Files
firewallissues/reference/PAN-OS/addressed/11.2.4-h12.html
T

459 lines
14 KiB
HTML

<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-296519</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a stream receiving a reconnect signal with an
associated error in
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>Wifclient</a
>
caused the entire pool to close, which resulted in a complete
disconnection.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-295560</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading Panorama and Log Collectors,
tunnel logs were not visible in Panorama or Splunk even though traffic
and threat logs were received.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-293673</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped all tasks due to an OOM
condition caused by a scheduled log export using FTP to an external
FTP server.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-292229</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama was unable to retrieve
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>userid</a
>
logs from the firewall for subscribed user-ip-mappings after Panorama
was rebooted.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-292202</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the system logs repeatedly displayed the alert
<span class="ph systemoutput"
>Clearing snmpd.log due to log overflow</span
>
due to the SNMP counters rolling over.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291716</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where PA-460 firewalls experienced out-of-memory (OOM)
conditions, leading to device crashes and reboots.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291631</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the firewall frequently rebooted.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291288</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted unexpectedly due to a
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process restart related to page allocation failures.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291094</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue the firewall experienced packet descriptor on chip and
buffer spikes, which led to dropped traffic due to an unidentified
traffic pattern.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291067</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
process periodically exceeded its virtual memory limit and restarted,
which led to intermittent outages.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-290542</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding when an additional header logging HTTP
header was split across 2 packets.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-290449</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when multiple scheduled vulnerability reports
were sent in the same email, only the first attached report was
displayed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287818</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where sessions timed out sooner than expected due to
the
<span class="ph systemoutput"
>pan_proxy_accumulation_restore_timeout</span
>
not initiating when the accumulation
<span class="ph systemoutput">session_init</span> failed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287803</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading firewalls to PAN-OS 11.1.6-h1,
certain websites weren't accessible when the accumulation proxy was
enabled. The proxy did not use the same DF bit state as the original
traffic, causing it to be fragmented and dropped elsewhere in the
network.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287782</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls configured in vwire mode modified DSCP
values from AF11 to CS0 on traffic passing through the firewall, even
when QoS policy rules and DSCP rewrite settings were not configured.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287622</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IPv6 traffic was affected after upgrading the
firewall to PAN-OS 11.1.6-h4 and later versions. With SSL decryption
enabled and a decryption policy configured for the traffic, the
firewall dropped packets due to receiving a
<span class="ph systemoutput">Packet Too Big</span> ICMP message. This
occurred because the PathMTU information update was incorrect for the
TCB (pan-server) when the firewall was acting as a server.
Additionally, the flow label under the IPv6 header was set to zero
while the packet was being transmitted out of the firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287601</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where commits took longer than expected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"> PAN-287423</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where content loading issues occurred on IPv6 websites
due to the firewall incorrectly setting the IPv6 header flow label to
0.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286299</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on firewalls running PAN-OS 11.1 releases where, after
being offboarded from Panorama, the firewall XML configuration file
retained template information from the previous Panorama
configuration. As a result, when the firewall and its configuration
were imported to another Panorama appliance, all configurations in the
<span class="ph uicontrol">Network</span> and
<span class="ph uicontrol">Device</span> tabs became read-only.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-285285</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where commits remained at 98% completion when static
route configuration cleanup was in progress.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"> PAN-286231</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a simultaneous selective push from Panorama to
multiple firewalls with different base configurations resulted in
configuration corruption, which caused the firewall to go down.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-280698</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall removed the TCP timestamp from
client hello messages that did not fit in a single packet, which
resulted in connection issues.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279706</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">M-600 appliances only</tt>) Fixed an issue where
Panorama did not update all
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>panreplay</a
>
database entries after performing a commit and full push to all
devices.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-276484</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not display license information for
Cloud NGFW firewalls under (<span class="ph uicontrol"
>Device Deployment &gt; Licenses</span
>) due to the inability to perform batch-license refreshes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273453</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where restarting the firewall did not initiate an
autocommit job, which caused the firewall to stop responding and the
HA interface to go down.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273300</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where upgrading to PAN-OS 11.0.4-h2 failed
with a validation error.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-265044</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the default software packet buffer size for the
Advanced Header Learning (AHL) feature was excessively large, which
led to inefficient use of software packet buffers.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260015</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where enabling Inline Cloud Analysis
features might cause the firewall to unexpectedly reboot, due to an
issue related to loopback data handling.
</div>
</td>
</tr>
</tbody>
</table>