|
PAN-306502
|
Fixed an issue where TLS connection failure occurred when traffic was
over TLS1.2 or below, header insertion was enabled on the firewall,
send TLS handshake to CTD was
enabled, and traffic hit a decryption policy rule configured with the
no-decrypt action.
|
|
PAN-306306
|
(Panorama appliances in FIPS-CC mode only)
Fixed interdevice TLS communication failures that occurred with RSA
and RSA-PSS signature algorithms across multiple layer 7 application
services.
|
|
PAN-306226
|
Fixed an issue where the TLS handshake did not complete and the
session did not go through. This occurred if the HTTP header insertion
applied to an HTTP CONNECT request passing through the firewall, the
scan-handshake feature was enabled, the session matched a decryption
policy rule with the decrypt action, and if the TLS client hello was
in a single packet and TLS 1.2 or below.
|
|
PAN-304496
|
Fixed an issue where, after unregistering an IP tag and registering a
different IP tag for the same IP address via XML API, the dynamic
address group membership was not updated on the dataplane, which
resulted in Security policy rules being enforced incorrectly.
|
|
PAN-303954
|
Fixed an issue where, when configuring Safenet HSMs in HA and
authentication HSM manually, the second HSM server failed to
authenticate due to the firewall overwriting the first HSM server's
certificate with the second HSM server's certificate.
|
|
PAN-303051
|
Fixed an issue on Panorama where a memory leak occurred related to the
reportd
process due to retaining memory that was temporarily used for report
generation instead of releasing the memory for reuse, which resulted
in continuous accumulation and memory exhaustion.
|
|
PAN-301801
|
Fixed an issue on Log Collectors where the Elasticsearch process
fluctuated intermittently between green and red states, which led to
interruptions in log collection. This issue occurred when the number
of shards exceeded the cluster's maximum supported threshold of
greater than 1000 shards per Elasticsearch instance.
|
|
PAN-300637
|
( VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where the firewall unexpectedly rebooted due to
repeated
varrcvr
process restarts.
|
|
PAN-300548
|
Fixed an issue where using the IKEv2 multiplier setting for VPN
re-authentication resulted in the firewall not re-authenticating at
the expected intervals when both sides initiated rekeying. The
internal re-authentication counter incremented when the local side
triggered the rekey, but not when the peer side triggered it.
|
|
PAN-297975
|
Fixed an issue where Panorama was unable to push the Trusted Root CA
configuration to Log Collectors via a Collector Group push due to the
Log Collector not supporting the
trusted-root-CA configuration.
|
|
PAN-297708
|
Fixed an issue where a long-lived session with many Machine Learning
(ML) model triggers caused a memory leak of feature states associated
with the ML model runs. This resulted in Spyware_State failure
increases, allocation max outs, and impaired policy matching.
|
|
PAN-297610
|
Fixed an issue where the firewall became unresponsive after an upgrade
due to the fsck command scanning
drive partitions in parallel with the root partition, which caused the
process to take an extended amount of time.
|
|
PAN-297295
|
(VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the firewall repeatedly restarted due to high
packet rates on the synthetic path in DPDK mode.
|
|
PAN-297005
|
Fixed an issue where exporting custom reports resulted in empty CSV
files.
|
|
PAN-296977
|
Fixed an issue where the web interface became unresponsive when
attempting to view
Ethernet interface details after
applying a filter in
Network > Interfaces.
|
|
PAN-296397
|
Fixed an issue on the Panorama web interface where previewing changes
after a commit to shared objects were not accurately displayed in the
push scope.
|
|
PAN-295578
|
Fixed an issue where GlobalProtect HIP data file download and
installation failed with the error message
An error occurred while processing request. Please try again after
some time or contact support
or No ETAG from response due to a
script exiting prematurely.
|
|
PAN-294307
|
Fixed an issue on Panorama where a
configd
SIGSEGV crash occurred when renaming objects within policy rules,
objects, or zones.
|
|
PAN-291009
|
Fixed an issue where, after a web server returned a 401 or 403 error,
the firewall was unable to decrypt HTTP/2 traffic, and the firewall
rejected all subsequent streams from the client.
|
|
PAN-290665
|
Fixed an issue with firewalls enabled with Security profiles where
certain traffic conditions caused high dataplane CPU utilization and
packet buffer exhaustion, which caused LACP flapping conditions.
|
|
PAN-288158
|
(VM-Series firewalls only) Fixed an issue where
the firewall became inaccessible via the web interface and SSH and
remained in an initializing state.
|
|
PAN-288097
|
Fixed an issue where on the firewall where the
routed
process stopped responding after changing the MTU or any link state
parameters when OSPF and PIM were enabled on the same interface.
|
|
PAN-284866
|
Fixed an issue where the LFC failed to validate Certificate Revocation
Lists (CRL) for SSL syslog connections, which caused a failure to
forward logs to external syslog servers.
|
|
PAN-280725
|
Fixed an issue where
all_pktproc
process repeatedly restarted, which caused dataplane failure and loss
of connectivity, including PAN-DB URL resolution. This occurred after
a commit push from Panorama and resulted in the firewall becoming
non-functional due to internal path monitoring failure and
configuration memory exhaustion.
|
|
PAN-278126
|
Fixed an issue where the number of registered IP Tags on Panorama did
not match the number of registered IP Tags on the managed firewalls
due to a change in file format between PAN-OS releases.
|
|
PAN-276484
|
Fixed an issue where Panorama did not display license information for
Cloud NGFW firewalls under (Device Deployment > Licenses) due to the inability to perform batch-license refreshes.
|
|
PAN-276321
|
Fixed an issue where User-ID mappings were not correctly redistributed
from Panorama to firewalls, causing some users to be identified as
unknown, which prevented access to
resources based on AD group membership.
|
|
PAN-274086
|
Fixed an issue where the firewall incorrectly assembled SIP NOTIFY and
REFER messages when processing SIP TCP packets that contained a
partial content-body from a previous SIP message and a complete header
and content-body from the next SIP message.
|
|
PAN-272245
|
Fixed an issue where the
dnsproxy
process stopped responding due to memory corruption caused by a race
condition when the allow list downloading was impacted by a
configuration change.
|
|
PAN-257616
|
Fixed an issue where selective push operations from Panorama to
managed firewalls failed with the error message
Failed to generate selective push configuration. Schema validation
failed. Please try a full push.
|
|
PAN-241694
|
Fixed an issue where memory leaks related to the
devsrvr
process occurred when downloading and pushing updates from the App-ID
Cloud Engine to the dataplane.
|