5503 lines
176 KiB
HTML
5503 lines
176 KiB
HTML
<table class="table colsep rowsep table-striped">
|
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
|
|
|
<colgroup>
|
|
<col style="width: 25%" />
|
|
<col style="width: 75%" />
|
|
</colgroup>
|
|
<thead class="thead">
|
|
<tr class="row rowsep">
|
|
<th class="entry">
|
|
<div class="p"><b class="ph b">Issue ID</b></div>
|
|
</th>
|
|
<th class="entry">
|
|
<div class="p"><b class="ph b">Description</b></div>
|
|
</th>
|
|
</tr>
|
|
</thead>
|
|
|
|
<tbody class="tbody">
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-314142</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where establishing log forwarding connections to the
|
|
Strata Logging Service (SLS) took longer than expected, which resulted
|
|
in delayed log visibility on SLS.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-313572</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
|
the dataplane restarted due to a segmentation fault.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-313258</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where PIM multicast routing failed on appliances with
|
|
advanced routing enabled.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-312706</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewalls restarted due to a function lacking
|
|
a NULL-pointer sanity check.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-312618</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall was unable to activate GlobalProtect
|
|
client software and displayed
|
|
<span class="ph systemoutput">SW LIMIT</span> messages related to
|
|
max-profiles and unsupported major and minor versions in the downgrade
|
|
list, which prevented successful software installation.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-311938</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where autocommits failed after an upgrade due to
|
|
configuration memory allocation issues and 100% policy rule cache
|
|
usage when both DNS Rewrite and URL Custom Category Match were
|
|
configured.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-311524</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where config-lock was not displayed on the web
|
|
interface.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-311087</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, when the
|
|
<span class="ph systemoutput">request shutdown system</span> CLI
|
|
command was executed, the firewall experienced a kernel panic and
|
|
automatically rebooted instead of shutting down
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-311073</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Panorama managed firewalls in HA configurations only</tt
|
|
>) Fixed an issue where firewalls incorrectly updated the modified
|
|
date and MD5 hash of policy rules during an HA sync commit job or a
|
|
subsequent local commit, even when no changes were made to the policy
|
|
rules.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-310499</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where, while configuring an an Application
|
|
Filter with Generative AI tags, the web interface did not retain
|
|
application exclusions that were added across multiple pages until you
|
|
clicked <span class="ph uicontrol">OK</span>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-310402</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where SNMP returned an incorrect down status for HSCI
|
|
and logging interfaces even when the interfaces were up, and counters
|
|
for the interfaces displayed only zero values.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-309853</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Firewalls with FIPS-CC enabled only</tt>) Fixed an
|
|
issue where, when attempting to make changes to the GlobalProtect
|
|
portal, an error message was displayed and configuration updates
|
|
failed.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-309831</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where an AI Runtime Security Firewall rebooted when
|
|
processing Cursor traffic.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-309826</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
|
files from SSL decrypted sessions were incorrectly forwarded to the
|
|
WildFire cloud for analysis even when
|
|
<span class="ph uicontrol"
|
|
>Allow Forwarding of Decryption Content</span
|
|
>
|
|
was disabled.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-309459</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where on PA-5420 firewalls, configuring security rules
|
|
with a number of static IMSI/IMEI/NSSAI entries exceeding 5,000
|
|
resulted in a commit failure. This occurred because the firewall
|
|
incorrectly reported the maximum supported static IMSI/IMEI/NSSAI IDs
|
|
as 5,000 (as seen in the
|
|
<span class="ph systemoutput"
|
|
>cfg.mobile-nw-id.max-static-entries</span
|
|
>
|
|
system state variable), instead of the documented limit of 100,000 for
|
|
the platform.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-309392</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the scroll bar did not appear when editing
|
|
<span class="ph uicontrol">Destination Addresses</span> for Policy
|
|
Based forwarding policy rules.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-309379</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>logrcvr</a
|
|
>
|
|
process stopped responding on DPCs, which prevented logs from being
|
|
forwarded.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-309300</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where management plane system resources configuration
|
|
size exceeded 28 MB for over 4 hours, and the following error message
|
|
was displayed:
|
|
<span class="ph systemoutput"
|
|
>Configuration size reaching device capacity limit</span
|
|
>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-309258</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where you were unable to delete a HIP object with
|
|
<span class="ph uicontrol">OR</span> in the name, even though you were
|
|
able to successfully create and commit the object.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-309009</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where log ingestion stopped on the Elasticsearch
|
|
cluster when the number of open shards was significantly higher than
|
|
the number of data nodes.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-308786</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue where
|
|
traffic log queries using the
|
|
<span class="ph systemoutput">device_name</span> filter returned no
|
|
results, and complex log queries that included negation operators
|
|
produced incorrect outputs.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-308668</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Prisma Access Remote Network firewalls where high
|
|
CPU utilization caused slowness and command timeouts.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-308654</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the Elasticsearch Close Indices process closed
|
|
more indices than expected and dropped the number of open shards below
|
|
the minimum of 800 per Elasticsearch instance. This occurred because
|
|
the process did not correctly account for the number of Elasticsearch
|
|
instances when calculating the maximum number of allowed open shards.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-308606</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where traffic was blocked due to a mismatch between the
|
|
URL category specified in the Security policy rule and the URL filter
|
|
profile when custom URL categories with the same FQDN were configured.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-308305</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, when you selected a signature policy rule in the
|
|
Anti-Spyware profile and clicked
|
|
<span class="ph uicontrol">Find Matching Signatures</span>, the
|
|
automatically created filter was incorrect and prevented matching
|
|
signatures from being displayed.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-308188</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after a successful commit and push from
|
|
Panorama, the management interface SSH profile configuration was
|
|
missing or empty on Log Collectors.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-308085</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>VM-Series firewalls in Microsoft Azure environments only</tt
|
|
>) Fixed an issue where, after resizing the VM, the HA2 link became
|
|
unstable. Frequent keep-alive failures occurred, and HA2 keep-alive
|
|
packets were simultaneously transmitted to multiple destination MAC
|
|
addresses and the peer firewall's interface MAC). This issue occurred
|
|
on firewalls with Accelerated Networking enabled.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-308060</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Firewalls in active/active HA configurations only</tt
|
|
>) Fixed an issue where the BFD session went down and did not recover
|
|
even though the BGP remained in an established state, which caused the
|
|
firewall to cease route learning and advertisement with the peer, even
|
|
though BGP keep-alives were exchanged correctly.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-307901</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where a leak in decryption counters caused resource
|
|
exhaustion, which led to a GlobalProtect service outage.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-307893</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the Strata Cloud Manager (SCM) web interface
|
|
failed to fetch External Dynamic List (EDL) details from Prisma Access
|
|
and displayed the error message
|
|
<span class="ph systemoutput">Could not fetch the EDL main info</span
|
|
>. This occurred because the XML query returned an external list
|
|
authentication failed response when the EDL entry lacked a valid
|
|
certificate.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-307806</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after replacing the MPC (Management Processor
|
|
Card) on a firewall, the
|
|
<span class="ph systemoutput">logdb</span> process incorrectly wrote
|
|
logs to the root partition instead of the /opt/panlogs partition,
|
|
which led to high root partition usage and a non-functional state.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-307795</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama incorrectly generated system logs
|
|
indicating a lost connection to its peer after an upgrade even when
|
|
High Availability was not configured.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-307773</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where enabling Post-Quantum Pre-Shared Key
|
|
(PPK) within an IKE Gateway profile that was configured as a part of a
|
|
template stack failed or was inconsistent when attempted via the web
|
|
interface, even when the keys were properly configured.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-307714</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
|
insufficient i-node space was available on the sysroot0 partition.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-307702</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
|
|
issue where traffic passing through AE layer 2 interfaces was
|
|
interrupted during HA failovers.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-307597</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where BGP peering sessions between a hub firewall and a
|
|
satellite firewall over GlobalProtect LSVPN failed to connect.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-307481</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed a commit failure issue that occurred after migrating from Legacy
|
|
to Advanced routing on firewalls where an OSPF authentication profile
|
|
was configured to use a 16-character MD5 key with key-ID 10.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-307453</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue for Panorama management servers where commit push
|
|
failed when
|
|
<span class="ph systemoutput">customer_info status</span> was a
|
|
<span class="ph systemoutput">failure</span> received from the
|
|
orchestrator, which prevented the system from processing and
|
|
validating the specified telemetry region correctly during the commit.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-307072</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where SNMP interface speed reporting incorrectly
|
|
identified 5Gbps interfaces as 1Gbps interfaces during an SNMP walk.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-307066</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where static DNS entries that were configured on the
|
|
firewall failed to resolve for client machines when DNS over TLS (DoT)
|
|
was enabled on the firewall DNS proxy for both client and server
|
|
settings.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-306934</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where traffic was unexpectedly blocked due to a
|
|
misconfiguration with an empty or invalid application filter. The
|
|
firewall incorrectly interpreted the empty filter as
|
|
<span class="ph uicontrol">match all cloud-apps</span>, which caused
|
|
the traffic to be denied.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-306903</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the firewall where, after upgrading, the system log
|
|
displayed the error message
|
|
<span class="ph uicontrol"
|
|
>Last config fetch FAILED. A commit is required for userid
|
|
functionality to work.</span
|
|
>
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-306886</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the root partition on the firewall or Panorama
|
|
management server filled up due to a file leak in the logging process.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-306884</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where after changing Panorama to logger mode, commits
|
|
failed due to the
|
|
<span class="ph uicontrol">panorama-admin</span> role assigned to
|
|
plugin management configuration users.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-306533</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where system logging for NTP events was delayed by
|
|
approximately 15 minutes.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-306451</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">VM-Series firewalls on AWS environments only</tt>)
|
|
Fixed an issue where, after upgrading the firewall to an affected
|
|
release, GlobalProtect clients did not connect with IPSec and instead
|
|
connected using SSL due to traffic flow being disabled when checking
|
|
for health check packets.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-306226</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the TLS handshake did not complete and the
|
|
session did not go through. This occurred if the HTTP header insertion
|
|
applied to an HTTP CONNECT request passing through the firewall, the
|
|
scan-handshake feature was enabled, the session matched a decryption
|
|
policy rule with the decrypt action, and if the TLS client hello was
|
|
in a single packet and TLS 1.2 or below.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-306225</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the firewall where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>sslmgr</a
|
|
>
|
|
process memory utilization continually increased due to memory
|
|
fragmentation.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-306215</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where creating device groups in bulk via XML API took
|
|
significantly more time and the web interface stopped responding.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-306103</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-3400 and PA-5400 Series firewalls only</tt>)
|
|
Fixed an issue where the firewall dataplane frequently restarted when
|
|
lockless QoS was enabled
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305922</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where the CLI output for the running
|
|
configuration intermittently inserted
|
|
<span class="ph systemoutput">set template stack</span> commands
|
|
within certificate hash data.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305919</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where exporting an ML-DSA certificate with PKCS12
|
|
resulted in an error file with the message
|
|
<span class="ph systemoutput">failed to process command</span>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305874</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the firewall where the output of the CLI commands
|
|
<span class="ph systemoutput"
|
|
>show running persistent-dipp-client pool</span
|
|
>
|
|
and
|
|
<span class="ph systemoutput"
|
|
>show running persistent-dipp-pool ip-utilization</span
|
|
>
|
|
displayed incorrect information or errors. This occurred due to the
|
|
command output including data from the network control dataplane.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305835</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where firewalls with Memory Integrity Checking
|
|
Architecture enabled rebooted unexpectedly due to accessing an invalid
|
|
memory address. This occurred because the forwarding data structure
|
|
index exceeded its designed limit.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305605</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where GlobalProtect gateway authentication failed due
|
|
to the firewall incorrectly bypassing SAML.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305557</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where LSVPN (Large Scale VPN) satellites failed to
|
|
authenticate to the gateway because the portal was providing a
|
|
zeroized certificate.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305552</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where DLP logs displayed an incorrect file type when
|
|
the firewall did not set the file type field.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305549</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall's service route functionality was
|
|
impacted due to a missing service route support code.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305502</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama was unable to forward logs to a syslog
|
|
server over TLSv1.3 when configured with SSL on a custom port. The
|
|
connection was established, but logs were not forwarded due to a
|
|
failure in the CRL check.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305414</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the web interface where checkboxes displayed as text
|
|
fields for Post-Quantum Cryptography (PQC) settings and Preferred
|
|
Session Settings, which prevented users from enabling PQC features via
|
|
the web interface.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305412</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the Logging Service License Status displayed a
|
|
license failure when the license status transitioned from valid to
|
|
expired and then back to valid even when the connection to the
|
|
Security Logging Service (SLS) was working.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305411</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after creating a logical interface with an
|
|
assigned IP address and adding it to a virtual router, the connected
|
|
route for the interface did not appear in the
|
|
<span class="ph systemoutput">show routing route</span> CLI command
|
|
output. This occurred even when the interface was up and learning ARP
|
|
entries.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305374</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where the first letter of a custom URL
|
|
category was not displayed in generated reports.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305301</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the timing of GlobalProtect lifetime expiry or
|
|
inactivity logout notifications used for GlobalProtect SSL tunnels
|
|
could cause the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>pan_task</a
|
|
>
|
|
process to stop responding and the dataplane to restart.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305188</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where TLS connections failed to establish in asymmetric
|
|
routing environments if the Client Hello was split into multiple
|
|
segments and arrived out of order.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305105</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where commits involving routing related network
|
|
configuration changes experienced slower than usual completion times
|
|
or remaining at 20% completion.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304840</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where multiple firewalls experienced high management
|
|
CPU utilization after upgrading to an affected release due to repeated
|
|
index regeneration occurring every 15 minutes, which caused periodic
|
|
CPU spikes above 90%.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304756</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where, after you disabled the shared
|
|
optimization feature, a full configuration push to multi-vsys devices
|
|
caused a validation error.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304746</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Panorama appliances and Panorama virtual appliances only</tt
|
|
>) Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>configd</a
|
|
>
|
|
process restarted when committing and pushing configuration for a new
|
|
WildFire cluster.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304718</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where OSPF and BGP outages occurred due to an
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>all_task</a
|
|
>
|
|
process restart during clientless VPN content rewrite processing.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304696</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the Cloud User-ID connection timed out because
|
|
the firewall took too long to process the OCSP response.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304689</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where device group users were able to view
|
|
and commit configuration changes that had been created by Superusers
|
|
but not yet committed, even with access domains configured.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304636</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where BGP aggregate routes were not created and discard
|
|
routes were not installed in the routing table.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304576</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall entered a non-functional state due
|
|
to segmentation fault within the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>all_pktproc</a
|
|
>
|
|
process that was caused by a session that involved http2 cleartext
|
|
traffic.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304538</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where traffic logs did not populate the
|
|
<span class="ph uicontrol">Source EDL</span> or
|
|
<span class="ph uicontrol">Destination EDL</span> fields when traffic
|
|
matched a Security policy rule that used predefined external dynamic
|
|
lists.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304496</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after unregistering an IP tag and registering a
|
|
different IP tag for the same IP address via XML API, the dynamic
|
|
address group membership was not updated on the dataplane, which
|
|
resulted in Security policy rules being enforced incorrectly.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304397</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the web interface where you were unable to test the
|
|
SCP server connection for Scheduled Log Exports, and the error message
|
|
<span class="ph uicontrol">key is invalid</span> was displayed.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304229</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the Panorama web interface where you were unable to
|
|
disable <span class="ph uicontrol">Lifesize</span> (<span
|
|
class="ph uicontrol"
|
|
>Templates > Network > Network Profiles > IPSec
|
|
Crypto</span
|
|
>).
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304205</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where, after upgrading to an affected
|
|
release, a partial commit via the API did not push configuration
|
|
changes to managed firewalls, and a full commit was required to
|
|
synchronize the configuration.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304177</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the web interface became unresponsive when you
|
|
attempted to modify Security policy rule items if the source-hip or
|
|
destination-hip settings were not already configured, and the web
|
|
interface did not display a relevant error message.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304148</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where a large number of GlobalProtect users experienced
|
|
failed gateway pre-logins with the error
|
|
<span class="ph uicontrol">Failed to create SAML SSO request</span>
|
|
during peak login times.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303959</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where traffic was incorrectly identified as
|
|
unknown-tcp/unknown-udp due to App-ID resource leak and eventually
|
|
dropped.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303954</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, when configuring Safenet HSMs in HA and
|
|
authentication HSM manually, the second HSM server failed to
|
|
authenticate due to the firewall overwriting the first HSM server's
|
|
certificate with the second HSM server's certificate.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303836</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where intermittent session-table resets on the AIRS VM
|
|
triggered packet drops, which led to packet loss in egress response
|
|
traffic.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303833</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama and managed devices incorrectly
|
|
displayed warning messages that indicated that an Advanced DNS
|
|
Security license and an Advanced Threat Prevention license were
|
|
required, even when a traditional DNS Security license was installed.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303826</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where scheduled software upgrades from the Software
|
|
Change Management (SCM) server to the firewall failed with a timeout
|
|
error during download.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303791</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where configuring a service route on a loopback
|
|
interface caused intermittent connectivity issues and disrupted
|
|
traffic due to the firewall being unable to resolve domain names.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303765</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where selective pushes failed when a
|
|
scheduled job was deleted from the Panorama configuration.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303745</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where inter-dataplane forwarding did not work for
|
|
sessions ingressing on Slot 2, which resulted in intermittent ping
|
|
failures to interfaces on Network Card 2 when traffic was forwarded to
|
|
Slot 3.
|
|
</div>
|
|
<div class="p">
|
|
<b class="ph b">Note</b>: With this fix, after a slot restart, the
|
|
global counter will still show dot1q errors for a short period.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303737</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where XML API commands failed with a
|
|
<span class="ph systemoutput">Method not found (policy_xml)</span>
|
|
error in dagger.log. The issue was due to session-distribution
|
|
commands in dagger files handling.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303722</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the firewall where configuring spyware and
|
|
vulnerability profiles in Security policy rules caused a memory leak
|
|
in the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>devsrvr</a
|
|
>
|
|
process with each configuration commit.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303700</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where GlobalProtect users were incorrectly dropped by
|
|
the default Security policy rule after upgrading to PAN-OS 12.1.2 when
|
|
IPv6 firewalling was disabled. This occurred due to policy rules
|
|
configured with geographic regions matching traffic incorrectly.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303671</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where third-party clients were unable to connect to the
|
|
GlobalProtect gateway after a successful login when the username was
|
|
entered in the domain\username format.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303663</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the firewall where SolarWinds monitoring systems
|
|
reported 100% usage for
|
|
<span class="ph systemoutput"
|
|
>Slot1 Data Processor-0 Hardware Packet Buffers</span
|
|
>
|
|
due to an inaccurate reported packet buffer.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303662</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where PA-455 firewalls running PAN-OS 11.2.4-h7
|
|
intermittently failed to generate system logs and trigger an HA
|
|
failover when a link-monitored interface was unplugged, despite the
|
|
interface's status being reflected as down on the GUI.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303627</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after committing a configuration change, the
|
|
firewall experienced traffic issues,
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>pan_task</a
|
|
>
|
|
crashes, and LACP interface failures.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303508</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall failed to fetch the device
|
|
certificate during initial installation.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303487</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama appliances in FIPS-CC mode did not push
|
|
the configured values for
|
|
<span class="ph systemoutput">max-session-count</span> and
|
|
<span class="ph systemoutput">max-session-time</span> to managed
|
|
firewalls that were not in FIPS mode.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303390</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the firewall where the DNS cache capacity was set to
|
|
an incorrect value, which caused the firewall to repeatedly send DNS
|
|
requests for FQDN objects even after receiving valid responses. This
|
|
resulted in the firewall not storing DNS responses in the cache for
|
|
more than 10-15 seconds despite the minimum FQDN refresh interval
|
|
being set to a higher value.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303379</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<span class="ph systemoutput">show system resources</span> CLI command
|
|
displayed incorrect CPU usage values that did not add up to 100%.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303156</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the session timer for a custom application did
|
|
not transition from the initial 3-way handshake timer to the
|
|
application timeout when out-of-order 3-way handshake packets were
|
|
detected.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303064</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, when a new tunnel interface was added to PIM
|
|
(<span class="ph uicontrol"
|
|
>Network > Logical Router > multicast > pim >
|
|
interfaces</span
|
|
>), commits were successful, but the new tunnel interface was not
|
|
successfully added under PIM.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303051</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where a memory leak occurred related to the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>reportd</a
|
|
>
|
|
process due to retaining memory that was temporarily used for report
|
|
generation instead of releasing the memory for reuse, which resulted
|
|
in continuous accumulation and memory exhaustion.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302983</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after committing changes on Panorama, a shared
|
|
post-rule moved to the end of the
|
|
<span class="ph systemoutput">post shared rulebase</span> on the
|
|
managed device instead of remaining at the top.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302921</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<span class="ph systemoutput"
|
|
>set auth radius-require-msg-authentic yes</span
|
|
>
|
|
and
|
|
<span class="ph systemoutput"
|
|
>show auth radius-require-msg-authentic</span
|
|
>
|
|
CLI commands were unavailable on Log Collectors.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302908</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall did not forward STP frames on Layer
|
|
2 VLAN interfaces, which prevented the construction of loop-free
|
|
topologies with connected switches.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302834</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama did not display decryption logs after a
|
|
certain date due to the decryption index being purged.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302811</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
|
|
issue where network traffic was disrupted due to the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>all_pktproc</a
|
|
>
|
|
process repeatedly restarting, which caused an HA failover.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302790</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, with Sender Side Loop Detection enabled, BGP
|
|
WITHDRAWAL updates were not sent to peers after a route was removed,
|
|
which caused stale routes to persist in the BGP table of neighboring
|
|
firewalls.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302737</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where API key generation failed after renewing an
|
|
expired API certificate, and the system continued to use the expired
|
|
certificate.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302567</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where firewalls incorrectly returned the message
|
|
<span class="ph uicontrol">API Error: Success</span> with the error
|
|
code 403 instead of the correct message
|
|
<span class="ph uicontrol">API Error: Invalid Credential</span>, when
|
|
Cisco-ISE server was used for MSCHAP-PEAP Radius auth.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302564</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the firewall where a path monitoring failure
|
|
occurred and caused the dataplane to restart.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302551</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall displayed as disconnected in the SLS
|
|
due to the serial number not being retrieved
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302471</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall rebooted unexpectedly due to a
|
|
missed null pointer check when certification verification was enabled
|
|
in a no-decrypt case. This occurred when either
|
|
<span class="ph uicontrol"
|
|
>block sessions with untrusted issuers</span
|
|
>
|
|
or
|
|
<span class="ph uicontrol"
|
|
>block sessions with expired certificates</span
|
|
>
|
|
was enabled in the decryption profile.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302428</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where daily scheduled report emails for
|
|
custom reports were delivered with no content and instead incorrectly
|
|
displayed the message
|
|
<span class="ph uicontrol">No matching data found</span>. With this
|
|
fix, the content is displayed correctly.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302387</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where on PA-7500 firewalls, SNMP incorrectly reported
|
|
the administrative and operational status of High Speed Chassis
|
|
Interconnect (HSCI) interfaces as down, even when the interfaces were
|
|
physically up. Additionally, interface counters for these interfaces
|
|
displayed all zeroes.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302254</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the web interface made calls to retrieve cloud
|
|
authentication service regions even when creating a non-cloud
|
|
authentication service profile.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302196</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the dataplane stopped responding when cleaning up
|
|
expired sessions currently in MICA ATP hold mode.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302127</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Firewalls in active/active HA configurations only</tt
|
|
>) Fixed an issue where adding a 26th floating IP address to an
|
|
aggregate ethernet interface in one vsys caused IPSec tunnels on
|
|
another vsys to stop working due to rekeying. This occurred due to the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>routed</a
|
|
>
|
|
process not detecting the unchanged virtual address, uninstalling it,
|
|
and then reinstalling it, which ended the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>ikemgr</a
|
|
>
|
|
connection on the virtual address.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302085</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where network values were not displayed in Panorama
|
|
with the error message
|
|
<span class="ph uicontrol"
|
|
>There is no value for the selected item</span
|
|
>. This was due to the device group passing vsysName in Panorama.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302073</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where the override icon in
|
|
<span class="ph uicontrol">Agent Config</span> did not change to the
|
|
revert icon after reverting a configuration change in a
|
|
template-stack.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301975</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
|
|
issue where the passive firewall incorrectly triggered PBP alerts even
|
|
with low packet rates.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301965</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where enabling Advanced Routing in a
|
|
template did not work.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301912</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama stopped responding when deploying
|
|
dynamic updates to managed devices.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301848</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where websites were incorrectly categorized with high
|
|
severity alerts (<span class="ph uicontrol"
|
|
>Monitoring > URL Filtering</span
|
|
>) even though they were assessed as low risk. This occurred due to
|
|
session information being unavailable during logging.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301733</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<span class="ph systemoutput">show cloud-auth-service-regions</span>
|
|
CLI command took longer than expected to complete due to timeouts
|
|
while fetching Cloud Authentication Service (CAS) regions.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301691</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where BGP stopped responding with the error message
|
|
<span class="ph systemoutput">Too many open files</span> when pushing
|
|
1000 eBGP (External BGP) neighbor configurations. With this fix, the
|
|
number of file descriptors for the BGP process is increased from 1024
|
|
to 8192.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301653</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where DNS traffic sessions prematurely terminated with
|
|
the message
|
|
<span class="ph systemoutput">resources-unavailable</span>. This
|
|
occurred due to IPv4 fragmented DNS responses causing the Advanced DNS
|
|
Security module to incorrectly pack the DNS payload multiple times
|
|
when forwarding to the cloud for inspection.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301600</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the firewall where, after an upgrade, OSPF
|
|
adjacencies remained in the exchange state, which resulted in an
|
|
incomplete routing table.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301496</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the DNS cache capacity was insufficient for
|
|
environments with a large number of FQDN address objects, which caused
|
|
the firewall to repeatedly send DNS requests for the same FQDN objects
|
|
even after it received valid responses.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301456</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where the
|
|
<span class="ph systemoutput">debug system reset-ztp</span> CLI
|
|
command was unavailable.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301430</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the web server did not specify the content type
|
|
in the header for font files, which could allow a browser to
|
|
misinterpret the content and potentially lead to cross-site scripting
|
|
(XSS) vulnerabilities.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301409</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama failed to perform a selective push to a
|
|
managed device when device tags were added or modified on the policy
|
|
rules. The selective push failed with the error message
|
|
<span class="ph systemoutput"
|
|
>Failed to generate selective push configuration. Schema validation
|
|
failed. Please try a full push</span
|
|
>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301386</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where BFD echo packets were dropped on Vwire interfaces
|
|
due to being incorrectly detected as a land attack when the source and
|
|
destination ports of the BFD packets were different.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301305</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
|
|
issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>all_task</a
|
|
>
|
|
process stopped responding and caused the passive firewall to reboot.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301290</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the Panorama web interface where a custom
|
|
administrator with device group and template permissions was unable to
|
|
upgrade devices to non-preferred releases due to the options to
|
|
uncheck base and preferred releases not being displayed.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301222</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where DNS Security logs incorrectly displayed a
|
|
sinkhole action for benign DNS categories due to the firewall saving
|
|
the drop or sinkhole action in session flags without discarding the
|
|
session.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301186</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the Panorama web interface where
|
|
<span class="ph uicontrol"
|
|
>Enable pushing device monitoring data to Panorama</span
|
|
>
|
|
was always checked, regardless of the actual configuration.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301113</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the XML API returned the error
|
|
<span class="ph systemoutput"
|
|
>Access to this vsys is unauthorized</span
|
|
>
|
|
when generating a report for a specific vsys, even when the
|
|
administrator had access to that vsys. This was due to the API session
|
|
not correctly populating the
|
|
<span class="ph systemoutput">vsysvector</span> field with the user's
|
|
allowed vsys.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301089</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Kubernetes pod health checks failed when the
|
|
pan-fw annotation was added. When the annotation was present, health
|
|
check traffic from the host's public IP address range to the pod CIDR
|
|
range was tunneled to the firewall by the pan-cni, which resulted in
|
|
asymmetric flows and no response from the pod endpoints.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301018</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where API queries for correlated category
|
|
logs incorrectly returned a count of 0.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300922</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the syslog connection was handled by the syslog
|
|
forwarding thread.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300916</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama management servers failed to forward
|
|
syslog messages via TLS to a syslog server when DNS resolution for
|
|
IPv6 addresses failed, and the system did not automatically fall back
|
|
to IPv4.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300906</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where XML API commands failed with a
|
|
<span class="ph systemoutput">Method not found (policy_xml)</span>
|
|
error in dagger.log. The issue was due to missing XML-related
|
|
functions for inline-cloud-proxy.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300671</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where traffic reports that were generated with
|
|
destination/source and destination/source hostnames were not displayed
|
|
in IPv4 format.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300664</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the Panorama and firewall web interface where
|
|
Applications pages became unresponsive after activating the SaaS
|
|
Inline license.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300638</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
|
the firewall stopped responding due to an out-of-bounds read when
|
|
parsing TLS 1.3 clientHello messages with large TLS clientHello
|
|
extensions where the
|
|
<span class="ph systemoutput">supported_versions</span> extension fell
|
|
outside the first TCP segment.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300637</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>VM-Series firewalls on Microsoft Azure environments only</tt
|
|
>) Fixed an issue where the firewall unexpectedly rebooted due to
|
|
repeated
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>varrcvr</a
|
|
>
|
|
process restarts.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300617</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the Elasticsearch cluster status displayed as red
|
|
due to unassigned shards, which prevented logs from updating.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300612</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-7500 firewalls only</tt>) Fixed an issue where
|
|
the firewall incorrectly reported the speed of 400G interfaces as 1G
|
|
when queried using SNMP
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300555</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
|
|
issue where the HA1-A interface reported an incorrect SNMP down value
|
|
even when the interface was physically up on the active firewall.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300548</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where using the IKEv2 multiplier setting for VPN
|
|
re-authentication resulted in the firewall not re-authenticating at
|
|
the expected intervals when both sides initiated rekeying. The
|
|
internal re-authentication counter incremented when the local side
|
|
triggered the rekey, but not when the peer side triggered it.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300423</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Data Processing Cards (DPCs) installed in slots 5
|
|
and 6 remained stuck in a starting state with the error
|
|
<span class="ph uicontrol"
|
|
>Signal detected for port xeS5-DP0 but Link Down</span
|
|
>
|
|
alerts, which resulted in device instability.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300280</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, on firewalls configured as an Area Border Router
|
|
(ABR) with a backbone area (0.0.0.0) and a stub area, external Type-5
|
|
Link State Advertisement (LSA) routes were not installed in the
|
|
routing table.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300227</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall dropped packets due to the incoming
|
|
flow being hashed to a flow bucket that was full.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300216</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, when SD-WAN Direct Internet Access was
|
|
configured and traffic traversed the cellular interface without a NAT
|
|
policy rule, intermittent cellular modem connectivity issues occurred,
|
|
which caused the firewall to disconnect and reconnect to the cellular
|
|
network.
|
|
</div>
|
|
<div class="p">
|
|
To use this fix, run the CLI command
|
|
<span class="ph systemoutput"
|
|
>set session teardown-upon-fwd-zonechange yes</span
|
|
>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300186</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the GlobalProtect portal exposed the internal IP
|
|
address of the gateway when accessed via the SAML20/SP/ACS endpoint.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300138</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where DNS queries stalled or repeatedly time out due to
|
|
multiple DNS responses with different CNAME values causing evasion
|
|
false positive alerts.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300055</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall experienced high disk utilization in
|
|
the /opt/pancfg/mgmt/content-preview directory due to older content
|
|
data not being automatically removed when an error occurred during the
|
|
process.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299915</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the Elasticsearch cluster health status displayed
|
|
as red on dedicated log collectors due to an expired Elasticsearch CC
|
|
certificate, which prevented log visibility from Panorama.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299910</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where unintended ARP packets were sent out from the
|
|
dataplane interface when the service route setting for DNS was
|
|
configured to use that interface.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299785</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-7500 and PA-5450 firewalls in FIPS-CC mode</tt>)
|
|
Fixed an issue where the affected firewalls would boot into
|
|
maintenance mode when a reboot was initiated from the web interface.
|
|
This was due to a device reboot triggering a power down to all slots,
|
|
leading to maintenance mode. A hard reboot would allow the firewall to
|
|
boot normally.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299772</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>VM-Series firewalls in active/passive configurations only</tt
|
|
>) Fixed an issue where, after an HA failover event, the newly active
|
|
firewall DHCP client interfaces failed to obtain IP addresses
|
|
automatically. This occurred because the DHCP client processes did not
|
|
initiate the necessary DHCP discover or renew requests
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299757</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Router Advertisements for IPv6 were not sent at
|
|
the configured time intervals.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299751</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall was unable to connect to the
|
|
Subscription License Service (SLS) due to a public and private key
|
|
pair mismatch with the device certificate.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299738</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where excessive dataplane debug logs were generated due
|
|
to the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>pan_task</a
|
|
>
|
|
process restarting, even without any dataplane debug logs or captures
|
|
being enabled by the administrator.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299706</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall repeatedly sent DNS requests for
|
|
FQDN objects despite even after receiving valid responses.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299705</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where API calls to commit changes on Panorama
|
|
intermittently failed when using the XML API with refresh=<span
|
|
class="ph systemoutput"
|
|
>no</span
|
|
>, which caused changes to not be applied to the partial-commit
|
|
configuration.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299623</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Panorama appliances in Management Only mode only</tt
|
|
>) Fixed an issue where the firewall incorrectly allowed access to the
|
|
web interface on a blocked port. Additionally, after configuring a
|
|
custom certificate, Panorama continued to present the self-signed
|
|
certificate on the blocked port.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299622</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the MFA timestamp was not redistributed between
|
|
standalone firewalls behind an Azure load balancer after upgrading,
|
|
which resulted in users being prompted to reauthenticate multiple
|
|
times.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299615</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, when the Network Packet Broker feature was
|
|
enabled, forward TLS (non-decrypted) traffic was not working as
|
|
expected when there were segmented client hellos and a no-decrypt rule
|
|
existed. This issue occurred when Zone Protection profiles were
|
|
configured for trust/untrust zones but not attached to NPB zones.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299495</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<span class="ph systemoutput"
|
|
>show system setting ssl-decrypt certificate</span
|
|
>
|
|
CLI command did not display certificates when XML output was enabled.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299450</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where PAN-OS
|
|
<span class="ph systemoutput">logrotate</span> did not rotate large
|
|
log files until the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>cron.daily</a
|
|
>
|
|
process ran, which resulted in the root partition filling up.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299242</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall's SSL proxy sent an empty HTTP2
|
|
SETTINGS message to the client before confirming server support, which
|
|
caused some clients to incorrectly assume HTTP/2 support and not fall
|
|
back to HTTP/1.1. Additionally, the firewall dropped HTTP1.1 400 Bad
|
|
Request frames from the server, which prevented the client from
|
|
correctly detecting the lack of HTTP/2 support.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299228</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where a session process consumed excessive CPU
|
|
resources, even when Data Loss Prevention (DLP) was not enabled. This
|
|
occurred due to the active threat list being iterated twice when
|
|
active threats were present in the session.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299161</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the bytes number overflowed for a specific
|
|
application, which caused Network Monitor graphs to display an
|
|
unexpectedly large volume of traffic.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299027</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Panorama virtual appliances in Management Mode only</tt
|
|
>) Fixed an issue where a maximum configuration size of 120 was
|
|
incorrectly enforced instead of 150 MB.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298945</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where OSCP HTTP POST requests were not formatted
|
|
correctly, which caused failures with strict responders.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298929</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
|
|
issue where, after upgrading the ESXi host to version 8.0.3, the
|
|
firewall interface went down on the active firewall due to a behavior
|
|
change in ESXi 8.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298907</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on PA-VM in AWS where, in a two-arm deployment
|
|
integrated with Gateway Load Balancer (GWLB), the firewall did not
|
|
preserve the GENEVE source port for internet traffic, resulting in
|
|
increased latency. The fix ensures the firewall preserves the outer
|
|
UDP source port of GENEVE encapsulation when sending traffic back to
|
|
GWLB.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298872</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>PA-400 Series firewalls in HA configurations only</tt
|
|
>) Fixed an issue where ports went down after an HA failover.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298617</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Optimized the commit workflow to reduce the size of the effective
|
|
configuration, resulting in lower memory consumption.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298514</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where WildFire clusters operating in FIPS-CC/ Non
|
|
FIPS-CC mode were not supported in earlier PAN-OS 12.1 releases.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298460</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Panorama appliances in HA configurations on Microsoft Azure
|
|
environments only</tt
|
|
>) Fixed an issue on the web interface where the plugin versions that
|
|
were displayed when hovering the cursor over the Green Match icon were
|
|
inconsistent even though the Panorama web interface reported the
|
|
versions as matching.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298387</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the firewall where the source and destination NAT IP
|
|
addresses did not display in traffic and threat logs.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298288</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where traffic loss occurred when two aggregate ethernet
|
|
interfaces were configured as vwire with only one member link active
|
|
in the aggregate ethernet interface, which occurred due to an
|
|
incorrect logic in active port map of AE interfaces.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298279</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama administrators defined in a SAML
|
|
Identity Provider (IdP) were unable to authenticate if their username
|
|
exceeded 32 characters, and the system logs displayed the failed
|
|
authentication attempt with a truncated username.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298252</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Data Loss Prevention (DLP) inspection of chunked
|
|
transfer encoding over TLS resulted in incomplete file downloads on
|
|
Outlook Web App (OWA) due to the WIF page size limit, which led to
|
|
corrupted or incomplete PDF attachments.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298141</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall experienced recurring kernel
|
|
segfaults related to multiple processes, which led to a SIGSEGV error.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298000</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>useridd</a
|
|
>
|
|
process stopped responding after an upgrade, which led to high packet
|
|
buffer congestion and an OOM condition.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297976</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall experienced extended boot times
|
|
after a reboot due to the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>configd</a
|
|
>
|
|
process needing to rebuild the ACE catalog after detecting
|
|
discrepancies that were caused by duplicate application checking
|
|
between the ACE catalog and content.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297975</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama was unable to push the Trusted Root CA
|
|
configuration to Log Collectors via a Collector Group push due to the
|
|
Log Collector not supporting the
|
|
<span class="ph systemoutput">trusted-root-CA</span> configuration.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297972</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where a dataplane crash occurred when traffic matched
|
|
Inline Cloud Analysis prefiltering signatures, even when Inline Cloud
|
|
Analysis features were not enabled.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297963</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where PA-400 Series firewalls were not properly caching
|
|
DNS responses for FQDN objects. The firewall was observed to
|
|
repeatedly send DNS requests for the same FQDN objects every 10-15
|
|
seconds, even after receiving valid responses, despite the minimum
|
|
FQDN refresh interval being set to a much higher value. This resulted
|
|
in excessive DNS queries originating from the firewall's management
|
|
interface.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297819</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall was unable to send device telemetry
|
|
files to Cortex Data Lake due to the firewall receiving an invalid
|
|
upload token.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297796</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where the policy review feature in
|
|
<span class="ph uicontrol">Dynamic Updates</span> failed to display
|
|
Security policy rules when the device group was set to
|
|
<span class="ph uicontrol">All</span>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297782</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where reassociating a vsys from one device
|
|
group to another in a multi-vsys environment resulted in another vsys
|
|
from the same firewall being removed from the original device group.
|
|
This resulted in the device being moved into the
|
|
<span class="ph uicontrol">no device groups attached</span> group, a
|
|
superuser was required to manually reattach the device.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297774</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the web interface where the TLS Version was
|
|
misspelled as <span class="ph uicontrol">TLS Vesrion</span> (<span
|
|
class="ph uicontrol"
|
|
>Device > Server Profiles > Email</span
|
|
>).
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297761</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall incorrectly categorized some URLs as
|
|
not-resolved due to a conflict with Top Level Domain (TLD) data
|
|
handling in the PAN-DB URL cloud. This affected URLs under domains
|
|
marked as TLDs, which the firewall incorrectly assumed did not have
|
|
any category.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297759</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on PA-7500 firewalls running in a cluster where
|
|
sub-interfaces were not discoverable via SNMP, which prevented proper
|
|
monitoring and statistics collection for sub-interfaces using
|
|
SNMP-based tools.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297749</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the redistribution agent status was blank on the
|
|
web interface on both the firewall and Panorama, even though the CLI
|
|
showed the agent as connected.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297610</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall became unresponsive after an upgrade
|
|
due to the <span class="ph systemoutput">fsck</span> command scanning
|
|
drive partitions in parallel with the root partition, which caused the
|
|
process to take an extended amount of time.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297609</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the CLI command
|
|
<span class="ph systemoutput"
|
|
>debug user-id refresh user-id agent all</span
|
|
>
|
|
failed with the error message
|
|
<span class="ph systemoutput"
|
|
>Invalid agent name. Agent name should be 1 to 31 characters
|
|
long.</span
|
|
>
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297540</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Panorama managed firewalls in HA configurations only</tt
|
|
>) Fixed an issue where the HA-Link-Monitor configuration pushed from
|
|
Panorama was converted to a local configuration on the peer device
|
|
after an HA sync, which caused subsequent Panorama pushes of link
|
|
monitor changes to be flagged as overwritten, and a forced template
|
|
push or manual clearing of the configuration on the firewall was
|
|
required.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297370</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where pushing a new object from Panorama to a Cloud
|
|
NGFW Device Group unexpectedly removed existing Panorama-pushed policy
|
|
rules, even though the
|
|
<span class="ph uicontrol">Push Preview</span> did not show any
|
|
deletions, which led to traffic disruptions.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297321</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Firewalls in active/active HA configurations only</tt
|
|
>) Fixed an issue where return packets from a phone gateway looped
|
|
between the HA pair instead of being encapsulated into the
|
|
GlobalProtect tunnel. This occurred when the inner session and the
|
|
outer IPSec tunnel terminated on different nodes, which led to
|
|
excessive retries and packet drops.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297320</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Panorama virtual appliances only</tt>) Fixed an
|
|
issue where scheduled configuration exports failed with an
|
|
<span class="ph systemoutput">invalid key</span> error when connecting
|
|
to a SCP server using non-default SCP port. Also, additional CLIs were
|
|
added to delete the known-hosts file.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297263</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-5220 firewalls only</tt>) Fixed an issue where
|
|
the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>ikemgr</a
|
|
>
|
|
process crashed intermittently, which caused IPSec tunnels to go down
|
|
randomly. With this fix, the IKE Security association data structures
|
|
are accessed in a thread-safe manner, and the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>ikemgr</a
|
|
>
|
|
process does not reference an invalid memory pointer during teardown
|
|
operations.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296977</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the web interface became unresponsive when
|
|
attempting to view
|
|
<span class="ph uicontrol">Ethernet</span> interface details after
|
|
applying a filter in
|
|
<span class="ph uicontrol">Network > Interfaces</span>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296752</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-1410 Firewalls only</tt>) Fixed an issue where
|
|
the firewall experienced high management CPU usage and repeatedly
|
|
rebooted when attempting to retrieve SMART data.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296749</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where email alerts sent from the firewall were marked
|
|
as spam due to the EHLO header containing only the firewall hostname
|
|
and not the fully qualified domain name (FQDN).
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296694</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall rebooted due to the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>useridd</a
|
|
>
|
|
process repeatedly restarting during an IP-port data type writes to
|
|
the redis from multiple sources such as TSA or XML in a scale
|
|
environment.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296666</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Prisma Access gateways did not pass usernames to
|
|
the WildFire portal, which caused the
|
|
<span class="ph uicontrol">Recipient User ID</span> to display as
|
|
<span class="ph uicontrol">unknown</span> on
|
|
wildfire.paloaltonetworks.com, even when the username was present in
|
|
the gateway logs.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296616</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, when a PBF policy rule with a monitoring profile
|
|
was configured, the intermediate firewall dropped the PBF monitoring
|
|
traffic, which caused the PBF rule to remain disabled on the local
|
|
firewall.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296598</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where EAL logs were not forwarded to the IoT Security
|
|
dashboard when the proxy server password contained special characters.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296535</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the firewall where BGP peers disconnected when more
|
|
than 500 BGP neighbors were configured in a single Logical Router
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296519</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where a stream receiving a reconnect signal with an
|
|
associated error in
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>Wifclient</a
|
|
>
|
|
caused the entire pool to close, which resulted in a complete
|
|
disconnection.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296443</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
|
|
the firewall had a lower maximum capacity for DIPP translated IP
|
|
addresses than the PA-5260, which caused configuration commit errors
|
|
during migration. With this fix, the maximum capacity on PA-5450
|
|
firewalls has been increased to 8000.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296397</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the Panorama web interface where previewing changes
|
|
after a commit to shared objects were not accurately displayed in the
|
|
push scope.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296283</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, on hardware platforms with the SaaS inline
|
|
license, Additional Header Logging (AHL) hash table creation proceeded
|
|
even when the feature was disabled through the CLI, potentially
|
|
leading to crashes.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296224</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Firewalls in active/active HA configurations only</tt
|
|
>) Fixed an issue where adding a 26th floating IP address to an
|
|
aggregate interface on one vsys caused IPSec tunnels in another vsys
|
|
to stop working due to rekeying issues.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296208</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall did not accept address groups in the
|
|
filter condition of a Log Forwarding Match list.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296206</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall incorrectly routed external Type-5
|
|
Link State Advertisements (LSAs) within a stub area when the firewall
|
|
was configured as an Area Border Router (ABR) in a stub area and
|
|
learned about an external prefix from another ABR connected to the
|
|
backbone area.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296202</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Firewalls in active/active HA configurations only</tt
|
|
>) Added a log enhancement to capture an issue where, when a commit
|
|
operation was in progress, newly deployed IP address tags that used
|
|
the XML API were not immediately reflected in address group
|
|
resolution, which delayed IP address mapping to address groups and
|
|
caused traffic to be incorrectly allowed or denied.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296020</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where commit operations failed during phase 1 when
|
|
configuring a non-default value for the Graceful Restart Hello Delay
|
|
due to an FRR parse error if the configured value was between 1 and 9.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295958</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where multicast output interfaces (OIFs) were missing
|
|
for up to 5 minutes after an HA failover or routing process restart,
|
|
which impacted new multicast sessions. This occurred due to an age-out
|
|
process triggered by unicast graceful restart conditions.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295951</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on firewalls in active/passive HA configurations where
|
|
CLI outputs incorrectly included XML formatting.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295950</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the output for some CLI commands incorrectly
|
|
included XML formatting.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295899</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where DNS resolution failed on Linux machines running
|
|
GlobalProtect client version 6.2.6 when connected with DNS Security
|
|
enabled. This occurred because the firewall incorrectly discarded DNS
|
|
packets when processing multiple DNS requests or responses over the
|
|
same session, even when no malicious verdict was received.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295854</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall generated two URL logs for a single
|
|
session.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295838</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on IKEv1 tunnels where, if the peer IKE gateway was
|
|
unreachable, the IKE Phase-1 Security association (SA) was not cleared
|
|
by DPD until Phase-2 rekeying occurred or until it was manually
|
|
cleared via the CLI because the DPDs were not sent accurately
|
|
according to the configured interval due to a miscalculation of the
|
|
DPD timer. This resulted in the tunnel taking longer than expected to
|
|
recover.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295803</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Addressed a memory leak issue under sc3 and automatic commit recovery
|
|
(ACR) code path.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295802</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where a memory leak related to the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>configd</a
|
|
>
|
|
process occurred.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295796</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall intermittently failed to forward
|
|
VXLAN GARP packets, which led to connectivity issues for wireless
|
|
clients in environments that used VXLAN tunnels for wireless access
|
|
points.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295766</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">VM-Series firewalls in HA configurations only</tt>)
|
|
Fixed an issue where Panorama displayed incorrect packet buffer values
|
|
on the web interface and the CLI.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295728</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where configuring an OSPFv2 NSSA area range caused
|
|
OSPF-learned routes to become unreachable due to the incorrect
|
|
installation of a discard route when the NSSA range prefix matched an
|
|
existing OSPF route.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295662</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama displayed the URL instead of the file
|
|
name for vulnerability threat logs fetched from the Logging Service.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295644</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Strata Logging Service (SLS) log forwarding
|
|
streams intermittently displayed as inactive.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295586</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after committing changes to a Certificate
|
|
Profile or other global configurations without any making changes to
|
|
the virtual system (vsys), the Data Redistribution include/exclude
|
|
lists were ignored on the firewall. This resulted in the firewall
|
|
receiving and processing User-ID information from all sources.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295578</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where GlobalProtect HIP data file download and
|
|
installation failed with the error message
|
|
<span class="ph systemoutput"
|
|
>An error occurred while processing request. Please try again after
|
|
some time or contact support</span
|
|
>
|
|
or <span class="ph systemoutput">No ETAG from response</span> due to a
|
|
script exiting prematurely.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295470</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the firewall where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>useridd</a
|
|
>
|
|
process continuously increased its memory consumption, which resulted
|
|
in an OOM condition that caused the firewall to restart.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295421</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the CLI command outputs incorrectly included XML
|
|
formatting tags.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295385</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where syslog forwarding dropped due to FQDN resolution
|
|
failures.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295257</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after onboarding a firewall to Panorama, IPsec
|
|
tunnels displayed IKEv2 in Panorama, even though the tunnels were
|
|
configured with IKEv1 locally on the firewall.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295245</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>useridd</a
|
|
>
|
|
process stopped responding because the client was unavailable.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295240</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the source user field was intermittently missing
|
|
in traffic logs, even when the IP address-to-user mapping was
|
|
available. This occurred due to a race condition where the log
|
|
generation process preceded the creation of the IP address-to-user
|
|
mapping.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295221</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after upgrading Panorama and Log Collectors from
|
|
PAN-OS 10.2.9 to PAN-OS 11.1.6-h6, Traffic and Threat logs were not
|
|
forwarded to a Splunk server over UDP.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295185</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue where
|
|
a custom administrator role with the permission
|
|
<span class="ph uicontrol">Network > QoS (Read Only)</span> was
|
|
unable to create a QoS profile, even when the
|
|
<span class="ph uicontrol">Policies > QoS (Enabled)</span> and
|
|
<span class="ph uicontrol"
|
|
>Network Profiles > QoS Profile (Enabled)</span
|
|
>
|
|
permissions were also set.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295095</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, when you used a syslog forwarding profile with
|
|
the CEF format, an additional string was appended to the end of the
|
|
log message when viewing the log entry from the Universal Forwarder
|
|
directory.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-294893</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where firewalls with the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>Send handshake messages to CTD for inspection</a
|
|
>
|
|
setting enabled caused incorrect security policy rules to be matched
|
|
during the TLS handshake. Additionally, the expected response page for
|
|
blocked URLs was not displayed.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-294770</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Firewalls in active/passive HA configurations</tt>)
|
|
Fixed an issue on firewalls where, after failover, certain subnets
|
|
were missing from the Link State Database, which prevented OSPF routes
|
|
from being immediately learned due to a Type-7 to Type-5 LSA
|
|
translation conflict in the ABR when the same LSA was advertised by
|
|
two peers in the NSSA area.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-294524</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where firewalls and Panorama management servers were
|
|
unable to view or download WildFire reports from a WF-500 appliance,
|
|
resulting in a 401 error in the report tab.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-294434</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where memory leaks occurred. These leaks were caused by
|
|
two distinct scenarios: the failure to deallocate memory for a nodeset
|
|
when a new nodeset was assigned to the same variable, and the failure
|
|
to free a UUID hash table during error conditions.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-294307</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where a
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>configd</a
|
|
>
|
|
SIGSEGV crash occurred when renaming objects within policy rules,
|
|
objects, or zones.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-294191</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where BGP did not generate a system log when the number
|
|
of prefixes received from a peer exceeded the configured threshold,
|
|
even with the Address Family Identifier and Peer Group settings
|
|
configured to trigger a warning.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-294179</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where viewing, refreshing, and comparing config
|
|
versions in <span class="ph uicontrol">Config Audit</span> caused the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>configd</a
|
|
>
|
|
process to stop responding. If the page loaded successfully, some
|
|
commit versions displayed incorrect or missing data.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-294161</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall rebooted unexpectedly due to the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>useridd</a
|
|
>
|
|
process restarting and causing an HA failover. This occurred due to
|
|
the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>configd</a
|
|
>
|
|
process timing out when running the CLI command
|
|
<span class="ph systemoutput">show user user-id-agent config all</span
|
|
>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-294123</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall removed all Infrastructure and Audit
|
|
logs, as well as <span class="ph systemoutput">logdb</span> and search
|
|
engine quotas, when the configured retention period was reached
|
|
instead of only removing logs older than the configured retention
|
|
period.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-294001</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama managed firewalls generated
|
|
<span class="ph uicontrol">Failed in get_pwchange_required</span>
|
|
error messages in the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>authd</a
|
|
>
|
|
logs for local administators.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293879</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the firewall where the VM monitor source remained in
|
|
the <span class="ph uicontrol">Getting All</span> status, which
|
|
prevented dynamic address groups from updating IP addresses for new
|
|
EC2 instances. This issue occurred due to a race condition where two
|
|
threads that simultaneously retrieved IP address tag information from
|
|
AWS VM monitoring sources became stuck while reading the XML file.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293858</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the file URL was not displayed on SCM LogViewer
|
|
when a file was downloaded. This issue affected logs with a subtype of
|
|
'file'.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293848</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama failed to push the default value of
|
|
<span class="ph uicontrol">None</span> for the secondary NTP server
|
|
address to managed firewalls, resulting in a commit validation error.
|
|
This occurred even when configuring the secondary NTP server address
|
|
as <span class="ph uicontrol">None</span> in Panorama's web interface,
|
|
and affected both newly deployed and long-standing production
|
|
firewalls after upgrading.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293847</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where EAL logs for traffic matching the
|
|
intrazone-default security rule were not forwarded to the IoT Security
|
|
portal.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293840</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the Panorama web interface where SNMP settings
|
|
configured in Panorama templates were incorrectly displayed as locally
|
|
configured.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293825</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where packets with bad TCP checksums were transmitted
|
|
even when the
|
|
<span class="ph systemoutput">Strict TCP/IP checksum</span> option was
|
|
enabled.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293708</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>configd</a
|
|
>
|
|
process stopped responding when a partial revert operation was
|
|
performed on a newly added rule in a rulebase that was empty in the
|
|
running configuration.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293686</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where importing a device state file was incorrectly
|
|
allowed during an existing commit job.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293561</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where users with a custom role-based administrator role
|
|
were unable to download the GlobalProtect client application via the
|
|
web interface even when the
|
|
<span class="ph uicontrol">GlobalProtect Client</span> option was
|
|
enabled in the admin role profile.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293297</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where a full push to device groups was
|
|
initiated instead of a selective push when using
|
|
<span class="ph uicontrol">Commit and Push Changes Made By</span> in
|
|
the commit and push.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293281</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the reported throughput and packet rate were
|
|
higher than the actual interface traffic due to a double counting
|
|
error.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293141</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue where
|
|
the web interface did not display the commit button for a custom
|
|
administrator when changes were made to a template while a device
|
|
group push was pending.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-292752</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where a command injection vulnerability could occur due
|
|
to improper input sanitization.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-292580</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue where
|
|
the software deployment validation process did not display the
|
|
required software version for dedicated log collectors (DLCs), and
|
|
downloading software images to multiple DLCs failed.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-292529</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where HA configuration synchronization failed between
|
|
HA firewalls due to an empty interface node present only in the
|
|
passive firewall's running-config.xml file.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-292447</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama did not display data in the
|
|
<span class="ph uicontrol">Feature Adoption</span> tab in Strata Cloud
|
|
Manager due to the system creating and deleting a CLI user for each
|
|
interval instead of reusing a permanent CLI user for telemetry.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-292306</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>authd</a
|
|
>
|
|
process stopped handling RADIUS authentication requests and required a
|
|
restart.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-292285</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Firewalls in active/passive HA configurations only</tt
|
|
>) Fixed an issue where network outages of approximately 30 seconds
|
|
occurred after a failover due to a delay in establishing the BGP
|
|
connection between the new active firewall and one of its peers and a
|
|
second delay in advertising prefixes learned from the firewall to
|
|
another peer.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-292242</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on M-200 and logging appliances where traffic logs were
|
|
intermittently truncated when forwarded using a TCP syslog
|
|
configuration. This issue occurred during the log forwarding stage due
|
|
to intermittent syslog drops caused by exceeding the forwarding queue
|
|
capacity.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-292220</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the Status LED on PA-7500 SFCs did not work.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-292079</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue where
|
|
the data on scheduled SaaS Application Usage Reports was different
|
|
than the data on on-demand reports generated via
|
|
<span class="ph uicontrol">Run Now</span>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-292019</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the Panorama web interface where cloud applications
|
|
were not displayed under
|
|
<span class="ph uicontrol">Objects > Applications</span> after a
|
|
new content upgrade and Cloud App Catalog download, and were only
|
|
visible in application groups, security policy rules, and the CLI.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291984</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where SSH/SFTP traffic was intermittently blocked by
|
|
URL filtering due to the firewall incorrectly applying URL categories
|
|
from previous sessions.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291940</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall established multiple TCP connections
|
|
to a syslog server, which caused logs to be dropped. This occurred
|
|
because the firewall established a new TCP session for each transfer
|
|
and the sessions were not closed, which resulted in a continuous
|
|
increase in connections over time.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291915</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the firewall where the PDT process experienced a
|
|
memory leak due to frequent dumping of fabric traffic statistics,
|
|
which resulted in high CPU utilization and instability.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291792</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-7050 firewalls on vwire instances only</tt>)
|
|
Fixed an issue where Bidirectional Forwarding Detection (BFD) echo
|
|
packets were dropped due to the firewall dropping packets with the
|
|
same source and destination IP addresses.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291706</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the software tag descriptor was always at 100,
|
|
which led to resource unavailability errors and prevented users from
|
|
obtaining DHCP IP addresses.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291660</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall incorrectly reported the speed of
|
|
25G interfaces as 1G when queried using SNMP for the ifHighSpeed OID.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291650</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall rebooted unexpectedly due to an OOM
|
|
condition.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291631</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
|
the firewall frequently rebooted.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291273</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where a PA-VM-Flex firewall in an air-gapped
|
|
environment failed to install the license when bootstrapping after a
|
|
factory reset when the ISO image contained a PAN-OS image.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291247</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where checksum values changed when downloading files
|
|
through TFTP on firewalls using subinterfaces.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291174</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Real Time Streaming Protocol (RTSP) video streams
|
|
did not work when connected through GlobalProtect due to the firewall
|
|
blocking 200 OK responses. This occurred because of incorrect NAT
|
|
translations for the 200 OK message from the server.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291067</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>devsrvr</a
|
|
>
|
|
process periodically exceeded its virtual memory limit and restarted,
|
|
which led to intermittent outages.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291009</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after a web server returned a 401 or 403 error,
|
|
the firewall was unable to decrypt HTTP/2 traffic, and the firewall
|
|
rejected all subsequent streams from the client.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-290954</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the web server used a low HTTP Strict Transport
|
|
Security (HSTS) max-age value of 86400 seconds for the
|
|
log.query.expression.js.php page.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-290948</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the proxy hid the Cache-Control header, which
|
|
prevented context switching.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-290938</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where multiple memory leaks occurred related to the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>configd</a
|
|
>
|
|
process.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-290851</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the Agent User Override Key was incorrectly
|
|
available for configuration on Panorama management servers when
|
|
running in FIPS-CC mode.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-290783</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<span class="ph systemoutput">debug dataplane nat sync-ippool</span>
|
|
command may not accurately account for all allocated ports or
|
|
display/sync leaks when multiple NAT rules use the same IP pool. This
|
|
could result in inaccurate reporting of leaked ports. The fix modifies
|
|
the implementation to directly compare the original pool against the
|
|
temporary pool across all vsys.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-290757</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the user, region, and external IP address were
|
|
reported as unknown in the AppSec logs due to an incorrect packet
|
|
adjust logic.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-290728</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where modifying an interface IP address on an existing
|
|
vsys caused a default <span class="ph uicontrol">vsys1</span> to be
|
|
created, which led to commit failures due to the maximum supported
|
|
number of vsys being reached.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-290681</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama and Panorama managed firewalls where
|
|
template settings reverted during a device group push when
|
|
<span class="ph uicontrol">Include Device and Network Templates</span>
|
|
was checked, even if no changes were made to the template. This caused
|
|
the SAML IDP server profile certificate to revert to an older, invalid
|
|
certificate, and resulted in GlobalProtect users being unable to
|
|
authenticate via SAML.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-289852</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where websites did not load when accumulation proxy was
|
|
enabled.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-289826</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where a selective push of policy rule
|
|
changes to a firewall caused the firewall to lose its Security policy
|
|
rules.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-289736</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where partial-revert operations were taking a long
|
|
time, causing config lock timeout issues and resulting in frequent
|
|
error messages being displayed:
|
|
<span class="ph uicontrol"
|
|
>Timed out while getting config lock. Please try again.</span
|
|
>
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-289706</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>authd</a
|
|
>
|
|
process crashed intermittently on VM-Series firewalls due to
|
|
authentication sequence failures. The crashes occurred during memory
|
|
management operations within a library while releasing memory to its
|
|
central cache.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-289578</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama managed firewalls where the source user,
|
|
source device vendor, source MAC address, and OS version information
|
|
were not visible in traffic logs and SCM when the user and device
|
|
access control lists were empty.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-289413</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where dataplane interfaces went down and configurations
|
|
were lost after a reboot.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-289383</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the MPLS interface eth1/6 went down and remained
|
|
down, even after replacing the SFP with a supported one and adjusting
|
|
duplex and speed settings.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-289067</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after upgrading Panorama in a High Availability
|
|
(HA) pair, the configuration logs stopped synchronizing from the
|
|
primary Panorama to the secondary Panorama. This issue occurred
|
|
because the log forwarding flag was permanently disabled due to the
|
|
connection state not being active when the
|
|
<span class="ph systemoutput">log-fwd-ctrl</span> message was
|
|
received.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-288938</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the Panorama web interface where the search bar
|
|
suddenly was not displayed, or the filter/clear filter icon moved to
|
|
the left of the search bar.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-288869</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where custom administrators with visibility into
|
|
specific vsys logs were able to view logs for all vsys.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-288388</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after an EDL certificate update or repository
|
|
migration, authentication failures caused the firewall to not fall
|
|
back to the last successfully cached EDL entries, which led to policy
|
|
rules that referenced the EDL to not be enforced.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-288175</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Addressed a stack buffer overflow memory leak under plugin management
|
|
code path.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-288141</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<span class="ph systemoutput">debug data-plane sync ippool</span> CLI
|
|
command did not work for Per Destination IP Pool (PDIPP) and caused a
|
|
memory leak.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-288139</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall incorrectly identified ports as
|
|
leaking when the session was not active even though the ports were
|
|
allocated.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-287599</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the prefix value for a BGP neighbor caused the
|
|
firewall to leak routes to a different BGP peer.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-287581</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Firewalls in active/passive HA configurations only</tt
|
|
>) Fixed an issue where the firewall did not process and transmit HA
|
|
path monitoring probes received from another HA cluster when the
|
|
firewall acted as a gateway for internal monitoring IP addresses used
|
|
in the HA path monitoring group, which caused HA flapping due to path
|
|
monitoring failures.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-287387</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where API jobs failed with the error
|
|
message
|
|
<span class="ph systemoutput"
|
|
>Server error: Timed out while getting config lock</span
|
|
>. This occurred due to slow set request performance when setting a
|
|
large number of address objects in a single set call.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-287086</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where PA-3420 firewalls experienced unexpected reboots
|
|
due to the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>all_task_7</a
|
|
>
|
|
process crashing with signal 6, leading to a non-functional state.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-287035</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, when an application stopped responding, a large
|
|
file was created in the /opt/panlogs directory, which caused the
|
|
partition to fill up.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-287034</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where sequence numbers were skipped for all types of
|
|
logs on the firewall due to audit logs being generated but not written
|
|
to disk when Audit Tracking was enabled.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-285758</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall web interface became unresponsive
|
|
while adding a description that contained 1062 bytes of character data
|
|
in a Security policy rule instead of displaying an error message when
|
|
the description exceeded the maximum allowed length.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-285672</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama managed firewalls where CLI commands to
|
|
convert a LSVPN to Serial Number and IP address authentication were
|
|
not applied if the GlobalProtect portal name contained a space.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-285213</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where proxy requests for certificate status (OCSP/CRL)
|
|
from
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>sslmgr</a
|
|
>
|
|
contained incorrect values that caused unknown certificates to be
|
|
blocked.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-285208</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall did not automatically recover after
|
|
a machine check exception (MCE) occurred.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-285181</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the wifclient was not configured to utilize the
|
|
GOMEMLIMIT feature.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-285169</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where Kerberos superusers were unable to
|
|
edit policy rules because the target device tab was grayed out.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-283704</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the PAN-OS DoS protection feature by default
|
|
blacklisted specific IP addresses, which caused outbound traffic
|
|
domain resolution to fail for clusters.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-283311</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where log forwarding to all syslog servers failed if
|
|
one syslog server that used TLS as the protocol became unreachable.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-283237</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where traffic logs incorrectly displayed the action as
|
|
<span class="ph uicontrol">allow</span> for traffic matching a
|
|
Security policy rule configured with the action set to
|
|
<span class="ph uicontrol">deny</span>. This issue occurred due to the
|
|
child session being used for policy rule lookup when a configuration
|
|
update triggered a rematch if the FTP-data application was not in the
|
|
rule.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-283101</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
|
|
issue where the
|
|
<span class="ph systemoutput">show wildfire status</span> CLI command
|
|
displayed an incorrect maximum file size of 4 KB for WildFire script
|
|
uploads even though the configured value was different.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-283053</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall experienced high disk space
|
|
utilization, which caused the firewall to become non-functional.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-282956</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on firewalls running PAN-OS 11.1 and later PAN-OS
|
|
releases where the portal and gateway configuration view did not
|
|
display rows and columns.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-282687</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where performing a selective revert of
|
|
configuration changes resulted in all configuration changes being
|
|
reverted.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-281721</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall generated high-severity system
|
|
alerts indicating that the configuration size exceeded the maximum
|
|
recommended size, even when the configuration size was within the
|
|
expected limits.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-281588</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where packet buffer depletion occurred due to the a
|
|
high number of
|
|
<span class="ph systemoutput">tcp_pkt_queued</span> packets when Jumbo
|
|
was enabled.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-281371</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Added an enhancement to the
|
|
<span class="ph systemoutput">show interface cellular</span> CLI
|
|
command to display all required information.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-280536</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where firewalls that were connected to the same Cloud
|
|
Identity Engine displayed inconsistent group membership information,
|
|
with some firewalls showing only a subset of users belonging to a
|
|
group. This occurred due to a full or incremental group sync failure.
|
|
</div>
|
|
<div class="p">
|
|
This fix introduces a retry mechanism for failed group queries to the
|
|
Cloud Identity Engine. To use this feature, run the following CLI
|
|
commands.
|
|
</div>
|
|
<div class="p">
|
|
To enable the retry mechanism:
|
|
<span class="ph systemoutput">debug user-id dscd retry-enable on</span
|
|
>.
|
|
</div>
|
|
<div class="p">
|
|
To set the retry time:
|
|
<span class="ph systemoutput"
|
|
>debug user-id dscd retry-time set-time <1-10></span
|
|
>. The default value is 5 seconds.
|
|
</div>
|
|
<div class="p">
|
|
To set the number of retry attempts:
|
|
<span class="ph systemoutput"
|
|
>debug user-id dscd retry attempts set-attempts <3-10></span
|
|
>. The default value is 5 attempts.
|
|
</div>
|
|
<div class="p">
|
|
To disable the retry mechanism:
|
|
<span class="ph systemoutput"
|
|
>debug user-id dscd retry-enable off</span
|
|
>.
|
|
</div>
|
|
<div class="p">
|
|
Additionally, a system log is now generated when a group sync fails,
|
|
and you are able to monitor the group sync status with the following
|
|
CLI commands:
|
|
</div>
|
|
<ul class="ul">
|
|
<li class="li">
|
|
<span class="ph systemoutput"
|
|
>show user group count list cloud-identity-engine</span
|
|
>
|
|
</li>
|
|
<li class="li">
|
|
<span class="ph systemoutput"
|
|
>show user group count name <group_name></span
|
|
>
|
|
</li>
|
|
</ul>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-279552</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where configuring a custom vulnerability object
|
|
signature condition failed to commit when the
|
|
<span class="ph uicontrol">negate</span> option was disabled on the
|
|
condition, and changes made to a custom vulnerability object were
|
|
successfully committed to Panorama but not pushed to the firewall.
|
|
This occurred when a vulnerability object contained two signatures.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-278288</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where IPv6 BGP peering established between virtual
|
|
routers even without dataplane connectivity. This occurred because the
|
|
firewall used the kernel for lookups instead of the dataplane. The CLI
|
|
set system setting loopback-workaround enable is mandatory then for
|
|
this lookup to be forced.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-277178</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where you were unable to delete a shared
|
|
object due to the rulebase incorrectly referencing the shared object
|
|
instead of the device group-specific object when the name was used.
|
|
</div>
|
|
<div class="p">
|
|
To use this fix, delete the original shared object after cloning it to
|
|
a device group with the same name.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-276745</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where GlobalProtect clients on Windows endpoints sent
|
|
an empty cookie to the gateway after a user logged out of the Windows
|
|
machine or rebooted. This triggered a full re-authentication instead
|
|
of using the existing authentication cookie, which resulted in the
|
|
generation of a new authentication cookie upon each login.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-275050</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the Japanese translation for the URL filtering
|
|
option to add a trailing slash to entries and the device license
|
|
status error was incorrect.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-274484</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where commits failed when
|
|
<span class="ph uicontrol">Data Services</span> was in a Service route
|
|
configuration was configured with the
|
|
<span class="ph uicontrol">MGMT</span> interface.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-274333</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the Logging Service License Status displayed as
|
|
red even though a valid license was installed on the firewall.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-273195</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall did not log the correct NAT IP
|
|
address and source zone for HTTP2 traffic with SSL decryption enabled
|
|
on RNHP nodes.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-273158</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-7000 Series firewalls only</tt>) Fixed an issue
|
|
where an incorrect ASIC configuration caused silent packet drops or
|
|
application slowness when receiving a mix of jumbo and non-jumbo
|
|
packets.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-272605</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall did not display VPC endpoints when
|
|
there was a large amount of VPC endpoints to interface mappings.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-272175</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where session rematch caused ACE cloud application
|
|
traffic to match the wrong policy.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-267965</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Firewalls on Amazon Web Services (AWS) environments only</tt
|
|
>) Fixed an issue where newly bootstrapped firewalls sent an
|
|
incorrect, non-DHCP-assigned hostname to the SNMP server. This
|
|
occurred because the SNMP process referred to a configuration file
|
|
that was not updated due to a missing configuration commit.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-267450</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>reportd</a
|
|
>
|
|
process stopped responding with a SIGSEGV at
|
|
<span class="ph systemoutput">schedule_report_es_response</span>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-264349</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the Management Processor Card (MPC) on modular
|
|
firewalls became unresponsive when a disk drive entered a low-power
|
|
state and failed to wake up.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-259853</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, when the DHCP server was enabled for
|
|
GlobalProtect, the commit error message was not properly displayed
|
|
when <span class="ph uicontrol">Any</span> was selected as the source
|
|
interface in the service router configuration (<span
|
|
class="ph uicontrol"
|
|
>Device > Setup > Service > Service Router
|
|
Configuration</span
|
|
>).
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-257195</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-5400 Series firewalls only</tt>) Fixed an issue
|
|
where the mp-monitor logs did not print disk SMART data.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-248913</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the Elasticsearch client certificate was not auto
|
|
renewed, which caused it to enter a Red state, and logs were not
|
|
displayed in Panorama.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-242952</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where high SSL traffic depleted flex memory, which
|
|
prevented the firewall from revalidating SSLVPN client CAs during
|
|
configuration pushes.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-241953</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall did not have a heartbeat mechanism
|
|
for the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>authd</a
|
|
>
|
|
process, which caused the firewall to become unresponsive if the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>authd</a
|
|
>
|
|
process stopped responding.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-185731</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall was unable to parse the URL path and
|
|
host when the host header was located in a different packet, which
|
|
resulted in the firewall not logging the URL path in the first packet.
|
|
</div>
|
|
<div class="p">
|
|
The fix is disabled by default. The following CLI commands can be used
|
|
to enable/disable the feature:
|
|
<ul id="panos-addressed-issues-12.1.5_ul-eql_d5r_t3c" class="ul">
|
|
<li class="li">
|
|
<span class="ph userinput"
|
|
>set system setting ctd url-crosspkt-host-path-caching
|
|
enable</span
|
|
>
|
|
</li>
|
|
<li class="li">
|
|
<span class="ph userinput"
|
|
>set system setting ctd url-crosspkt-host-path-caching
|
|
disable</span
|
|
>
|
|
</li>
|
|
<li class="li">
|
|
<span class="ph userinput"
|
|
>set system setting ctd url-crosspkt-host-path-caching
|
|
default</span
|
|
>
|
|
</li>
|
|
</ul>
|
|
set system setting ctd url-crosspkt-host-path-caching enable set
|
|
system setting ctd url-crosspkt-host-path-caching disable set system
|
|
setting ctd url-crosspkt-host-path-caching default
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|