Files

4.9 KiB

type, product, version
type product version
Addressed PAN-OS 10.2.16-h4

PAN-297349

Fixed an issue where the MIB ID returned an incorrect value via SNMP.

PAN-295342

Fixed an issue where the pan_comm process stopped responding due to insufficient time allocated to read file descriptors when processing long messages.

PAN-294770

Firewalls in active/passive HA configurations

Fixed an issue on firewalls where, after failover, certain subnets were missing from the Link State Database, which prevented OSPF routes from being immediately learned due to a Type-7 to Type-5 LSA translation conflict in the ABR when the same LSA was advertised by two peers in the NSSA area.

PAN-293673

Fixed an issue where the firewall stopped all tasks due to an OOM condition caused by a scheduled log export using FTP to an external FTP server.

PAN-292539

CN-Series firewalls only

Fixed an issue where the firewall generated incomplete or corrupted tech support files (TSF) due to high disk usage on the management plane.

PAN-289239

Fixed an issue on Panorama where a new virtual system (vsys) was automatically created with the name of a device group.

PAN-287842

Fixed an issue where the comm process stopped responding due to missing heartbeats, which resulted in a system alert and HA communication loss on slot1.

PAN-287838

Panorama appliances only

Fixed an issue on the web interface where resetting the rule hit counter for multiple policy rules failed with the error message Failed to reset rule-hit job.

PAN-287734

Fixed an issue where the error message Scan ERR: Internal Err 1002 was generated unexpectedly when WIF shared memory use was high.

PAN-286615

Fixed an issue where the firewall double-freed shared memory when the shared memory usage reached 100% when sending large payloads. This occurred when DLP, Advanced Advanced Threat Protection (ATP), Advanced WildFire (AWF), or Advanced URL Filtering were enabled.

PAN-286231

Fixed an issue where a simultaneous selective push from Panorama to multiple firewalls with different base configurations resulted in configuration corruption, which caused the firewall to go down.

PAN-284003

Fixed an issue where clients did not receive a valid response when searching a website due to a compression error.

PAN-282277

Fixed an issue where an OOM condition on the logrcvr process caused interface flapping, and the interface unexpectedly went down and then recovered without intervention.

PAN-280536

Fixed an issue where firewalls that were connected to the same Cloud Identity Engine displayed inconsistent group membership information, with some firewalls showing only a subset of users belonging to a group.

PAN-279901

An issue was fixed where the firewall dropped fragmented TLS ClientHello packets, which blocked access to certain websites. This occurred because the packets arrived truncated, in varying sizes and orders, and the firewall's heuristics failed to handle them correctly.

To enable this fix, run: debug dataplane set ssl-decrypt accumulate-client-hello disjoined yes

PAN-279500

Fixed an issue where TLS connections failed to establish in asymmetric routing environments if the firewall did not see server-to-client (s2c) packets of the TLS handshake.

To use this fix, run the following CLI command: debug dataplane set ssl-decrypt accumulate-client-hello asym-disable yes.

PAN-278288

Fixed an issue where IPv6 BGP peering established between virtual routers even without dataplane connectivity. This occurred because the firewall used the kernel for lookups instead of the dataplane.

PAN-276484

Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (Device Deployment > Licenses) due to the inability to perform batch-license refreshes.

PAN-277034

Fixed an issue where WildFire reports were not fully displayed and were not downloadable due to static resources not being found.

PAN-267614

Fixed an issue where the Panorama web interface was slower than expected due to high CPU utilization on the mongodb process.

PAN-220293

Fixed an issue where the firewall management plane could not display BGP peer details when using the CLI command show advanced-routing bgp peer detail logical-router . This was due to the bgp_frr.py script failing to parse the IPv6 address family section of the show ip bgp neighbors json output.

PAN-231386

Fixed an issue where the configd process stopped responding during certificate verification.

PAN-202905

Fixed an issue on the firewall web interface where the Next Hop value was not displayed in the static route configuration, the admin-dist values were empty, and the path-monitor parameters were not listed in the management server web interface when the firewall was configured in FRR mode.

PAN-191026

Fixed an issue where the debug log receiver statistics CLI command did not display entries for hipmatch logs.