the portal authentication to fail with a
+ valid cert required error.
+
+ |
+
|
+ PAN-270549
+ |
+
+
+ Fixed an issue where some TLS connections were not handled correctly,
+ which led to instability in the dataplane.
+
+ |
+
|
+ PAN-270493
+ |
+
+
+ Fixed an issue where the
+ Low free buffer limit output was
+ not available.
+
+ |
+
|
+ PAN-270248
+ |
+
+
+ Fixed an issue where the firewall failed to forward logs to a SNMP
+ trap server if the SNMP manager IP address was unable to be resolved.
+
+ |
+
|
+ PAN-270193
+ |
+
+
+ Fixed an issue where the Panorama management server changed its
+ certificate authority (CA) unexpectedly, which caused managed
+ firewalls to disconnect.
+
+ |
+
|
+ PAN-270068
+ |
+
+
+ Fixed an issue where the firewall attempted to connect to the AppID
+ cloud using gRPC even when App-ID Cloud Engine was disabled.
+
+ |
+
|
+ PAN-269913
+ |
+
+
+ Fixed an issue threat reports were empty when generated from Panorama,
+ but displayed correctly when generated from the firewall.
+
+ |
+
|
+ PAN-269716
+ |
+
+
+ Fixed an issue where half-closed TCP sessions did not refresh the
+ session timeout when continuously receiving data after setting the
+ cfg.session.tcp-no-refresh-fin-rst
+ option toTrue.
+
+ |
+
|
+ PAN-269624
+ |
+
+
+ Fixed an issue where GlobalProtect clients failed to connect with the
+ error message
+ The device or feature requires a GlobalProtect subscription
+ license.
+
+ |
+
|
+ PAN-269456
+ |
+
+
+ Fixed an issue where the firewall rebooted unexpectedly when
+ configuring the GlobalProtect portal and gateway from Panorama.
+
+ |
+
|
+ PAN-269291
+ |
+
+
+ Fixed an issue where the scheduled report generation script did not
+ return debug information.
+
+ |
+
|
+ PAN-269286
+ |
+
+
+ Fixed an issue where the firewall did not query for an AAAA record
+ when only IPv6 was enabled for the management interface.
+
+ |
+
|
+ PAN-269264
+ |
+
+
+ Fixed an issue where the firewall did not send the client hello to the
+ server when the server hello message contained a certificate with a
+ common name of 0.0.0.0.
+
+ |
+
|
+ PAN-269193
+ |
+
+
+ Fixed an issue where the firewall redirected the user to the first
+ application instead of the portal page with a list of applications
+ when multiple applications were configured for GlobalProtect
+ clientless VPN along with any user match.
+
+ |
+
|
+ PAN-269191
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the aggressive clean-up threshold for disk space was set to 95% in
+ system monitor.
+
+ |
+
|
+ PAN-269091
+ |
+
+
+ Fixed an issue where the
+ varrcvr
+ process stopped responding.
+
+ |
+
|
+ PAN-269052
+ |
+
+
+ Fixed an issue where traffic was blocked by a URL filtering profile
+ even though the Security policy rule did not have a URL filtering
+ profile configured.
+
+ |
+
|
+ PAN-269027
+ |
+
+
+ Fixed an issue related to external dynamic lists that caused commit
+ times on the firewall to be higher than expected.
+
+ |
+
|
+ PAN-268909
+ |
+
+
+ Fixed an issue where IP address tags were removed from firewalls after
+ a management server or
+ useridd
+ process restart. This occurred when a Panorama serial-number based
+ configuration was used for User-ID redistribution.
+
+ |
+
|
+ PAN-268800
+ |
+
+
+ Fixed an issue where a large number of logs caused the
+ logrcvr
+ process to stop responding.
+
+ |
+
|
+ PAN-268708
+ |
+
+
+ Fixed an issue where PDF summary and email reports displayed IPv6
+ addresses instead of IPv4 addresses.
+
+ |
+
|
+ PAN-268707
+ |
+
+
+ Fixed an issue where the XML API call to clear rule hit count using
+ device group syntax failed with an error.
+
+ |
+
|
+ PAN-268629
+ |
+
+
+ Fixed an issue where traffic did not match the correct security policy
+ when using an application-filter that references a cloud application.
+ This occurred when a high number of cloud applications were attached
+ with a custom tag.
+
+ |
+
|
+ PAN-268606
+ |
+
+
+ Fixed an issue where GlobalProtect users with client certificates
+ received an authentication failure message without entering a password
+ and clicking connect or
+ login.
+
+ |
+
|
+ PAN-268597
+ |
+
+
+ Fixed an issue where the firewall displayed 0 bytes received for
+ GlobalProtect SSL sessions in the traffic logs.
+
+ |
+
|
+ PAN-268569
+ |
+
+
+ Fixed an issue where the web interface was slower than expected when
+ logging in and filtering for policies.
+
+ |
+
|
+ PAN-268489
+ |
+
+ Fixed a Threat log PCAP ID overwrapping issue.
+ |
+
|
+ PAN-268425
+ |
+
+
+ Fixed an issue where the
+ execute show transceiver-detail all
+ XML API command returned an incorrect value for the low temperature
+ alarm threshold.
+
+ |
+
|
+ PAN-268279
+ |
+
+
+ Fixed an issue where autocommits failed if the management IPv6 gateway
+ was the same as the dataplane interface IP address.
+
+ |
+
|
+ PAN-268276
+ |
+
+
+ Fixed an issue where GlobalProtect clients intermittently failed to
+ connect to the gateway with the error message
+ could not connect to gateway.
+
+ |
+
|
+ PAN-268168
+ |
+
+
+ Fixed an issue where uploading files that were 5GB or larger to Google
+ Drive or Youtube failed when a decryption policy rule for http2 was
+ enabled
+
+ |
+
|
+ PAN-268127
+ |
+
+
+ Fixed an issue where tagging devices in Panorama did not work as
+ expected.
+
+ |
+
|
+ PAN-268118
+ |
+
+
+ Fixed an issue on firewalls in active/passive HA configurations where,
+ after a failover, irrelevant routing FIB entries were seen in the
+ routing table on the newly active firewall.
+
+ |
+
|
+ PAN-267912
+ |
+
+
+ Fixed an issue on the Panorama web interface where
+ Application and
+ Category was not able to be selected
+ under Test Policy Match.
+
+ |
+
|
+ PAN-267660
+ |
+
+
+ Fixed an issue where UserID stopped working when the
+ show object registered user CLI
+ command was used with start-point and limit options.
+
+ |
+
|
+ PAN-267650
+ |
+
+
+ Fixed an issue where the firewall did not detect the eth1/1 and eth1/2
+ interfaces when you created a firewall on an ESXi 8 server.
+
+ |
+
|
+ PAN-267614
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected due to high CPU utilization on the
+ mongodb
+ process.
+
+ |
+
|
+ PAN-267580
+ |
+
+
+ Fixed an issue where an External Dynamic List (EDL) IP address in an
+ unsupported format was recognized as valid on the firewall.
+
+ |
+
|
+ PAN-267518
+ |
+
+
+ Fixed an issue where WildFire submission logs incorrectly reported
+ allowed malicious samples even when they were blocked by threat
+ prevention profiles.
+
+ |
+
|
+ PAN-267426
+ |
+
+
+ (Firewalls in HA configuration only) Fixed an
+ issue where the
+ Network pre-negotiation enabled page
+ did not display on the firewall dashboard.
+
+ |
+
|
+ PAN-267381
+ |
+
+
+ Fixed an issue where the firewall failed to upload a macOSX file if
+ the file had a MIME boundary.
+
+ |
+
|
+ PAN-267235
+ |
+
+
+ Fixed an issue where the firewall did not send User-ID redistribution
+ messages to Panorama when the firewall had multiple virtual systems
+ configured and one of the virtual systems had a display name that was
+ the same as the existing vsys name.
+
+ |
+
|
+ PAN-267128
+ |
+
+
+ Fixed an issue where the firewall dropped packets if the log rate
+ exceeded the configured maximum log rate.
+
+ |
+
|
+ PAN-267045
+ |
+
+
+ Fixed an issue on the firewall where ICMP ping loss occurred after
+ installing a Network Processing Card (NPC) in slot 7.
+
+ |
+
|
+ PAN-267001
+ |
+
+
+ Fixed an issue where multicast streams were unstable with ECMP and
+ dropped every 30 seconds.
+
+ |
+
|
+ PAN-266905
+ |
+
+
+ Fixed an issue where sessions ended with the message
+ decrypt error in the logs for
+ traffic that matched a
+ no-decrypt policy.
+
+ |
+
|
+ PAN-266800
+ |
+
+
+ (PA-800 firewalls in HA configurations only)
+ Fixed an issue where the Link LEDs for ethernet1/9 to ethernet1/12 did
+ not turn off after a failover.
+
+ |
+
|
+ PAN-266704
+ |
+
+
+ Fixed an issue where filtering BGP routes by peer name in Advanced
+ Routing Engine (ARE) did not display the correct routes.
+
+ |
+
|
+ PAN-266698
+ |
+
+
+ Fixed an issue where an email was able to be transferred to the
+ destination MTA even when the firewall detected a suspicious file with
+ a reset-bot action when it was encrypted by STARTTLS.
+
+ |
+
|
+ PAN-266695
+ |
+
+
+ Fixed an issue on Panorama where a cyclic nested address group
+ configuration caused the
+ configd
+ process to stop responding after a commit.
+
+ |
+
|
+ PAN-266688
+ |
+
+
+ Fixed an issue on the firewall where traffic matched a custom
+ signature even if the custom signature was removed from the
+ configuration.
+
+ |
+
|
+ PAN-266653
+ |
+
+
+ Fixed an issue where unexpected path monitor failures caused the
+ firewall to stop responding.
+
+ |
+
|
+ PAN-266574
+ |
+
+
+ Fixed an issue where users were unable connect to the portal due to
+ Certificate Revocation List (CRL) checks due to the downloaded CRL
+ file being expired, which caused the CRL cache to be bypassed.
+
+ |
+
|
+ PAN-266559
+ |
+
+
+ Fixed an issue where partial commits failed when objects that were
+ referenced in a high number of Security policy rules were renamed. In
+ such cases below error would be seen in configd logs, "Limit printing
+ dirty xpaths in journal at count 3000"
+
+
+ To overcome the 3000 xpaths change limit, use the command to set the
+ limit to a higher value and restart configd daemon. " debug
+ management-server max-ref-xpaths "
+
+ |
+
|
+ PAN-266462
+ |
+
+
+ Fixed an issue where selective pushes did not work as expected when
+ the device group was renamed by a different admin user.
+
+ |
+
|
+ PAN-266427
+ |
+
+
+ Fixed an issue on the firewall where, when a high number of SD-WAN
+ branch sites or interfaces were not connected, SD-WAN processes and
+ tund
+ processes stopped responding due to a high probing rate.
+
+ |
+
|
+ PAN-266391
+ |
+
+
+ Fixed an issue where the number of hints values were not updated even
+ when there were no hint files on the system.
+
+ |
+
|
+ PAN-266354
+ |
+
+
+ Fixed an issue where Hybrid-SWG explicit proxy connections failed when
+ the number of destination domains exceeded 1024.
+
+ |
+
|
+ PAN-266312
+ |
+
+
+ Fixed an issue where BFD sessions took longer than expected to
+ establish after an HA failover due to BGP.
+
+ |
+
|
+ PAN-266279
+ |
+
+
+ Fixed an issue on Panorama where the default version of IKE gateway
+ was not set to IKEv2 only mode, which caused VPN establishment issues
+ if the firewall recognized a new configuration as IKEv1.
+
+ |
+
|
+ PAN-266116
+ |
+
+
+ Fixed an issue where URLs did not work due to certificate revocation
+ list (CRL) requests failing.
+
+ |
+
|
+ PAN-265931
+ |
+
+
+ Added debug functionality in the
+ packet-diag
+ log to address an issue regarding policy rule matching.
+
+ |
+
|
+ PAN-265926
+ |
+
+
+ (PA-3400 Series firewalls only) Fixed an issue
+ where the
+ all_task
+ process stopped responding, which caused the firewall to reboot.
+
+ |
+
|
+ PAN-265916
+ |
+
+
+ Fixed an issue where double-clicking the login button returned the
+ error message
+ Login session expired.
+
+ |
+
|
+ PAN-265900
+ |
+
+
+ Fixed an issue where the firewall stopped responding due to a
+ tund
+ process or SD-WAN process restart.
+
+ |
+
|
+ PAN-265791
+ |
+
+
+ Fixed an issue where the
+ all_task process stopped
+ responding, which caused the dataplane to go down.
+
+ |
+
|
+ PAN-265686
+ |
+
+
+ Fixed an issue where the GlobalProtect portal logged passwords in
+ cleartext.
+
+ |
+
|
+ PAN-265434
+ |
+
+
+ Fixed an issue where the flow process restarted with the error message
+ SIGABRT __GI_raise __GI_abort __libc_message malloc_printer.
+
+ |
+
|
+ PAN-265014
+ |
+
+
+ Fixed an issue where changes made to device groups with the same
+ prefix name were not visible in the commit scope.
+
+ |
+
|
+ PAN-264912
+ |
+
+
+ Fixed an issue where the firewall did not shut down completely.
+
+ |
+
|
+ PAN-264866
+ |
+
+
+ Fixed an issue on Panorama where you were unable to change the order
+ of traffic steering rules.
+
+ |
+
|
+ PAN-264845
+ |
+
+
+ Fixed an issue where the Log Forwarding for Security Services feature
+ did not correctly filter policy rules with log forwarding profiles.
+
+ |
+
|
+ PAN-264570
+ |
+
+
+ Fixed an issue where the maximum session limit for a vsys was
+ 4,194,290.
+
+ |
+
|
+ PAN-264538
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the
+ all_task
+ process stopped responding and a reboot was required.
+
+ |
+
|
+ PAN-264477
+ |
+
+
+ Fixed an issue where the firewall did not start Elasticsearch after a
+ commit if Elasticsearch was not previously enabled and started.
+
+ |
+
|
+ PAN-264423
+ |
+
+
+ Fixed an issue where the firewall sent a 503 response when a client
+ connected to a web server when the firewall was configured as a web
+ proxy and authentication bypass for Kerberos was enabled.
+
+ |
+
|
+ PAN-264289
+ |
+
+
+ Fixed an issue where the CLI and XML API values for the show system
+ environment command did not match.
+
+ |
+
|
+ PAN-264246
+ |
+
+
+ Fixed an issue where the Authentication Portal did not work properly
+ with session cookies when the request to the portal contained the
+ header Sec-Fetch-Site=cross-site.
+
+ |
+
|
+ PAN-264169
+ |
+
+
+ (PA-5400 Series firewalls only) Fixed an issue
+ where the firewall sent correlated event logs to the syslog server
+ using the management interface instead of the log interface.
+
+ |
+
|
+ PAN-264053
+ |
+
+
+ Fixed an issue where the firewall stopped responding after the
+ all_task
+ process stopped responding.
+
+ |
+
|
+ PAN-263749
+ |
+
+
+ Fixed an issue where disk space that was used by file descriptors was
+ not freed, which caused the root partition to become full and Panorama
+ to be inaccessible.
+
+ |
+
|
+ PAN-263674
+ |
+
+
+ (VM-Series firewalls in HA configurations only)
+ Fixed an issue where the firewall rebooted due to multiple HA
+ failovers.
+
+ |
+
|
+ PAN-263654
+ |
+
+
+ Fixed an issue where multiple DNS responses with different CNAME
+ values caused evasion false positive alerts.
+
+ |
+
|
+ PAN-263544
+ |
+
+
+ Fixed an issue where management plane CPU usage increased after
+ upgrading when there was a full-mesh User-ID redistribution
+ configuration between multiple firewalls.
+
+ |
+
|
+ PAN-263291
+ |
+
+
+ Fixed an issue where Microsoft Outlook did not work as expected when
+ the GlobalProtect clientless VPN was configured.
+
+ |
+
|
+ PAN-263086
+ |
+
+
+ (PA-455 firewalls in HA configurations only)
+ Fixed an issue where the HA LED light on the front panel did not turn
+ on even when HA was enabled.
+
+ |
+
|
+ PAN-263063
+ |
+
+
+ Enhanced debugging capability when the control network to DP0 was not
+ reliable when the J2C port was down.
+
+ |
+
|
+ PAN-262819
+ |
+
+
+ (PA-3410, PA-3420, and PA-3430 firewalls only)
+ Fixed an issue where the maximum supported number of zones was 200.
+
+ |
+
|
+ PAN-262782
+ |
+
+
+ Fixed an issue on the firewall where
+ cfg.developer.tasks had a default
+ configuration of True, which
+ capped dataplane CPU performance at 50% in production.
+
+ |
+
|
+ PAN-262729
+ |
+
+
+ (Panorama appliances only) Fixed an issue where
+ the
+ configd
+ process experienced continuous high CPU utilization and repeatedly
+ restarted.
+
+ |
+
|
+ PAN-262375
+ |
+
+
+ (Firewalls in active/active HA configurations only) Fixed an issue where non-tunneled internal GlobalProtect gateway
+ client information was not synced between firewall peers when using a
+ floating IP address.
+
+ |
+
|
+ PAN-262373
+ |
+
+
+ Fixed an issue where the error message
+ Failed to reload config files
+ displayed in the system logs even when device telemetry was not
+ enabled.
+
+ |
+
|
+ PAN-262372
+ |
+
+
+ Fixed an issue where the firewall generated the error message
+ Successfully generating a new set of config files
+ in the system logs even when device telemetry was not enabled.
+
+ |
+
|
+ PAN-262278
+ |
+
+
+ Fixed an issue where the service route setting for HTTP was not
+ applied when the source interface IP address was set via an address
+ object, which caused HTTP traffic to be sent from the management
+ interface.
+
+ |
+
|
+ PAN-262063
+ |
+
+
+ Fixed an issue where the firewall did not display the converted
+ configurations before a commit and reboot, and the commit failed when
+ attempting to migrate from MS to FRR mode.
+
+ |
+
|
+ PAN-262040
+ |
+
+
+ Fixed an issue where the XML API key length exceeded the buffer size
+ when the API key lifetime was changed from the default value.
+
+ |
+
|
+ PAN-261999
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where enabling flow basic on firewalls caused ARP
+ entries to be removed on both firewalls.
+
+ |
+
|
+ PAN-261998
+ |
+
+
+ Fixed an issue where the firewall configuration process restarted
+ during an External Dynamic List refresh or a commit and push
+ operation.
+
+ |
+
|
+ PAN-261997
+ |
+
+
+ Fixed an issue where the firewall displayed incorrect statistics for
+ mac_transmit_err and send_deffered on PA-440 appliances running PAN-OS
+ 10.1.9-h3.
+
+ |
+
|
+ PAN-261936
+ |
+
+
+ Fixed an issue where WildFire submission logs were not displayed when
+ filtered by Sender Address.
+
+ |
+
|
+ PAN-261825
+ |
+
+
+ Fixed an issue where traffic was dropped when Data Loss Prevention or
+ Advanced URL Filtering were enabled. This occurred when the payload
+ size was greater than 3.5 KB.
+
+ |
+
|
+ PAN-261824
+ |
+
+
+ Fixed an issue where frequent
+ brdagent
+ errors occurred.
+
+ |
+
|
+ PAN-261739
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the firewall displayed 0 for the physical port
+ counters read from MAC.
+
+ |
+
|
+ PAN-261677
+ |
+
+
+ Fixed an issue where multiple
+ smartctl
+ processes entered a d state due
+ to failure to read from the kernel partition, which resulted in high
+ CPU and management impact.
+
+ |
+
|
+ PAN-261602
+ |
+
+
+ Fixed an issue where GlobalProtect Decryption logs were not forwarded
+ to Panorama.
+
+ |
+
|
+ PAN-261597
+ |
+
+
+ Fixed an issue where the
+ all_pktproc
+ process stopped responding, which caused the firewall to become
+ unavailable.
+
+ |
+
|
+ PAN-261570
+ |
+
+
+ (Firewalls in active/active HA configurations only) Fixed an issue where packet loss occurred when dataport was used
+ for HA3 for asymmetrically routed traffic during commits and a virtual
+ wire was configured .
+
+ |
+
|
+ PAN-261429
+ |
+
+
+ Fixed an issue where the
+ show auth radius-require-msg-authentic
+ command CLI displayed no output.
+
+ |
+
|
+ PAN-261390
+ |
+
+
+ Fixed an issue that caused the Panorama web interface to be slower
+ than expected due to disabling completion-cache by default.
+
+ |
+
|
+ PAN-261312
+ |
+
+
+ Fixed an issue where a commit for a policy and configuration dump
+ overlapped, which resulted in a null pointer exception.
+
+ |
+
|
+ PAN-261182
+ |
+
+
+ Fixed an issue where the firewall dropped a retransmitted SYN packet
+ when using the TCP Fast Open option.
+
+ |
+
|
+ PAN-261074
+ |
+
+
+ Fixed an issue where the firewall delayed video file transfers over
+ SMB when Exclude Video Traffic from
+ the Tunnel feature was enabled and no applications were added to the
+ list.
+
+ |
+
|
+ PAN-260879
+ |
+
+
+ Fixed an issue where the Panorama port 28270 did not adhere to the
+ restricted TLS version and ciphers set in the
+ Secure Communication Settings.
+
+ |
+
|
+ PAN-260752
+ |
+
+
+ Fixed an issue where the firewall did not support TLSv1.3 in the
+ Clientless VPN, which caused the portal page to not load.
+
+ |
+
|
+ PAN-260720
+ |
+
+
+ Fixed an issue where the
+ dsdc
+ process stopped responding after receiving an unexpected API return
+ value.
+
+ |
+
|
+ PAN-260700
+ |
+
+
+ Fixed an issue where the firewall was unable to load application
+ metadata from the chunk files. This occurred when the application
+ metadata entry was larger than the buffer used to read it, which
+ resulted in an incomplete entry that caused commit failures.
+
+ |
+
|
+ PAN-260564
+ |
+
+
+ Fixed an issue on firewalls in HA configurations where a network loop
+ was detected by switches after suspending HA on the active firewall.
+
+ |
+
|
+ PAN-260358
+ |
+
+
+ Fixed an issue where the firewall did not include the NAS-ID and
+ NAS-IP attributes in the RADIUS Access-Request message when using
+ PEAP-MSCHAPv2 authentication.
+
+ |
+
|
+ PAN-260300
+ |
+
+
+ (PA-5410, PA-5420, PA-5430, PA-5440 and PA-5445 firewalls only) Fixed an issue related to the
+ all_pktproc
+ process where DPC slot 3 stopped responding.
+
+ |
+
|
+ PAN-260279
+ |
+
+
+ Fixed an issue where selective push operations failed with the error
+ message:
+ Failed to generate selective push configuration. Schema validation
+ failed. Please try a full push.
+
+ |
+
|
+ PAN-260229
+ |
+
+
+ Fixed an issue where HA path monitoring using VWire did not work as
+ expected after a reboot.
+
+ |
+
|
+ PAN-260186
+ |
+
+
+ Fixed an issue where Panorama pushed content to devices that did not
+ have a Threat Prevention license.
+
+ |
+
|
+ PAN-260113
+ |
+
+
+ Fixed an issue where the web interface stopped responding when
+ configuring the GlobalProtect gateway when the language was set to
+ Japanese.
+
+ |
+
|
+ PAN-260059
+ |
+
+
+ Fixed an issue where
+ Device Telemetry Regions did not
+ show up with the latest content due to content files not being parsed
+ for the region list when Telemetry was turned off.
+
+ |
+
|
+ PAN-260003
+ |
+
+
+ Fixed an issue where commits failed when you set
+ Use Management interface for all and
+ MGMT was configured for
+ Data Services.
+
+ |
+
|
+ PAN-259870
+ |
+
+
+ (PA-7000b firewalls only) Fixed an issue where
+ Luna Network Hardware Security Modules (HSM) did not work after an
+ upgrade or downgrade.
+
+ |
+
|
+ PAN-259865
+ |
+
+
+ (VM-Series firewalls across all public and private clouds) Fixed an issue where the firewall experienced high dataplane CPU
+ usage when SSL Decryption was enabled.
+
+ |
+
|
+ PAN-259767
+ |
+
+
+ Fixed an issue where GlobalProtect users were unable to connect when
+ the option
+ Block sessions if the certificate was not issued to the
+ authenticating device
+ was enabled in the certificate profile.
+
+ |
+
|
+ PAN-259343
+ |
+
+
+ Fixed an issue on the Panorama web interface where the
+ Configuration tab did not accurately
+ display changes made to URL filtering profiles.
+
+ |
+
|
+ PAN-259140
+ |
+
+
+ Fixed an issue where the
+ request wildfire registration channel public
+ API command failed with the error message
+ Method not found.
+
+ |
+
|
+ PAN-259091
+ |
+
+
+ Fixed an issue where the CLI command
+ show user ip-user-mapping-mp all
+ displayed the total timeout value instead of the current timeout value
+ when the
+ set cli op-command-xml-output on
+ CLI command was used.
+
+ |
+
|
+ PAN-258912
+ |
+
+
+ (PA-7000b firewalls only) Fixed an issue where
+ the firewall web interface displayed an incorrect HSM client version
+ when the client was upgraded to version 7.2.0.220.
+
+ |
+
|
+ PAN-258743
+ |
+
+
+ Fixed an issue where, when you attempted to select a redistribution
+ profile when creating a BGP Redistribute policy rule, the firewall
+ displayed an empty dropdown.
+
+ |
+
|
+ PAN-258680
+ |
+
+
+ Fixed an issue on Panorama where, when you removed Security profile
+ groups from a Security policy rule via the CLI and committed the
+ change, the Security policy rule was deleted.
+
+ |
+
|
+ PAN-258570
+ |
+
+
+ Fixed an issue where the firewall might reboot unexpectedly due to the
+ varrcvr
+ process progressively using more memory when WildFire file forwarding
+ is handling PE files.
+
+ |
+
|
+ PAN-257960
+ |
+
+
+ Fixed an issue where ICD's virtual memory continuously increased due
+ to an increase in unknown IP addresses, which resulted in high
+ management plane CPU utilization.
+
+ |
+
|
+ PAN-257594
+ |
+
+
+ Added support for export and import of SC3 CA certificates on Panorama
+ appliances during RMA.
+
+ |
+
|
+ PAN-257515
+ |
+
+
+ Fixed an issue where Possible Domain Fronting Detection for HTTP/2
+ generated false positives. With this change, domain fronting is
+ limited to HTTP/1.
+
+ |
+
|
+ PAN-257355
+ |
+
+
+ Fixed an issue where a false positive HTTP/TLS evasion alert was
+ generated when the domain had DNS load balance.
+
+ |
+
|
+ PAN-257183
+ |
+
+
+ Fixed an issue where the firewall dropped DNS traffic when using DNS
+ Security.
+
+ |
+
|
+ PAN-257070
+ |
+
+
+ Fixed an issue where querying URL filtering logs with the filter
+ (url_category_list contains 'artificial-intelligence' ) displayed both
+ the artificial-intelligence and the shopping categories.
+
+ |
+
|
+ PAN-256904
+ |
+
+
+ Fixed an issue where the firewall inconsistently blocked URLs due to
+ intermittent URL category misidentification.
+
+ |
+
|
+ PAN-256867
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process stopped responding while processing session logs for
+ forwarding to the LFC.
+
+ |
+
|
+ PAN-256670
+ |
+
+
+ Fixed an issue where scheduled email reports were sent without PDF
+ attachments if the firewall was in FIPS-CC mode.
+
+ |
+
|
+ PAN-256560
+ |
+
+
+ Fixed an issue where exporting a
+ Custom Report to CSV format did not
+ display the full report if it contained non-ASCII characters.
+
+ |
+
|
+ PAN-256138
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ firewalls with a DNS server IP address received by DHCP from Amazon
+ Web Services (AWS) had a delay in resolving FQDNs after a reboot.
+
+ |
+
|
+ PAN-255759
+ |
+
+
+ Fixed an issue where the firewall was unable to match HIP data with
+ the correct anti-malware object for Windows Defender.
+
+ |
+
|
+ PAN-255619
+ |
+
+
+ Fixed an intermittent issue where file downloads from websites failed
+ when decrypting HTTP/2 traffic.
+
+ |
+
|
+ PAN-255611
+ |
+
+
+ Fixed an issue on the firewall where newly added routes were not
+ automatically sorted based on subnets when added to a redistribution
+ profile.
+
+ |
+
|
+ PAN-255441
+ |
+
+
+ Fixed an issue where BGP-ARE routes were not advertised due to a peer
+ route map filter.
+
+ |
+
|
+ PAN-255294
+ |
+
+
+ (PA-3410 firewalls only) Fixed an issue with an
+ incorrectly open port.
+
+ |
+
|
+ PAN-255190
+ |
+
+
+ Fixed an issue where the TCP timeout value was reflected incorrectly
+ when using application override for a custom application in TAP mode.
+
+ |
+
|
+ PAN-255020
+ |
+
+
+ Fixed an issue where the Panorama web interface did not display the
+ push scope data for custom admin users when performing a partial
+ commit and push.
+
+ |
+
|
+ PAN-254293
+ |
+
+
+ Fixed an issue where an explicit proxy caused intermittent SSL
+ handshake failures to SAP applications accessing public URLs.
+
+ |
+
|
+ PAN-253921
+ |
+
+
+ Fixed an issue where the firewall displayed the following error
+ message:
+ critical userid registe 0 fail to integrate the update of
+ registered ip addresses since 2 seconds ago; critical system log
+ alerts observed.
+
+ |
+
|
+ PAN-252978
+ |
+
+
+ (PA-3200 Series firewalls only) Fixed an issue
+ where interfaces running at 10 Gbps did not display the speed and
+ duplex information in the CLI or displayed only as
+ auto.
+
+ |
+
|
+ PAN-252336
+ |
+
+
+ Fixed an issue where newly added devices or existing deleted devices
+ on the primary Panorama appliance were not updated on the secondary
+ Panorama appliance if the secondary Panorama appliance experienced an
+ HA sync commit failure.
+
+ |
+
|
+ PAN-251724
+ |
+
+
+ Fixed an issue where users matched incorrect Security policy rules
+ with a HIP profile.
+
+ |
+
|
+ PAN-251533
+ |
+
+
+ (PA-450 firewalls only) Fixed an issue on the
+ web interface where the DHCPv6 client was not available for VLAN
+ interfaces.
+
+ |
+
|
+ PAN-251442
+ |
+
+
+ Fixed an issue where the firewall rebooted into maintenance mode if
+ the authentication process restarted repeatedly.
+
+ |
+
|
+ PAN-250928
+ |
+
+
+ (PA-5450 firewalls in active/active HA configurations only) Fixed an issue where firewall traffic was silently dropped when
+ sent to the peer owner.
+
+ |
+
|
+ PAN-250048
+ |
+
+
+ Fixed an issue where applications did not load via the Clientless VPN
+ portal when the portal was hosted on an L3 VLAN interface.
+
+ |
+
|
+ PAN-249748
+ |
+
+
+ Fixed an issue where, when a dynamic address group with more than
+ 500,000 addresses was created, the firewall displayed the error
+ message
+ pan_cfg_addresses_from_xmlhash failed.
+
+ |
+
|
+ PAN-247141
+ |
+
+
+ Fixed an issue where DNS traffic did not match the intended SD-WAN
+ policy rule when NAT was enabled.
+
+ |
+
|
+ PAN-245683
+ |
+
+
+ Fixed an issue where committing a configuration change on a Panorama
+ managed firewall caused a short outage for GlobalProtect clients.
+
+ |
+
|
+ PAN-243283
+ |
+
+
+ (PA-3400 Series firewalls only) Fixed an issue
+ where the firewall had a lower maximum number of Security profiles
+ than expected.
+
+ |
+
|
+ PAN-242602
+ |
+
+
+ Fixed an issue where GlobalProtect clients experienced slow SMB-V3
+ download throughput when passing through a Prisma IPSec tunnel and the
+ firewall and the SMB-V3 session owner dataplane was the same as the
+ IPSec-ESP tunnel on the multi-dataplane firewall.
+
+ |
+
|
+ PAN-241953
+ |
+ + + | +
|
+ PAN-241474
+ |
+
+
+ (PA-5200 Series firewalls only) Fixed an issue
+ where the firewall did not increment the flow_parse_ip_cksm counter
+ when traffic with an IP address checksum error was received.
+
+ |
+
|
+ PAN-240144
+ |
+
+
+ Fixed an issue where a multi-vsys firewall failed to authenticate to
+ GlobalProtect with a new group that had the same name (suffixed or
+ prefixed) as an existing group.
+
+ |
+
|
+ PAN-237294
+ |
+
+
+ Fixed an issue where the interface rate counter intermittently went to
+ zero frequently.
+
+ |
+
|
+ PAN-237106
+ |
+
+
+ Fixed an issue where LSVPN satellite certificates were generated with
+ serial numbers with over than 40 hex characters, which led to issues
+ with revoking or deleting the certificates.
+
+ |
+
|
+ PAN-234993
+ |
+
+
+ Fixed an issue where CPU base gateway auto-scaling failed, which
+ caused performance issues.
+
+ |
+
|
+ PAN-234411
+ |
+
+
+ Fixed an issue where the
+ authd
+ process stopped responding.
+
+ |
+
|
+ PAN-233868
+ |
+
+
+ Fixed an issue where the firewall took an incorrect action for
+ overlapping custom and edl-url-categories in a policy rule.
+
+ |
+
|
+ PAN-226184
+ |
+
+
+ Fixed an issue where push operations from Panorama were slow due to
+ the
+ rasmgr
+ process taking longer than expected.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-290996
+
+ This issue is now resolved. See PAN-OS 11.1.10-h1 Addressed Issues
+
+ |
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS)
+ counters incorrectly return a value of 0 for each virtual system
+ (VSYS), despite the firewall actively processing connections.
+
+ |
+
|
+ PAN-286255
+ |
+
+
+ Fixed an issue where, when the firewall received an unexpected
+ termination request for SSL sessions, the dataplane experienced a slow
+ buffer resource leak.
+
+ |
+
|
+ PAN-285941
+ |
+
+
+ Fixed an issue where high memory consumption occurred on the
+ logrcvr
+ process.
+
+ |
+
|
+ PAN-284073
+ |
+
+
+ Fixed an issue on the firewall that caused commits to fail and the web
+ interface to become inaccessible.
+
+ |
+
|
+ PAN-283954
+ |
+
+
+ Fixed an issue where the
+ configd
+ process stopped responding due to a circular reference between address
+ groups.
+
+ |
+
|
+ PAN-283168
+ |
+
+
+ Fixed an issue related to syslog forwarding that caused the
+ logrcvr
+ process stopped responding.
+
+ |
+
|
+ PAN-282697
+ |
+
+
+ Fixed an issue where traffic was delayed significantly when it used
+ No Authentication Explicit Proxy and
+ matched a decryption policy rule.
+
+ |
+
|
+ PAN-282454
+ |
+
+
+ Fixed an issue where, when you added the
+ Virtual System Name column under
+ Unified Logs, the column did not
+ remain visible in the table if you closed and re-opened the tab.
+
+ |
+
|
+ PAN-282391
+ |
+
+
+ Fixed an issue on Panorama where a memory leak occurred after cloning
+ a template, resulting in an increase in memory use, which caused OOM
+ errors.
+
+ |
+
|
+ PAN-282359
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected.
+
+ |
+
|
+ PAN-282206
+ |
+
+
+ Fixed an issue where configuring Secure Web Gateway (SWG) in
+ no-auth mode led to latency when no
+ decryption policy rules or
+ No-decrypt policy rules were
+ present.
+
+ |
+
|
+ PAN-282069
+ |
+
+
+ Fixed an issue on Panorama where Security policy rules were removed
+ from device groups when you cloned or edited Security policy rules
+ that used more than 63 characters.
+
+ |
+
|
+ PAN-281885
+ |
+
+
+ Fixed an issue where, when exporting and importing CSV files, the hash
+ values of pre-shared key variables set at template and template stack
+ levels changed inconsistently, which resulted in both variables
+ displaying the same hash value.
+
+ |
+
|
+ PAN-281882
+ |
+
+
+ Fixed an issue where OSPF was redistributing connected routes beyond
+ the intended loopback IP.
+
+ |
+
|
+ PAN-281649
+ |
+
+
+ Fixed an issue where the index size limit was incorrectly calculated
+ and indices rolled over earlier than expected, which resulted in high
+ memory and OOM errors.
+
+ |
+
|
+ PAN-281269
+ |
+
+
+ (PA-5220, PA-5250, and PA-5420 firewalls) Fixed
+ an issue where the firewall management server memory usage
+ continuously increased.
+
+ |
+
|
+ PAN-280942
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process stopped responding.
+
+ |
+
|
+ PAN-280700
+ |
+
+
+ Fixed an Issue where commits failed with the error
+ invalid IPv6 x:x - must be global/link-local unicast
+ when the management IPv6 address had a specific value.
+
+ |
+
|
+ PAN-280477
+ |
+
+
+ Fixed an issue on the web interface were you were unable to scroll up
+ or down to view source zones in a NAT policy rule.
+
+ |
+
|
+ PAN-279691
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where the firewall didn't synchronize IPSec SAs
+ (security associations) to the passive firewall if the tunnel was not
+ initially established by the active firewall.
+
+ |
+
|
+ PAN-279647
+ |
+
+
+ Fixed an issue where threat names were displayed differently on the
+ web interface and the exported CSV file.
+
+ |
+
|
+ PAN-279621
+ |
+
+
+ Fixed an issue where processes stopped responding when HTTPS Forward
+ traffic was run.
+
+ |
+
|
+ PAN-279400
+ |
+
+
+ Fixed an issue where, when
+ Restrict Certificate Extensions was
+ enabled on decryption profiles, the basic constraints extension was
+ overwritten incorrectly.
+
+ |
+
|
+ PAN-279209
+ |
+
+
+ Fixed an issue where changes made to the management interface
+ permitted IP address list in a global template were not pushed to the
+ template stack or firewalls.
+
+ |
+
|
+ PAN-279195
+ |
+
+
+ Fixed an issue on Panorama where
+ Device Health displayed the device
+ memory as 0%.
+
+ |
+
|
+ PAN-279065
+ |
+
+
+ Fixed an issue where the firewall sent logs with
+ connection succeeded to the syslog
+ server every time a connection was established, which resulted in
+ excessive logs.
+
+ |
+
|
+ PAN-278190
+ |
+
+
+ Fixed an issue on Panorama where a scheduled report with SLS data had
+ an invalid translated-query.
+
+ |
+
|
+ PAN-277755
+ |
+
+
+ Fixed an issue that caused the
+ request system private-data-reset
+ CLI command to fail.
+
+ |
+
|
+ PAN-277417
+ |
+
+
+ Fixed an memory leak issue related to TLS inbound decryption.
+
+ |
+
|
+ PAN-277018
+ |
+
+
+ Fixed an issue where FTP data connections did not work for EPRT with
+ Source IP + Port translation enabled on the firewall.
+
+ |
+
|
+ PAN-276862
+ |
+
+
+ Fixed an issue on Panorama where the
+ logd
+ process stopped responding unexpectedly.
+
+ |
+
|
+ PAN-276616
+ |
+
+
+ Fixed an issue on the firewall where half-duplex settings on Ethernet
+ was not visible.
+
+ |
+
|
+ PAN-276412
+ |
+
+
+ Fixed an issue where you were unable to download XML files from
+ Panorama > Summary > Backups.
+
+ |
+
|
+ PAN-274907
+ |
+
+
+ Fixed an issue on Panorama where
+ Config Audit Commit Date displayed
+ the timestamp of the configuration edit instead of the commit time.
+
+ |
+
|
+ PAN-274750
+ |
+
+
+ Fixed an issue where the detailed log view in Panorama did not display
+ all packet details for traffic logs received from the cloud.
+
+ |
+
|
+ PAN-274726
+ |
+
+
+ Fixed an issue where Wildfire signature generation was enabled on all
+ nodes in a cluster instead of only the active node.
+
+ |
+
|
+ PAN-274569
+ |
+
+
+ Fixed an issue where the QSPF transceiver interface displayed an
+ incorrect range figure on the temperature alarm.
+
+ |
+
|
+ PAN-274314
+ |
+
+
+ (PA-1400 Series firewalls, PA-3400 Series firewalls, and PA-5400
+ Series firewalls only) Fixed an issue where, when the
+ pan_task
+ process restarted, control plane packets were dropped, which could
+ impact LACP and pings to host interfaces.
+
+ |
+
|
+ PAN-273870
+ |
+
+
+ Fixed an issue on the firewall where you were unable to local changes
+ that were made via the web interface.
+
+ |
+
|
+ PAN-273422
+ |
+
+
+ Fixed an issue where traffic failed when Inline cloud analysis
+ (Advanced Threat Prevention) was enabled in the Anti-Spyware profile
+ with the action set to anything other than
+ allow or
+ alert and the maximum latency
+ condition was reached.
+
+ |
+
|
+ PAN-273141
+ |
+
+
+ Fixed an issue where GlobalProtect clients experienced slow file
+ transfer download throughput when passing through an IPSec tunnel.
+
+ |
+
|
+ PAN-271701
+ |
+
+
+ Fixed an issue where Advanced Services, App-ID Cloud Engine (ACE), and
+ Enhanced Application Log stopped working due to incorrect memory usage
+ accounting, which caused memory usage to remain at 99% after an
+ extended period of time.
+
+ |
+
|
+ PAN-271498
+ |
+
+
+ (PA-7000 Series firewalls, PA-5200 firewalls, and PA-5400f firewalls
+ in FIPS mode only) Fixed an issue where decrypted traffic repeatedly failed and
+ frequent reboots were required.
+
+ |
+
|
+ PAN-271273
+ |
+
+
+ Fixed an issue where dynamic update downloads failed when
+ IPv6 firewalling was enabled on the
+ firewall and both IPv4 and IPv6 were configured on the management
+ interface.
+
+ |
+
|
+ PAN-271175
+ |
+
+
+ Fixed an issue where the
+ all_task
+ process stopped responding with a SIGABRT.
+
+ |
+
|
+ PAN-271151
+ |
+
+
+ Fixed an issue where the GlobalProtect client did not automatically
+ initiate a Kerberos SSO connection after logging in to Windows.
+
+ |
+
|
+ PAN-270192
+ |
+
+
+ Fixed an issue where Panorama did not display the management IP
+ address of devices onboard via ZTP.
+
+ |
+
|
+ PAN-269404
+ |
+
+
+ Fixed an issue where the firewall did not reset the maximum latency
+ timer for hold mode.
+
+ |
+
|
+ PAN-268705
+ |
+
+
+ Fixed an intermittent issue where the firewall failed to process FTP
+ traffic after upgrading to PAN-OS 10.1.14.
+
+ |
+
|
+ PAN-268614
+ |
+
+
+ Fixed an issue on the web interface where, when all rules were
+ highlighted when a read-only admin user clicked the
+ Highlight Unused Rules checkbox.
+
+ |
+
|
+ PAN-267936
+ |
+
+
+ Fixed an issue where commits failed with a validation error when you
+ changed the encryption level and re-encryption option on a Panorama
+ managed firewall.
+
+ |
+
|
+ PAN-267444
+ |
+
+
+ Fixed an issue where large file downloads or uploads failed or
+ remained in an incomplete state when using DLP HTTP2 mirror mode.
+
+ |
+
|
+ PAN-266589
+ |
+
+
+ Fixed an issue where the firewall was unable to generate a tech
+ support file when management server debug was disabled.
+
+ |
+
|
+ PAN-263465
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process stopped responding due to a memory leak and buffer overrun.
+
+ |
+
|
+ PAN-263270
+ |
+
+
+ Fixed an issue where, after a commit was performed from Strata Cloud
+ Manager, the SD-WAN configuration containing BGP routes did not
+ display on the hub firewall.
+
+ |
+
|
+ PAN-263052
+ |
+
+
+ Fixed an issue where the
+ request logdb migrate-to-panorama start end-time <start-time>
+ <type>
+ CLI command did not work as expected, and you were unable to resend
+ logs from a firewall to Panorama or a log collector.
+
+ |
+
|
+ PAN-260015
+ |
+
+
+ Fixed an issue on the firewall where the dataplane restarted due to
+ insufficient allocation of memory buffers.
+
+ |
+
|
+ PAN-259610
+ |
+
+
+ Fixed an issue where Wildfire content installation failed for WF-500B
+ clusters when deployed from Panorama using the deployment schedule.
+
+ |
+
|
+ PAN-255914
+ |
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) environments
+ only) Fixed an issue where a newly bootstrapped firewall required a
+ management server restart, relicensing, or license push from Panorama
+ to invoke the device certificate.
+
+ |
+
|
+ PAN-254524
+ |
+
+
+ Fixed an issue on Panorama where, when the
+ Commit and Push button was clicked
+ during a selective
+ Commit and Push operation, the
+ window stopped responding, which caused the operation to be delayed.
+
+ |
+
|
+ PAN-253127
+ |
+
+
+ Fixed an issue where, after upgrading to PAN-OS 11.0.2-h3, the
+ hardware pool DFLT became highly utilized, and the packet buffer
+ gradually increased.
+
+ |
+
|
+ PAN-249574
+ |
+
+
+ Fixed an issue where selective pushes failed due to a missing log
+ collector reference.
+
+ |
+
|
+ PAN-245064
+ |
+
+
+ (Multi-vsys firewalls only) Fixed an issue
+ where commits failed on the firewall after selecting
+ Export or push device config bundle
+ on Panorama and a force push was required.
+
+ |
+
|
+ PAN-238208
+ |
+
+
+ Fixed an issue where the firewall API returned inconsistent responses
+ to a failed call using a valid API key. With this fix, the firewall
+ returns the error
+ Session is invalid if the session is
+ not available for the cookie.
+
+ |
+