|
PAN-307901
|
Fixed an issue where a leak in decryption counters caused resource
exhaustion, which led to a GlobalProtect service outage.
|
|
PAN-307702
|
(Firewalls in HA configurations only) Fixed an
issue where traffic passing through AE layer 2 interfaces was
interrupted during HA failovers.
|
|
PAN-306451
|
(VM-Series firewalls on AWS environments only)
Fixed an issue where, after upgrading the firewall to an affected
release, GlobalProtect clients did not connect with IPSec and instead
connected using SSL due to traffic flow being disabled when checking
for health check packets.
|
|
PAN-306103
|
(PA-3400 and PA-5400 Series firewalls only)
Fixed an issue where the firewall dataplane frequently restarted when
lockless QoS was enabled
|
|
PAN-303959
|
Fixed an issue where traffic was incorrectly identified as
unknown-tcp/unknown-udp due to App-ID resource leak and eventually
dropped.
|
|
PAN-301409
|
Fixed an issue where Panorama failed to perform a selective push to a
managed device when device tags were added or modified on the policy
rules. The selective push failed with the error message
Failed to generate selective push configuration. Schema validation
failed. Please try a full push.
|
|
PAN-301222
|
Fixed an issue where DNS Security logs incorrectly displayed a
sinkhole action for benign DNS categories due to the firewall saving
the drop or sinkhole action in session flags without discarding the
session.
|
|
PAN-300638
|
(VM-Series firewalls only) Fixed an issue where
the firewall stopped responding due to an out-of-bounds read when
parsing TLS 1.3 clientHello messages with large TLS clientHello
extensions where the
supported_versions extension fell
outside the first TCP segment.
|
|
PAN-295803
|
Addressed a memory leak issue under sc3 and automatic commit recovery
(ACR) code path.
|
|
PAN-289723
|
Fixed an issue where the firewall web interface continuously loaded
and not display any output when viewing the Route Table or FIB table
(More Runtime Stats). This issue
occurred when L3 configurations were added to ethernet and AE
interfaces.
|