301 lines
9.6 KiB
HTML
301 lines
9.6 KiB
HTML
<table class="table colsep rowsep table-striped">
|
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
|
|
|
<colgroup>
|
|
<col style="width: 25%" />
|
|
<col style="width: 75%" />
|
|
</colgroup>
|
|
<thead class="thead">
|
|
<tr class="row rowsep">
|
|
<th class="entry">
|
|
<div class="p"><b class="ph b">Issue ID</b></div>
|
|
</th>
|
|
<th class="entry">
|
|
<div class="p"><b class="ph b">Description</b></div>
|
|
</th>
|
|
</tr>
|
|
</thead>
|
|
|
|
<tbody class="tbody">
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-310868</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where PA Explicit proxy blocked ICMP packets from
|
|
flowing towards Envoy for Geneve due to the router not camping MSS
|
|
when the MTU was lower in the path.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-307901</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where a leak in decryption counters caused resource
|
|
exhaustion, which led to a GlobalProtect service outage.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-306502</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed two issues that impacted TLSv1.2 or earlier sessions when the
|
|
traffic matched a decryption policy rule with the no-decrypt action:
|
|
</div>
|
|
<ul class="ul">
|
|
<li class="li">
|
|
Connections failed when both HTTP header insertion (<span
|
|
class="ph uicontrol"
|
|
>Objects > Security Profiles > URL Filtering > HTTP
|
|
Header Insertion</span
|
|
>) and
|
|
<span class="ph uicontrol"
|
|
>Send handshake messages to CTD for inspection</span
|
|
>
|
|
(<span class="ph uicontrol"
|
|
>Device > Setup > Session > Decryption Settings > SSL
|
|
Decryption Settings</span
|
|
>) were enabled.
|
|
</li>
|
|
<li class="li">
|
|
New sessions failed due to software packet buffer resource
|
|
depletion, which occurred when
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>Log Successful SSL Handshake</a
|
|
>
|
|
was disabled in the decryption policy rule and the decryption
|
|
profile attached to the rule had both
|
|
<span class="ph uicontrol"
|
|
>Block sessions with expired certificates</span
|
|
>
|
|
and
|
|
<span class="ph uicontrol"
|
|
>Block sessions with untrusted issuers</span
|
|
>
|
|
disabled.
|
|
</li>
|
|
</ul>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-306103</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-3400 and PA-5400 Series firewalls only</tt>)
|
|
Fixed an issue where the firewall dataplane frequently restarted when
|
|
lockless QoS was enabled
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303959</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where traffic was incorrectly identified as
|
|
unknown-tcp/unknown-udp due to App-ID resource leak and eventually
|
|
dropped.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302767</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where IPv6 IPsec WAN support was not available in
|
|
Prisma Access.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301222</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where DNS Security logs incorrectly displayed a
|
|
sinkhole action for benign DNS categories due to the firewall saving
|
|
the drop or sinkhole action in session flags without discarding the
|
|
session.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300638</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
|
the firewall stopped responding due to an out-of-bounds read when
|
|
parsing TLS 1.3 clientHello messages with large TLS clientHello
|
|
extensions where the
|
|
<span class="ph systemoutput">supported_versions</span> extension fell
|
|
outside the first TCP segment.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297295</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>VM-Series firewalls in Microsoft Azure environments only</tt
|
|
>) Fixed an issue where the firewall repeatedly restarted due to high
|
|
packet rates on the synthetic path in DPDK mode.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295803</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Addressed a memory leak issue under sc3 and automatic commit recovery
|
|
(ACR) code path.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-294488</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where certificate data was missing in decryption logs
|
|
for <span class="ph uicontrol">No decrypt</span> policy rules and
|
|
TLS1.2 traffic after upgrading, and the
|
|
<tt class="ph tt">Subject Common Name</tt>,
|
|
<span class="ph uicontrol">Issuer Common Name</span>,
|
|
<span class="ph uicontrol">Certificate Start Date</span>,<span
|
|
class="ph uicontrol"
|
|
>
|
|
Certificate End Date</span
|
|
>, <span class="ph uicontrol">Certificate Serial Number</span>, and
|
|
<span class="ph uicontrol">Certificate Fingerprint</span> fields were
|
|
blank in the decryption logs.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-283563</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the GlobalProtect gateway firewall intermittently
|
|
failed to assign an IP address to GlobalProtect clients from the DHCP
|
|
server, even after successfully receiving a DHCP offer. This occurred
|
|
when the DHCP retry and timeout settings were overwritten due to
|
|
parsing results being stored in the same variable, which caused the
|
|
last gateway configuration to take effect.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-271438</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall calculated available memory
|
|
incorrectly on CENTOS devices, which caused the firewall to display
|
|
high memory usage alerts even when sufficient memory was available.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-267328</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>all_task</a
|
|
>
|
|
process stopped responding, which caused the firewall to stop
|
|
processing traffic.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-259853</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, when the DHCP server was enabled for
|
|
GlobalProtect, the commit error message was not properly displayed
|
|
when <span class="ph uicontrol">Any</span> was selected as the source
|
|
interface in the service router configuration (<span
|
|
class="ph menucascade"
|
|
><span class="ph uicontrol">Device</span
|
|
><span class="ph uicontrol">Setup</span
|
|
><span class="ph uicontrol">Service</span
|
|
><span class="ph uicontrol"
|
|
>Service Router Configuration</span
|
|
></span
|
|
>).
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-258039</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall displayed the incorrect rule name
|
|
when a threat log was generated for Inline Cloud Analyzed CMD
|
|
Injection Traffic Detection.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|