Files
aaron.axvig b36247faf4
Test and deploy / deploy (push) Successful in 29s
Added remaining PAN-OS 10.2 reference files
2026-07-29 12:45:46 -05:00

1839 lines
54 KiB
HTML

<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p">
<b class="ph b"><b class="ph b">PAN-231823</b></b>
</div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-5916"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-5916</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-209275</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Override cookie authentication into the
GlobalProtect gateway failed when an allow list was configured under
the authentication profile.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-201627</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue in next-generation firewall deployments where, when
SD-WAN was configured, the dataplane restarted if all SD-WAN member
links were down due to an out-of-memory (OOM) condition or during a
reboot when all SD-WAN tunnels were down.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-200771</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>syslog-ng</a
>
was unable to start due to a design change in the syslog configuration
file.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-199654</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where ACC reports did not work for custom RBAC users
when more than 12 access domains were associated with the username.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-199311</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Log Forwarding Card (LFC) failed to forward
logs to the syslog server.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-199099</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when decryption was enabled, Safari and Google
Chrome browsers on Apple Mac computers rejected the server certificate
created by the firewall because the Authority Key Identifier was
copied from the original server certificate and did not match the
Subject Key Identifier on the forward trust certificate.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-198733</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
<span class="ph systemoutput">dmin tcpdump</span> was hardcoded to
eth0 instead of bond0.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-198332</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5400 Series only</tt>) Fixed an issue where
swapping Network Processing Cards (NPCs) caused high root partition
use.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-198266</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when predicts for UDP packets were created, a
configuration change occurred that triggered a new policy lookup,
which caused the dataplane stopped responding when converting the
predict. This resulted in a dataplane restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-198244</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where using the
<span class="ph systemoutput">load config partial</span> CLI command
to x-paths removed address object entries from address groups.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-197576</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where commits pushed from Panorama caused a memory leak
related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>mgmtsrvr</a
>
process.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197484</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5400 Series firewalls</tt>) Fixed an issue where
the firewall forwarded packets to the incorrect aggregate ethernet
interface when Policy Based Forwarding (PBF) was used.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197383</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to PAN-OS 10.2 release, the
firewall ran a RAID rebuild for the log disk after ever every reboot.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197244</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on firewalls with Forward Proxy enabled where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process stopped responding due to missed heartbeats.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196993</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an incorrect regex key was generated to
invalidate the completions cache, which caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process to stop responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196953</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
jumbo frames were dropped.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196445</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where restarting the Network Processing Card (NPC) or
the Data Processing Card (DPC) did not bring up all the network
interfaces.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196398</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7000 Series SMC-B firewalls only</tt>) Fixed an
issue where the firewall did not capture data when the active
management interface was MGT-B.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196227</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logd</a
>
process stopped responding, which caused Panorama to reboot into
maintenance mode.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196005</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-3200 Series, PA-5200 Series, and PA-5400 Series firewalls
only</tt
>) Fixed an issue where GlobalProtect IPSec tunnels disconnected at
half the inactivity logout timer value.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195707</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama appliances configured as log collectors
where Panorama repeatedly rebooted into maintenance mode.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195689</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where WildFire submission logs did not load on the
firewall web interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195628</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue that caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process to miss heartbeats and stop responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195625</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>authd</a
>
frequently created SSL sessions, which resulted in an OOM condition.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195360</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with firewalls in Microsoft Azure environments where
BGP flapping occurred due to the firewall incorrectly treating
capability from BGP peering as unsupported.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195223</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process restarted when receiving a GTPv2 Modify Bearer Request packet
if the Serving GPRS Support Node (SGSN) used the same key as the
Serving Gateway (SGW).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195181</b></div>
</td>
<td class="entry relcol">
<div class="p">
Added enhancements to improve the load on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_comm</a
>
process during SNMP polling.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p">
<b class="ph b"><b class="ph b">PAN-194993</b></b>
</div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue that occurred when authenticating into GlobalProtect
with authentication override cookies and SAML where, if the cookie was
invalid, authentication did not fall back to SAML.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194826</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">WF-500 and WF-500-B appliances only</tt>) Fixed an
issue where log system forwarding did not work over a TLS connection.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194782</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where, if you added a new local or
non-local administrator account or an admin user to a template,
authentication profiles were incorrectly referenced.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194708</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where URL filtering logs (<span class="ph menucascade"
><span class="ph uicontrol">Monitor</span
><span class="ph uicontrol">Logs</span
><span class="ph uicontrol">URL Filtering</span></span
>) incorrectly truncated a 16KB Header value and did not display the
Header values that followed the truncated 16KB header.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194694</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where multiple SNMP requests being made to the firewall
caused in the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_comm</a
>
process to stop responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194601</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue that caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process to stop responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194588</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-7000 Series firewalls with LFCs (Log Forwarding Cards), PA-7050
firewalls with SMC-B (Switch Management Cards), and PA-7080
firewalls only</tt
>) Fixed an issue where the
<span class="ph systemoutput">logrcvr_statistics</span> output was not
recorded in mp-monitor.log.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194481</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue in ESXi where the bootstrapped VM-Series firewalls with
the Software Licensing Plugin had
<span class="ph systemoutput">:xxx</span> appended to their hostnames.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194408</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when policy rules had the apps that implicitly
depended on web browsing configured with the service
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>application default</a
>, traffic did not match the rule correctly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194406</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the MTU from SD-WAN interfaces was recalculated
after a configuration push from Panorama or a local commit, which
caused traffic disruption.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194262</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect application failed to connect
when a user or group was configured under the portal
<span class="ph uicontrol">Config Selection Criteria</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194152</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-5410, PA-5420, PA-5430, and PA-5440 firewalls in HA
configurations only</tt
>) Fixed an issue where HA1-A and HA1-B port information didn't match
to front panel mappings and, when one firewall was on PAN-OS 10.2.3 or
a later release and the other was on PAN-OS 10.2.2 or an earlier
release, a split-brain situation occurred.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194129</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
slot 2 did not use all features correctly if a DPC was used instead of
an NPC.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194097</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on firewalls in high availability (HA) active/passive
configurations where
<span class="ph systemoutput">_ha_d_session_msgbuf</span> overflowed
on the passive firewall during an upgrade, which caused the firewall
to enter a non-functional state.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193981</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls in Microsoft Azure environments only</tt
>) Fixed an issue where the firewall stopped monitoring HA failure and
floating IP addresses did not get moved to the newly active firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193899</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where advanced mode factory reset (<span
class="ph menucascade"
><span class="ph uicontrol">Maintenance Mode</span
><span class="ph uicontrol">Factory Reset</span
><span class="ph uicontrol">Advanced</span
><span class="ph uicontrol">select a specific image</span></span
>) was only compatible with PAN-OS 10.1.3 or later version images.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193818</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall device server failed to resolve URL
cloud FQDNs, which interrupted URL category lookup.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193766</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the GlobalProtect portal was not accessible.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193765</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where commits failed the following error displayed in
the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
log:
<span class="ph systemoutput"
>Unable to populate ids into candidate config: Error: Error
populating id for 'sg2+DMZ to FirstAM Scanner-1</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193763</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where the dataplane CPU spiked, which
caused traffic to be affected during commits or content updates.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193744</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-3200 Series firewalls only</tt>) Fixed an issue
where, when the HA2 HSCI connection was down, the system log displayed
<span class="ph systemoutput">Port HA1-b: down</span> instead of
<span class="ph systemoutput">Port HSCI: Down</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193732</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5400 Series firewalls only</tt>) Fixed an issue
where the firewall incorrectly handled internal transactions.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193707</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SAML authentication failed during commits with
the following error message:
<span class="ph systemoutput"
>revocation status could not be verified (reason: )</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193483</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue
where, during Layer-7 packet inspection where traffic was being
inspected for threat signature and data patterns, multiple processes
stopped responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193392</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where RTP packets dropped due to conflicting duplicate
flows.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193251</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when SAML was configured as the authentication
method for GlobalProtect, the SAML page did not load when using a
browser.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193235</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where duplicate log entries were displayed on Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193201</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where auto-commits failed after an upgrade if an
imported certificate size was greater than the size of a buffer.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193132</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-220 firewalls only</tt>) Fixed an issue where a
commit and push from Panorama caused high dataplane CPU utilization.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-192944</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process caused an OOM condition.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-192739</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the error message
<span class="ph systemoutput">Machine Learning found virus</span> was
displayed in threat CSV logs as
<span class="ph uicontrol">Threat ID/Name</span> when WildFire Inline
ML detected malware.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-192726</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dropped TCP traffic inside IPSec
tunnels.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-192673</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7050-SMC-B firewalls only</tt>) Fixed an issue
where the LFC syslog-ng service failed to start after an upgrade.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-192666</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
uploading certificates via API failed within the first 30 minutes of a
bootstrap.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-192551</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5400 Series firewalls only</tt>) Fixed an issue
where the firewall incorrectly processed path monitoring packets.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-192404</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where ARP broadcasts occurring in the same time
interval and network segment as HA path monitoring pings triggered an
ARP cache request, which prevented the firewall from sending ICMP echo
requests to the monitored destination IP address and caused an HA path
monitoring failover.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-192330</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Bootstrapped VM-Series firewalls in Microsoft Azure environments
only</tt
>) Fixed an issue where the firewall did not automatically receive the
<span class="ph">Strata Logging Service</span> license.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-192052</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when next hop MAC address entries weren't found
on the offload processor for active traffic, update messages flooded
the firewall, which caused resource contention and traffic disruption.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-191874</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where monthly scheduled reports did not display
information after upgrading to PAN-OS 10.2.0.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-191847</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama appliance was unable to generate
scheduled custom reports due to the large number of files stored in
the
<span class="ph systemoutput">opt/pancfg/mgmt/custom-reports</span>
directory.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-191726</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an SCP export of the device state from the
firewall added single quotes ( ' ) to the filename.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-191558</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after an upgrade to PAN-OS 10.1.5, Global Find
did not display all results related to a searched item.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-191269</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the NAT pool leaked for passive mode FTP predict
sessions.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-191222</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama became inaccessible when after a push to
the collector group.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-191218</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5400 Series firewalls only</tt>) Fixed an issue
where the session log storage quota could not be changed via the web
interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-191216</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, on Apple iOS devices, SAML authentication did
not connect to the GlobalProtect portal.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-191214</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Elasticsearch process stopped responding,
which caused an OOM condition.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-190657</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IPSec tunnels did not rekey due to the security
association being deleted too early.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-190448</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue in ACC reports where IPv6 addresses were displayed
instead of IPv4 addresses.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189894</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with the web interface where the template stack didn't
show inherited values of
<span class="ph uicontrol"
>Template &gt; Authentication Portal Settings</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189861</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on firewalls in HA configurations where intermittent
system alerts on the active firewall caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_comm</a
>
process to restart continuously.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189859</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where an administrator was unable to
<span class="ph uicontrol">Import Custom URL Category Content</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189762</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a predict session didn't match with the traffic
when both source NAT and destination NAT were enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189723</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were unable to configure dynamic address
groups to use more than 64,000 IP addresses in a Security policy.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189414</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TCP packets were dropped during the first zone
transfer when DNS security was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189304</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama appliance didn't display logs or
generate reports for a device group containing MIPs platform that
forwarded logs to <span class="ph">Strata Logging Service</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189270</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue that caused a memory leak on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189225</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where BGP routes were lost or uninstalled after
disabling jumbo frames on the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189114</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the dataplane went down, which caused an HA
failover.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-188867</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dropped packets when the session
payload was too large.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-188489</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
dynamic content updates weren't automatically pushed to the firewall
licensed using the Panorama Software Firewall License plugin when
<span class="ph uicontrol"
>Automatically push content when software device registers to
Panorama</span
>
(<span class="ph menucascade"
><span class="ph uicontrol">Panorama</span
><span class="ph uicontrol">Templates</span
><span class="ph uicontrol">Add Stack</span></span
>) was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-188338</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where canceling a commit caused the commit process to
remain at 70% and the firewall had to be rebooted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-188303</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the serial number displayed as
<span class="ph systemoutput">unknown</span> after running the
<span class="ph systemoutput">show system state</span> CLI command.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-188096</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue
where, on firewalls licensed with Software NGFW Credit (VM-FLEX-4 and
higher), HA clustering was unable to be established.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-187985</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were unable to configure a QoS Profile as
percentage for Clear Text Traffic.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-187890</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph">Strata Logging Service</span> connection incorrectly
displayed as disconnected when a service route was in use.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-187805</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a process (<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>) stopped responding and the dataplane restarted during certificate
construction or destruction.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-187476</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when hip-redistribution is enabled, Panorama
doesn't display a part of HIP information.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-187234</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an intermittent issue where web pages submitted for analysis by
Advanced URL Filtering cloud inline categorization experienced high
latency.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-186891</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where NetFlow packets contained incorrect octet counts.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-186418</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama displayed a discrepancy in RAM
configured on the VMware host.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-186134</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where performing a commit and push
intermittently failed to push the committed configuration to managed
firewalls.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-186075</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the firewall rebooted after receiving large packets while in DPDK mode
on Azure virtual machines running CX4 (MLx5) drivers.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-185787</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where logging in to the Panorama web interface did not
work and the following error message displayed:
<span class="ph systemoutput"
>Timed out while getting config lock. Please try again</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-185283</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where using the
<span class="ph systemoutput">name-of-threatid contains log4j</span>
filter didn't produce expected results.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-184702</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">M-700 appliances in Log Collector mode only</tt>)
Fixed an issue on the Panorama management server where the Panorama
appliance failed to connect to Panorama when added as a managed log
collector.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-184068</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5200 Series firewalls only</tt>) Fixed an issue
where the firewall generated pause frames, which caused network
latency.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-183788</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with SCEP certificate enrollment where the incorrect
Registration Authority (RA) certificate was chosen to encrypt the
enrollment request.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-185750</b></div>
</td>
<td class="entry relcol">
<div class="p">
Updated an issue to eliminate failed
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_comm</a
>
software issues that caused the dataplane to restart unexpectedly
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-183270</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a bootstrapped firewall connected only to the
first log collector in a log collector group.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-183184</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where enabling SSL decryption with a Hardware Security
Model (HSM) caused a dataplane restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-183166</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where system, configuration, and alarm logs were queued
up on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process and were not forwarded out or written to disk until an
autocommit was passed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-182689</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a signature from a previous WildFire package
triggered virus detection even though the signature was no longer
present in the current WildFire package.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-182539</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with Panorama appliances in HA configurations where
dedicated log collectors did not send local system or configuration
logs to both Panorama appliances.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-182212</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SNMP reported the
<span class="ph systemoutput">panVsysActiveTcpCps</span> and
<span class="ph systemoutput">panVsysActiveUdpCps</span> value to be
0.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-181277</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where VPN tunnels in SD-WAN flapped due to duplicate
tunnel IDs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-179543</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>flow_mgmt</a
>
process stopped responding when attempting to clear the session table,
which caused the dataplane to restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-179258</b></div>
</td>
<td class="entry relcol">
<div class="p">Fixed an issue where system disk migration failed.</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-178243</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">Shared Gateway</span> was not visible in
the <span class="ph uicontrol">Virtual System</span> drop down when
configuring a Layer3 aggregate subinterface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-178194</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with the web interface where, when only the Advanced
URL Filtering license was activated, the message
<span class="ph systemoutput"
>License required for URL filtering to function</span
>
was incorrectly displayed and the
<span class="ph uicontrol">URL Filtering Profile &gt; Inline ML</span>
section was disabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-177482</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol"
>ACC &gt; App Scope &gt; Threat Monitor</span
>
showed <span class="ph uicontrol">NO DATA TO DISPLAY</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-172501</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were unable to revert HA mode settings to the
default values from the web interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-171714</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when NetBIOS format (domain\user) was used for
the IP address-to-username mapping and the firewall received the group
mapping information from the Cloud Identity Engine, the firewall did
not match the user to the correct group.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-157215</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue that occurred when two FQDNs were resolved to the same
IP address and were configured as the same src/dst of the same rule.
If one FQDN was later resolved to a different IP address, the IP
address resolved for the second FQDN was also changed, which caused
traffic with the original IP address to hit the incorrect rule.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-151469</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where packets were dropped unexpectedly due to errors
parsing the IP version field.
</div>
</td>
</tr>
</tbody>
</table>