344 lines
8.3 KiB
Markdown
344 lines
8.3 KiB
Markdown
---
|
|
type: Addressed
|
|
product: PAN-OS
|
|
version: 11.1.4-h4
|
|
---
|
|
|
|
## PAN-265963
|
|
|
|
Fixed an issue where the escd process caused a memory
|
|
leak when session resiliency was enabled on the firewall.
|
|
|
|
## PAN-265349
|
|
|
|
Fixed an issue where multiple segments of HTTP proxy connect messages
|
|
were not handled correctly by proxy.
|
|
|
|
## PAN-264421
|
|
|
|
Fixed an issue on Panorama where Push Scope
|
|
did not populate automatically after changing the device group
|
|
configuration.
|
|
|
|
## PAN-263987
|
|
|
|
Fixed an issue on the firewall where, when a NAT transversal IPSec
|
|
tunnel was terminated, and the NAT rule that was applied to the
|
|
NAT-T IPSec tunnel was on the same firewall, traffic flowing through
|
|
the tunnel was not correctly translated.
|
|
|
|
## PAN-263559
|
|
|
|
Fixed an issue where the dataplane stopped responding and the
|
|
firewall unexpectedly rebooted due to multiple process restarts.
|
|
|
|
## PAN-263226
|
|
|
|
Fixed an issue where, when SSL decryption was enabled and Client
|
|
Hello messages spanned multiple TCP segments, some SSL decrypted
|
|
sessions failed.
|
|
|
|
## PAN-262593
|
|
|
|
Fixed an issue where traffic to websites failed on the Google Chrome
|
|
web browser on Secure Web Gateway (SWG) nodes.
|
|
|
|
## PAN-262340
|
|
|
|
Fixed an issue where FQDN resolution failed for address objects, and
|
|
all FQDN traffic was denied by the interzone-default policy
|
|
rule.
|
|
|
|
## PAN-262287
|
|
|
|
Fixed an issue where dereferencing a NULL pointer that occurred when
|
|
App-ID stopped responding caused the firewall to restart.
|
|
|
|
## PAN-261991
|
|
|
|
Fixed an issue where traffic that did not match a decryption policy
|
|
rule, or matched a no-decrypt policy rule, failed when accumulation
|
|
proxy was enabled and a Zone Protection profile was configured with
|
|
syn-cookies enabled.
|
|
|
|
## PAN-261917
|
|
|
|
Fixed an issue where websites with a no-decrypt policy rule were
|
|
decrypted in traffic log when using a Google Chrome browser with PQC
|
|
enabled.
|
|
|
|
## PAN-261909
|
|
|
|
Fixed an issue where the GlobalProtect client did not display the
|
|
dialog box for an MFA verification code.
|
|
|
|
## PAN-261489
|
|
|
|
Fixed an issue where an out-of-memory (OOM) condition caused a
|
|
firewall outage.
|
|
|
|
## PAN-261484
|
|
|
|
Fixed an issue on the firewall where DPDK allocated twice the amount
|
|
of memory as requested for pre-allocation.
|
|
|
|
## PAN-261001
|
|
|
|
Fixed an issue where GlobalProtect users were unable to switch
|
|
gateways after upgrading to GlobalProtect version 6.2.3.
|
|
|
|
## PAN-260974
|
|
|
|
Fixed an issue where the Cloud Identity Engine (CIE) user context did
|
|
not correctly redistribute user/IP address port mapping to
|
|
on-premises firewalls.
|
|
|
|
## PAN-259997
|
|
|
|
```caveat
|
|
PA-3410, PA-3420, and PA-3430 firewalls only
|
|
```
|
|
|
|
Fixed an
|
|
issue where the install failed when upgrading from PAN-OS 10.2.3-h3
|
|
and later 10.2 releases to PAN-OS 10.2.10 due to the number of
|
|
configured vsys zones exceeding the zone limit in PAN-OS
|
|
10.2.10.
|
|
|
|
## PAN-259769
|
|
|
|
Fixed an issue where the GlobalProtect portal was not accessible via
|
|
a web browser and displayed the error
|
|
ERR_EMPTY_RESPONSE.
|
|
|
|
## PAN-259151
|
|
|
|
Fixed an issue where unused objects were pushed to the firewall,
|
|
which caused configuration pushes to fail with the error
|
|
Number of address groups exceed platform
|
|
capacity.
|
|
|
|
## PAN-258736
|
|
|
|
Fixed an issue where policy rule configurations pushed from Panorama
|
|
were not reflected on the firewall if the rule had 63
|
|
characters.
|
|
|
|
## PAN-258225
|
|
|
|
Fixed an issue on the Panorama web interface where Security policy
|
|
rules loaded more slowly than expected.
|
|
|
|
## PAN-257957
|
|
|
|
```caveat
|
|
Firewalls and Panorama appliances in FIPS-CC mode only
|
|
```
|
|
|
|
Fixed an issue where the authd process restarted if RADIUS
|
|
PAP/CHAP authentication was used.
|
|
|
|
## PAN-257925
|
|
|
|
```caveat
|
|
CN-Series firewalls only
|
|
```
|
|
|
|
Fixed an issue where the CLI
|
|
command show system setting ctd state did not
|
|
work as expected.
|
|
|
|
## PAN-256725
|
|
|
|
Fixed an issue on the Panorama interface where
|
|
Traffic and
|
|
Unified event details loaded more slowly
|
|
than expected.
|
|
|
|
## PAN-256666
|
|
|
|
Fixed an issue where the configdprocess stopped responding
|
|
when Commit and Push operations were performed on multiple
|
|
device groups.
|
|
|
|
## PAN-256385
|
|
|
|
```caveat
|
|
CN-Series firewalls only
|
|
```
|
|
|
|
Fixed an issue where
|
|
communication was broken between the management plane and the
|
|
dataplane when anti-spyware profiles were configured in a Security
|
|
policy rule.
|
|
|
|
## PAN-256350
|
|
|
|
Fixed an issue where, when you cloned an admin role or an LDAP server
|
|
profile and then changed the name of the clone, the configuration
|
|
change was not reflected on the managed firewall after pushing the
|
|
configuration from Panorama.
|
|
|
|
## PAN-256320
|
|
|
|
```caveat
|
|
Firewalls in active/passive HA configurations only
|
|
```
|
|
|
|
Fixed
|
|
an issue where GTP sessions remained as allocated sessions on the
|
|
passive firewall even when there were no active sessions.
|
|
|
|
## PAN-255930
|
|
|
|
Fixed an issue where persistent DIPP NAT entries were deleted even
|
|
when being used during an active session.
|
|
|
|
## PAN-255266
|
|
|
|
Fixed an issue where you were unable to clone a template stack with
|
|
the Pre-Shared Key variable.
|
|
|
|
## PAN-254826
|
|
|
|
Fixed an issue where the firewall stopped responding when processing
|
|
traffic.
|
|
|
|
## PAN-254671
|
|
|
|
Fixed an issue where excessive Timed out while getting
|
|
config lock error messages were generated when
|
|
making bulk changes via XML API.
|
|
|
|
## PAN-254423
|
|
|
|
Fixed an issue on Panorama where custom role-based admin users with
|
|
read only access were able to make changes to configurations.
|
|
|
|
## PAN-253626
|
|
|
|
Fixed an issue on Panorama where unused objects were pushed to the
|
|
firewall, which caused the push operations to intermittently fail.
|
|
|
|
## PAN-253213
|
|
|
|
Fixed an issue where the firewall sent HIP notifications every time
|
|
it received a HIP report instead of every two hours.
|
|
|
|
## PAN-252300
|
|
|
|
Fixed an issue where you were unable to select device groups in the
|
|
push scope for user accounts.
|
|
|
|
## PAN-251676
|
|
|
|
Fixed an issue on Panorama appliances in large-scale deployments
|
|
where configd process core files consumed more space in
|
|
the /opt/panlogs partition than was available.
|
|
|
|
## PAN-251655
|
|
|
|
Fixed an issue where the firewall stopped forwarding files to the
|
|
WildFire cloud and a restart of the varrcvr process was
|
|
required.
|
|
|
|
## PAN-250787
|
|
|
|
Fixed an issue where network issues between the firewall and the log
|
|
collector caused logrcvr process memory exhaustion.
|
|
|
|
## PAN-250419
|
|
|
|
Fixed an issue where XML API explorer inserted a plus (+) character
|
|
in the Xpath when a space was used in the object name.
|
|
|
|
## PAN-250062
|
|
|
|
Fixed an issue where device telemetry failed after upgrading due to
|
|
bundle generation failure.
|
|
|
|
## PAN-249266
|
|
|
|
Fixed an issue where the config process virtual memory
|
|
was exceeded due to delays in post-commit processing.
|
|
|
|
## PAN-249011
|
|
|
|
Fixed an issue where the firewall became unresponsive when committing
|
|
a configuration change with a large number of uncommitted changes in
|
|
the replay database.
|
|
|
|
## PAN-247099
|
|
|
|
Fixed an issue where the firewall decrypted traffic unexpectedly when
|
|
the client hello was spread across multiple packets.
|
|
|
|
## PAN-246304
|
|
|
|
Fixed an issue on Panorama where commits failed due to a timeout in
|
|
the sysd process during decryption.
|
|
|
|
## PAN-246220
|
|
|
|
Fixed an issue where a dynamic peer connection was rejected when
|
|
using an FQDN for the peer address.
|
|
|
|
## PAN-244039
|
|
|
|
```caveat
|
|
PA-5450 firewalls only
|
|
```
|
|
|
|
Fixed an issue where the firewall
|
|
dropped packets when attempting to reuse a TCP session.
|
|
|
|
## PAN-243098
|
|
|
|
Fixed an issue with corrupted images when SSL decryption and Security
|
|
profiles were configured.
|
|
|
|
## PAN-241781
|
|
|
|
Fixed an issue where partial commit and commit-all operations took
|
|
more time than expected to create the job ID.
|
|
|
|
## PAN-241044
|
|
|
|
Fixed an issue where traffic was denied by the interzone-default
|
|
policy rule when a Security policy rule with an FQDN destination was
|
|
configured.
|
|
|
|
## PAN-234560
|
|
|
|
Fixed an issue where the daily summary report displayed IPv6
|
|
addresses instead of IPv4 addresses.
|
|
|
|
## PAN-233727
|
|
|
|
Fixed an issue on the web interface where the following error message
|
|
was incorrectly displayed for an IKE gateway with a valid
|
|
configuration: ikev2->pq-ppk->negotiation-mode is
|
|
invalid.
|
|
|
|
## PAN-237582
|
|
|
|
Fixed an issue where logs were intermittently missing on the log
|
|
collector due to missing aliases for some indices
|
|
|
|
## PAN-234094
|
|
|
|
Fixed an issue on Panorama where Deploy Master Keyresulted in
|
|
the error message Failed to communicate with device due to a low
|
|
connection timeout value.
|
|
|
|
## PAN-232214
|
|
|
|
Fixed an issue where GlobalProtect clients remained in the connecting
|
|
state during portal pre-login when Kerberos single sign-on (SSO) was
|
|
enabled.
|
|
|
|
## PAN-230825
|
|
|
|
Fixed an issue where link flaps occurred on Panorama appliances in HA
|
|
configurations.
|