Files
aaron.axvig b36247faf4
Test and deploy / deploy (push) Successful in 29s
Added remaining PAN-OS 10.2 reference files
2026-07-29 12:45:46 -05:00

5902 lines
173 KiB
HTML
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">WF500-5976</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">WF-500 appliances only</tt>) Fixed an issue where
files were incorrectly detected as malicious.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">WF500-5953</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where testing the same file sample using a PowerShell
script returned different verdicts in Private Cloud and Public Cloud.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">WF500-5920</b></div>
</td>
<td class="entry relcol">
<div class="p">Fixed an issue where an elink parser did not work.</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p">
<b class="ph b"><b class="ph b">PAN-231823</b></b>
</div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-5916"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-5916</a
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-220741</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/passive HA configurations only</tt
>) Fixed an issue where, when redistribution agent connections to the
passive firewall failed, excessive system alerts for the failed
connection were generated. With this fix, system alerts are logged
every 5 hours instead of 10 minutes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-219686</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a device group push operation from Panorama
failed with the following error on managed firewalls.
</div>
<div class="p">
<span class="ph systemoutput"
>vsys -&gt; vsys1 -&gt; plugins unexpected here</span
>
</div>
<div class="p">
<span class="ph systemoutput">vsys is invalid</span>
</div>
<div class="p"><span class="ph systemoutput">Commit failed</span></div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-216656</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to fully process the user
list from a child group when the child group contained more than 1,500
users.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-216314</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-3200 Series firewalls only</tt>) Fixed an issue
where, after upgrading to or from PAN-OS 10.1.9 or PAN-OS 10.1.9-h1,
offloaded application traffic sessions disconnected even when a
session was active. This occurred due to the application default
session timeout value being exceeded.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-215911</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue that resulted in a race condition, which caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process to stop responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-215488</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an expired Trusted Root CA was used to sign the
forward proxy leaf certificate during SSL Decryption.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-215461</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the packet descriptor leaked over time with GRE
tunnels and keepalives.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-215125</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where false negatives occurred for some script samples.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-214634</b></div>
</td>
<td class="entry relcol">
<div class="p">Fixed an issue where an elink parser did not work.</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-214624</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process stopped responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-214337</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall related to the
<span class="ph systemoutput">gp_broker</span> configuration transform
that led to longer commit times.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-214037</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-5440, PA-5430, PA-5420, and PA-5410 firewalls only</tt
>) Fixed an issue where firewalls in active/active HA configurations
experienced packet drop when running asymmetric traffic.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-213973</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>authd</a
>
process stopped responding during a cleanup of authentication server
context.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-213661</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where memory allocation failure caused dataplane
processes to restart. This issue occurred when decryption was enabled
and the device was under heavy L7 usage.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-213011</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when using multi-factor authentication (MFA)
with RADIUS OTP, the challenge message
<span class="ph uicontrol"
>Enter Your Microsoft verification code</span
>
did not appear when accessing the GlobalProtect portal via browser.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-212982</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process stopped responding with MICA HTTP2 traffic.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-212409</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where there were duplicate IPSec Security Associations
(SAs) for the same tunnel, gateway, or proxy ID.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-211242</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where missed heartbeats caused the Data Processing Card
(DPC) and its corresponding Network Processing Card (NPC) to restart
due to internal packet path monitoring failure.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210919</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Data Processing Card remained in a
<span class="ph systemoutput">Starting</span> state after a restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210892</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">M-600 and M-700 appliances only</tt>) Fixed an
issue where the Elasticsearch shard count grew continuously without
limit.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210875</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process stopped responding due to software packet buffer 3 trailer
corruption, which caused the firewall to restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210561</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process repeatedly restarted due to missed heartbeats.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210481</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where botnet reports were not generated on the
firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210449</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the value for shared objects used in policy rules
were not displayed on multi-vsys firewalls when pushed from Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210331</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not send device telemetry files
to <span class="ph">Strata Logging Service</span> with the error
message
<span class="ph systemoutput"
>Send File to Strata Logging Service Receiver Failed</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210327</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5200 Series firewalls only</tt>) Fixed an issue
where upgrading to PAN-OS 10.1.7, an internal loop caused an increase
in the packets received per second.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210237</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where system logs generated by Panorama for commit
operations showed the severity as
<span class="ph uicontrol">High</span> instead of
<span class="ph uicontrol">Informational</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210080</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process stopped responding when add and delete member parameters in an
incremental sync query were empty.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-209660</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a selective push from Panorama to multiple
firewalls failed due to a missing configuration file, which caused a
communication error.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-209346</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to PAN-OS 10.2.3, HA peers
received conflicting ARP messages that indicated a duplicate IP
address.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-209305</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a memory space issue where the content and threat detection
(CTD) process flow cleanup during inline cloud analysis did not work.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-209226</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the feature bits function reused shared memory,
which resulted in a memory allocation error and caused the dataplane
to go down.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-209069</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IP addresses in the
<span class="ph uicontrol">X-Forwarded-For</span> (XFF) field were not
logged when the IP address contained an associated port number.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-209021</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where packets were fragmented when SD-WAN VPN tunnel
was configured on aggregate ethernet interfaces and sub-interfaces.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-208987</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5400 Series only</tt>) Fixed an issue where
packets were not transmitted from the firewall if its fragments were
received on different slots. This occurred when aggregate ethernet
(AE) members in an AE interface were placed on a different slot.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p">
<b class="ph b"><b class="ph b">PAN-208922</b></b>
</div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address an issue where an authenticated
administrator was able to commit a specifically created configuration
to read local files and resources from the system (<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2023-38046"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2023-38046</a
>).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-208930</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7000 Series firewalls only</tt>) Fixed an issue
where auto-tagging in log forwarding did not work.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-208877</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding when freeing the HTTP2 stream, which caused
the dataplane to go down.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-208737</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where domain information wasn't populated in IP
address-to-username matching after a successful GlobalProtect
authentication using an authentication override cookie.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-208724</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where port pause frame settings did not work as
expected and incorrect pause frames occurred.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-208718</b></div>
</td>
<td class="entry relcol">
<div class="p">
Additional debug information was added to capture internal details
during traffic congestion.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-208711</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5200 Series firewalls only</tt>) The CLI command
<span class="ph systemoutput"
>debug dataplane set pow no-desched yes/no</span
>
was added to address an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process stopped responding and caused traffic issues.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-208537</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">licensed-device-capacity</span> was
reduced when multiple device management license key files were
present.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-208485</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where NAT policies were not visible on the CLI if they
contained more than 32 characters.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-208189</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue when traffic failed to match and reach all destinations
if a Security policy rule includes FQDN objects that resolve to two or
more IP addresses.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-208157</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where malformed hints sent from the firewall caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logd</a
>
process to stop responding on Panorama, which caused a system reboot
into maintenance mode.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-208079</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Microsoft Azure environments only</tt
>) Fixed an issue where the PAN-DB engine did not start when using a
VM-Series firewall Flex based CPU.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207983</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama in Management Only mode where the logdb
database incorrectly collected traffic, threat, GTP, decryption, and
corresponding summary logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207940</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where platforms with RAID disk checks were performed
weekly, which caused logs to incorrectly state that RAID was
rebuilding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207891</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where log migration did not complete after
an upgrade.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207740</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue that resulted in a race condition, which caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process to stop responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207738</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">ocsp-next-update-time</span> CLI command
did not execute for leaf certificates with certificate chains that did
not specify OCSP or CRL URLs. As a result, the next update time was 60
minutes even if a different time was set.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207663</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a Clientless VPN issue where JSON stringify caused issues with
the application rewrite.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207629</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a selective push to firewalls failed if the
firewalls were enabled with multiple vsys and the push scope contained
shared objects in device groups.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207623</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where log migration did not complete as
expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207610</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-5200 Series and PA-7000 Series firewalls only</tt
>) Fixed an issue where
<span class="ph uicontrol">Log Admin Activity</span> was not visible
on the web interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207602</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where file streams were opened or closed twice due to a
race condition which caused Linux to stop responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207601</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where URL cloud connections were unable to resolve the
proxy server hostname.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207533</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with firewalls in HA configurations where ARP and IPv6
multicast packets were transmitted from the passive firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207455</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process stopped responding when processing client certificate requests
from the server in TLS1.3.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207426</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a selective push did not include the
<span class="ph uicontrol"
>Share Unused Address and Service Objects with Devices</span
>
option on Panorama, which caused the firewall to not receive the
objects during the configuration push.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207400</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Octeon based platforms where fragmented VLAN tagged
packets dropped on an aggregate interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207390</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, even after disabling Telemetry, Telemetry system
logs were still generated.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207260</b></div>
</td>
<td class="entry relcol">
<div class="p">
A commit option was enabled for Device Group and Template
administrators after a password change.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207045</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-800 Series firewalls only</tt>) Fixed an issue
where PAN-SFP-SX transceivers used on ports 5 to 8 did not renegotiate
with peer ports after a reload.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207043</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on PAN-OS 10.2.3 where ports 41-44 remained down when
the PAN-QSFP28-DAC-5M cable was connected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206963</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">M-700 Appliances only</tt>) A CLI command was added
to check the status of each physical port of a bond1 interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206921</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect client certificate authentication
failed on a gateway when the gateway was placed behind a NAT.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206858</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a segmentation fault occurred due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process being restarted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206796</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph systemoutput">cfg.lcaas-region</span> was not reset
when it was empty, which caused
<span class="ph">Strata Logging Service</span> onboarding to fail.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206755</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue when a scheduled multi-device group push occurred, the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding, which caused the push to fail.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206658</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a timeout issue in the Intel
<span class="ph systemoutput">ixgbe</span> driver that resulted in
internal path monitoring failure.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206629</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls in AWS environments only</tt>)
Fixed an issue where a newly bootstrapped firewalls did not forward
logs to Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206393</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5280 firewalls only</tt>) Fixed an issue where
memory allocation errors caused decryption failures that disrupted
traffic with SSL forward proxy enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206382</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where authentication sequences were not populated in
the drop down when selecting authentication profiles during
administrator creation in a template.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206253</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-3400 Series firewalls only</tt>) Fixed an issue
where the default log rate value was too low, and the maximum
configurable log rate was capped incorrectly, which caused the
firewall to not generate more than 6826 logs per second.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206251</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-7000 Series firewalls with Log Forwarding Cards (LFCs) only</tt
>) Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process did not send the
<span class="ph systemoutput">system-start</span> SNMP trap during
startup.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206233</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_comm</a
>
process stopped responding when a content update and a cloud
application update occurred at the same time.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206128</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-7000 Series firewalls with NPCs (Network Processing Cards)
only</tt
>) Improved debugging capability for an issue where the firewall
restarted due to heartbeat failures and then failed with the following
error message: <span class="ph systemoutput">Power not OK</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206077</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on firewalls in active/active HA configurations where,
after upgrading to PAN-OS 10.1.6-h6, the active primary firewall did
not send HIP reports to the active secondary firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206069</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to boot up on older Intel
CPUs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206017</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">show dos-protection rule</span> command
displayed a character limit error.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206005</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-3400 Series firewalls only</tt>) Fixed an issue
where the <span class="ph systemoutput">l7_misc</span> memory pool was
undersized and caused connectivity loss when the limit was reached.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205995</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where logs from unaffected log collector groups were
not displayed when a log collector was down.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205955</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where RAID rebuilds occurred even with healthy disks
and a clean shutdown.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205877</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Added debug commands
for an issue where a MAC address flap occurred on a neighbor firewall
when connecting both MGT-A and MGT-B interfaces.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205829</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where logs did not display
<span class="ph uicontrol">Host-ID</span> details for GlobalProtect
users despite having a quarantine Security policy rule. This occurred
due to a missed local cache lookup.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205804</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a WildFire scheduled update for
managed devices triggered multiple
<span class="ph systemoutput">UploadInstall</span> jobs per minute.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205729</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-3200 Series and PA-7000 Series firewalls only</tt
>) Fixed an issue where the CPLD watchdog timeout caused the firewall
to reboot unexpectedly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205699</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the cloud plugin configuration was automatically
deleted from Panorama after a reboot or a
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205590</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the fan tray fault LED light was on even though
no alarm was reported in the system environment.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205473</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls on Microsoft Hyper-V only</tt>)
Fixed an issue where the firewall did not receive any traffic on Layer
3 sub-interfaces from the trunk port.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205453</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where running reports or queries under a user group
caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process to stop responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205451</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_com</a
>
process stopped responding due to aggressive commits.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205428</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where WildFire submissions failed if the file name
contained special characters.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205396</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SD-WAN adaptive SaaS path monitoring did not work
correctly during a next hop link down failure.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205337</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue in the
<span class="ph uicontrol">Run Now</span> section of custom reports
where <span class="ph uicontrol">Threat/Content Name</span> displayed
in hypertext, and hovering over the text with the mouse displayed the
message
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>undefined</a
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205260</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where there was an IP address conflict after a reboot
due to a transaction ID collision.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205255</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a rare issue that caused the dataplane to restart unexpectedly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205231</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a commit operation remained at 55% for longer
than expected if more than 7,500 Security policy rules were
configured.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205222</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were unable to add a new application in a
selected policy rule.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205211</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process stopped responding while querying logs (<span
class="ph uicontrol"
>Monitor &gt; Logs &gt; &lt;logtype&gt;</span
>).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205187</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Elasticsearch did not start properly when a newly
installed Panorama virtual appliance powered on for the first time,
which caused the Panorama virtual appliance to not query logs
forwarded from the managed firewall to a Log Collector.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205096</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where promoted sessions were not synced with all
cluster members in an HA cluster.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205030</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when a session hit policy based forwarding with
symmetric return enabled was not offloaded, the firewall received
excessive return-mac update messages, which resulted in resource
contention and traffic disruption.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204892</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the web interface was not accessible
and displayed the error
<span class="ph systemoutput">504 Gateway Not Reachable</span> due to
the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>mgmtsrvr</a
>
process not responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-204851</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when performing an advanced factory reset from
maintenance mode on a firewall running PAN-OS 10.2.2 or an earlier
release and downgrading to PAN-OS 10.1.0 or an earlier release, the
firewall entered into maintenance mode after the reboot.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204838</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">dot1q</span> VLAN tag was missing in ARP
reply packets.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204830</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where logging in via the web interface or CLI did not
work until an auto-commit was complete.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204749</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where sudden, large bursts of traffic destined for an
interface that was down caused packet buffers to fill, which stalled
path monitor heartbeat packets.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204690</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where selective configuration pushes failed due to
schema validation when both the device group and template stack had
the same name.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204663</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where you were unable to context switch
from one managed firewall to another.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204582</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when a firewall acting as a DHCP client received
a new DHCP IP address, the firewall did not release old DHCP IP
addresses from the IP address stack.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204581</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when accessing a web application via the
GlobalProtect Clientless VPN, the web application landing page
continuously reloaded.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204575</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-7000 Series firewalls with Log Forwarding Cards (LFCs) only</tt
>) Fixed an issue where the firewall did not forward logs to the log
collector.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204482</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where searching threat logs (<span class="ph uicontrol"
>Monitor &gt; Logs &gt; Threat</span
>) using the
<span class="ph systemoutput">partial hash</span> parameter did not
work, which resulted in an invalid operator error.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204456</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logd</a
>
process that caused high memory consumption.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204335</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama became unresponsive, and when refreshed,
the error
<span class="ph uicontrol">504 Gateway not Reachable</span> was
displayed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204307</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-5440, PA-5430, PA-5420 and PA-5410 firewalls only</tt
>) Fixed an issue where, when moving interfaces from one aggregate
group to another while the interface's link state was down, traffic
was not properly routed through the aggregate group until after a
second commit.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204271</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the quarantine device list did not display due to
the maximum memory being reached.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204238</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when
<span class="ph uicontrol">View Rulebase as Groups</span> was enabled,
the <span class="ph uicontrol">Tags</span> field did not display a
scroll down arrow for navigation.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204216</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where URL categorization failed and the firewall
displayed the URL category as
<span class="ph systemoutput">not-resolved</span> for all traffic and
the following error message was displayed in the device server logs
<span class="ph systemoutput"
>Error(43): A libcurl function was given a bad argument</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204118</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where browser sessions stopped responding for device
group template admin users with access domains that had many device
groups or templates.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204068</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a newly created vsys (virtual system) in a
template was not able to be pushed from Panorama to the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-203964</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in FIPS-CC mode only</tt>) Fixed an issue
where the firewall went into maintenance mode due to downloading a
corrupted software image, which resulted in the error message
<span class="ph systemoutput"
>FIPS-CC failure. Image File Authentication Error</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-203851</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with firewalls in HA configurations where host
information profile (HIP) sync did not work between peer firewalls.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-203796</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where legitimate syn+ack packets were dropped after an
invalid syn+ack packet was ingressed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-203681</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances in FIPS-CC mode only</tt>)
Fixed an issue where a leaf certificate was unable to be imported into
a template stack.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-203663</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where administrators were unable to change the password
of a local database for users configured as a local admin user via an
authentication profile.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-203653</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where dynamic updates were completed even when
configuration commits failed, which caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process to stop responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-203618</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when SSL/TLS Handshake Inspection was enabled,
SSL/TLS sessions were incorrectly reset if a Security policy rule with
no Security profiles configured was matched.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-203604</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect authentication failed for SAML
username with a special character.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-203563</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with Content and Threat Detection allocation storage
space where performing a commit failed with a
<span class="ph systemoutput">CUSTOM_UPDATE_BLOCK</span> error
message.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-203430</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the User-ID agent had
<span class="ph systemoutput">collector name/secret</span> configured,
the configuration was mandatory on clients on PAN-OS 10.0 and later
releases.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-203402</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an intermittent issue where forward session installs were
delayed, which resulted in latencies.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-203362</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>rasmgr</a
>
process restarted due to a null reference.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-203339</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where services failed due to the RAID rebuild not being
completed on time.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-203330</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the certificate for an External Dynamic List
(EDL) incorrectly changed from invalid to valid, which caused the EDL
file to be removed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-203320</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where configuring the firewall to connect with Panorama
using an auth key and creating the auth key without adding the managed
firewall to Panorama first, the auth key was incorrectly decreased
incrementally.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-203147</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in FIPS-CC mode only</tt>) Fixed an issue
where the firewall unexpectedly rebooted when downloading a new PAN-OS
software image.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-203137</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
HSCI ports did not come up when QSFP DAC cables were used.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202946</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput"
>request high-availability session-reestablish</span
>
command was not available for API.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202918</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where processing route-table entries did not work as
expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202872</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an incorrect URL list limit displayed during a
commit.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202783</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-7000 Series firewalls with 100G NPC (Network Processing Cards)
only</tt
>) Fixed an issue where sudden, large bursts of traffic destined for
an interface that was down caused packet buffers to fill, which
stalled path monitor heartbeat packets.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202722</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the factor completion time for login events
learned through XML API displayed as
<span class="ph uicontrol">1969/12/31 19:00:00</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202593</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where expanding Global Find results displayed only the
top level and second level of a searched item.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202544</b></div>
</td>
<td class="entry relcol">
<div class="p">
An enhancement was made to collect CPLD register data after a path
monitor failure.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202543</b></div>
</td>
<td class="entry relcol">
<div class="p">
An enhancement was made to improve path monitor data collection by
verifying the status of the control network.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202535</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Device Telemetry configuration for a region
was unable to be set or edited via the web interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202451</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph systemoutput"
>Retrieve Framed-IP-Address attribute</span
>
from the authentication server fails generating GlobalProtect
connection failure with the error
<span class="ph systemoutput">Assign private IP address failed</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202450</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">device-client-cert</span> was set to
expire on December 31, 2023. With this fix, the expiration date has
been extended.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202295</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where read-only superusers were unable to see the
Commit All job status, warnings, or errors for Panorama device groups.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202282</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where stats dump files did not display all necessary
reports.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202264</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
an automatic site license activation for a PAYG license did not
register in the Customer Support Portal.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202248</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, due to a tunnel content inspection (TCI) policy
match, IPSec traffic did not pass through the firewall when NAT was
performed on the traffic.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202194</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an SD-WAN link issue that occurred when Aggregate Ethernet
without a member interface was configured as an SD-WAN interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202140</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>comm</a
>
process stopped responding due to an OOM condition.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202101</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls stopped responding after an upgrade due
to configuration corruption.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202095</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where the language setting is not
retained.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202040</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-220 firewalls only</tt>) Fixed an issue where
ECDSA fingerprints were not displayed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202012</b></div>
</td>
<td class="entry relcol">
<div class="p">
A debug command was introduced to control Gzip encoding for the
GlobalProtect Clientless VPN application.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-201973</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-3400 Series firewalls only</tt>) Fixed an issue
where the management interface could not be assigned as an HA port.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-201954</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where NAT policy rules were deleted on managed devices
after a successful push from Panorama to multiple device groups. This
occurred when NAT policy rules had
<span class="ph uicontrol">device_tags</span> selected in the target
section.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-201910</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where some Security profiles consumed a large amount of
memory, which reduced the number of supported Security profiles below
the stated maximum for a platform.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-201900</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an internal path monitoring failure issue that caused the
dataplane to go down.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-201860</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph uicontrol">Device Quarantine</span> list was not
redistributed or updated on Panorama and Prisma Access in a full mesh
topology.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-201858</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the SD-WAN interface Maximum Transmission Unit
(MTU) led to incorrect fragmentation of IPSec traffic.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-201839</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect HIP match failed for Mac users due
to invalid characters being present in the subject alternative
attributes in the certificate on the HIP report.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-201818</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where INIT SCTP packets were dropped after being
processed by the CTD, and silent drops occurred even with SCTP no-drop
function enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-201714</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with GlobalProtect where attempting to authenticate
with the GlobalProtect gateway returned a 502 error code.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-201701</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall generated system log alerts if the
raid for a system or log disk was corrupted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-201639</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with Saas Application Usage reports where
<span class="ph uicontrol"
>Applications with Risky Characteristics</span
>
displayed only two applications per section.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-201632</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
stopped responding with a segmentation fault due to an invalid
interface port.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-201601</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding after adding customer hyperscan signatures.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-201587</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">App Pcaps</span> directory size was
incorrectly detected which caused commit errors.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-201580</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process stopped responding due to an invalid vsys_id request.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-201561</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where LSVPN satellite authentication cookies were not
synced across high availability LSVPN portals.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-201360</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with Panorama managed log collector statistics where
the oldest logs displayed on the primary Panorama appliance and the
secondary Panorama appliance did not match.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-201357</b></div>
</td>
<td class="entry relcol">
<div class="p">
The CLI command
<span class="ph systemoutput"
>debug dataplane set pow no-desched yes</span
>
was added to address an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process stopped responding and caused traffic issues.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-201136</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IGMP packets were offloaded with frequent IGMP
Join and Leave messages from the client.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-201085</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
inserting the NPC and DPC on slot2 created excessive logs in the
<span class="ph systemoutput">bcm.log</span> file.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-200946</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with firewalls in active/passive HA configurations
where GRE tunnels went down due to recursive routing when the passive
firewall was booting up. When the passive firewall became active and
no recursive routing was configured, the GRE tunnel remained down.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-200914</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-3440 firewalls only</tt>) Fixed an issue where
the default NAT DIPP pool oversubscription was set to 2 instead of 4.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-200845</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">M-600 Appliances in Management-only mode only</tt>)
Fixed an issue where XML API queries failed due to the configuration
size being larger than expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-200774</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SCEP certificate import did not work on the
firewall when the certificate name contained a period ( . ).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-200676</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with firewalls in active/passive HA configurations
where the user counts in the management plane were not synchronized
between the active and the passive firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-200463</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where disabling
<span class="ph systemoutput">strict-username-check</span> did not
apply to admin users authenticating with SAML.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-200356</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph uicontrol">Elapsed seconds</span> field incorrectly
displayed as 0 for DHCP packets coming from the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-200354</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not initiate scheduled log
reports.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-200160</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a memory leak issue on Panorama related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logd</a
>
process that caused an out-of-memory (OOM) condition.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-200116</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Elasticsearch displayed red due to frequent
tunnel check failures between HA clusters.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-200103</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where decryption logs were not displayed under
<span class="ph uicontrol">Manage Custom Reports</span> for custom
Panorama admin users.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-200102</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall web interface that prevented
applications from loading under any policy or in any location where
application IDs were able to be refreshed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-200035</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall reported
<span class="ph systemoutput">General TLS Protocol Error</span> for
TLSv1.3 when the firewall closed a TCP connection to the server via a
FIN packet without waiting for the handshake to complete.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-200019</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where
<span class="ph uicontrol">Virtual Routers</span> (<span
class="ph uicontrol"
>Network &gt; Virtual Routers</span
>) was not available when configuring a custom Panorama admin role
(<span class="ph uicontrol">Panorama &gt; Admin Roles</span>).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-199965</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process stopped responding on log collectors during query and report
operations due to a race condition between request handling threads.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-199821</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph uicontrol">Include/Exclude IPs</span> filter under
<span class="ph uicontrol">Data Redistribution</span> did not
consistently filter IP addresses correctly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-199807</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the dataplane frequently restarted due to high
memory usage on wifclient.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-199726</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with firewalls in HA configurations where both
firewalls responded with gARP messages after a switchover.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-199661</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls in ESXI environments only</tt>)
Fixed an issue where the number of used packet buffers was not
calculated properly, and packet buffers displayed as a higher value
than the correct value, which triggered PBP Alerts. This occurred when
the driver name was not compatible with new DPDK versions.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-199612</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a sync issue with firewalls in active/active HA configurations.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-199570</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where uploading certificates using a custom admin role
did not work as expected after a context switch.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-199543</b></div>
</td>
<td class="entry relcol">
<div class="p">
Resolved failed authentication for Radius and TLS where shared secret
was striped for FIPS mode
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-199500</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when many NAT policy rules were configured, the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_comm</a
>
process stopped responding after a configuration commit due to a high
number of debug messages.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-199410</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where system logs for
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>syslog</a
>
activities were categorized as
<span class="ph uicontrol">general</span> under
<span class="ph uicontrol">Type</span> and
<span class="ph uicontrol">EVENT</span> columns.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-199214</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an intermittent issue where downloading
<span class="ph systemoutput">threat pcap</span> via XML API failed
with the following error message:
<span class="ph systemoutput"
>/opt/pancfg/session/pan/user_tmp/XXXXX/YYYYY.pcap does not
exist</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-199141</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where renaming a device group and then performing a
partial commit led to the device group hierarchy being incorrectly
changed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-198920</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where configuration changes caused a previously valid
interface ID to become invalid due to HA switchovers delaying the
configuration push.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-198889</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logd</a
>
process stopped responding if some devices in a collector group were
on a PAN-OS 10.1 device and others were on a PAN-OS 10.0 release. This
issue affected the devices on a PAN-OS 10.0 release.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-198871</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue when both URL and Advanced URL licenses were installed,
the expiry date was not correctly checked.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-198718</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5280 firewalls only</tt>) Fixed an issue where
memory allocation failures caused increased decryption failures.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-198693</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where decrypted SSH sessions were interrupted with a
decryption error.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-198691</b></div>
</td>
<td class="entry relcol">
<div class="p">
Added an alternate health endpoint to direct health probes on the
firewall (https://firewall/unauth/php/health.php) to address an issue
where <span class="ph systemoutput">/php/login.php</span> performance
was slow when large amounts of traffic were being processed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-198575</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where data did not load when filtering by
<span class="ph uicontrol">Threat Name</span> (<span
class="ph uicontrol"
>ACC &gt; Threat Activity</span
>).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-198333</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the SaaS PDF report incorrectly displayed the
sanctioned application tag count as 1.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-198306</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process stopped responding when booting up the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-198174</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when viewing traffic or threat logs from the
<span class="ph uicontrol">Application Command Center</span> (ACC) or
<span class="ph uicontrol">Monitor</span> tabs, performing a reverse
DNS lookup caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>dnsproxy</a
>
process to restart if DNS server settings were not configured.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-198078</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where VXLAN keepalive packets were dropped randomly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-198038</b></div>
</td>
<td class="entry relcol">
<div class="p">
A CLI command was added to address an issue where long-lived sessions
were aging out even when there was ongoing traffic.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197953</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logd</a
>
process stopped responding due to forwarded threat logs, which caused
Panorama to reboot into maintenance mode.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197935</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an intermittent issue where XML API IP address tag registration
failed on firewalls in a multi-vsys environment.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197919</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when path monitoring for a static route was
configured with a new Ping Interval value, the value was not used as
intended.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197908</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph">Strata Logging Service</span> flaps occurred for long
durations which caused a memory leak related to the
<span class="ph systemoutput">mgmtsrvr</span> process.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197877</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an intermittent issue on Panorama where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>distributord</a
>
process stopped responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197872</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process generated false positive critical errors.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197847</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where disabling the
<span class="ph systemoutput">enc-algo-aes-128-gcm</span> cipher did
not work when using an SSL/TLS profile.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197737</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the connection to the PAN-DB server failed with
following error message:
<span class="ph systemoutput"
>Failed to send req type[3], curl error: Couldn't resolve host
name</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197729</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where repeated configuration pushes from Panorama
resulted in a management server memory leak.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197678</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the dataplane stopped responding, which caused
internal path monitoring failure.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197582</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to PAN-OS 10.1.6, the firewall
reset SSL connections that used policy-based forwarding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197563</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue in the User Activity Report where output fields started
with the letter
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>b</a
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197549</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where making GlobalProtect gateway configuration
changes resulted in a HIP notification error.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197426</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where, when attempting to view the
<span class="ph uicontrol">Monitor page</span>, the error
<span class="ph uicontrol">invalid term</span> was displayed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197386</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic that was subject to network packet broker
inspection entered a looping state due to incorrect session offload.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197339</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where template configuration for the User-ID agent was
not reflected on the template stack on Panorama appliances on PAN-OS
10.2.1.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197298</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the audit comment archive for Security rule
changes output had overlapping formats.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197203</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an intermittent issue where, if SSL/TLS Handshake Inspection was
enabled, multiple processes stopped responding when the firewall was
processing packets.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197121</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where incorrect user details were displayed under the
<span class="ph uicontrol">USER DETAIL</span> drop-down (<span
class="ph uicontrol"
>ACC &gt; Network activity &gt; User activity</span
>).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197115</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the total number of in-used HIP profiles
was greater than 32, traffic from the GlobalProtect Agent did not hit
the expected Security policy rule configured with the HIP profile even
though a HIP match log was generated.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197097</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where LSVPN did not support IPv6 addresses on the
satellite firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196954</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a memory leak issue related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>distributord</a
>
process.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196874</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the firewall accepted ICMP redirect
messages on the management interface, the firewall did not clear the
route from the cache.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196840</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where exporting a Security policy rule that contained
Korean language characters to CSV format resulted in the policy
description being in a non-readable format.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196811</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where logout events without a username caused high CPU
usage.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196715</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you could not directly edit
<span class="ph uicontrol">Services</span> and
<span class="ph uicontrol">Address</span> objects from the
<span class="ph uicontrol">Policies</span> tab.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196704</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol"
>Preview Changes on Panorama Push to Devices</span
>
incorrectly displayed changes to encrypted entries.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196701</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not properly measure the
Panorama connection keepalive timer, which caused a Panorama HA
failover to take longer than expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196671</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-3400 Series firewalls and PA-5410, PA-5420, and PA-5430
firewalls only</tt
>) Addressed an issue to improve network latency,
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196583</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Cisco TrustSEc plugin triggered a flood of
redundant register/unregister messages due to a failed IP address tag
database search.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196566</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process restarted repeatedly which let to an OOM condition.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196558</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IP address tag policy updates were delayed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196474</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when a decryption profile was configured with
TLSv1.2 or later, web pages utilizing TLS1.0 were blocked with an
incorrect <span class="ph systemoutput">ERR_TIME_OUT</span> message
instead of an
<span class="ph systemoutput">ERR_CONNECTION_RESET</span> message.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196467</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where enabling strict IP address checks in a Zone
Protection profile caused GRE tunnel packets to be dropped.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196457</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where extraneous logs displayed in the Traffic log when
Security policy settings were changed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196452</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DNS queries failed from source port 4789 with a
NAT configuration.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196450</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where certificates with whitespaces in the name or
common name (CN) were not able to be imported.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196410</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were unable to customize the risk value in
<span class="ph uicontrol">Risk-of-app</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196309</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where a
firewall configured with a Policy-Based Forwarding policy flapped when
a commit was performed, even when the next hop was reachable.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196131</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>comm</a
>
process stopped responding when a show command was executed in two
sessions.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196105</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where using special characters in a
password caused authentication to fail when connecting to the
GlobalProtect portal with GlobalProtect satellite configured.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196050</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where logs did not populate when one log
collector in a log collector group was down.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196003</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph uicontrol">Adjust Columns</span> options for Panorama
traffic logs did not correctly auto-adjust the columns.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195988</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where commits failed when an AS path regular expression
that included the ( _ ) character was specified in the virtual router
BGP configuration export rule.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195893</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where daily PDF summary reports were not generated when
the <span class="ph uicontrol">Application Report</span> was selected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195869</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where scheduled custom reports based on firewall data
did not display any information.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195828</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SNMP reported the
<span class="ph systemoutput">panVsysActiveTcpCps</span> and
<span class="ph systemoutput">panVsysActiveUdpCps</span> value to be
0.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195792</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when generating a stats dump file for a managed
device from Panorama (<span class="ph uicontrol"
>Panorama &gt; Support &gt; Stats Dump File</span
>), the file did not display any data.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195790</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where syslog traffic that was sent from the management
interface to the syslog server even when a destination IP address
service route was configured.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195713</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where clientless VPN applications were not displayed in
the GlobalProtect portal page.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195695</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the AppScope Summary report and PDF report export
function did not work as expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195669</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with Panorama appliances in HA configurations where a
passive Panorama appliance generated
<span class="ph systemoutput"
>CMS Redistribution Client is connected to global collector</span
>
messages.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195659</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with firewalls in HA configurations where ping
responses from the target IP addresses were much delayed after a
configuration push.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195583</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after renaming an object, configuration pushes
from Panorama failed with the commit error
<span class="ph uicontrol">object name is not an allowed keyword</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195526</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall system log received a large amount
of error messages when attempting a connection between the firewall
and Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195374</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/passive HA configurations only</tt
>) Fixed an issue where, when redistribution agent connections to the
passive firewall failed, excessive system alerts for the failed
connection were generated. With this fix, system alerts are logged
every 5 hours instead of 10 minutes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195201</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where high volume DNS Security traffic caused the
firewall to reboot.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195200</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not attach and email scheduled
reports (<span class="ph uicontrol"
>Monitor &gt; PDF &gt; Reports &gt; Email Scheduler</span
>) when the size of the email attachments was large.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195114</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where proxy ARP responded on the wrong interface when
the same subnet was in two virtual routers.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195107</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7000s Series firewalls with LFCs only</tt>)
Fixed an issue where the IP address of the LFC displayed as
<span class="ph uicontrol">unknown</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195064</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the log collector did not forward correlation
logs to the syslog server.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194912</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the CLI command
<span class="ph systemoutput">show applications list</span> did not
return any outputs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194812</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where generating reports via XML API failed when the
serial number was set as
<span class="ph systemoutput">target</span> in the query.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194805</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where scheduled configuration backups to the SCP server
failed with error message
<span class="ph systemoutput">No ECDSA host key is known</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194737</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where path monitor displayed as deleted when it was
disabled, which caused a preview change in the summary for static
routes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194704</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with SIP ALG where improper NAT was applied when
Destination NAT ran out of IP addresses.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194615</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the packet broker session timeout value did not
match the master sessions timeout value after the firewall received a
TCP FIN or RST packet. The fix ensures that Broker session times out
within 1 second after the master session timed out.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194441</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the dataplane CPU usage was higher than expected
due to packet looping in the broker session when the network packet
broker was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194175</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a commit push to managed firewalls
failed when objects were added as source address exclusions in a
Security policy and
<span class="ph uicontrol"
>Share Unused Address and Service Objects with Devices</span
>
was unchecked.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194068</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5200 Series firewalls only</tt>) Fixed an issue
where the firewall unexpectedly rebooted with the log message
<span class="ph systemoutput">Heartbeat failed previously</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194043</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">Managed Devices &gt; Summary</span> did not
reflect new tag values after an update.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194031</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-220 Firewalls only</tt>) Fixed an issue where
system log configurations did not work as expected due to insufficient
process timeout after a
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-194025</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>ikemgr</a
>
process stopped responding due to a timing issue, which caused VPN
tunnels to go down.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193879</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the push scope was delayed for commit
and push operations.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193831</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where internal routes were added to the routing table
even after disabling dynamic routing protocols.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193808</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a memory leak issue in the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>mgmtsrvr</a
>
process that resulted in an OOM condition.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193733</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in multi-vsys environments only</tt>)
Fixed an issue where IP tag addresses were not synced to all virtual
systems (vsys) when they were pushed to the firewall from Panorama via
XML API.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193619</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where air gapped firewalls and Panorama appliances
performed excessive validity checks to updates.paloaltonetworks.com,
which caused software installs to fail.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193558</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where log retention settings
<span class="ph uicontrol">Multi Disk</span> did not display correct
values on the firewall web interface when the settings were configured
using a Panorama template or template stack.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193396</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the source user name was displayed in traffic
logs even when
<span class="ph uicontrol">Show User Names In Logs and Reports</span>
was disabled for a custom admin role.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193323</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where root partition utilization reached 100% due to
mdb old logs not being purged as expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193281</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process stopped responding after a content update on the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193245</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when using
<span class="ph systemoutput">syslog-ng</span> forwarding via SSL,
with a Base Common Name (CN) and multiple Subject Alternative Names
(SANs) were listed in the certificate.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193175</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph systemoutput">PBP Drops (8507)</span> threat logs were
incorrectly logged as
<span class="ph systemoutput">SCTP Init Flood (8506)</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193043</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with the where firewalls in Google Cloud Platforms
(GCP) inserted the hostname as
<span class="ph systemoutput">PA-VM</span> in the syslog header
instead of the DHCP assigned hostname when logs were being sent to the
syslog server.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193026</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where warning messages were generated during commits
when configuration details of two profiles were identical.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-192681</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where HIP database storage on the firewall reached full
capacity due to the firewall not purging older HIP reports.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-192513</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where log migration did not work when converting a
Legacy mode Panorama appliance to Log Collector mode.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-192456</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect SSL VPN processing during a high
traffic load caused the dataplane to stop responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-192417</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where botnet reports were not generated on the
firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-192296</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when you saved a SaaS application report as a
PDF or sent it to print, the size of the report was smaller than
expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-192244</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where scheduled log export jobs continued to run even
after being deleted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-192193</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where exporting a list of managed collectors via the
Panorama web interface failed with the following error message:
<span class="ph systemoutput"
>Export Error, Error while exporting</span
>
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-192188</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
the
<span class="ph systemoutput"
>show running resource-monitor ingress-backlogs</span
>
CLI command failed with the following error message:
<span class="ph systemoutput"
>Server error : Failed to intepret the DP response</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-192092</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with firewalls in active/passive configurations only
where the registered cookie from the satellite firewall to the passive
firewall did not sync, which caused authentication between the
satellite firewall and the GlobalProtect portal firewall to fail after
a failover event.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-192076</b></div>
</td>
<td class="entry relcol">
<div class="p">
Added debug logs for visibility into an OpenSSL memory initialization
issue that caused unexpected failovers.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-191997</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where log queries did not successfully filter the
<span class="ph systemoutput">unknown</span> category.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-191652</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with Prisma Cloud where a commit push failed due to the
error
<span class="ph systemoutput"
>Error: failed to handle TDB_UPDATE_BLOCK</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-191463</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not handle packets at Fastpath
when the interface pointer was null.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-191408</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not correctly receive dynamic
address group information from Panorama after a reboot or initial
connection.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-191390</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the management plane CPU was incorrectly calculated as high when
logged in the mp-monitor.log.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-191352</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an intermittent issue where high latency was observed on the web
interface and CLI due to high CPU usage related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>sadc</a
>
process.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-191235</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with firewalls in HA configurations where the passive
firewall attempted to connect to a hardware security module (HSM)
client when a service route was configured, which caused dynamic
updates and software updates to fail.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-191032</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where
<span class="ph uicontrol">Managed Devices</span> displayed
<span class="ph uicontrol">Unknown</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-190533</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where addresses and address groups were not displayed
for users in Security admin roles.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-190502</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Policy filter and Policy optimizer filter
were required to have the exact same syntax, including nested
conditions with rules that contained more than one tag when filtering
via the <span class="ph systemoutput">neq</span> operator.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-190454</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, while authenticating, the allow list check
failed for vsys users when a SAML authentication profile was
configured under <span class="ph uicontrol">shared location</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-190409</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-5450 and PA-3200 Series firewalls that use an FE101 processor
only</tt
>) Fixed an issue where packets in the same session were forwarded
through a different member of an aggregate ethernet group when the
session was offloaded. The fix is that you can use the following CLI
command to change the default tag setting to the tuple setting:
</div>
<div class="p">
<span class="ph systemoutput"
>admin@firewall&gt; set session lag-flow-key-type ?</span
>
</div>
<div class="p"><span class="ph systemoutput">&gt; tag tag</span></div>
<div class="p">
<span class="ph systemoutput">&gt; tuple tuple</span>
</div>
<div class="p">
<span class="ph systemoutput">tag</span> is the default behavior (tag
based on the CPU, tuple based on the FE).
</div>
<div class="p">
<span class="ph systemoutput">tuple</span> is the new behavior, where
both CPU and FE use the same selection algorithm.
</div>
<div class="p">Use the following command to display the algorithm:</div>
<div class="p">
<span class="ph systemoutput"
>admin@firewall&gt; show session lag-flow-key-type</span
>
</div>
<div class="p">
<span class="ph systemoutput">dp0: tuple based on fe100</span>
</div>
<div class="p">
<span class="ph systemoutput">dp1: tuple based on fe100</span>
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-190266</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue that stopped the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process to stop responding at the
<span class="ph systemoutput">pan_sdwan_qualify_if_ini</span>
function.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189960</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where you were unable to view the last
address object moved to the shared template list.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189866</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with the web interface where group include lists used
server profiles instead of LDAP proxy.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189783</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where container resource limits were not enforced for
all processes when running inside a container.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189719</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where
<span class="ph uicontrol">Test Server Connection</span> failed in an
HTTP server profile with the following error message:
<span class="ph systemoutput"
>failed binding local connection end</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189718</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the number of sessions did not reach the expected
maximum value with Security profiles.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189666</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect portal connections failed after
random commits when multiple agent configurations were provisioned and
configuration selection criteria using certificate profile was used.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189643</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when QoS was enabled on an IPSec tunnel, traffic
failed due to applying the wrong tunnel QoS ID.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189518</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where incoming DNS packets with looped compression
pointers caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>dnsproxyd</a
>
process to stop responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189425</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where
<span class="ph uicontrol"
>Export Panorama and devices config bundle</span
>
(<span class="ph uicontrol">Panorama &gt; Setup &gt; Operations</span
>) failed with the following error message:
<span class="ph systemoutput"
>Failed to redirect error to /var/log/pan/appweb3-panmodule.log
(Permission denied)</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189379</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where FQDN based Security policy rules did not match
correctly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189375</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when migrating the firewall, the firewall
dropped packets when trying to re-use the TCP session.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189335</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>varrcvr</a
>
process restarted repeatedly, which caused the firewall to restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189300</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama appliances in active/passive HA
configurations reported the false positive system log
<span class="ph systemoutput">Failed to sync vm-auth-key</span> when a
VM authentication key was generated on the active appliance.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189200</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where sinkholes did not occur for AWS Gateway Load
Balancer dig queries.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189027</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the dataplane CPU utilization provided from the
web interface or via SNMP was incorrect.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-188933</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the UDP checksum wasn't correctly calculated for
VXLAN traffic after applying NAT.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-188912</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where authentication failed due to a process
responsible for handling authentication requests going into an
irrecoverable state.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-188519</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue
where, when manually deactivating the license, the admin user did not
receive the option to download the token file and upload it to the
Customer Support Portal (CSP) to deactivate the license.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-188904</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where web pages and web page contents were not properly
loaded when cloud inline categorization was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-188506</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">ctd_dns_malicious_fwd</span> counter
incorrectly increased incrementally.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-188403</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where the interzone-default rule
hit count was not displayed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-188348</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where encapsulating Security payload packets
originating from the firewall were dropped when strict IP address
check was enabled in a zone protection profile.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-188291</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when using Global Find on the web interface to
search for a given
<span class="ph uicontrol"
>Hostname Configuration (Device &gt; Setup &gt; Management)</span
>, clicking the search result directed you to the appropriate Hostname
configuration, but did not change the respective
<span class="ph uicontrol">Template</span> field automatically.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-188272</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-5200 Series and PA-7000 Series firewalls only</tt
>) Fixed an issue where
<span class="ph uicontrol">Support UTF-8 For Log Output</span> wasn't
visible on the web interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-188118</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with firewalls in FIPS mode that prevented device
telemetry from connecting.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-187763</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DNS Security logs did not display a threat
category, threat name, or threat ID when domain names contained 64 or
more characters.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-187438</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5400 Series firewalls only</tt>) Fixed an issue
where HSCI interfaces didnt come up when using BiDi transceivers.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-187279</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where not all quarantined devices were displayed as
expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-186530</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the current date was incorrectly printed as the
last license check date.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-186471</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when exporting to CSV in Global Find, the
firewall truncated names of rules that contained over 40 characters.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-186412</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where invalid
<span class="ph systemoutput">packet-ptr</span> was seen in work
entries.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-186294</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where commits from Panorama failed on the firewall due
to the virtual router name character limit.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-186270</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when HA was enabled and a dynamic update
schedule was configured, the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process unexpectedly stopped responding during configuration commits.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-185770</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall displayed the error message
<span class="ph systemoutput">Malformed Request</span> when an email
address included an ampersand ( &amp; ) when configuring an email
server profile.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-185466</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where WildFire submission did not work as expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-185394</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7000 Series firewalls only</tt>) Fixed an issue
where not all changes to the template were reflected on the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-185360</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when Captive Portal Authentication was
configured,
<span class="ph systemoutput">l3svc_ngx_error.log</span> and
<span class="ph systemoutput">l3svc_access.log</span> did not roll
over after exceeding 10 megabytes, which caused the root partition to
reach full utilization.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-185287</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-7050 firewalls with Network Processing Cards (NPCs) only</tt
>) Debug commands were added to address an issue where the firewall's
NPC Slot2 failed and multiple dataplane processes stopped responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-185234</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the packet buffer utilization was displayed as high even when no
traffic was traversing the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-184744</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not decrypt SSL traffic due to a
lack of internal resources allocated for decryption.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-184708</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where scheduled report emails (<b class="ph b"
>Monitor&gt;PDF Reports&gt;Email Scheduler</b
>) were not emailed as expected if they included a SaaS Application
Usage report.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-183524</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GTPv2-c and GTP-U traffic was identified with
<span class="ph systemoutput">insufficient-data</span> in the traffic
logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-183375</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic arriving on a tunnel with a bad IP
address header checksum was not dropped.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-183126</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where you were able to attempt to push a
number of active schedules to the firewall that was greater than the
firewall's maximum capacity.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-182875</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where certificate generation using SCEP did not take
more than one organizational unit (OU).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-182732</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect gateway inactivity timer wasn't
refreshed even though traffic was passing through the tunnel.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-182167</b></div>
</td>
<td class="entry relcol">
<div class="p">
Removed a duplicate save filter Icon in the Audit Comment Archive for
Security Rule Audit Comments tab.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-181968</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-400 Series firewalls in active/passive HA configurations
only</tt
>) Fixed an issue where, when HA failover occurred, link up on all
ports took longer than expected, which caused traffic outages.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-181334</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where users with custom admin roles and access domains
were unable to view address objects or edit Security rules.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-181129</b></div>
</td>
<td class="entry relcol">
<div class="p">
Improved protection against unexpected packets and error handling for
traffic identified as SIP.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-180948</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an external dynamic list fetch failed with the
error message
<span class="ph systemoutput"
>Unable to fetch external dynamic list. Couldn't resolve host name.
Using old copy for refresh</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-180690</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dropped IPv6 Bi-Directional
Forwarding (BFD) packets when IP Spoofing was enabled in a Zone
Protection Profile.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-179174</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where exported PDF report of the ACC was the incorrect
color after upgrading from a PAN-OS 10.1 or later release.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-178951</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where Agentless User-ID lost parent
Security group information after the Security group name of the nested
groups on Active Directory was changed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-178728</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>dcsd</a
>
process stopped responding when attempting to read the config to
update its redis database.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-177942</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when grouping HA peers, access domains that were
configured using multi-vsys firewalls deselected devices or virtual
systems that were in other configured access domains.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-177562</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where PDF reports were not translated to the configured
local language.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-177201</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when a Panorama appliance on a PAN-OS 9.0 or
later release pushed built-in external dynamic lists to a firewall on
a PAN-OS 8.1 release, the external dynamic list was removed, but the
rule was still pushed to the firewall. With this fix, Panorama will
show a validation error when attempting to push a pre-defined external
dynamic list to a firewall on a PAN-OS 8.1 release.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-176989</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the CLI command to show SD-WAN tunnel members
caused the firewall to stop responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-176379</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when multiple routers were configured under a
Panorama template, you were only able to select its own virtual router
for next hop.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-175244</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding when adding, deleting or listing an
authentication key.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-175142</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where executing a debug command caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process to stop responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-175061</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where filtering threat logs using any value under
<span class="ph uicontrol">THREAT ID/NAME</span> displayed the error
<span class="ph uicontrol">Invalid term</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-174953</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall didn't update URL categories from
the management plane to the dataplane cache.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-174781</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not send an SMTP 541 error
message to the email client after detecting a malicious file
attachment.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-174680</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when adding new configurations, Panorama didn't
display a list of suggested template variables when typing in a
relevant field.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-174027</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where attempting to rename mapping for
address options caused a push to fail with the following error
message:
<span class="ph systemoutput">Error: Duplicate address name.</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-171927</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where incorrect results were displayed when filtering
logs in the <span class="ph uicontrol">Monitor</span> tab.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-171300</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a password change in a template did
not reset an expired password flag on the firewall, which caused the
user to change their password when logging in to a firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-170414</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue related to an OOM condition in the dataplane, which was
caused by multiple <span class="ph systemoutput">panio</span> commands
using extra memory.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-157199</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-220 firewalls only</tt>) Fixed an issue where
the GlobalProtect portal was not reachable with IPv6 addresses.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-142701</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not delete Stateless SCTP
sessions after receiving an SCTP Abort packet.
</div>
</td>
</tr>
</tbody>
</table>