|
PAN-268823
|
Fixed an issue where
Monitor > Log Display did not
display all logs when you applied a filter.
|
|
PAN-268501
|
Fixed an issue where the firewall was unable to generate a TSF file
due to a full root partition.
|
|
PAN-268339
|
Fixed an issue where
syslog-ng failed to start due to
the syslog-ng.config file being corrupted when upgrading from PAN-OS
10.2.9-h1 to PAN-OS 10.2.11.
|
|
PAN-267660
|
Fixed an issue where UserID stopped working when the
show object registered user CLI
command was used with start-point and limit options.
|
|
PAN-266698
|
Fixed an issue where an email was able to be transferred to the
destination MTA even when the firewall detected a suspicious file with
a reset-bot action when it was encrypted by STARTTLS.
|
|
PAN-266695
|
Fixed an issue on Panorama where a cyclic nested address group
configuration caused the
configd
process to stop responding after a commit.
|
|
PAN-266427
|
Fixed an issue on the firewall where, when a high number of SD-WAN
branch sites or interfaces were not connected, SD-WAN processes and
tund
processes stopped responding due to a high probing rate.
|
|
PAN-265963
|
Fixed an issue where the
escd
process caused a memory leak when session resiliency was enabled on
the firewall.
|
|
PAN-265900
|
Fixed an issue where the firewall stopped responding due to a
tund
process or SD-WAN process restart.
|
|
PAN-265742
|
Fixed an issue on the Panorama web interface where the
OK button on the GlobalProtect
gateway configuration dialog box was not clickable.
|
|
PAN-265686
|
Fixed an issue where the GlobalProtect portal logged passwords in
cleartext.
|
|
PAN-264249
|
Fixed an issue on the firewall where SNMP queries timed out when using
SNMP.
|
|
PAN-264246
|
Fixed an issue where the Authentication Portal did not work properly
with session cookies when the request to the portal contained the
header Sec-Fetch-Site=cross-site.
|
|
PAN-263973
|
Fixed an issue where log collectors had a low incoming log rate.
|
|
PAN-263843
|
(VM-Series firewalls only) Fixed an issue where
the firewall received no-license packet buffers instead of memory
based packet buffer numbers.
|
|
PAN-263749
|
Fixed an issue where disk space that was used by file descriptors was
not freed, which caused the root partition to become full and Panorama
to be inaccessible.
|
|
PAN-263674
|
(VM-Series firewalls in HA configurations only)
Fixed an issue where the firewall rebooted due to multiple HA
failovers.
|
|
PAN-263291
|
Fixed an issue where Microsoft Outlook did not work as expected when
the GlobalProtect clientless VPN was configured.
|
|
PAN-263287
|
The PAN-COMMON-MIB.my file was updated to support new object
identifiers (OID) to poll interface use via SNMP with table
identifiers.
|
|
PAN-263270
|
Fixed an issue where, after a commit was performed from Strata Cloud
Manager, the SD-WAN configuration containing BGP routes did not
display on the hub firewall.
|
|
PAN-262946
|
Fixed an issue on the firewall where logging in via the CLI or web
interface did not work due to increased memory usage.
|
|
PAN-261936
|
Fixed an issue where WildFire submission logs were not displayed when
filtered by Sender Address.
|
|
PAN-261673
|
(VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where, when Accelerated Networking was enabled,
traffic was dropped because of the
flow_parse_ip_hdr counter related
to an Nvidia driver issue.
|
|
PAN-261602
|
Fixed an issue where GlobalProtect Decryption logs were not forwarded
to Panorama.
|
|
PAN-260842
|
A CLI command was introduced to address an issue where TCP packets
were out of order.
|
|
PAN-260796
|
Fixed an issue where servers were not accessible through an active SSL
GlobalProtect VPN tunnel until a new connection was established or the
session was cleared on the firewall.
|
|
PAN-260752
|
Fixed an issue where the firewall did not support TLSv1.3 in the
Clientless VPN, which caused the portal page to not load.
|
|
PAN-260604
|
Fixed an issue where the firewall displayed inaccurate throughput
utilization stats in NetFlow analyzer tools.
|
|
PAN-260564
|
Fixed an issue on firewalls in HA configurations where a network loop
was detected by switches after suspending HA on the active firewall.
|
|
PAN-260546
|
(PA-440 firewalls only) Fixed an issue where
the system clock reset to the epoch date and time after 8 to 12 weeks
of shelf life or no power.
|
|
PAN-260316
|
Fixed an issue where the
all_task
process stopped responding and the firewall rebooted.
|
|
PAN-260290
|
Fixed an issue for fixed model licenses to support new content size
requirements by reducing the total sessions supported to be equivalent
to their flex memory counterpart
|
|
PAN-260279
|
Fixed an issue where selective push operations failed with the error
message:
Failed to generate selective push configuration. Schema validation
failed. Please try a full push.
|
|
PAN-259910
|
Fixed an issue where the firewall reported the same value over
consecutive SNMP polls when asynchronous mode was enabled.
|
|
PAN-259870
|
(PA-7000b firewalls only) Fixed an issue where
Luna Network Hardware Security Modules (HSM) did not work after an
upgrade or downgrade.
|
|
PAN-259767
|
Fixed an issue where GlobalProtect users were unable to connect when
the option
Block sessions if the certificate was not issued to the
authenticating device
was enabled in the certificate profile.
|
|
PAN-259727
|
(Panorama appliances in HA configurations only)
Fixed an issue where Panorama became unresponsive and displayed a 504
gateway timeout error when accessing the web interface or the CLI.
|
|
PAN-258996
|
Fixed an issue where the firewall displayed the SFP ports as
PowerDown when the SFP
transceiver was removed and reinserted or the port was shut down and
brought back up on the peer device.
|
|
PAN-258912
|
(PA-7000b firewalls only) Fixed an issue where
the firewall web interface displayed an incorrect HSM client version
when the client was upgraded to version 7.2.0.220.
|
|
PAN-258570
|
Fixed an issue where the firewall might reboot unexpectedly due to the
varrcvr
process progressively using more memory when WildFire file forwarding
is handling PE files.
|
|
PAN-258166
|
(PA-220 firewalls only) Fixed an issue where
the root partition frequently reached 100%.
|
|
PAN-257736
|
(PA-5450 firewalls only) Fixed an issue where
traffic to benign applications was was impacted by holding TCP
sequential segments for MLC inspection and not releasing the full
chain after a benign verdict was received.
|
|
PAN-257601
|
(PA-5450 firewalls only) Fixed an issue where
Networking Cards (NC) experienced an internal link fault which caused
path monitoring failure on the Dataplane Processing Card (DPC).
|
|
PAN-257327
|
(PA-5440 firewalls only) Fixed an issue where a
failover event occurred unexpectedly on the firewall.
|
|
PAN-256560
|
Fixed an issue where exporting a
Custom Report to CSV format did not
display the full report if it contained non-ASCII characters.
|
|
PAN-256115
|
Fixed an issue where, after replacing a Panorama appliance or log
collector, the secondary Panorama appliance or log collector displayed
a disconnected status for the
inter-log collector connection.
|
|
PAN-255653
|
Fixed an HA failover issue where, when Management Processing Card
(MPC) or Base Card (BC) failures occurred, the HA link went down,
which caused fpp-down events on one firewall.
|
|
PAN-255190
|
Fixed an issue where the TCP timeout value was reflected incorrectly
when using application override for a custom application in TAP mode.
|
|
PAN-253829
|
Fixed an issue where the CLI command
show running security-policy
timed out when the Security policy was large.
|
|
PAN-252300
|
Fixed an issue where you were unable to select device groups in the
push scope for user accounts.
|
|
PAN-252270
|
Fixed an issue on the firewall where changes were incorrectly applied
after a reboot or a restart of the
configd
process.
|
|
PAN-251385
|
Fixed an issue where the
configd
process stopped responding when processing system logs.
|
|
PAN-251035
|
Fixed an issue where selective push operations did not push
certificate changes to the firewall.
|
|
PAN-250928
|
(PA-5450 firewalls in active/active HA configurations only) Fixed an issue where firewall traffic was silently dropped when
sent to the peer owner.
|
|
PAN-250585
|
Fixed an issue where the firewall CPU use increased after upgrading
from PAN-OS 10.2.4-h4 to PAN-OS 10.2.8 due to a change in system
resource reporting by the REST API.
|
|
PAN-247857
|
(PA-7050 firewalls in HA configurations only)
Fixed an issue on the firewall where a dataplane process restarted
when updating the routing table.
|
|
PAN-247190
|
(VM-Series firewalls only) Fixed an issue where
the firewall was unable to connect to Panorama after manually
uploading the license key.
|
|
PAN-246699
|
Fixed an issue on Panorama where
Rule Usage and
Apps Seen under Security policy
rules stopped incrementing.
|
|
PAN-244039
|
(PA-5450 firewalls only) Fixed an issue where
the firewall dropped packets when attempting to reuse a TCP session.
|
|
PAN-243235
|
Fixed an issue where Panorama stopped responding and rebooted
repeatedly after an upgrade.
|
|
PAN-242479
|
Fixed an issue where a high number of packets caused high packet
descriptors on the firewall when handling EtherIP traffic.
|
|
PAN-241022
|
Fixed an issue where rib-out routes were not displayed due to the next
hop of BGP local routes not getting matched with export filters.
|
|
PAN-241004
|
Fixed an issue where DNS Proxy dropped client requests of the type
ns for a root domain.
|
|
PAN-240990
|
Fixed an issue where
l3svc.py displayed incorrect
logs.
|
|
PAN-239165
|
Fixed an issue where adding an interface in a route filter resulted in
an OSPF LSA Type-5 packet check failure, which caused redistributed
routes to be removed.
|
|
PAN-238610
|
Fixed an issue with the Panorama Virtual Appliance where, after the
mgmtsrvr
restarted on the passive appliance, stale IP address tags were pushed
to the connected firewalls with the message
clear all registered ip addresses.
|
|
PAN-237246
|
Fixed an issue where the
all_pktproc
process repeatedly restarted, which caused the firewall to go into a
nonfunctional state.
|
|
PAN-233965
|
Fixed an issue where the
tund
process stopped responding, which caused push operation to managed
firewalls or making changes to local firewalls to fail.
|
|
PAN-232530
|
Fixed an issue where the
useridd
process ran out of memory and restarted when the number of user or
user groups exceeded the threshold.
|
|
PAN-229686
|
Fixed an issue where eBGP remained in an idle state after disabling
and enabling BGP configurations.
|
|
PAN-229526
|
Fixed an issue where the
mprelay
process stopped responding due to a netflow session refresh taking
longer than expected to complete.
|
|
PAN-224472
|
Fixed an issue where the TCP timeout did not refresh for sessions
using challenge-ACK, which caused the session to timeout.
|
|
PAN-222590
|
Fixed an issue where a semicolon appeared at the end of file names of
data filtering logs.
|
|
PAN-218873
|
Fixed an issue where a HIP mask was reused when an existing IP address
user mapping was updated by a new IP address user mapping that had a
different username but the same IP address.
|
|
PAN-218279
|
Fixed an issue on Panorama where hostname variables displayed as
unknown when exporting template or
template stack variables in CSV format.
|
|
PAN-214122
|
Fixed an issue where the
ikemgr
process stopped responding when processing a high number of IKEv2 SA
requests.
|
|
PAN-213045
|
(WF-500-B appliances only) Fixed an issue where
the WildFire appliance failed to fetch device certificates due to a
syntax error in the system database format.
|
|
PAN-195661
|
Fixed an issue where the firewall did not insert the IP address tag
into the dynamic address group after a device server restart, which
caused traffic that matched the dynamic address group Security policy
rule base failed.
|
|
PAN-193285
|
Fixed an issue where the policy optimizer feature did not add entries
back to the mongodb database
after removing them during an upgrade or downgrade.
|
|
PAN-188998
|
Fixed an issue where the firewall logged excessive SSL VPN debug
information.
|