Added remaining PAN-OS 11.1 reference files

This commit is contained in:
2026-04-15 14:25:08 -05:00
parent d5b54d5a6b
commit f5bf9648f6
43 changed files with 19422 additions and 42 deletions
+36
View File
@@ -0,0 +1,36 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-237871</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>WF-500 appliances and PAN-DB private cloud deployments only</tt
>) Fixed an issue where the
<span class="ph systemoutput">root-cert</span> was set to expire on
December 31, 2023. With this fix, the expiration date has been
extended.
</div>
</td>
</tr>
</tbody>
</table>
+103
View File
@@ -0,0 +1,103 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-238792</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed the following device certificate issues:
<ul id="concept-ezx_1vl_11c_ul-vdr_dlv_5zb" class="ul">
<li class="li">
The firewall was unable to automatically renew the device
certificate-Fetching device certificates failed incorrectly with
the error message
<span class="ph systemoutput">OTP is not valid</span>.
</li>
<li class="li">
Firewalls disconnected from
<span class="ph">Strata Logging Service</span> after renewing the
device certificate.
</li>
<li class="li">
The device certificate was not correctly generated on the log
forwarding card (LFC).
</li>
<li class="li">
WildFire cloud logs did not log thermite certificate usage status.
</li>
</ul>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-237876</b></div>
</td>
<td class="entry relcol">
<div class="p">
Extended the firewall Panorama root CA certificate which was
previously set to expire on April 7th, 2024.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-231771</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall issued /box/getserv/ requests with
PAN-OS 7.1.0 and did not take device certificates.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-227568</b></div>
</td>
<td class="entry relcol">
<div class="p">
When a device certificate is installed, renewed, or removed, the
firewall will reconnect to the WildFire cloud to use the newest
certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-215576</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">userID-Agent</span> and
<span class="ph systemoutput">TS-Agent</span> certificates were set to
expire on November 18, 2024. With this fix, the expiration date has
been extended to January 2032.
</div>
</td>
</tr>
</tbody>
</table>
+41
View File
@@ -0,0 +1,41 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252214</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-3400"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-3400</a
>.
</div>
</td>
</tr>
</tbody>
</table>
+61
View File
@@ -0,0 +1,61 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-272809</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-0012"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-0012</a
>
(<a
class="xref"
href="https://security.paloaltonetworks.com/PAN-SA-2024-0015"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>PAN-SA-2024-0015</a
>) and
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-9474"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-9474</a
>.
</div>
</td>
</tr>
</tbody>
</table>
+280
View File
@@ -0,0 +1,280 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-233557</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after using Panorama to configure per policy
persistent DIPP, downgrading the firewall using Panorama and then
upgrading the firewall back to a later PAN-OS release, the global DIPP
configuration was not successfully converted b ack to the per policy
persistent DIPP rules.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-230359</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SAML authentication failed with the error message
<span class="ph systemoutput"
>Failed to verify signature against certificate</span
>
when <span class="ph systemoutput">ds:KeyName</span> was in the IdP
metadata.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-227639</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph uicontrol">ACC</span> displayed an incorrect DNS-base
application traffic byte count.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-227376</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory overrun caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process to stop responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-227368</b></div>
</td>
<td class="entry relcol">
<div dir="ltr" class="p">
Fixed an issue where GlobalProtect users could not connect the app to
a portal or gateway and GlobalProtect Clientless VPN users were unable
to access applications when authentication took longer than 20
seconds.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-226418</b></div>
</td>
<td class="entry relcol">
<div class="p">
A CLI command was added to address an issue where long-lived sessions
aged out even when there was ongoing traffic.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-226198</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process repeatedly restarted when attempting to make configuration
changes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-225920</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where duplicate predict sessions didn't release NAT
resources.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-225886</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where if you enabled explicit proxy mode for the web
proxy, intermittent errors and unexpected TCP reconnections may have
occurred.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-225169</b></div>
</td>
<td class="entry relcol">
<div class="p">
Added a CLI command to view
<span class="ph">Strata Logging Service</span> queue usage.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-224772</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a high memory usage issue with the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>mongodb</a
>
process that caused an OOM condition.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-224145</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue in multi-vsys environments where, when Panorama was on
a PAN-OS 10.2 release and the firewall was on a PAN-OS 10.1 release,
commits failed on the firewall when inbound inspection mode was
configured in the decryption policy rule.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-223457</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, if the number of group queries exceeded the Okta
rate limit threshold, the firewall cleared the cache for the groups.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-221126</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where email server profiles (<span class="ph uicontrol"
>Device &gt; Server Profiles &gt; Email and Panorama &gt; Server
Profiles &gt; Email</span
>) to forward logs as email notifications were not forwarded in a
readable format.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-218555</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not receive dynamic address
updates pushed from Panorama during initial registration to Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-213931</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process cache was not in sync with the mapping on the firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-206913</b></div>
</td>
<td class="entry relcol">
Fixed an issue where, when DHCPv6 client was configured on firewalls in
active/passive HA configurations, releasing the IPv6 address from the
client released the IPv6 address from only the active firewall.
</td>
</tr>
</tbody>
</table>
+41
View File
@@ -0,0 +1,41 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252214</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-3400"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-3400</a
>.
</div>
</td>
</tr>
</tbody>
</table>
+61
View File
@@ -0,0 +1,61 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-272809</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-0012"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-0012</a
>
(<a
class="xref"
href="https://security.paloaltonetworks.com/PAN-SA-2024-0015"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>PAN-SA-2024-0015</a
>) and
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-9474"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-9474</a
>.
</div>
</td>
</tr>
</tbody>
</table>
+242
View File
@@ -0,0 +1,242 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-239241</b></div>
</td>
<td class="entry relcol">
Extended the root certificate for WildFire appliances to December 31,
2032.
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-238792</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed the following device certificate issues:
<ul id="concept-id5_nkr_vzb_ul-vdr_dlv_5zb" class="ul">
<li class="li">
The firewall was unable to automatically renew the device
certificate-Fetching device certificates failed incorrectly with
the error message
<span class="ph systemoutput">OTP is not valid</span>.
</li>
<li class="li">
Firewalls disconnected from
<span class="ph">Strata Logging Service</span> after renewing the
device certificate.
</li>
<li class="li">
The device certificate was not correctly generated on the log
forwarding card (LFC).
</li>
<li class="li">
WildFire cloud logs did not log thermite certificate usage status.
</li>
</ul>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-237935</b></div>
</td>
<td class="entry relcol">
<div class="p">
Extended the offline PAN-DB, Panorama, and WildFire certificates which
were previously set to expire on September 2, 2024.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-237876</b></div>
</td>
<td class="entry relcol">
Extended the firewall Panorama root CA certificate which was previously
set to expire on April 7th, 2024.
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-236605</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding due to a deadlock related to
rule-hit-count.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-235385</b></div>
</td>
<td class="entry relcol">
<div class="p">Enhanced wifclient cloud connectivity redundancy.</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-234929</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where tabs in the
<span class="ph uicontrol">ACC</span> such as
<span class="ph uicontrol">Network Activity</span>
<span class="ph uicontrol">Threat Activity</span> and
<span class="ph uicontrol">Blocked Activity</span> did not display
data when you applied a <span class="ph uicontrol">Time</span> filter
of <span class="ph uicontrol">Last 15 Minutes</span>,
<span class="ph uicontrol">Last Hour</span>,
<span class="ph uicontrol">Last 6 Hours</span>, or
<span class="ph uicontrol">Last 12 Hours</span>, and the data that was
displayed with the
<span class="ph uicontrol">Last 24 Hours</span> filter was not
accurate. Reports that were run against summary logs also did not
display accurate results.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-233957</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
the NAT private pool was not used properly when enabling slot 6 DPC.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-233191</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
the Data Processing Card (DPC) restarted due to path monitor failure
after QSFP28 disconnected from the Network Processing Card (NPC).
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-232358</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
the interface on QSFP28 ports did not go down when the Tx cable was
removed from the QSFP28 module.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-231771</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall issued /box/getserv/ requests with
PAN-OS 7.1.0 and did not take device certificates.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-231658</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DNS resolution failed when interfaces were
configured as DHCP and a DNS server was provided via DHCP while also
statically configured with DNS servers.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-231194</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to clear hints from the
disk.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-227568</b></div>
</td>
<td class="entry relcol">
<div class="p">
When a device certificate is installed, renewed, or removed, the
firewall will reconnect to the WildFire cloud to use the newest
certificate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-215576</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph synph">userID-Agent</span> and
<span class="ph systemoutput">TS-Agent</span> certificates were set to
expire on November 18, 2024. With this fix, the expiration date has
been extended to January 2032.
</div>
</td>
</tr>
</tbody>
</table>
+73
View File
@@ -0,0 +1,73 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-242879</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the dataplane restarted when advanced features
such as Advanced Threat Protection, Advanced WildFire, and Advanced
URL Filtering hit max latency under inline mode.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-242634</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-1400 Series, PA-3400 Series, and PA-5400 Series firewalls
only</tt
>) Fixed an issue where a large packet burst from the dataplane to the
management plane caused the DPDK kernel network interface to become
unresponsive.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-240166</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when explicit proxy was configured on the
firewall, websites loaded more slowly than expected or did not load
due to DNS using TCP.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-239279</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the proxy did not accept new connections.
</div>
</td>
</tr>
</tbody>
</table>
+181
View File
@@ -0,0 +1,181 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-264421</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where
<span class="ph uicontrol">Push Scope</span> did not populate
automatically after changing the device group configuration.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-263226</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where decryption based traffic failed on Explicit Proxy
nodes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262831</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an intermittent
issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding, which caused the firewall to restart.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-262593</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic to websites failed on the Google Chrome
web browser on Secure Web Gateway (SWG) nodes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261991</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic that did not match a decryption policy
rule, or matched a no-decrypt policy rule, failed when accumulation
proxy was enabled and a Zone Protection profile was configured with
syn-cookies enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261917</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where websites with a no-decrypt policy rule were
decrypted in traffic log when using a Google Chrome browser with PQC
enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259769</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect portal was not accessible via a
web browser and displayed the error
<span class="ph systemoutput">ERR_EMPTY_RESPONSE</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-258736</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where policy rule configurations pushed from Panorama
were not reflected on the firewall if the rule had 63 characters.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-253213</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall sent HIP notifications every time it
received a HIP report instead of every two hours.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252300</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were unable to select device groups in the
push scope for user accounts.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-245690</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph uicontrol">Managed Collectors</span> health status on
Panorama displayed as empty.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-209574</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with HTTP/2 traffic where downloading large files did
not work when decryption was enabled.
</div>
</td>
</tr>
</tbody>
</table>
+157
View File
@@ -0,0 +1,157 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry"><b class="ph b">PAN-262287</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where dereferencing a NULL pointer that occurred caused
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
processes to stop responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261673</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Microsoft Azure environments only</tt
>) Fixed an issue where, when Accelerated Networking was enabled,
traffic was dropped because of the<span class="ph systemoutput">
flow_parse_ip_hdr</span
>
counter related to an Nvidia driver issue.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259151</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where unused objects were pushed to the firewall, which
caused configuration pushes to fail with the error
<span class="ph systemoutput"
>Number of address groups exceed platform capacity</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259002</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where frequent external dynamic list updates caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process to restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257601</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
Networking Cards (NC) experienced an internal link fault which caused
path monitoring failure on the Dataplane Processing Card (DPC).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257327</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a failover event occurred unexpectedly on the
firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253626</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where unused objects were pushed to the
firewall, which caused the push operations to intermittently fail.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-236191</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the web interface performance was slower than
expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-222542</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7000 Series firewalls only</tt>) Fixed an issue
where Log Forward Cards (LFC) were incorrectly identified as
distribution policies, which caused packet loss due to traffic, BFD,
and other control packets being forwarded to the LFC.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,61 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-272809</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-0012"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-0012</a
>
(<a
class="xref"
href="https://security.paloaltonetworks.com/PAN-SA-2024-0015"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>PAN-SA-2024-0015</a
>) and
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-9474"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-9474</a
>.
</div>
</td>
</tr>
</tbody>
</table>
+245
View File
@@ -0,0 +1,245 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-272809</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-0012"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-0012</a
>
(<a
class="xref"
href="https://security.paloaltonetworks.com/PAN-SA-2024-0015"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>PAN-SA-2024-0015</a
>) and
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-9474"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-9474</a
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-269000</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding due to a NULL
pointer dereference when path monitoring failed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-265785</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted due to a
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>sysd</a
>
variable being modified before it was created.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-265179</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a kernel race condition caused the firewall to
reboot with a kernel panic.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263973</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where log collectors had a low incoming log rate.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263208</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5440 and PA-5445 firewalls only</tt>) Fixed an
issue where interrupts were generated at a certain packet rate, and
dataplane processes missed heartbeats, which caused the dataplane to
go down.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259881</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where traffic log details were not
displayed under <span class="ph uicontrol">detailed log view</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259351</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-3393"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-3393</a
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256223</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where device telemetry log collection filled the root
partition.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255747</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where CLI commands returned
<span class="ph systemoutput"
>Server error: op command for client dagger timed out as client is
not available</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253485</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/passive HA configurations only</tt
>) Fixed an issue where dataplane packet capture filter configuration
failed on the active firewall with the error
<span class="ph systemoutput"
>op command for client dagger timed out as client is not
available</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-249300</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when CUID was enabled, the CUID firewall pub
node was slower than expected when processing incoming traffic and
User-ID mapping redistribution between PAN-OS nodes was impacted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-219805</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process stopped responding due to a race condition.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,95 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-279604</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where scheduled SaaS application usage reports were
generated incorrectly, and the login page was displayed instead of the
report content.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-273085</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where you were unable to edit or
create policy rules.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-272006</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not trigger a kernel core dump
as a large core when the CPLD (Complex Programmable Logic Device) sent
a Non-Maskable Interrupt (NMI) to the CPU.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-271926</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TLS 1.3 decryption failed with a bad record MAC
error when the firewall was configured to decrypt and inspect TLS
traffic.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270549</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where some TLS connections were not handled correctly,
which led to instability in the dataplane.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-268727</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic was dropped when the accumulation proxy
was enabled and header insertion modified packets.
</div>
</td>
</tr>
</tbody>
</table>
+84
View File
@@ -0,0 +1,84 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252214</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-3400"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-3400</a
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-246949</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where custom admin users were not able to click
<span class="ph uicontrol">OK</span> in the push scope selection
window when device group or template were disabled under commit in the
admin roles.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-244013</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where, when a new content
package was installed, new
<span class="ph uicontrol">Anti-Spyware Signatures</span> and new
<span class="ph uicontrol">Vulnerability Signatures</span> were not
visible in their respective profiles.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-243951</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama appliances in active/passive HA
configurations where managed devices displayed as out-of-sync on the
passive appliance when peer configuration changes were made to the
SD-WAN configuration on the active peer.
</div>
</td>
</tr>
</tbody>
</table>
+430
View File
@@ -0,0 +1,430 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252214</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-3400"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-3400</a
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-251013</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where the
<span class="ph uicontrol">Virtual Router</span> and
<span class="ph uicontrol">Virtual System</span>
configurations for the template incorrectly showed as
<span class="ph uicontrol">none</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250686</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where selective push operations did not work when more
than one admin user simultaneously performed changes and partial
commits on Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-249931</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where configuration pushes from Panorama on PAN-OS
11.1.1 to a firewall on a PAN-OS 10.2 release failed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-249808</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding when performing multi-device group pushes
via XML API.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-247403</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the push scope CLI command took longer than expected, which caused the
web interface to be slow.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><b class="ph b">PAN-246960</b></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls failed to fetch content updates from
the Wildfire Private Cloud due to an
<span class="ph uicontrol">Unsupported protocol</span> error.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-244894</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where turning off
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>mprelay</a
>
logging caused *mprelay* heartbeat failure.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-244622</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where FIB re-push did not work with Advanced Routing
enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-244227</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where inconsistent FIB entries across the dataplane
were not detected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-242309</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a higher byte count (s2c) was observed for
DNS-Base application.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-242027</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all-task</a
>
process repeatedly restarted during memory allocation failures.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-241141</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where creating more than one address object in the same
XML API request resulted in a commit error.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-240477</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a temporary hardware issue that caused PAN-SFP-PLUS-CU-5M to not
be able to link up on PA-3400 and PA-1400 Series firewalls.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-240308</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where ElasticSearch did not work as expected when
raid-mounts were not fully ready after a reboot.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-239367</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where a memory leak associated with the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process occurred.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-239354</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DNS resolution was delayed when an Antispyware
policy rule was applied to both client to firewall and firewall to
internal DNS server legs of a connection.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-238643</b></div>
</td>
<td class="entry relcol">
Fixed an issue where a memory leak caused multiple processes to stop
responding when VM Information Sources was configured
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-237537</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when deleting CTD entries, the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process stopped responding which resulted in dataplane failure.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-237208</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process stopped and the firewall rebooted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-233789</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with push and commit and push operations where the user
was not correctly bound to the scope, which caused all device groups
to be selected for a selective push.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-233692</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped, which caused performance issues.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-233684</b></div>
</td>
<td class="entry relcol">
Fixed an issue on Panorama where
<span class="ph uicontrol">Push to Devices</span> or
<span class="ph uicontrol">Commit and Push</span> operations took longer
than expected on the web interface.
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-231148</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where no DHCP option list was defined when using
GlobalProtect.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-230746</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where device groups with a large
number of managed firewalls displayed the
<span class="ph uicontrol">Policy</span> page more slowly than
expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205482</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process where Panorama displayed the error
<span class="ph uicontrol">Server not responding</span> when editing
policies.
</div>
</td>
</tr>
</tbody>
</table>
+288
View File
@@ -0,0 +1,288 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-258225</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where Security policy
rules loaded more slowly than expected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-257615</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where logs did not display or displayed
intermittently on the web interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-256725</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama interface where
<span class="ph uicontrol">Traffic</span> and
<span class="ph uicontrol">Unified</span> event details loaded more
slowly than expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255868</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-3400 Series firewalls only</tt>) Fixed an issue
where the firewall entered maintenance mode after enabling kernel data
collection during the silent reboot.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255266</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were unable to clone a template stack with
the Pre-Shared Key variable.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254411</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding, which caused
<span class="ph uicontrol">RR_CONNECTION_REFUSED</span> error messages
to be displayed in admin sessions.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-253546</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a TLS client hello was split into multiple
packets and arrived out of order, so the packets were dropped and the
session terminated.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-251563</b></div>
</td>
<td class="entry relcol">
<div class="p">
Added CPLD enhancement to capture external power issues.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-247099</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall decrypted traffic unexpectedly when
the client hello was spread across multiple packets.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-246772</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where the dataplane went down due to a
path monitor failure caused by an OOM condition related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-246059</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where forwarded logs were not visible on Panorama due
to the Elasticsearch service not starting when it encountered old and
unsupported indices.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-245428</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where FIB entries aged out and were incorrectly removed
after an HA failover event.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-244548</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where ECMP sessions changed destination MAC addresses
mid-session, which caused connections to be reset.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-243098</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with corrupted images when SSL decryption and Security
profiles were configured.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-240739</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the ECMP FIB update on the dataplane didn't clear
the pending change flag, which caused the next non-ECMP FIB update to
miss the latest generation ID and age out after 5 minutes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-240612</b></div>
</td>
<td class="entry relcol">
<div class="p">Fixed a kernel panic caused by a third-party issue.</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-240596</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding due to an invalid memory address.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-236133</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SSL traffic was impacted when
<span class="ph uicontrol">SSL Command and Control detector</span> for
Incline Cloud Analysis was set to<span class="ph uicontrol">
reset-both</span
>, <span class="ph uicontrol">reset-client</span>,
<span class="ph uicontrol">reset-server</span>, or
<span class="ph uicontrol">drop</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-234560</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the daily summary report displayed IPv6 addresses
instead of IPv4 addresses.
</div>
</td>
</tr>
</tbody>
</table>
+284
View File
@@ -0,0 +1,284 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-242627</b></div>
</td>
<td class="entry relcol">
<div class="p">Fixed an issue where selective push did not work.</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-242561</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect tunnels disconnected shortly after
being established when SSL was used as the transfer protocol.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-242519</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where scheduled email reports failed if the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>@</a
>
symbol before the mail client was missing.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-241504</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where filtering logs under the
<span class="ph uicontrol">Monitor</span> tab was slower than
expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-239769</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where object references in a rule were renamed, and a
selective revert of the changes with
<span class="ph uicontrol">Commit changes by me</span> caused a
reference error.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-238769</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls in FIPS-CC mode only</tt>)
Fixed an issue where upgrading Panorama caused all locally created
Security policy rule actions to Deny.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-238586</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DNS resolution failure from the LFC resulted in
WildFire public cloud connectivity failure.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-236120</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the /opt/panlogs partition reached capacity due
to the logdb-quota for the User-ID log folder not being matched.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-235840</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after a configuration push from Panorama to
managed firewalls, the status displayed as
<span class="ph uicontrol">None</span> and the push took longer than
expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-235585</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when custom signatures and predefined signatures
shared the same literal pattern part, the custom signature caused an
incorrect calculation for the length of the predefined signature,
which resulted in App-ID not detecting correctly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-234279</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>ikemgr</a
>
process crashed due to an IKEv1 timing issue, which caused commits to
fail with the following error message:
<span class="ph systemoutput"
>Client ikemgr requesting last config in the middle of a
commit/validate, aborting current commit</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-230106</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to retrieve the most
current external dynamic list information from the server due to
hostname resolution failure.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-227397</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where selective pushes on Panorama removed a previously
pushed configuration from the firewalls.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-226785</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where accessing websites with HTTP to HTTPS redirect
failed via explicit proxy.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-225337</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama related to Shared configuration objects
where configuration pushes to multi-vsys firewalls failed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-225203</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Log Forwarding Card (LFC) did not honor the
negotiated MSS on the logging connection.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-224954</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading and rebooting a Panorama
appliance in Panorama or Log Collector mode, managed firewalls
continuously disconnected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-223259</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where selective pushes failed with the error message
<span class="ph systemoutput"
>Failed to generate selective push configuration. Unable to retrieve
last in-sync configuration for the device, either a push was never
done or version is too old. Please try a full push</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-216941</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances in Log Collector mode only</tt
>) Fixed an issue where Panorama stopped processing and saving logs.
</div>
</td>
</tr>
</tbody>
</table>
+45
View File
@@ -0,0 +1,45 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256765</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were unable to push variables from Panorama
in service routes for non-cluster templates.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255868</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-3400 Series firewalls only</tt>) Fixed an issue
where the firewall entered maintenance mode after enabling kernel data
collection during the silent reboot.
</div>
</td>
</tr>
</tbody>
</table>
+281
View File
@@ -0,0 +1,281 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-265336</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-800 Series, PA-3200 Series, PA-5200 Series, and PA-5450
firewalls only</tt
>) Fixed an issue where the copper ports flapped when generating a
technical support file or executing telemetry.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-265287</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall experienced a packet buffer leak in
the dataplane of the network processing card (NPC) when processing
certain net messages.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-265287</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall experienced a packet buffer leak in
the dataplane of the NPC when processing certain net messages.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-263973</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where log collectors had a low incoming log rate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-262287</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where dereferencing a NULL pointer that occurred caused
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
processes to stop responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261485</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dropped the Real Time Transport
Protocol (RTP) session for the second SIP call on Persistent-DIPP
connections when the source port of the client device was reset.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259733</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a custom report was not deleted on Panorama when
expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259151</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where unused objects were pushed to the firewall, which
caused configuration pushes to fail with the error
<span class="ph systemoutput"
>Number of address groups exceed platform capacity</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257912</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding when it received
RADIUS traffic and user equipment (UE) traffic at the same time on an
NPC.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257615</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where logs did not display or displayed
intermittently on the web interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257601</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
Networking Cards (NC) experienced an internal link fault which caused
path monitoring failure on the Dataplane Processing Card (DPC).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257327</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5440 firewalls only</tt>) Fixed an issue where a
failover event occurred unexpectedly on the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256725</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama interface where
<span class="ph uicontrol">Traffic</span> and
<span class="ph uicontrol">Unified</span> event details loaded more
slowly than expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254794</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama management server stopped
responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253626</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where unused objects were pushed to the
firewall, which caused the push operations to intermittently fail.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250394</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a large amount of group data caused serialization
errors and prevented synchronization.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-246708</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding when the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
repeatedly restarted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-243098</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with corrupted images when SSL decryption and Security
profiles were configured.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-222542</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7000 Series firewalls only</tt>) Fixed an issue
where Log Forward Cards (LFC) were incorrectly identified as
distribution policies, which caused packet loss due to traffic, BFD,
and other control packets being forwarded to the LFC.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,61 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-272809</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-0012"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-0012</a
>
(<a
class="xref"
href="https://security.paloaltonetworks.com/PAN-SA-2024-0015"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>PAN-SA-2024-0015</a
>) and
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-9474"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-9474</a
>.
</div>
</td>
</tr>
</tbody>
</table>
+237
View File
@@ -0,0 +1,237 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-272809</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-0012"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-0012</a
>
(<a
class="xref"
href="https://security.paloaltonetworks.com/PAN-SA-2024-0015"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>PAN-SA-2024-0015</a
>) and
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-9474"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-9474</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269000</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding due to a NULL
pointer dereference when path monitoring failed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-265785</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted due to a
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>sysd</a
>
variable being modified before it was created.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-263208</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5440 and PA-5445 firewalls only</tt>) Fixed an
issue where interrupts were generated at a certain packet rate, and
dataplane processes missed heartbeats, which caused the dataplane to
go down.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260604</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall displayed inaccurate throughput
utilization stats in NetFlow analyzer tools.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259881</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where traffic log details were not
displayed under <span class="ph uicontrol">detailed log view</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259351</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-3393"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-3393</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-258799</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when updating a Security Policy
<span class="ph uicontrol">Policy Optimizer</span>, the web interface
stopped responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-256223</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where device telemetry log collection filled the root
partition.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-255915</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory leak in the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>sslmgr</a
>
process caused the firewall to restart.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-254826</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding when processing
traffic.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-254794</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama management server stopped
responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-254577</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a core file was created on the Log Forwarding
Card (LFC) due to a third-party software issue.
</div>
</td>
</tr>
</tbody>
</table>
+115
View File
@@ -0,0 +1,115 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259733</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a custom report was not deleted on Panorama when
expected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259473</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
the chassis shut down when FAN1 was removed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254411</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding, which caused
<b class="ph b">ERR_CONNECTION_REFUSED</b> error messages to be
displayed in admin sessions.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-253546</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a TLS client hello was split into multiple
packets and arrived out of order, so the packets were dropped and the
session terminated.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-249814</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where multiple
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
processes stopped responding, which caused the dataplane to fail.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-247099</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall decrypted traffic unexpectedly when
the client hello was spread across multiple packets.
</div>
</td>
</tr>
</tbody>
</table>
+166
View File
@@ -0,0 +1,166 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259480</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>varrcvr</a
>
process stopped responding after running out of memory due to how the
process queued and dequeued files for WildFire file forwarding when a
WildFire Analysis Security profile was enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-257925</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">CN-Series firewalls only</tt>) Fixed an issue where
the CLI command
<span class="ph systemoutput">show system setting ctd state</span> did
not work as expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257615</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where logs did not display or displayed
intermittently on the web interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-257462</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>varrcvr</a
>
process where the management plane CPU was higher than expected during
WildFire updates.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-256385</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">CN-Series firewalls only</tt>) Fixed an issue where
communication was broken between the management plane and the
dataplane when anti-spyware profiles were configured in a Security
policy rule.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-254373</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not handle error code 500
responses from the WildFire cloud correctly.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-251639</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an out-of-memory condition occurred due to a
memory leak related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>varrvcr</a
>
process when a WildFire Analysis security profile was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-248148</b></div>
</td>
<td class="entry relcol">
<div class="p">Jumbo frame feature support is enabled.</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-225213</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">Push All Changes</span> displayed changes
that were already committed in the push scope for another device group
after performing a selective commit and selective push to the first
device group.
</div>
</td>
</tr>
</tbody>
</table>
+133
View File
@@ -0,0 +1,133 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263226</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where decryption based traffic failed on Explicit Proxy
nodes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-262593</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic to websites failed on the Google Chrome
web browser on Secure Web Gateway (SWG) nodes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261991</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic that did not match a decryption policy
rule, or matched a no-decrypt policy rule, failed when accumulation
proxy was enabled and a Zone Protection profile was configured with
syn-cookies enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261917</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where websites with a no-decrypt policy rule were
decrypted in traffic log when using a Google Chrome browser with PQC
enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259769</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect portal was not accessible via a
web browser and displayed the error
<span class="ph systemoutput">ERR_EMPTY_RESPONSE</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-257957</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls and Panorama appliances in FIPS-CC mode only</tt
>) Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>authd</a
>
process restarted if RADIUS PAP/CHAP authentication was used.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-242331</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Prisma Access remote network firewalls
intermittently created incorrect user-to-IP-address mappings.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-232214</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients remained in the connecting
state during portal pre-login when Kerberos single sign-on (SSO) was
enabled.
</div>
</td>
</tr>
</tbody>
</table>
File diff suppressed because it is too large Load Diff
+167
View File
@@ -0,0 +1,167 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-245690</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph uicontrol">Managed Collectors</span> health status on
Panorama displayed as empty.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259733</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a custom report was not deleted on Panorama when
expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259480</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>varrcvr</a
>
process stopped responding after running out of memory due to how the
process queued and dequeued files for WildFire file forwarding when a
WildFire Analysis Security profile was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257615</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where logs did not display or displayed
intermittently on the web interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257462</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>varrcvr</a
>
process where the management plane CPU was higher than expected during
WildFire updates.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257028</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/passive HA configurations only</tt
>) Fixed an issue where firewalls entered a non-functional state and
displayed the error message
<span class="ph systemoutput"
>Dataplane down: path monitor failure during the fail-over</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255711</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall displayed a malformed request error
when selecting a custom format and clicking
<span class="ph uicontrol">OK</span> on the configuration window due
to the log type
<span class="ph uicontrol">Correlation</span> incorrectly being
displayed (<span class="ph uicontrol"
>Device &gt; Log Setting - Correlation &gt; Syslog Server Profile
&gt; Custom Log Format &gt; Correlation</span
>).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254373</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not handle error code 500
responses from the WildFire cloud correctly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-225213</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">Push All Changes</span> displayed changes
that were already committed in the push scope for another device group
after performing a selective commit and selective push to the first
device group.
</div>
</td>
</tr>
</tbody>
</table>
File diff suppressed because it is too large Load Diff
+174
View File
@@ -0,0 +1,174 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-282236</b></div>
</td>
<td class="entry relcol">
Fixed an issue where large IPv6 packets were reassembled on the firewall
when the packets arrived fragmented over an IPv4 tunnel.
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-280471</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where navigating
<span class="ph menucascade"
><span class="ph uicontrol">Panorama</span
><span class="ph uicontrol">Monitor</span
><span class="ph uicontrol">Logs</span></span
>
was slower than expected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279746</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SMTP packets were not sent out when the Client
Hello arrived at the firewall in multiple out-of-order segments and
the traffic was not subject to SSL decryption.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279191</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a GlobalProtect gateway stopped responding when
handling HTTP/1.1 traffic with web inspection enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-278684</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-445 firewalls only</tt>) Fixed an issue where
the firewall did not properly power cycle during a reboot.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-275905</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama web interface was slower than
expected and Elasticsearch CPU usage was high.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-275032</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Elasticsearch cluster certificate (CC) status
displayed with a past expiration date, which caused all shards to be
unassigned.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273141</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients experienced slow file
transfer download throughput when passing through an IPSec tunnel.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272085</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall might crash and reboot when DoH is
enabled for DNS Security and multiple DoH transactions are sent in a
single HTTP/1 connection.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270744</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where API calls to Panorama failed with the error
<span class="ph systemoutput"
>Server error : Timed out while getting config lock. Please try
again</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268279</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where autocommits failed if the management IPv6 gateway
was the same as the dataplane interface IP address.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-242130</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall displayed the speed and duplex of
its dataplane interfaces as
<span class="ph uicontrol">Unknown</span> even though the link was up.
</div>
</td>
</tr>
</tbody>
</table>
@@ -0,0 +1,32 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-282022</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed the support limitation for the Panorama M-600 and M-700
appliances.
</div>
</td>
</tr>
</tbody>
</table>
+383
View File
@@ -0,0 +1,383 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-282022</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed the support limitation for the Panorama M-600 and M-700
appliances.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-281885</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when exporting and importing CSV files, the hash
values of pre-shared key variables set at template and template stack
levels changed inconsistently, which resulted in both variables
displaying the same hash value.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-280505</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the web interface did not display a message to
commit prior changes before attempting a partial configuration load.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-280243</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall lost the pre-shared key
configuration assigned from a PSK variable when an unrelated device
group configuration was loaded.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279336</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the CLI did not display a message to commit prior
changes before loading a partial configuration.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279176</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the configuration audit displayed inaccurate
information after partially loading the configuration via the CLI,
which caused the audit to flag the configuration as deleted or
changed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-277762</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
unexpected failovers occurred on firewalls running PAN-OS 11.2.2-h2.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-275713</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>dscd</a
>
process stopped responding when
<span class="ph uicontrol">Endpoint Serial Number</span> was enabled,
which resulted in the
<span class="ph uicontrol">Active Directory</span> returning a list of
serial numbers for a specific firewall from the Cloud Identity Engine.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-275077</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DNS Security intermittently logs malicious domain
URLs as Alert instead of taking a Sinkhole action, even when
configured to Sinkhole malicious DNS domains.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-274750</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the detailed log view in Panorama did not display
all packet details for traffic logs received from the cloud.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273694</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted due to an out-of-bounds
memory access that occurred as a result of the SIP content length
value being split across packets.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272538</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding during a commit-all validation when there
were uncommitted changes and
<span class="ph systemoutput">share-unused-objects-with-devices</span>
was set to off.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272171</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dropped the AAAA DNS server response
and caused delays in traffic from Ubuntu or Linux clients when DNS
Security was enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270607</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/passive HA configurations only</tt
>) Fixed an issue where OSPF failed to establish after a failover from
the active firewall to the passive firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271351</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-0116"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-0116</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267091</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where Elasticsearch repeatedly restarted.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-264678</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">Preview Changes</span> did not display
configuration changes in
<span class="ph uicontrol">Commit and push &gt; Push Scope</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-262511</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on firewalls in HA configurations where OSPF neighbors
were not established after an HA failover.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261825</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic was dropped when Data Loss Prevention or
Advanced URL Filtering were enabled. This occurred when the payload
size was greater than 3.5 KB.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259706</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the web interface was slower than
expected or unresponsive when monitoring definitions were added in the
Kubernetes plugin.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-257183</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dropped DNS traffic when using DNS
Security.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-254174</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-0115"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-0115</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-248762</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the Advanced Routing Engine was configured
with OSPF, the firewall stopped responding when attempting to connect
to the neighbor while exchanging route maps.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-239201</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where partial commit or partial validation operations
failed for non-super user administrators with the error
<span class="ph systemoutput"
>&lt;device-group-name&gt; is invalid. meta data not found for dg
&lt;device-group-name&gt;</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-235733</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the displayed NTP information was incorrect if
the DNS servers timed out.
</div>
</td>
</tr>
</tbody>
</table>
+200
View File
@@ -0,0 +1,200 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286255</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the firewall received an unexpected
termination request for SSL sessions, the dataplane experienced a slow
buffer resource leak.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-282069</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where Security policy rules were removed
from device groups when you cloned or edited Security policy rules
that used more than 63 characters.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-280942</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process stopped responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273949</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall generated the following error
message in the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>snmpd</a
>
logs:
<span class="ph systemoutput"
>pan_get_keystr_from_cryptod(pan_snmpinterface.c:181): Key
X2F1dGhfa2V5 import from cryptod failed</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271273</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where dynamic update downloads failed when
<span class="ph uicontrol">IPv6 firewalling</span> was enabled on the
firewall and both IPv4 and IPv6 were configured on the management
interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270193</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama management server changed its
certificate authority (CA) unexpectedly, which caused managed
firewalls to disconnect.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268614</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where, when all rules were
highlighted when a read-only admin user clicked the
<span class="ph uicontrol">Highlight Unused Rules</span> checkbox.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-265621</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph uicontrol">restart</span> option for IPSec tunnels was
greyed out when you attempted to restart the tunnel from
<span class="ph menucascade"
><span class="ph uicontrol">Network</span
><span class="ph uicontrol">IPSec Tunnels</span
><span class="ph uicontrol">IKE Info</span></span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260300</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-5410, PA-5420, PA-5430, PA-5440 and PA-5445 firewalls only</tt
>) Fixed an issue related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process where DPC slot 3 stopped responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259535</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall failed to boot up after running
power cycle tests due to
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>ehmon</a
>
process heartbeat failures.
</div>
</td>
</tr>
</tbody>
</table>
+261
View File
@@ -0,0 +1,261 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-292261</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall repeatedly reported an unreachable
syslog server as <span class="ph systemoutput">back online</span> when
the server remained unavailable. This resulted in misleading
alternating connection status messages in the system logs.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287423</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where content loading issues occurred on IPv6 websites
due to the firewall incorrectly setting the IPv6 header flow label to
0.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286255</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the firewall received an unexpected
termination request for SSL sessions, the dataplane experienced a slow
buffer resource leak.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-282069</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where Security policy rules were removed
from device groups when you cloned or edited Security policy rules
that used more than 63 characters.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-280942</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process stopped responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-280698</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall removed the TCP timestamp from
client hello messages that did not fit in a single packet, which
resulted in connection issues.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279901</b></div>
</td>
<td class="entry relcol">
<div class="p">
An issue was fixed where the firewall dropped fragmented TLS
ClientHello packets, which blocked access to certain websites. This
occurred because the packets arrived truncated, in varying sizes and
orders, and the firewall's heuristics failed to handle them correctly.
</div>
<div class="p">
To enable this fix, run:
<span class="ph userinput"
>debug dataplane set ssl-decrypt accumulate-client-hello disjoined
yes</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273949</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall generated the following error
message in the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>snmpd</a
>
logs:
<span class="ph systemoutput"
>pan_get_keystr_from_cryptod(pan_snmpinterface.c:181): Key
X2F1dGhfa2V5 import from cryptod failed</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271273</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where dynamic update downloads failed when
<span class="ph uicontrol">IPv6 firewalling</span> was enabled on the
firewall and both IPv4 and IPv6 were configured on the management
interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270193</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama management server changed its
certificate authority (CA) unexpectedly, which caused managed
firewalls to disconnect.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268614</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where, when all rules were
highlighted when a read-only admin user clicked the
<span class="ph uicontrol">Highlight Unused Rules</span> checkbox.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-265621</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph uicontrol">restart</span> option for IPSec tunnels was
greyed out when you attempted to restart the tunnel from
<span class="ph menucascade"
><span class="ph uicontrol">Network</span
><span class="ph uicontrol">IPSec Tunnels</span
><span class="ph uicontrol">IKE Info</span></span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260300</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-5410, PA-5420, PA-5430, PA-5440 and PA-5445 firewalls only</tt
>) Fixed an issue related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process where DPC slot 3 stopped responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259535</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall failed to boot up after running
power cycle tests due to
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>ehmon</a
>
process heartbeat failures.
</div>
</td>
</tr>
</tbody>
</table>
+165
View File
@@ -0,0 +1,165 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-301801</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Log Collectors where the Elasticsearch process
fluctuated intermittently between green and red states, which led to
interruptions in log collection. This issue occurred when the number
of shards exceeded the cluster's maximum supported threshold of
greater than 1000 shards per Elasticsearch instance.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-292159 and PAN-271216</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-4615"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-4615</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291661</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama appliances and Log Collectors where, after
an upgrade, Elasticsearch intermittently entered into a Red state
before automatically recovering.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286164</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-4614"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-4614</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-282093</b></div>
</td>
<td class="entry relcol">
<div class="p">
Enhanced the CLI command
<span class="ph systemoutput">request legacy reset</span> to delete
the legacy certificate files that were being used to connect with the
secondary Panorama appliance.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-278296</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the system MAC address of the aggregate interface
was the same on the active firewall and the passive firewall after an
upgrade.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272539</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Panorama appliances on Microsoft Azure environments only</tt
>) Fixed an issue where user to IP address mapping was missing for
some users connected to specific Prisma Access gateways, which caused
the collection layer Azure firewall to not form the mapping.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271221</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-4615"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-4615</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-251715</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall closed the SSL connection to the
user ID agent.
</div>
</td>
</tr>
</tbody>
</table>
+797
View File
@@ -0,0 +1,797 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-265963</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>escd</a
>
process caused a memory leak when session resiliency was enabled on
the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-265349</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where multiple segments of HTTP proxy connect messages
were not handled correctly by proxy.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-264421</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where
<span class="ph uicontrol">Push Scope</span> did not populate
automatically after changing the device group configuration.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263987</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where, when a NAT transversal IPSec
tunnel was terminated, and the NAT rule that was applied to the NAT-T
IPSec tunnel was on the same firewall, traffic flowing through the
tunnel was not correctly translated.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-263559 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the dataplane stopped responding and the firewall
unexpectedly rebooted due to multiple process restarts.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263226</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when SSL decryption was enabled and Client Hello
messages spanned multiple TCP segments, some SSL decrypted sessions
failed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262593</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic to websites failed on the Google Chrome
web browser on Secure Web Gateway (SWG) nodes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262340</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where FQDN resolution failed for address objects, and
all FQDN traffic was denied by the interzone-default policy rule.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262287</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where dereferencing a NULL pointer that occurred when
App-ID stopped responding caused the firewall to restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261991</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic that did not match a decryption policy
rule, or matched a no-decrypt policy rule, failed when accumulation
proxy was enabled and a Zone Protection profile was configured with
syn-cookies enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261917</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where websites with a no-decrypt policy rule were
decrypted in traffic log when using a Google Chrome browser with PQC
enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261909</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect client did not display the
dialog box for an MFA verification code.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261489</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an out-of-memory (OOM) condition caused a
firewall outage.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261484</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where DPDK allocated twice the amount
of memory as requested for pre-allocation.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261001</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect users were unable to switch
gateways after upgrading to GlobalProtect version 6.2.3.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260974</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Cloud Identity Engine (CIE) user context did
not correctly redistribute user/IP address port mapping to on-premises
firewalls.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259997</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-3410, PA-3420, and PA-3430 firewalls only</tt>)
Fixed an issue where the install failed when upgrading from PAN-OS
10.2.3-h3 and later 10.2 releases to PAN-OS 10.2.10 due to the number
of configured vsys zones exceeding the zone limit in PAN-OS 10.2.10.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259769</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect portal was not accessible via a
web browser and displayed the error
<span class="ph systemoutput">ERR_EMPTY_RESPONSE</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259151 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where unused objects were pushed to the firewall, which
caused configuration pushes to fail with the error
<span class="ph systemoutput"
>Number of address groups exceed platform capacity</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-258736</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where policy rule configurations pushed from Panorama
were not reflected on the firewall if the rule had 63 characters.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-258225</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where Security policy
rules loaded more slowly than expected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-257957 </b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls and Panorama appliances in FIPS-CC mode only</tt
>) Fixed an issue where the <i class="ph i">authd </i>process
restarted if RADIUS PAP/CHAP authentication was used.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257925</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">CN-Series firewalls only</tt>) Fixed an issue where
the CLI command
<span class="ph userinput">show system setting ctd state</span> did
not work as expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256725</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama interface where
<span class="ph uicontrol">Traffic</span> and
<span class="ph uicontrol">Unified</span> event details loaded more
slowly than expected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-256666 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the <i class="ph i">configd</i>process stopped
responding when <b class="ph b">Commit and Push </b>operations were
performed on multiple device groups.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256385</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">CN-Series firewalls only</tt>) Fixed an issue where
communication was broken between the management plane and the
dataplane when anti-spyware profiles were configured in a Security
policy rule.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-256350 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when you cloned an admin role or an LDAP server
profile and then changed the name of the clone, the configuration
change was not reflected on the managed firewall after pushing the
configuration from Panorama.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-256320 </b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/passive HA configurations only</tt
>) Fixed an issue where GTP sessions remained as allocated sessions on
the passive firewall even when there were no active sessions.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255930</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where persistent DIPP NAT entries were deleted even
when being used during an active session.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255266</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were unable to clone a template stack with
the Pre-Shared Key variable.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254826</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding when processing
traffic.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254671</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where excessive
<span class="ph systemoutput"
>Timed out while getting config lock</span
>
error messages were generated when making bulk changes via XML API.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254423</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where custom role-based admin users with
read only access were able to make changes to configurations.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-253626 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where unused objects were pushed to the
firewall, which caused the push operations to intermittently fail.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253213</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall sent HIP notifications every time it
received a HIP report instead of every two hours.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-252300 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were unable to select device groups in the
push scope for user accounts.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-251676</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama appliances in large-scale deployments where
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process core files consumed more space in the /opt/panlogs partition
than was available.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-251655 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped forwarding files to the
WildFire cloud and a restart of the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>varrcvr</a
>
process was required.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250787</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where network issues between the firewall and the log
collector caused
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process memory exhaustion.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250419</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where XML API explorer inserted a plus (+) character in
the Xpath when a space was used in the object name.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250062</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where device telemetry failed after upgrading due to
bundle generation failure.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-249266</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>config</a
>
process virtual memory was exceeded due to delays in post-commit
processing.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-249011 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall became unresponsive when committing
a configuration change with a large number of uncommitted changes in
the replay database.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-247099</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall decrypted traffic unexpectedly when
the client hello was spread across multiple packets.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-246304 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where commits failed due to a timeout in
the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>sysd</a
>
process during decryption.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-246220 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a dynamic peer connection was rejected when using
an FQDN for the peer address.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-244039</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
the firewall dropped packets when attempting to reuse a TCP session.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-243098</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with corrupted images when SSL decryption and Security
profiles were configured.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-241781</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where partial commit and commit-all operations took
more time than expected to create the job ID.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-241044</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic was denied by the interzone-default
policy rule when a Security policy rule with an FQDN destination was
configured.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-234560</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the daily summary report displayed IPv6 addresses
instead of IPv4 addresses.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-233727</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where the following error message
was incorrectly displayed for an IKE gateway with a valid
configuration:
<span class="ph systemoutput"
>ikev2-&gt;pq-ppk-&gt;negotiation-mode is invalid</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-237582 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where logs were intermittently missing on the log
collector due to missing aliases for some indices
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-234094 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where
<b class="ph b">Deploy Master Key</b>resulted in the error message
Failed to communicate with device due to a low connection timeout
value.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-232214 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients remained in the connecting
state during portal pre-login when Kerberos single sign-on (SSO) was
enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-230825</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where link flaps occurred on Panorama appliances in HA
configurations.
</div>
</td>
</tr>
</tbody>
</table>
+359
View File
@@ -0,0 +1,359 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-272809</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-0012"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-0012</a
>
(<a
class="xref"
href="https://security.paloaltonetworks.com/PAN-SA-2024-0015"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>PAN-SA-2024-0015</a
>) and
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-9474"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-9474</a
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-268823</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph menucascade"
><span class="ph uicontrol">Monitor</span
><span class="ph uicontrol">Log Display</span></span
>
did not display all logs when you applied a filter.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-265785</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted due to a
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>sysd</a
>
variable being modified before it was created.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-264883</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7080 appliances with LPCs only</tt>) Fixed an
issue where syslog forwarding over TCP stopped after upgrading.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263369</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where commits from Panorama to Panorama virtual
appliances failed with the error message
<span class="ph systemoutput"
>Internal error during commit processing. Commit/Validate
failed</span
>
after upgrading Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261673</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Microsoft Azure environments only</tt
>) Fixed an issue where, when Accelerated Networking was enabled,
traffic was dropped because of the
<span class="ph systemoutput">flow_parse_ip_hdr</span> counter related
to an Nvidia driver issue.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261371</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-5410 firewalls in active/passive high availability (HA)
configurations only</tt
>) Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process restarted, which caused the firewall to reboot.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261209</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/active HA configuration only</tt
>) Fixed an issue where the firewall displayed the HA2 status as down
when the HSCI port was used for both HA2 and HA3.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260905</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the HS: Fiber Port Eth1/2 did not come up on a
cold boot and remained in an incorrect state.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260316</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding and the firewall rebooted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259351</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-5921"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-3393</a
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259002</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where frequent external dynamic list updates caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process to restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257601</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
Networking Cards (NC) experienced an internal link fault which caused
path monitoring failure on the Dataplane Processing Card (DPC).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257327</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a failover event occurred unexpectedly on the
firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256223</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where device telemetry log collection filled the root
partition.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254794</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama management server stopped
responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-249384</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where configuration locks were observed
during a partial rulebase commit.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-243240</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the using QoS caused packet buffer utilization to
increase exponentially and the
<span class="ph systemoutput">PKI POOL DFLT</span> pool depleted until
a reboot was performed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-242479</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a high number of packets caused high packet
descriptors on the firewall when handling EtherIP traffic.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-230893</b></div>
</td>
<td class="entry relcol">
<div class="p">
Added a CLI command to address an issue where system lock files
blocked authentication.
</div>
</td>
</tr>
</tbody>
</table>
+646
View File
@@ -0,0 +1,646 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273215</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a syntax error in the index generation script
caused a high management plane CPU load after upgrading.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271912</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the *configd* process stopped
responding when filtering in the configuration audit window after
upgrading to PAN-OS 11.1.3.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271613</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where configuration pushes from Panorama to the
firewall failed due to an OOXML commit error.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271314</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where pushing changes to a prefix list used for BGP
from Panorama affected OSPF routes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270224</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where indices were not opened after a query.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269956</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process stopped responding, which caused internal path monitor
failures.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269899</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama web interface was slower than
expected when querying for device tags.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269673</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where ElasticSearch was not set up after an upgrade.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269000</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding due to a NULL
pointer dereference when path monitoring failed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268972</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama was slower than expected when using a
high number of device group tags in a non-shared context.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268501</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to generate a TSF file
due to a full root partition.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-266639</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where administrators were unable to edit or add virtual
router configurations when a filter was applied to the viewer.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-266114</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when a new set of URL logs came in, the content
of the earlier URL and traffic logs were lost.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-265973</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where administrator sessions were logged out with an
<span class="ph systemoutput">ERR_CONNECTION_REFUSED</span> error on
the browser.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-265742</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where the
<span class="ph uicontrol">OK</span> button on the GlobalProtect
gateway configuration dialog box was not clickable.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-265219</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
GRE traffic did not work properly.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-264871</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding when viewing IP addresses on dynamic
address groups with a large number of IP addresses.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-264249</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where SNMP queries timed out when using
SNMP.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-263973</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where log collectors had a low incoming log rate.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-263287</b></div>
</td>
<td class="entry relcol">
<div class="p">
The PAN-COMMON-MIB.my file was updated to support new object
identifiers (OID) to poll interface use via SNMP with table
identifiers.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-263208</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5440 and PA-5445 firewalls only</tt>) Fixed an
issue where interrupts were generated at a certain packet rate, and
dataplane processes missed heartbeats, which caused the dataplane to
go down.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-263017</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to mount a disk partition
due to a corrupted filesystem.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261485</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dropped the Real Time Transport
Protocol (RTP) session for the second SIP call on Persistent-DIPP
connections when the source port of the client device was reset.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260604</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall displayed inaccurate throughput
utilization stats in NetFlow analyzer tools.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260512</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where accessing the IP address of the device address
group objects from the user interface caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process to stop responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260461</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic logs showed a non-zero destination port
number on ICMP echo sessions through the firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260417</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where
<span class="ph systemoutput">UpdateLicDB</span> was triggered every
few minutes when firewalls with PAYG licenses were onboarded.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260235</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall sent Threat logs and URL logs to an
external syslog server without Security profile settings when Enhanced
Application Logging was enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259910</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall reported the same value over
consecutive SNMP polls when asynchronous mode was enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259881</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where traffic log details were not
displayed under <span class="ph uicontrol">detailed log view</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259802</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Panorama appliances in high availability (HA) clusters only</tt
>) Fixed an issue where, after replacing a secondary Panorama
appliance in a Panorama HA cluster, the ElasticSearch cluster was
unable to establish SSL tunnels due to SSLHandshakeException errors.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259078</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where WildFire Analysis reports were not generated and
the following error message was displayed:
<span class="ph systemoutput">Error 500: Internal Server Error</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-258799</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when updating a Security Policy
<span class="ph uicontrol">Policy Optimizer</span>, the web interface
stopped responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-257961</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where
<span class="ph uicontrol">Test Security Policy Match</span> failed
when the <span class="ph uicontrol">From</span> or
<span class="ph uicontrol">To</span> zone fields were populated.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-255915</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory leak in the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>sslmgr</a
>
process caused the firewall to restart.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-254904</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a core file was generated by
/usr/local/bin/logd during a restart.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-254577</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a core file was created on the Log Forwarding
Card (LFC) due to a third-party software issue.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-253829</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the CLI command
<span class="ph systemoutput">show running security-policy</span>
timed out when the Security policy was large.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-252381</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama web interface was slower than
expected when opening interfaces, virtual routers, and zones in a
template or template stack.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-250394</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a large amount of group data caused serialization
errors and prevented synchronization.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-249581</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where stale BGP routes were advertised to peers even
when they were not present in the local RIB table.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-246699</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the
<span class="ph uicontrol">Rule Usage</span> and
<span class="ph uicontrol">Apps Seen</span> under Security policy
rules stopped incrementing.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-246567</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a firewall with a copper SFP transceiver
(PAN-SFP-CG) flapped during a commit.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-242331</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Prisma Access remote network firewalls
intermittently created incorrect user-to-IP-address mappings.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-241004</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DNS Proxy dropped client requests of the type
<span class="ph systemoutput">ns</span> for a root domain.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-235808</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances in Log Collector mode only</tt
>) Fixed an issue where an unnamed core file was generated after a
reboot.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-233197</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the CLI command to set the FEC parameter for the
front panel ports was not supported on platforms supporting 25G and
100G.
</div>
</td>
</tr>
</tbody>
</table>
+271
View File
@@ -0,0 +1,271 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256181</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the management interface and front panel port
interface statistics were not populated in asynchronous mode of SNMP
operations.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255868</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-3400 Series firewalls only</tt>) Fixed an issue
where the firewall entered maintenance mode after enabling kernel data
collection during the silent reboot.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253317</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Microsoft Azure environments only</tt
>) Fixed an issue where you were unable to log in to the firewall
after a private data reset.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252517</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SNMP failed to respond to multiple Object
Identifier (OID) queries in a single SNMP GET request.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-251639</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an out of memory condition might occur due to a
memory leak in the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>varrcvr</a
>
process when a Wildfire Analysis security profile is enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250597</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Global Find for a Panorama pushed shared address
object displayed <span class="ph uicontrol">Others</span> in the
results.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250270</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where partial commits did not merge changes when the
complete rule base was updated with edit operations via XML API.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-249814</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where multiple
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
processes stopped responding, which caused the dataplane to fail.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-249292</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Microsoft Azure environments only</tt
>) Fixed an issue where CPU usage was higher than expected after a
hotplug event when Accelerated Networking was enabled for the
management interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-245157</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls in Microsoft Azure environments only</tt
>) Fixed an issue where the firewall restarted after an HA failover
when DPDK was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-245125</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls in Microsoft Azure environments only</tt
>) Fixed an issue where file descriptors were not closed due to
invalid configurations.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-244746</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where changes committed on Panorama were not reflected
on the firewall after a successful push.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-238183</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama displayed deviating device system logs
for non-connected interfaces.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-236497</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to purge expired GTP-U
sessions that remained as allocated sessions even after the TTL was
expired.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-234977</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when a Layer 2 interface that was a member of a
VLAN was down, all traffic transmitted over the VLAN was dropped.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-231642</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where users that were
logged in through multiple sessions were able to see an active lock on
only one session.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-214773</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where RTP packets traversing inter-vsys were dropped on
the outgoing vsys.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202095</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where the language setting was not
retained.
</div>
</td>
</tr>
</tbody>
</table>
+61
View File
@@ -0,0 +1,61 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-272809</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-0012"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-0012</a
>
(<a
class="xref"
href="https://security.paloaltonetworks.com/PAN-SA-2024-0015"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>PAN-SA-2024-0015</a
>) and
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-9474"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-9474</a
>.
</div>
</td>
</tr>
</tbody>
</table>
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
+945
View File
@@ -0,0 +1,945 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-290996</b></div>
<div class="p">
<tt class="ph tt">This issue is now resolved. See </tt
><a
class="xref"
href="/content/techdocs/en_US/pan-os/11-1/pan-os-release-notes/pan-os-11-1-10-known-and-addressed-issues/pan-os-11-1-10-h1-addressed-issues.html"
title=""
data-scope="local"
data-format="dita"
data-type=""
target="_self"
>PAN-OS 11.1.10-h1 Addressed Issues</a
>
</div>
</td>
<td class="entry relcol">
<div class="p">
When performing an SNMP walk, the Connections Per Second (CPS)
counters incorrectly return a value of 0 for each virtual system
(VSYS), despite the firewall actively processing connections.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-286255</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the firewall received an unexpected
termination request for SSL sessions, the dataplane experienced a slow
buffer resource leak.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-285941</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where high memory consumption occurred on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-284073</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall that caused commits to fail and the web
interface to become inaccessible.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-283954</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding due to a circular reference between address
groups.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-283168</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue related to syslog forwarding that caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process stopped responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-282697</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic was delayed significantly when it used
<span class="ph uicontrol">No Authentication Explicit Proxy</span> and
matched a decryption policy rule.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-282454</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when you added the
<span class="ph uicontrol">Virtual System Name</span> column under
<span class="ph uicontrol">Unified Logs</span>, the column did not
remain visible in the table if you closed and re-opened the tab.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-282391</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a memory leak occurred after cloning
a template, resulting in an increase in memory use, which caused OOM
errors.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-282359</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama web interface was slower than
expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-282206</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where configuring Secure Web Gateway (SWG) in
<span class="ph uicontrol">no-auth</span> mode led to latency when no
decryption policy rules or
<span class="ph uicontrol">No-decrypt</span> policy rules were
present.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-282069</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where Security policy rules were removed
from device groups when you cloned or edited Security policy rules
that used more than 63 characters.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-281885</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when exporting and importing CSV files, the hash
values of pre-shared key variables set at template and template stack
levels changed inconsistently, which resulted in both variables
displaying the same hash value.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-281882</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where OSPF was redistributing connected routes beyond
the intended loopback IP.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-281649</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the index size limit was incorrectly calculated
and indices rolled over earlier than expected, which resulted in high
memory and OOM errors.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-281269</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5220, PA-5250, and PA-5420 firewalls</tt>) Fixed
an issue where the firewall management server memory usage
continuously increased.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-280942</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process stopped responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-280700</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an Issue where commits failed with the error
<span class="ph systemoutput"
>invalid IPv6 x:x - must be global/link-local unicast</span
>
when the management IPv6 address had a specific value.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-280477</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface were you were unable to scroll up
or down to view source zones in a NAT policy rule.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-279691</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/passive HA configurations only</tt
>) Fixed an issue where the firewall didn't synchronize IPSec SAs
(security associations) to the passive firewall if the tunnel was not
initially established by the active firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-279647</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where threat names were displayed differently on the
web interface and the exported CSV file.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-279621</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where processes stopped responding when HTTPS Forward
traffic was run.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-279400</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when
<span class="ph uicontrol">Restrict Certificate Extensions</span> was
enabled on decryption profiles, the basic constraints extension was
overwritten incorrectly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-279209</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where changes made to the management interface
permitted IP address list in a global template were not pushed to the
template stack or firewalls.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-279195</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where
<span class="ph uicontrol">Device Health</span> displayed the device
memory as 0%.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-279065</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall sent logs with
<span class="ph uicontrol">connection succeeded</span> to the syslog
server every time a connection was established, which resulted in
excessive logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-278190</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a scheduled report with SLS data had
an invalid translated-query.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-277755</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue that caused the
<span class="ph systemoutput">request system private-data-reset</span>
CLI command to fail.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-277417</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an memory leak issue related to TLS inbound decryption.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-277018</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where FTP data connections did not work for EPRT with
Source IP + Port translation enabled on the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-276862</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logd</a
>
process stopped responding unexpectedly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-276616</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where half-duplex settings on Ethernet
was not visible.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-276412</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were unable to download XML files from
<span class="ph uicontrol">Panorama &gt; Summary &gt; Backups</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-274907</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where
<span class="ph uicontrol">Config Audit Commit Date</span> displayed
the timestamp of the configuration edit instead of the commit time.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-274750</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the detailed log view in Panorama did not display
all packet details for traffic logs received from the cloud.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-274726</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Wildfire signature generation was enabled on all
nodes in a cluster instead of only the active node.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-274569</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the QSPF transceiver interface displayed an
incorrect range figure on the temperature alarm.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-274314</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-1400 Series firewalls, PA-3400 Series firewalls, and PA-5400
Series firewalls only</tt
>) Fixed an issue where, when the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process restarted, control plane packets were dropped, which could
impact LACP and pings to host interfaces.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-273870</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where you were unable to local changes
that were made via the web interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-273422</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic failed when Inline cloud analysis
(Advanced Threat Prevention) was enabled in the Anti-Spyware profile
with the action set to anything other than
<span class="ph uicontrol">allow</span> or
<span class="ph uicontrol">alert</span> and the maximum latency
condition was reached.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-273141</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients experienced slow file
transfer download throughput when passing through an IPSec tunnel.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-271701</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Advanced Services, App-ID Cloud Engine (ACE), and
Enhanced Application Log stopped working due to incorrect memory usage
accounting, which caused memory usage to remain at 99% after an
extended period of time.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-271498</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-7000 Series firewalls, PA-5200 firewalls, and PA-5400f firewalls
in FIPS mode only</tt
>) Fixed an issue where decrypted traffic repeatedly failed and
frequent reboots were required.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-271273</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where dynamic update downloads failed when
<span class="ph uicontrol">IPv6 firewalling</span> was enabled on the
firewall and both IPv4 and IPv6 were configured on the management
interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-271175</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding with a SIGABRT.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-271151</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect client did not automatically
initiate a Kerberos SSO connection after logging in to Windows.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-270192</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not display the management IP
address of devices onboard via ZTP.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-269404</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not reset the maximum latency
timer for hold mode.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-268705</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an intermittent issue where the firewall failed to process FTP
traffic after upgrading to PAN-OS 10.1.14.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-268614</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where, when all rules were
highlighted when a read-only admin user clicked the
<span class="ph uicontrol">Highlight Unused Rules</span> checkbox.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-267936</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where commits failed with a validation error when you
changed the encryption level and re-encryption option on a Panorama
managed firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-267444</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where large file downloads or uploads failed or
remained in an incomplete state when using DLP HTTP2 mirror mode.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-266589</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to generate a tech
support file when management server debug was disabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263465</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process stopped responding due to a memory leak and buffer overrun.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263270</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after a commit was performed from Strata Cloud
Manager, the SD-WAN configuration containing BGP routes did not
display on the hub firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263052</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput"
>request logdb migrate-to-panorama start end-time &lt;start-time&gt;
&lt;type&gt;</span
>
CLI command did not work as expected, and you were unable to resend
logs from a firewall to Panorama or a log collector.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260015</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where the dataplane restarted due to
insufficient allocation of memory buffers.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259610</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Wildfire content installation failed for WF-500B
clusters when deployed from Panorama using the deployment schedule.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255914</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Amazon Web Services (AWS) environments
only</tt
>) Fixed an issue where a newly bootstrapped firewall required a
management server restart, relicensing, or license push from Panorama
to invoke the device certificate.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254524</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where, when the
<span class="ph uicontrol">Commit and Push</span> button was clicked
during a selective
<span class="ph uicontrol">Commit and Push</span> operation, the
window stopped responding, which caused the operation to be delayed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253127</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to PAN-OS 11.0.2-h3, the
hardware pool DFLT became highly utilized, and the packet buffer
gradually increased.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-249574</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where selective pushes failed due to a missing log
collector reference.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-245064</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Multi-vsys firewalls only</tt>) Fixed an issue
where commits failed on the firewall after selecting
<span class="ph uicontrol">Export or push device config bundle</span>
on Panorama and a force push was required.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-238208</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall API returned inconsistent responses
to a failed call using a valid API key. With this fix, the firewall
returns the error
<span class="ph uicontrol">Session is invalid</span> if the session is
not available for the cookie.
</div>
</td>
</tr>
</tbody>
</table>
+42 -42
View File
@@ -1,163 +1,163 @@
{
"PAN-OS": {
"11.1.0": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-0-known-and-addressed-issues/pan-os-11-1-0-addressed-issues",
"known": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-0-known-and-addressed-issues/pan-os-11-1-0-known-issues"
},
"11.1.0-h1": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-0-known-and-addressed-issues/pan-os-11-1-0-h1-addressed-issues",
"known": ""
},
"11.1.0-h2": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-0-known-and-addressed-issues/pan-os-11-1-0-h2-addressed-issues",
"known": ""
},
"11.1.0-h3": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-0-known-and-addressed-issues/pan-os-11-1-0-h3-addressed-issues",
"known": ""
},
"11.1.0-h4": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-0-known-and-addressed-issues/pan-os-11-1-0-h4-addressed-issues",
"known": ""
},
"11.1.1": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-1-known-and-addressed-issues/pan-os-11-1-1-addressed-issues",
"known": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-1-known-and-addressed-issues/pan-os-11-1-1-known-issues"
},
"11.1.1-h1": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-1-known-and-addressed-issues/pan-os-11-1-1-h1-addressed-issues",
"known": ""
},
"11.1.1-h2": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-1-known-and-addressed-issues/pan-os-11-1-1-h2-addressed-issues",
"known": ""
},
"11.1.2": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-2-known-and-addressed-issues/pan-os-11-1-2-addressed-issues",
"known": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-2-known-and-addressed-issues/pan-os-11-1-2-known-issues"
},
"11.1.2-h1": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-2-known-and-addressed-issues/pan-os-11-1-2-h1-addressed-issues",
"known": ""
},
"11.1.2-h3": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-2-known-and-addressed-issues/pan-os-11-1-2-h3-addressed-issues",
"known": ""
},
"11.1.2-h4": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-2-known-and-addressed-issues/pan-os-11-1-2-h4-addressed-issues",
"known": ""
},
"11.1.2-h9": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-2-known-and-addressed-issues/pan-os-11-1-2-h9-addressed-issues",
"known": ""
},
"11.1.2-h12": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-2-known-and-addressed-issues/pan-os-11-1-2-h12-addressed-issues",
"known": ""
},
"11.1.2-h14": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-2-known-and-addressed-issues/pan-os-11-1-2-h14-addressed-issues",
"known": ""
},
"11.1.2-h15": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-2-known-and-addressed-issues/pan-os-11-1-2-h15-addressed-issues",
"known": ""
},
"11.1.2-h16": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-2-known-and-addressed-issues/pan-os-11-1-2-h16-addressed-issues",
"known": ""
},
"11.1.2-h18": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-2-known-and-addressed-issues/pan-os-11-1-2-h18-addressed-issues",
"known": ""
},
"11.1.3": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-3-known-and-addressed-issues/pan-os-11-1-3-addressed-issues",
"known": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-3-known-and-addressed-issues/pan-os-11-1-3-known-issues"
},
"11.1.3-h1": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-3-known-and-addressed-issues/pan-os-11-1-3-h1-addressed-issues",
"known": ""
},
"11.1.3-h2": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-3-known-and-addressed-issues/pan-os-11-1-3-h2-addressed-issues",
"known": ""
},
"11.1.3-h4": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-3-known-and-addressed-issues/pan-os-11-1-3-h4-addressed-issues",
"known": ""
},
"11.1.3-h6": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-3-known-and-addressed-issues/pan-os-11-1-3-h6-addressed-issues",
"known": ""
},
"11.1.3-h10": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-3-known-and-addressed-issues/pan-os-11-1-3-h10-addressed-issues",
"known": ""
},
"11.1.3-h11": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-3-known-and-addressed-issues/pan-os-11-1-3-h11-addressed-issues",
"known": ""
},
"11.1.3-h13": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-3-known-and-addressed-issues/pan-os-11-1-3-h13-addressed-issues",
"known": ""
},
"11.1.4": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-4-known-and-addressed-issues/pan-os-11-1-4-addressed-issues",
"known": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-4-known-and-addressed-issues/pan-os-11-1-4-known-issues"
},
"11.1.4-h1": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-4-known-and-addressed-issues/pan-os-11-1-4-h1-addressed-issues",
"known": ""
},
"11.1.4-h4": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-4-known-and-addressed-issues/pan-os-11-1-4-h4-addressed-issues",
"known": ""
},
"11.1.4-h7": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-4-known-and-addressed-issues/pan-os-11-1-4-h7-addressed-issues",
"known": ""
},
"11.1.4-h9": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-4-known-and-addressed-issues/pan-os-11-1-4-h9-addressed-issues",
"known": ""
},
"11.1.4-h13": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-4-known-and-addressed-issues/pan-os-11-1-4-h13-addressed-issues",
"known": ""
},
"11.1.4-h15": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-4-known-and-addressed-issues/pan-os-11-1-4-h15-addressed-issues",
"known": ""
},
"11.1.4-h16": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-4-known-and-addressed-issues/pan-os-11-1-4-h16-addressed-issues",
"known": ""
},
"11.1.4-h17": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-4-known-and-addressed-issues/pan-os-11-1-4-h17-addressed-issues",
"known": ""
},
"11.1.4-h18": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-4-known-and-addressed-issues/pan-os-11-1-4-h18-addressed-issues",
"known": ""
},
"11.1.4-h25": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-4-known-and-addressed-issues/pan-os-11-1-4-h25-addressed-issues",
"known": ""
},
"11.1.4-h27": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-4-known-and-addressed-issues/pan-os-11-1-4-h27-addressed-issues",
"known": ""
},
"11.1.5": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-5-known-and-addressed-issues/pan-os-11-1-5-addressed-issues",
"known": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-5-known-and-addressed-issues/pan-os-11-1-5-known-issues"
},
"11.1.5-h1": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-5-known-and-addressed-issues/pan-os-11-1-5-h1-addressed-issues",
"known": ""
},
"11.1.6": {
@@ -245,11 +245,11 @@
"known": ""
},
"11.1.8": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-8-known-and-addressed-issues/pan-os-11-1-8-addressed-issues",
"known": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-8-known-and-addressed-issues/pan-os-11-1-8-known-issues"
},
"11.1.9": {
"addressed": "",
"addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-9-known-and-addressed-issues/pan-os-11-1-9-addressed-issues",
"known": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-9-known-and-addressed-issues/pan-os-11-1-9-known-issues"
},
"11.1.10": {