|
PAN-306306
|
(Panorama appliances in FIPS-CC mode only)
Fixed interdevice TLS communication failures that occurred with RSA
and RSA-PSS signature algorithms across multiple layer 7 application
services.
|
|
PAN-303051
|
Fixed an issue on Panorama where a memory leak occurred related to the
reportd
process due to retaining memory that was temporarily used for report
generation instead of releasing the memory for reuse, which resulted
in continuous accumulation and memory exhaustion.
|
|
PAN-302927
|
Fixed an issue where, after upgrading Panorama, the
Push to Devices option did not
display selected devices, and the
OK and
Cancel
buttons did not function as expected. Selecting
OK did not close the window, and
selecting Cancel returned to the
main push screen with the push selected devices displaying as empty.
Despite this, selecting Push or
Validate Device Group Push still
pushed to the previously canceled, non-displayed devices.
|
|
PAN-301801
|
Fixed an issue on Log Collectors where the Elasticsearch process
fluctuated intermittently between green and red states, which led to
interruptions in log collection. This issue occurred when the number
of shards exceeded the cluster's maximum supported threshold of
greater than 1000 shards per Elasticsearch instance.
|
|
PAN-301691
|
Fixed an issue where BGP stopped responding with the error message
Too many open files when pushing
1000 eBGP (External BGP) neighbor configurations. With this fix, the
number of file descriptors for the BGP process is increased from 1024
to 8192.
|
|
PAN-301456
|
Fixed an issue on Panorama where the
debug system reset-ztp CLI
command was unavailable.
|
|
PAN-300216
|
Fixed an issue where, when SD-WAN Direct Internet Access was
configured and traffic traversed the cellular interface without a NAT
policy rule, intermittent cellular modem connectivity issues occurred,
which caused the firewall to disconnect and reconnect to the cellular
network.
To use this fix, run the CLI command
set session teardown-upon-fwd-zonechange yes.
|
|
PAN-300138
|
Fixed an issue where DNS queries stalled or repeatedly time out due to
multiple DNS responses with different CNAME values causing evasion
false positive alerts.
|
|
PAN-299815
|
Fixed an issue on multi-vsys firewalls where a host was not removed
from the quarantine list after receiving a redistribution message from
Panorama. This occurred when Panorama was configured to redistribute
quarantine messages to a firewall cluster, and the GlobalProtect
configuration and redistribution were built out in a vsys other than
vsys1.
|
|
PAN-298387
|
Fixed an issue on the firewall where the source and destination NAT IP
addresses did not display in traffic and threat logs.
|
|
PAN-297610
|
Fixed an issue where the firewall became unresponsive after an upgrade
due to the
fsck
command scanning drive partitions in parallel with the root partition,
which caused the process to take an extended amount of time.
|
|
PAN-297005
|
Fixed an issue where exporting custom reports resulted in empty CSV
files.
|
|
PAN-296977
|
Fixed an issue where the web interface became unresponsive when
attempting to view
Ethernet interface details after
applying a filter in
|
|
PAN-296694
|
Fixed an issue where the firewall rebooted due to the
useridd
process repeatedly restarting during an IP-port data type writes to
the redis from multiple sources such as TSA or XML in a scale
environment.
|
|
PAN-296535
|
Fixed an issue on the firewall where BGP peers disconnected when more
than 500 BGP neighbors were configured in a single Logical Router
|
|
PAN-295899
|
Fixed an issue where DNS resolution failed on Linux machines running
GlobalProtect client version 6.2.6 when connected with DNS Security
enabled. This occurred because the firewall incorrectly discarded DNS
packets when processing multiple DNS requests or responses over the
same session, even when no malicious verdict was received.
|
|
PAN-276525
|
Resolved multiple issues affecting IPSec tunnels using NAT Traversal
(NAT-T) when a Dynamic NAT policy was configured (including Dynamic
NAT or DIPP). During rekey events, tunnels could go down or flap due
to incorrect session handling. This issue impacted both cluster and
standalone deployments.
|
|
PAN-209516
|
Fixed an issue where, when creating an interface, an error occurred
when you clicked OK without
providing a value in the Tag field
even though the field was not displayed as mandatory.
|
|
PAN-185731
|
Fixed an issue where the firewall was unable to parse the URL path and
host when the host header was located in a different packet, which
resulted in the firewall not logging the URL path in the first packet.
The fix is disabled by default. The following CLI commands can be used
to enable/disable the feature: set system setting ctd
url-crosspkt-host-path-caching enable set system setting ctd
url-crosspkt-host-path-caching disable set system setting ctd
url-crosspkt-host-path-caching default
|