Files

709 lines
22 KiB
HTML

<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-304088</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TCP traffic stopped working from Prisma Access
clients to TCP services behind the Service Connection (SC) after a
dataplane upgrade to an affected release.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-303559</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after manually creating a device telemetry
bundle, the hour_cli_output.txt file within the bundle had a file size
of 0 bytes. This occurred when checking the bundle content after
enabling device telemetry and setting the device telemetry upload
endpoint.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-301828</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when a firewall was managed by Strata Cloud
Manager and configured to use a proxy server for external connections,
the management server did not use the configured settings to connect
to the Cloud Management service.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-300906</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where XML API commands failed with a
<span class="ph systemoutput">Method not found (policy_xml)</span>
error in dagger.log. The issue was due to missing XML-related
functions for inline-cloud-proxy.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-298505</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading an HA pair of PA-7050 firewalls,
the vsys ID changed in sequence, causing autocommit failures with
validation errors. This occurred when the multi-vsys firewall had
virtual systems created and pushed from Panorama, and the vsys ID was
not in a correct sequence because the unused vsys was deleted from
Panorama and pushed to devices.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-298387</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where the source and destination NAT IP
addresses did not display in traffic and threat logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-297972</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a dataplane crash occurred when traffic matched
Inline Cloud Analysis prefiltering signatures, even when Inline Cloud
Analysis features were not enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297775</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading, the
<span class="ph uicontrol">Visible Virtual Systems</span> field
started to reference the vsys name instead of the vsys ID, which
caused inter-vsys routing to fail. This occurred when a vsys display
name matched one of the vsys IDs.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297240</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where attempting to generate reports in a WildFire FIPS
Private Cloud or WF-500 deployment returned 401 errors.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-295560</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading Panorama and Log Collectors,
tunnel logs were not visible in Panorama or Splunk even though traffic
and threat logs were received.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"> PAN-295385</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where syslog forwarding dropped due to FQDN resolution
failures.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-295257</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after onboarding a firewall to Panorama, IPsec
tunnels displayed IKEv2 in Panorama, even though the tunnels were
configured with IKEv1 locally on the firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-295221</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading Panorama and Log Collectors,
Traffic and Threat logs were not forwarded to a Splunk server over
UDP.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-294893</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls with the
<span class="ph uicontrol"
>Send handshake messages to CTD for inspection</span
>
setting enabled caused incorrect security policy rules to be matched.
Specifically, traffic not identified as openai-base or openai-chatgpt
applications was incorrectly matched by the
ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected
response page for blocked URLs was not displayed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-294524</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls and Panorama management servers were
unable to view or download WildFire reports from a WF-500 appliance,
resulting in a 401 error in the report tab.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-294320</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>mprelay</a
>
process repeatedly restarted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-294161</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted unexpectedly due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process restarting and causing an HA failover. This occurred due to
the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process timing out when running the CLI command
<span class="ph systemoutput">show user user-id-agent config all</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-292447</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not display data in the
<span class="ph uicontrol">Feature Adoption</span> tab in Strata Cloud
Manager due to the system creating and deleting a CLI user for each
interval instead of reusing a permanent CLI user for telemetry.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"> PAN-291940</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall established multiple TCP connections
to a syslog server, which caused logs to be dropped. This occurred
because the firewall established a new TCP session for each transfer
and the sessions were not closed, which resulted in a continuous
increase in connections over time.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-291716</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where during a commit, the firewall experienced an
out-of-memory (OOM) condition due to a memory leak and displayed an
error message. This issue caused the device to crash and reboot
unexpectedly.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291653</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect host ID field was
intermittently blank in traffic logs on Prisma Access, even when the
user was connected and had the correct host ID information. This
occurred when the IP address to host ID entry expired and the entry
was re-insterted without the dataplane flag being set.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-291635</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where cookie surrogate cache entries remained
unresolved after an
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>idmgr</a
>
process reset due to the request not being retransmitted. This
occurred because the timestamp in the cache entry was refreshed even
when the UID was 0, which prevented the retransmission of the request
if the initial response was not received.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-291283</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a memory leak associated with the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process occurred during commits, which caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process to restart and the commit to fail.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291067</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
process periodically exceeded its virtual memory limit and restarted,
which led to intermittent outages.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-289859</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama virtual appliances only</tt>) Fixed an
issue where Panorama failed to mount logging disks larger than 2TB due
to a partitioning error.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-289405</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Added the CLI
command
<span class="ph systemoutput">no-refresh-discard-session</span> to
address an issue where the discarded session time to live (TTL) did
not refresh at the default value.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-289383</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the MPLS interface eth1/6 went down and remained
down, even after replacing the SFP with a supported one and adjusting
duplex and speed settings.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-289249</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory leak occurred on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process when a WildFire update was initiated while device telemetry
data collection was in progress. This resulted in an OOM condition.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-289109</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama web interface was slower than
expected during configuration operations and a configuration lock time
out occurred during a commit.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-288097</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where on the firewall where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>routed</a
>
process stopped responding after changing the MTU or any link state
parameters when OSPF and PIM were enabled on the same interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287803</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading, certain websites weren't
accessible when the accumulation proxy was enabled. The proxy did not
use the same DF bit state as the original traffic, causing it to be
fragmented and dropped elsewhere in the network.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287782</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls configured in vwire mode modified DSCP
values from AF11 to CS0 on traffic passing through the firewall, even
when QoS policy rules and DSCP rewrite settings were not configured.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287622</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IPv6 traffic was affected after upgrading the
firewall. With SSL decryption enabled and a decryption policy
configured for the traffic, the firewall dropped packets due to
receiving a <span class="ph systemoutput">Packet Too Big</span> ICMP
message. This occurred because the PathMTU information update was
incorrect for the TCB (pan-server) when the firewall was acting as a
server. Additionally, the flow label under the IPv6 header was set to
zero while the packet was being transmitted out of the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-287601</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where commits took longer than expected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287387</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where API jobs failed with the error
message
<span class="ph systemoutput"
>Server error: Timed out while getting config lock</span
>. This occurred due to slow set request performance when setting a
large number of address objects in a single set call.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"> PAN-283053</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall experienced high disk space
utilization, which caused the firewall to become non-functional.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-282277</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an OOM condition on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process caused interface flapping, and the interface unexpectedly went
down and then recovered without intervention.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-281776</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where the error message
<span class="ph systemoutput"
>PPPoEv6 Client Interface cannot be enabled with DHCPv6 client</span
>
was generated when overriding aggregate interfaces even when no DHCPv6
or PPPoE was configured.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-278836</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after an upgrade, GlobalProtect attempted to use
the embedded browser instead of the default browser for gateway
authentication even when it was configured to use the default browser.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-272245</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>dnsproxy</a
>
process stopped responding due to memory corruption caused by a race
condition when the allow list downloading was impacted by a
configuration change.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267450</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process stopped responding with a SIGSEGV at
<span class="ph systemoutput">schedule_report_es_response</span>.
</div>
</td>
</tr>
</tbody>
</table>