|
PAN-314319
|
Fixed an issue where the firewall experienced increased packet drops
and slower performance after an upgrade due to high burst traffic.
|
|
|
|
|
PAN-313572
|
(VM-Series firewalls only) Fixed an issue where
the dataplane restarted due to a segmentation fault.
|
|
PAN-312706
|
Fixed an issue where the firewalls restarted due to a function lacking
a NULL-pointer sanity check.
|
|
PAN-311524
|
Fixed an issue where config-lock was not displayed on the web
interface.
|
|
PAN-311250
|
(Panorama appliances and Log Collectors only)
Fixed an issue where logs from multiple devices were not visible on
Panorama even though the Elasticsearch health status on the dedicated
Log Collectors appeared green.
|
|
PAN-311073
|
(Panorama managed firewalls in HA configurations only) Fixed an issue where firewalls incorrectly updated the modified
date and MD5 hash of policy rules during an HA sync commit job or a
subsequent local commit, even when no changes were made to the policy
rules.
|
|
PAN-308786
|
(Panorama appliances only) Fixed an issue where
traffic log queries using the
device_name filter returned no
results, and, additionally complex log queries that included negation
operators produced incorrect outputs.
|
|
PAN-308654
|
Fixed an issue where the Elasticsearch Close Indices process closed
more indices than expected and dropped the number of open shards below
the minimum of 800 per Elasticsearch instance. This occurred because
the process did not correctly account for the number of Elasticsearch
instances when calculating the maximum number of allowed open shards.
|
|
PAN-307702
|
(Firewalls in HA configurations only) Fixed an
issue where traffic passing through AE layer 2 interfaces was
interrupted during HA failovers.
|
|
PAN-307597
|
Fixed an issue where BGP peering sessions between a hub firewall and a
satellite firewall over GlobalProtect LSVPN failed to connect.
|
|
PAN-306555
|
Fixed an issue where the firewall stopped responding, which led to
service outages.
|
|
PAN-306451
|
(VM-Series firewalls on AWS environments only)
Fixed an issue where, after upgrading the firewall to an affected
release, GlobalProtect clients did not connect with IPSec and instead
connected using SSL due to traffic flow being disabled when checking
for health check packets.
|
|
PAN-305700
|
Fixed an issue where a reboot loop occurred when OSPF interfaces were
configued with a link type of
point-to-point.
|
|
PAN-305552
|
Fixed an issue where DLP logs displayed an incorrect file type when
the firewall did not set the file type field.
|
|
PAN-304746
|
( Panorama appliances and Panorama virtual appliances only) Fixed an issue where the
configd
process restarted when committing and pushing configuration for a new
WildFire cluster.
|
|
PAN-304718
|
Fixed an issue where OSPF and BGP outages occurred due to an
all_task
process restart during clientless VPN content rewrite processing.
|
|
PAN-304696
|
Fixed an issue where the Cloud User-ID connection timed out because
the firewall took too long to process the OCSP response.
|
|
PAN-304576
|
Fixed an issue where the firewall entered a non-functional state due
to segmentation fault within the
all_pktproc
process that was caused by a session that involved http2 cleartext
traffic
|
|
PAN-303745
|
Fixed an issue where inter-dataplane forwarding did not work for
sessions ingressing on Slot 2, which resulted in intermittent ping
failures to interfaces on Network Card 2 when traffic was forwarded to
Slot 3. Note: With this fix, after a slot restart, the global counter
will still show dot1q errors for a short period.
|
|
PAN-303722
|
Fixed an issue on the firewall where configuring spyware and
vulnerability profiles in Security policy rules caused a memory leak
in the
devsrvr
process with each configuration commit.
|
|
PAN-301731
|
Fixed an issue where, when the firewall was unable to establish an SCM
connection due to the discovery service returning a 404 error when the
device was not yet known to the service, the firewall did not retry
the attempt as expected.
|
|
PAN-300664
|
Fixed an issue on the Panorama and firewall web interface where
Applications pages became unresponsive after activating the SaaS
Inline license.
|
|
PAN-299705
|
Fixed an issue where API calls to commit changes on Panorama
intermittently failed when using the XML API with refresh=no, which caused changes to not be applied to the partial-commit
configuration.
|
|
PAN-299495
|
Fixed an issue where the
show system setting ssl-decrypt certificate
CLI command did not display certificates when XML output was enabled.
|
|
PAN-298945
|
Fixed an issue where OSCP HTTP POST requests were not formatted
correctly, which caused failures with strict responders.
|
|
PAN-297540
|
(Panorama managed firewalls in HA configurations only) Fixed an issue where the HA-Link-Monitor configuration pushed from
Panorama was converted to a local configuration on the peer device
after an HA sync, which caused subsequent Panorama pushes of link
monitor changes to be flagged as overwritten, and a forced template
push or manual clearing of the configuration on the firewall was
required.
|
|
PAN-296694
|
Fixed an issue where the firewall rebooted due to the
useridd
process repeatedly restarting during an IP-port data type writes to
the redis from multiple sources such as TSA or XML in a scale
environment.
|
|
PAN-295803
|
Addressed a memory leak issue under sc3 and automatic commit recovery
(ACR) code path.
|
|
PAN-295802
|
Fixed an issue where a memory leak related to the
configd
process occurred.
|
|
PAN-294379
|
Fixed an issue where, when SD-WAN SaaS Application path monitoring
failed for all interfaces, the firewall stopped forwarding traffic
even if the ISP links and default gateway probing were still active.
|
|
PAN-292306
|
Fixed an issue where the
authd
process stopped handling RADIUS authentication requests and required a
restart.
|
|
PAN-290938
|
Fixed an issue where multiple memory leaks occurred related to the
configd
process.
|
|
PAN-288175
|
Addressed a stack buffer overflow memory leak under plugin management
code path.
|
|
PAN-287159
|
Fixed an issue where file uploads to Dropbox stalled when using a
PA-CPT device with MLC2 and DLP Mirror mode enabled for HTTP2 traffic.
This occurred because the proxy was unable to decrement packet counts
properly when the queue was large, resulting in a receive window size
of 0 for the parent session.
|
|
PAN-279364
|
(VM-Series firewalls with multiple NICs only)
Fixed an issue were the queue count in the task dump displayed an
incorrect number of queues for SR-IOV interfaces due to the queue
mapping logic incorrectly using a non-multi-NIC function.
|
|
PAN-278688
|
Fixed an issue where DNS Security threat logs were not displayed on
the firewall when packet capture was enabled and the domain name
length was 62 characters.
|
|
PAN-274742
|
(VM-Series firewalls only) Fixed an issue where
the task-queue dump CLI command
returned incorrect information in multi-nic mode.
|
|
PAN-259785
|
Fixed an issue where the
devsrvr
process restarted and created a core dump because two threads did not
terminate correctly.
|