Files

4496 lines
132 KiB
HTML

<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-268823</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">Monitor &gt; Log Display</span> did not
display all logs when you applied a filter.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-265963</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>escd</a
>
process caused a memory leak when session resiliency was enabled on
the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-265785</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted due to a
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>sysd</a
>
variable being modified before it was created.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-265462</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were unable to download PDFs when connected
via a Clientless VPN.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-265344</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">Import GlobalProtect Client Package</span>
did not work after clicking <span class="ph uicontrol">OK</span> after
selecting a valid package under
<span class="ph uicontrol"
>Device &gt; GlobalProtect Client &gt; Upload</span
>).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-265287</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall experienced a packet buffer leak in
the dataplane of the network processing card (NPC) when processing
certain net messages.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-264806</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-3440 firewalls only</tt>) Fixed an issue where
the firewall was unable to validate or commit a configuration when it
was imported from another firewall model.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-264369</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph uicontrol">7 Day Threat Report</span> was empty in the
scheduled reports sent via email.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-264249</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where SNMP queries timed out when using
SNMP.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263987</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where, when a NAT transversal IPSec
tunnel was terminated, and the NAT rule that was applied to the NAT-T
IPSec tunnel was on the same firewall, traffic flowing through the
tunnel was not correctly translated.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263956</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-440 firewalls only</tt>) Fixed an issue where a
firewall running PAN-OS 11.1.2-h3 only displayed the
<span class="ph uicontrol">Auto</span> option for the interface duplex
setting.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263505</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-850 firewalls only</tt>) Fixed an issue where
the firewall stopped responding and rebooted after upgrading to PAN-OS
11.1.4.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263287</b></div>
</td>
<td class="entry relcol">
<div class="p">
The PAN-COMMON-MIB.my file was updated to support new object
identifiers (OID) to poll interface use via SNMP with table
identifiers.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263278</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the management interface flapped when IPv6 was
disabled and DHCPv6 was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263226</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when SSL decryption was enabled and Client Hello
messages spanned multiple TCP segments, some SSL decrypted sessions
failed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263164</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Netflow User ID information was truncated to 31
characters.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262902</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where cloning region objects did
not work.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262593</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic to websites failed on the Google Chrome
web browser on Secure Web Gateway (SWG) nodes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262415</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a partial configuration load failed for
configuration files that contained
<span class="ph uicontrol">regenerate-hostkeys</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262410</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph uicontrol">App Scope</span> graph did not display for
all days when selecting
<span class="ph uicontrol">Last 60 days</span> or
<span class="ph uicontrol">Last 90 days</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262340</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where FQDN resolution failed for address objects, and
all FQDN traffic was denied by the interzone-default policy rule.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262287</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where dereferencing a NULL pointer that occurred when
App-ID stopped responding caused the firewall to restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262254</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall experienced an OOM condition and the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process stopped responding, which caused the firewall to drop
interfaces from their respective aggregate groups.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261991</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic that did not match a decryption policy
rule, or matched a no-decrypt policy rule, failed when accumulation
proxy was enabled and a Zone Protection profile was configured with
syn-cookies enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261935</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall unexpectedly rebooted when replacing
or inserting SFPs from an old firewall into a new RMA firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261831</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in HA configuration only</tt>) Fixed an
issue where link-down events did not occur after an HA failover.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261671</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect clients randomly fell back to the
SSL tunnel as the gateway dropped the initial three keepalive packets.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261639</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall incorrectly logged the XFF IP in
threat logs when a single HTTP header was used.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261489</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an out-of-memory (OOM) condition caused a
firewall outage.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261485</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dropped the Real Time Transport
Protocol (RTP) session for the second SIP call on Persistent-DIPP
connections when the source port of the client device was reset.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261484</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where DPDK allocated twice the amount
of memory as requested for pre-allocation.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261371</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-5410 firewalls in active/passive HA configurations only</tt
>) Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process restarted, which caused the firewall to reboot.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261209</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/active HA configuration only</tt
>) Fixed an issue where the firewall displayed the HA2 status as down
when the HSCI port was used for both HA2 and HA3.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261174</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where importing a certificate for a
template stack configuration incorrectly prompted for a passphrase as
a required field.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261028</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not autocommit after a reboot
when the cellular interface was configured as a local interface for
the IPSec Satellite and the IP address was allocated dynamically.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261019</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Evasive Empire C2 Traffic Detection generated
benign verdicts and max latency timeout logs simultaneously when the
MICA ATP action was configured as
<span class="ph uicontrol">reset-both</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260974</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Cloud Identity Engine (CIE) user context did
not correctly redistribute user/IP address port mapping to on-premises
firewalls.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260928</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect failed to connect when using LDAP
authentication with machine certificates with the error message
<span class="ph systemoutput"
>You are not authorized to connect to GlobalProtect portal</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260905</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the HS: Fiber Port Eth1/2 did not come up on a
cold boot and remained in an incorrect state.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260842</b></div>
</td>
<td class="entry relcol">
<div class="p">
A CLI command was introduced to address an issue where TCP packets
were out of order.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260633</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not send a client certificate
after a TLS Certificate Request when establishing a secure syslog
connection.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260546</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-440 firewalls only</tt>) Fixed an issue where
the system clock reset to the epoch date and time after 8 to 12 weeks
of shelf life or no power.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260512</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where accessing the IP address of the device address
group objects from the user interface caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process to stop responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260316</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding and the firewall rebooted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260218</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where BGP Aggregate Advertise filters did not work as
expected when the summary option was enabled, and only summarized
routes were advertised.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260193</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect on macOS clients did not connect
when using a client certificate and the X.509 policy was set to
<span class="ph uicontrol">Use System Default</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260132</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where secondary IP addresses with a /32 prefix
configured on Layer 3 interfaces were not reachable in FRR mode.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260114</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall generated a
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
core file when processes were restarted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259910</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall reported the same value over
consecutive SNMP polls when asynchronous mode was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259883</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewalls behind an Amazon Web Services (AWS)
Gateway Load Balancer (GWLB) stopped responding when processing GENEVE
packets with the reserved bit set.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259881</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where traffic log details were not
displayed under <span class="ph uicontrol">detailed log view</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259802</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances in HA clusters only</tt>) Fixed
an issue where, after replacing a secondary Panorama appliance in a
Panorama HA cluster, the ElasticSearch cluster was unable to establish
SSL tunnels due to SSLHandshakeException errors.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259769</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect portal was not accessible via a
web browser and displayed the error
<span class="ph systemoutput">ERR_EMPTY_RESPONSE</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259706</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the web interface was slower than
expected or unresponsive when monitoring definitions were added in the
Kubernetes plugin.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259535</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall failed to boot up after running
power cycle tests due to
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>ehmon</a
>
process heartbeat failures.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259370</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where
<span class="ph uicontrol"
>Correlation Log Detail &gt; Match Evidence</span
>
did not populate.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259351</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-5921"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-3393</a
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259344</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where performing a configuration commit on a firewall
locally or from Panorama caused a memory leak related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process and resulted in an OOM condition.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259200</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall displayed truncated zone names in
the <span class="ph uicontrol">Block IP List</span> log when a zone
name contained more than 14 characters.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259151</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where unused objects were pushed to the firewall, which
caused configuration pushes to fail with the error
<span class="ph systemoutput"
>Number of address groups exceed platform capacity</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259002</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where frequent external dynamic list updates caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process to restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-258996</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall displayed the SFP ports as
<span class="ph systemoutput">PowerDown</span> when the SFP
transceiver was removed and reinserted or the port was shut down and
brought back up on the peer device.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-258757</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where upgrades failed with validation
errors.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-258734</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where virtual wire ports did not go down when moving
from an active state to a suspended state.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-258576</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where products in HIP
objects were not displayed correctly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-258442</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where changes made to the split tunnel configuration on
the Prisma Access gateway were not reflected on the GlobalProtect
client.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-258240</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
issue where HA path monitoring did not work as expected when using
vwire.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-258225</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where Security policy
rules loaded more slowly than expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-258188</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama Template where the virtual wire
subinterface page did not display all fields and the
<span class="ph uicontrol">OK</span> button did not work.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-258166</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-220 firewalls only</tt>) Fixed an issue where
the root partition frequently reached 100%.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257961</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where
<span class="ph uicontrol">Test Security Policy Match</span> failed
when the <span class="ph uicontrol">From</span> or
<span class="ph uicontrol">To</span> zone fields were populated.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257957</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls and Panorama appliances in FIPS-CC mode only</tt
>) Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>authd</a
>
process restarted if RADIUS PAP/CHAP authentication was used.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257925</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">CN-Series firewalls only</tt>) Fixed an issue where
the CLI command
<span class="ph systemoutput">show system setting ctd state</span> did
not work as expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257912</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding when it received
RADIUS traffic and user equipment (UE) traffic at the same time on a
Network Processing Card (NPC)
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257747</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall incorrectly displayed the error
message
<span class="ph systemoutput"
>IoT Security license is required for feature to function</span
>
even when the firewall had a valid Enterprise IoT security license.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257660</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where show commands were hidden for superusers in
read-only roles.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257652</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Internal Host Detection for IPv6 did not work
after upgrading to a PAN-OS 10.2 release.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257638</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dataplane stopped responding, which
caused BGP flaps between hubs and branches.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257624</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall web interface was blank after
logging in.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257619</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the
<span class="ph uicontrol">Task Manager</span> took longer than
expected to display managed FW report tasks details when its empty
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257601</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
Networking Cards (NC) experienced an internal link fault which caused
path monitoring failure on the Dataplane Processing Card (DPC).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257600</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall returned a 404 error for all sites
accessed through the clientless VPN portal.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257432</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process stopped responding, which caused a log query issue.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257390</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5250 firewalls only</tt>) Fixed an issue where
the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process stopped responding due to a segmentation fault.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257327</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5440 firewalls only</tt>) Fixed an issue where a
failover event occurred unexpectedly on the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257267</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
observed warning message during commit completion &amp; critical
system log when configuration size exceeded the maximum recommended
configuration size.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257117</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where CSV or PDF exports of zones did not contain all
zones.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257028</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/passive HA configurations only</tt
>) Fixed an issue where firewalls entered a non-functional state and
displayed the error message
<span class="ph systemoutput"
>Dataplane down: path monitor failure during the fail-over</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257021</b></div>
</td>
<td class="entry relcol">
<div class="p">
"Fixed an issue on the web interface where
<span class="ph uicontrol">Match Evidence</span> log details for
<span class="ph uicontrol">Monitor &gt; Correlated events</span> did
not populate."
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256960</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a custom portal login page was not displayed
correctly in the GlobalProtect portal when using a customized portal
landing page.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256939</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where disk space was low in
<span class="ph systemoutput">/opt/pancfg/</span>, which caused
dynamic content installation to fail.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256738</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls in HA configurations only</tt>)
Fixed an issue where BGP routes from the active firewall were lost
when the passive firewall was rebooted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256725</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama interface where
<span class="ph uicontrol">Traffic</span> and
<span class="ph uicontrol">Unified</span> event details loaded more
slowly than expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256669</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the memory usage reported by SNMP did not match
the memory usage reported by the top command.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256666</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding when
<span class="ph uicontrol">Commit and Push</span> operations were
performed on multiple device groups.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256652</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where content updates were processed incorrectly, which
caused a mismatch between a Threat ID's signature and its
corresponding action.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256518</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama was unable to push firmware updates to a
VM-Series firewall with a PAYG license.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256449</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DHCPv6 relay was not working in Advanced Routing
mode when the firewall was configured as a DHCP relay agent.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256385</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">CN-Series firewalls only</tt>) Fixed an issue where
communication was broken between the management plane and the
dataplane when anti-spyware profiles were configured in a Security
policy rule.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256362</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue in Panorama where shared address objects used in the
GlobalProtect configuration agents were not considered as used and not
pushed to Firewall that causes commit-all failure error
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256350</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when you cloned an admin role or an LDAP server
profile and then changed the name of the clone, the configuration
change was not reflected on the managed firewall after pushing the
configuration from Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256327</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Panorama virtual appliances on Microsoft Azure environments
only</tt
>) Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logd</a
>
process repeatedly restarted due to a buffer overflow when generating
a traffic summary from a traffic log.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256249</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface that occurred when changing the
pre-shared key to a variable (<span class="ph uicontrol"
>Network &gt; Network Profiles &gt; IKE Gateways</span
>).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256223</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where device telemetry log collection filled the root
partition.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256115</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after replacing a Panorama appliance or log
collector, the secondary Panorama appliance or log collector displayed
a <span class="ph uicontrol">disconnected</span> status for the
inter-log collector connection.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256051</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where enabling flow basic caused the
firewall to stop responding due to a
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>masterd</a
>
process restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255930</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where persistent DIPP NAT entries were deleted even
when being used during an active session.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255895</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama administrators with the
<span class="ph uicontrol">Panorama Administrator</span> dynamic
administrator type were not able to create or modify BGP timer
profiles or BGP dampening profiles.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255820</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the WildFire signature generation check box in
Panorama did not register a change in the configuration.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255773</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where errors related to applications in
<span class="ph uicontrol">Content-preview</span> caused commit
failures.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255711</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall displayed a malformed request error
when selecting a custom format and clicking
<span class="ph uicontrol">OK</span> on the configuration window due
to the log type
<span class="ph uicontrol">Correlation</span> incorrectly being
displayed (<span class="ph uicontrol"
>Device &gt; Log Setting - Correlation &gt; Syslog Server Profile
&gt; Custom Log Format &gt; Correlation</span
>).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255660</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/active HA configurations only</tt
>) Fixed an issue where the path monitor displayed as up even when
routes to the destination IP address were removed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-255579</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-7500 Series firewalls and Panorama appliances only</tt
>) Fixed an issue where dataplane logs were displayed after a delay.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255396</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when using serial number and IP address
authentication, and multiple gateways were configured, the portal
returned the last gateway in the list and disregarded the satellite
assignment by serial number.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255391</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to filter logs using the
ISO 8601 timestamp format after upgrading to PAN-OS 11.0.4 or a later
release.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255360</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall booted into maintenance mode when
there was no connectivity to the specified hardware security module
(HSM).
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-255285</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when only the HSCI-A link was connected on
firewall cluster nodes, and the management interface went down, a
split brain condition occurred.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255282</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-450 firewalls in HA configurations only</tt>)
Fixed an issue where the firewall remained in an active state and all
traffic stopped until a failover to the passive firewall was
performed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255252</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama administrators with the type Dynamic
were unable to create, modify, or delete BGP Dampening profiles.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255163</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">CN-Series firewalls only</tt>) Fixed an issue where
the system database key that stored the configuration status of the
dataplane pod was not updated frequently.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-255116</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when QoS was enabled, traffic on an NGFW cluster
node that went from an MC-LAG interface to a destination stopped when
a member of the MC-LAG went down.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p">
<b class="ph b"><b class="ph b">254927</b></b>
</div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7500 Series firewalls only</tt>) Fixed an issue
where data packets sent to threat inspection processing on the
networking card caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process to stop responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254901</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect user-to-IP address mapping was
removed even though the tunnel for the specific user was up and
traffic was being passed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254875</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-410 firewalls only</tt>) Fixed an issue where
the firewall rebooted unexpectedly due to multiple
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process restarts.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p">
<b class="ph b"><b class="ph b">PAN-254827</b></b>
</div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when you changed an IP address on a management
interface on an NGFW cluster node, commit-all operations did not push
the updated IP address.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254826</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding when processing
traffic.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254797</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5400 Series firewalls only</tt>) Fixed an issue
where you were unable to use SNMP polling o monitor the status of
power supply units.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254704</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>LSVPN Portal firewalls in active/passive HA configurations only</tt
>) Fixed an issue where the satellite cookie key did not sync between
LSVPN portal HA firewalls, which resulted in re-authentication of
satellites with the portal during the event of HA failover.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254671</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where excessive
<span class="ph systemoutput"
>Timed out while getting config lock</span
>
error messages were generated when making bulk changes via XML API.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254629</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Management Processing Card where excessive logs
were generated for an error.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254577</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a core file was created on the Log Forwarding
Card due to a third-party software issue.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254423</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where custom role-based admin users with
read only access were able to make changes to configurations.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254422</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall required a restart when an SD-WAN
policy rule was pushed from Panorama.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-254351</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an NGFW cluster node remained in a suspended
state when GRE tunnel termination was used with keepalive enabled on
both ends.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254301</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect logs showed the public IPv4 address
in the private IPv4 address field for logs generated during
portal/gateway negotiation.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254241</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding due to a high
number of SD-WAN probes being sent.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254181</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">CN-Series firewalls only</tt>) Fixed an issue where
firewall pods and application pods repeatedly restarted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254124</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7050 firewalls with DPC and 100G NPCs only</tt>)
Fixed an issue on the firewall where you were unable to change the
flow key type from tag to tuple.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253829</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the CLI command
<span class="ph systemoutput">show running security-policy</span>
timed out when the Security policy was large.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253819</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a
<span class="ph uicontrol">User Activity Report</span> was not
generated by <span class="ph uicontrol">Run Now</span> or not emailed
through the <span class="ph uicontrol">Email Schedule</span> when the
locale setting was not English.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253626</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where unused objects were pushed to the
firewall, which caused the push operations to intermittently fail.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253584</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where ikemgr process unexpectedly stopped due to a
memory mapping in an incorrect location.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-253557</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after a cluster manager restart on the leader
node of an NGFW cluster, traffic stopped due to only the state machine
transitioning to unknown and not the leader.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253452</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect users were unable to connect to the
GlobalProtect gateway and received the error
<span class="ph systemoutput">Gateway does not exist</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-253466</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, on NFGW cluster nodes, an expected packet buffer
leak occurred with FTP/SIP traffic over an extended period of time.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253250</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when ASPath Prepend was configured, AS override
did not work.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253085</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall restarted when the parsing of the
cross-pkt http origin header failed when processing a translator
website.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252974</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-450 firewalls only</tt>) Fixed an issue where
specific routes were not advertised when BGP Aggregate was configured
with the advertise filter.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252867</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an incorrect memory reference in an IoT API
caused the <span class="ph systemoutput">wifclient</span> process to
stop responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252816</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where multiple SSHD process restarts triggered a
firewall reboot when the login banner and SSH host keys were updated
at the same time.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252801</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the LSVPN tunnel monitoring status displayed as
<span class="ph uicontrol">No data available</span> after re-key
events.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252411</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when log files were purged from the rollup
summary logs, the summary report still used the rollup summary data,
which resulted in the summary report displaying less data.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252370</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where services with the reserved keyword
<span class="ph uicontrol">application-default</span> were allowed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252270</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where changes were incorrectly applied
after a reboot or a restart of the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252224</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not forward logs to a syslog server
over an SSL connection using CRL as a revocation verification method.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252161</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>gp_broker</a
>
process stopped responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252131</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-5200 Series and PA-7000 Series firewalls only</tt
>) Fixed an issue where an unsupported SFP caused the firewall to
restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252036</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect portal was not
configured, accessing the GlobalProtect gateway still loaded a portal
malformed page.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252029</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding when processing
authentication requests.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-251929</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where inbound decryption did not work when FIPS self
tests were turned on.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-251732</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Oracle traffic over generic routing encapsulation
(GRE) was dropped when the traffic passed through the firewall using
tunnel content inspection (TCI).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-251684</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the LEDs for copper ports lighted up when SFP
links were up.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-251676</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama appliances in large-scale deployments where
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process core files consumed more space in the /opt/panlogs partition
than was available.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-251661</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory overwrite occurred during HTTP/2 header
inflation.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-251656</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where enabling lockless QoS caused traffic disruptions.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-251501</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after a reboot, NGFW cluster nodes failed to
rejoin a cluster due to a timing issue.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-251372</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a policy-based forwarding (PBF) did not work for
a server-to-client (S-C) flow when the source port was specified.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-251035</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where selective push operations did not push
certificate changes to the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250948</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issues where GlobalProtect on Microsoft Windows devices did
not attempt CNAME resolution for sinkhole.paloaltonetworks.com.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250909</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when creating a Security policy rule via the
CLI, validation was not implemented and the same object was able to be
referenced in the policy twice.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250756</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where querying threat logs using the threat name, such
as <span class="ph systemoutput">generic:&lt;site&gt;</span> did not
work.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250716</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">Panorama &gt; Push to Devices</span>
displayed device group and template entries that had been changed by
other administrators.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250703</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the task manager failed with a 504 error when a
large number of previous jobs or tasks were present.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250530</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where management traffic routed via the dataplane was
being decrypted instead of bypassing the decryption lookup.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250462</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the session logout time for the firewall was
incorrect when viewing via context switch from Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250455</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect portal authentication incorrectly
timed out after 30 seconds when the timeout value was set to 1 minute.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250443</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
multiple processes exited due to an OOM condition and caused a network
outage.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250419</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where XML API explorer inserted a plus (+) character in
the Xpath when a space was used in the object name.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250405</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">CN-Series firewalls only</tt>) Fixed an issue on
the firewall where
<span class="ph systemoutput">websrvr</span> related messages
displayed repeatedly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250394</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a large amount of group data caused serialization
errors and prevented synchronization.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250311</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the domain was not mapped when using certificate
profile authentication on GlobalProtect.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250258</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where the Certificate Name character
limit was 31 characters instead of 63 characters.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250146</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where templates incorrectly showed
that telemetry was enabled when it was not enabled. With this fix, the
telemetry setting is not displayed in the template on the web
interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250127</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where commits failed with the error message
<span class="ph systemoutput">set is not allowed</span> when
<span class="ph uicontrol">default originate</span> was enabled with a
route map that included a set action.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250062</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where device telemetry failed after upgrading due to
bundle generation failure.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-250043</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, on an NGFW cluster node, operations failed when
QoS interfaces were configured with an egress max that exceeded 68,000
Mbps.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250021</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">Change Summary</span> and
<span class="ph uicontrol">Preview Changes</span> displayed
inconsistent information when changing an admin user password.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250005</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Advanced Routing migration script did not
migrate BGP import policy rules correctly when the policy rule was
configured with an exact match condition.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-249855</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dropped the active source of the
Multicast source via MSDP when they were not received from the MSDP
peer firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-249727</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, on an NGFW cluster node, the
<span class="ph uicontrol">Custom/Pre-defined</span> URL category was
not in the session flow data, which caused it to be excluded from the
promoted session after a failover.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-249548</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding during a high
availability (HA) failover with continued traffic.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-249533</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an internal error message was displayed when you
selected
<span class="ph uicontrol"
>Exclude video traffic from the tunnel (Windows and macOS
only)</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-249404</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where the commit lock for
a device group and template with the same name was not visible.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-249266</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>config</a
>
process virtual memory was exceeded due to delays in post-commit
processing.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-249194</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SaaS quality profile probes were dropped on the
SD-WAN hub.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-249132</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama DG where the address group object created
with <span class="ph uicontrol">Disable Override</span> property in
Parent DG was overridden by child DG via CLI.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-249072</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where content upgrade installation failed with the
error
<span class="ph systemoutput"
>Error: can't find cert &lt;cert&gt; when using cloud
interfaces</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-248945</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where commits failed when you committed a configuration
to advertise the default route (0.0.0.0/0) as a BGP network statement
(<span class="ph uicontrol">Advanced Routing &gt; BGP settings</span
>).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-248841</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the SSL response time was not displayed in the
GlobalProtect log.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-248762</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the Advanced Routing Engine was configured
with OSPF, the firewall stopped responding when attempting to connect
to the neighbor while exchanging route maps.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-248618</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">show chassis inventory</span> in the XML
API output did not include the chassis serial number.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-248542</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the NPB policy type was missing from
configuration policy updates, which caused error messages to
incorrectly display in the system logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-248312</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not re-encapsulate the DNS
Security Sinkhole Domain Response into GENEVE when the firewall was
integrated with AWS Gateway Load Balancer (GWLB) and Cloud NGFW.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-248285</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall went into maintenance mode or
stopped responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-248211</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where commits failed when Advanced Routing
was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-247857</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7050 firewalls in HA configurations only</tt>)
Fixed an issue on the firewall where a dataplane process restarted
when updating the routing table.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-247754</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where successful
<span class="ph uicontrol">Commit and Push</span> operations performed
by SAML authenticated users were not reflected on the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-247230</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the syslog forwarding configuration did not
include the full path for Security policy rules.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-247190</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the firewall was unable to connect to Panorama after manually
uploading the license key.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-247052</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an intermittent issue where the OSPF ABR option was disabled
when a static route was added.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-246803</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with failed pre-login cookies that caused GlobalProtect
portal configurations to show as empty.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-246567</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a firewall with a copper SFP transceiver
(PAN-SFP-CG) flapped during a commit.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-246416</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding when processing
specific HTTP response packets due to an incorrect offset calculation.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-246304</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where commits failed due to a timeout in
the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>sysd</a
>
process during decryption.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-246256</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall received the following error message
in the system logs after rebooting:
<span class="ph systemoutput"
>fail to read ncores: cfg.paltform.cores</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-246220</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a dynamic peer connection was rejected when using
an FQDN for the peer address.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-246209</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IPSec VPN tunnels went down after receiving a
DHCP server message that the DHCP client cleared the IP address on the
interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-245993</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where API calls to move the BGP export rules failed
with the error
<span class="ph systemoutput">The request could not be handled</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-245845</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall displayed a message that the license
was invalid even though all licenses were up to date.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-245682</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where
<span class="ph uicontrol">Commit and Push</span> progress displayed
over 100%.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-245545</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when you were connected to the VPN and enabled
the client accelerator, you were disconnected from the VPN.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-245058</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where tagging a new user
failed the error message
<span class="ph systemoutput">Tags addition failed</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-244743</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where intermittent 500 errors occurred when making API
calls to the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-244708</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect VPN connection inactivity TTL
value became negative, which caused the VPN to disconnect when the
system time was changed back to the past time.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-244262</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where interface settings were not saved when the
template was overridden in the candidate configuration while enabling
DNS settings.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-244035</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5220 firewalls only</tt>) Fixed an issue on the
web interface where the displayed dataplane CPU usage was up to 20%
less than the correct CPU usage.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-243969</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama managed firewalls where you were unable to
add a new Layer 3 interface to a template with a zone, VR, IP address,
and SD-WAN interface profile configured.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-243968</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the correct portal agent configuration for
GlobalProtect was not matched. This occurred when CRL checks failed
due to unavailability.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-243957</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall TLS/SSL service profile exclusion
settings were not correctly applied on the captive portal.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-243908</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where custom object import for spyware got stuck on
uploading page and seen uploaded successfully after refreshing GUI
tab.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-243816</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where new users were unable to change their password
during the first login when the
<span class="ph uicontrol">Max session count</span> was set to 1 and
<span class="ph uicontrol"
>Require Password Change on First Login</span
>
was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-243787</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the CLI command
<span class="ph systemoutput">delete user-file ssh-known-hosts</span>
did not remove the SSH host keys.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-243786</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where custom GlobalProtect reports
displayed inaccurate values.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-243773</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the DHCP server stopped responding with the error
<span class="ph systemoutput">IP address is already in use</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-243674</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were unable to configure NDP proxy with IPv6
address /88 on a Layer 3 interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-243240</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the using QoS caused packet buffer utilization to
increase exponentially and the
<span class="ph systemoutput">PKI POOL DFLT</span> pool depleted until
a reboot was performed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-243223</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where authentication to the GlobalProtect gateway
failed due to an invalid Satellite certificate.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-243190</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the show commands for HSCI ports did not provide
information about optics and light levels.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-243123</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SNMPv3 traps were not sent when using FQDN server
addresses.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-243098</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with corrupted images when SSL decryption and Security
profiles were configured.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-242960</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not honor the peer
<span class="ph uicontrol">Desired Minimum Tx Interval</span> when in
a BFD INIT state.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-242958</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall intermittently logged
<span class="ph systemoutput">connect-agent-failure</span> messages
for service connection instances due to bi-directional host ID
redistribution.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-242957</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph uicontrol">Rule usage</span> columns of overridden
default policy rules on the Security policy page stopped responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-242826</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with the REST API syntax when creating a DHCP server
configuration for an existing subinterface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-242739</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where the dataplane repeatedly
restarted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-242479</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a high number of packets caused high packet
descriptors on the firewall when handling EtherIP traffic.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-242431</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the BGP timer setting was in read-only mode for
custom admin users when Advanced Routing was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-242331</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Prisma Access remote network firewalls
intermittently created incorrect user-to-IP-address mappings.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-242130</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall displayed the speed and duplex of
its dataplane interfaces as
<span class="ph uicontrol">Unknown</span> even though the link was up.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-241871</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to create new IPSec
tunnels when the tunnel monitor flapped.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-241821</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">Global Search</span> did not show results
past the second level.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-241781</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where partial
<span class="ph systemoutput">commit</span> and
<span class="ph systemoutput">commit-all</span> operations took more
time than expected to create the job ID.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-241772</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when TLSv1.3 was used, an incorrect error
message <span class="ph systemoutput">invalid padding</span> was
displayed instead of the expected error message
<span class="ph systemoutput">Invalid server certificate</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-241655</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall incorrectly categorized URLs as
<span class="ph uicontrol">phishing</span> due to machine learning
analysis
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>MLAV</a
>
incorrectly marking the URLs as malicious.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-241536</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where admin users with the Custom Panorama
Admin role were unable to add, edit, or delete route filters under
<span class="ph uicontrol">Routing Profiles</span>
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-241519</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where incorrect log filters were displayed under
unified logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-241295</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama pushed permitted IP address lists were
editable on the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-241044</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic was denied by the interzone-default
policy rule when a Security policy rule with an FQDN destination was
configured.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-241004</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DNS Proxy dropped client requests of the type
<span class="ph systemoutput">ns</span> for a root domain.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-240990</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph systemoutput">l3svc.py</span> displayed incorrect
logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-240723</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Threat logs were logged within a 5 second
interval instead of the exact detection time when the logging rate was
low.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-240225</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where authentication failed on web-based GlobalProtect
portal.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-239952</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/passive HA configurations only</tt
>) Fixed an issue where HA sync messages from the active firewall took
longer than expected to reach the passive firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-239695</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding due to an
internal server error when accessing certificates with the block
private key option enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-239532</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to identify the URL
category in the session details.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-239409</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">lodash.js</span> version installed on
the firewall was not accurately reflected in PanXML.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-239246</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the CLI command
<span class="ph systemoutput"
>debug user-id dump hip-based-profile-database-entry</span
>
returned an incorrect value in the output for the
<span class="ph systemoutput">total size of hip reports</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-239201</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where partial commit or partial validation operations
failed for non-super user administrators with the error
<span class="ph systemoutput"
>&lt;device-group-name&gt; is invalid. meta data not found for dg
&lt;device-group-name&gt;</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-239165</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where adding an interface in a route filter resulted in
an OSPF LSA Type-5 packet check failure, which caused redistributed
routes to be removed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-239143</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with accessing websites when URL filtering profiles
were configured with the
<span class="ph uicontrol">block-continue</span> action and the server
used HTTP/2.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-239138</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a decryption rule with the Log Successful TLS
handshakes option disabled still generated successful decryption logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-239036</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding on Panorama due to an out-of-memory
condition.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-238813</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the DNS proxy was unable to handle UDP DNS
replies with a length of over 512 bytes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-238793</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Panorama virtual appliances in Microsoft Azure environments
only</tt
>) Fixed an issue where a bootstrapped Panorama appliance did not
automatically retrieve the CDL license, which resulted in the firewall
not automatically sending logs to CDL.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-238741</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after a selective push of the configuration, a
parent device group object with multiple child device groups was not
shown in the device group's push scope.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-238303</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5220 firewalls only</tt>) Fixed an issue where
multicast streaming did not recover when multicast traffic was
offloaded.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-238266</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the default
<span class="ph systemoutput">lag-flow-key-type</span> was different
between the dataplane and the forwarding engine.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-237582</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where logs were intermittently missing on the log
collector due to missing aliases for some indices.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-237109</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the application page was not launched directly
after the login page when only one application was configured.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-236909</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when you committed the first configuration
change after booting up the firewall, the external dynamic list file
download failed until the list was refreshed. This occurred when the
configuration was pushed with a certificate profile.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-236830</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic that was correctly detected on the
firewall as the threat category
<span class="ph uicontrol">DNS</span> was detected on Panorama as the
threat category <span class="ph uicontrol">N/A</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-236574</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where User-ID traffic was incorrectly identified as SSL
application instead of
<span class="ph systemoutput">paloalto-userid-agent</span>
application.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-236447</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted and the kernel log
displayed the following message:
<span class="ph systemoutput">
0.000000] Linux version 4.18.0-240.1.1.27.pan.x86_64</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-236182</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when forward message processing received an
invalid payload with a message length of 0 in the buffer header, the
firewall rebooted unexpectedly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-236059</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on firewalls in HA configuration where the IoT content
version was not synced from the active firewall to the passive
firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-235808</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances in Log Collector mode only</tt
>) Fixed an issue where an unnamed core file was generated after a
reboot.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-235529</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Active Directory IP-address-to-user mappings
were not updated on
<span class="ph uicontrol">Mappings &amp; Tags</span> on the Cloud
Identity Engine.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-235110</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-220 firewalls only</tt>) Fixed an issue where
the web interface did not load after an upgrade.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-234461</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where excess
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>distributord</a
>
process memory use caused processes to restart due to OOM conditions.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-234272</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where scheduled device group reports included data from
other device groups.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-234107</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Smart Card authentication failed when the SAN
field contained additional details.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-234082</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama virtual appliances only</tt>) Fixed an
issue where Saas reports were generated with a report period of 0
days.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-233681</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>authd</a
>
process on Prisma Access firewalls stopped responding after receiving
the <span class="ph systemoutput">SIGUSR1</span> signal.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-232833</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the following error message displayed for IoT
trial licenses:
<span class="ph systemoutput"
>IoT Security license is required for the feature to function</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-232792</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama where the web interface did not display
the <span class="ph uicontrol">Scheduled Config Push</span> page.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-232594</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Panorama managed CN-Series firewalls in HA configurations only</tt
>) Fixed an issue where an error occurred while adding tags.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-232550</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SNMPv3 authentication failed when using SHA-512
Auth protocol.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-232263</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama virtual appliances only</tt>) Fixed an
issue where multiple processes stopped responding due to a traffic
outage, which was caused by a corrupted content file.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-231065</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the CLI command
<span class="ph systemoutput"
>show applications list &lt;Application-group/application
filters&gt; device-group &lt;name of device-group&gt;</span
>
returned incomplete result.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-230934</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where HTTP/S, SSH, and PING were enabled on the AUX
port by default even when these administrative management services
were not enabled on the interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-230902</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where you were unable to
configure L3 net-inspect rules for a template stack.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-230893</b></div>
</td>
<td class="entry relcol">
<div class="p">
Added a CLI command to address an issue where system lock files
blocked authentication.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-230825</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where link flaps occurred on Panorama appliances in HA
configurations.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-228555</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect logs returned no data when using
the filter
<span class="ph systemoutput">( private_ip eq 0.0.0.0 )</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-227978</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the web interface did not accurately list the
status of the port when NGFW clustering was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-226789</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls in Amazon Web Services (AWS) environments
only</tt
>) Fixed an issue template values were missing in newly spun firewalls
in auto scale deployments without an explicit push with forced
template values from Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-226365</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with the output format of certificate issuer and
subject fields during certificate creation.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-226280</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">ConfigPushScheduler</span> REST API
failed when the target device was a firewall with a non-default
management profile.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-226125</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph uicontrol">Management Interface Telnet Service</span>
was disabled but the service was still allowed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-225806</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where LACP packets did not reach the dataplane, which
caused the firewall to stop forwarding traffic.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-225228</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where filtering threat logs using any value under
<span class="ph uicontrol">THREAT ID/NAME</span> displayed the error
<span class="ph uicontrol">Invalid term</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-224729</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were unable to create duplicate entries in
Advanced Routing AS path prepend the BGP filter route map.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-221096</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IPSec transport mode failed when the firewall was
the initiator.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-218873</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a HIP mask was reused when an existing IP address
user mapping was updated by a new IP address user mapping that had a
different username but the same IP address.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-215882</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were unable to connect to the GlobalProtect
gateway when the gateway was scaled up automatically.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-214430</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where some commands did not have executable
permissions.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-212197</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were able to create local administrator
usernames that contained only numbers.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207972</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where the BGP routing table did
not display advertised routes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202619</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when SPI values were different for static and
dynamic Satellite tunnel IP addresses during IPSec tunnel
renegotiation, traffic issues occurred between the satellite and the
gateway.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197428</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IKE negotiation with distinguished name
identification did not work.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193285</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the policy optimizer feature did not add entries
back to the <span class="ph systemoutput">mongodb</span> database
after removing them during an upgrade or downgrade.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-192176</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the management server access log file did not
rotate, which caused the root partition to become full and led to
system instability.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-164885</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where
<span class="ph uicontrol">Commit and Push</span> or
<span class="ph uicontrol">Push to Devices</span> operations failed
when an external dynamic list was configured to check for updates
every 5 minutes due to the commit and external dynamic fetch processes
overlapping.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-76904</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5410 firewalls only</tt>) Fixed an issue where
the management interface went down and an error message displayed in
the <span class="ph systemoutput">show interface management</span> CLI
command output.
</div>
</td>
</tr>
</tbody>
</table>