1016 lines
31 KiB
HTML
1016 lines
31 KiB
HTML
<table class="table colsep rowsep table-striped">
|
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
|
|
|
<colgroup>
|
|
<col style="width: 25%" />
|
|
<col style="width: 75%" />
|
|
</colgroup>
|
|
<thead class="thead">
|
|
<tr class="row">
|
|
<th class="entry">
|
|
<div class="p">Issue ID</div>
|
|
</th>
|
|
<th class="entry">
|
|
<div class="p">Description</div>
|
|
</th>
|
|
</tr>
|
|
</thead>
|
|
|
|
<tbody class="tbody">
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">—</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixes were made to address the following CVEs:
|
|
<ul id="concept-nzg_cmn_vjc_ul-pzg_cmn_vjc" class="ul">
|
|
<li class="li">
|
|
<a
|
|
class="xref"
|
|
href="https://security.paloaltonetworks.com/CVE-2026-0283"
|
|
title=""
|
|
data-scope="external"
|
|
data-format="html"
|
|
data-type=""
|
|
target="_blank"
|
|
>CVE-2026-0283</a
|
|
>
|
|
</li>
|
|
<li class="li">
|
|
<a
|
|
class="xref"
|
|
href="https://security.paloaltonetworks.com/CVE-2026-0287"
|
|
title=""
|
|
data-scope="external"
|
|
data-format="html"
|
|
data-type=""
|
|
target="_blank"
|
|
>CVE-2026-0287</a
|
|
>
|
|
</li>
|
|
<li class="li">
|
|
<a
|
|
class="xref"
|
|
href="https://security.paloaltonetworks.com/CVE-2026-0279"
|
|
title=""
|
|
data-scope="external"
|
|
data-format="html"
|
|
data-type=""
|
|
target="_blank"
|
|
>CVE-2026-0279</a
|
|
>
|
|
</li>
|
|
<li class="li">
|
|
<a
|
|
class="xref"
|
|
href="https://security.paloaltonetworks.com/CVE-2026-0282"
|
|
title=""
|
|
data-scope="external"
|
|
data-format="html"
|
|
data-type=""
|
|
target="_blank"
|
|
>CVE-2026-0282</a
|
|
>
|
|
</li>
|
|
<li class="li">
|
|
<a
|
|
class="xref"
|
|
href="https://security.paloaltonetworks.com/CVE-2026-0288"
|
|
title=""
|
|
data-scope="external"
|
|
data-format="html"
|
|
data-type=""
|
|
target="_blank"
|
|
>CVE-2026-0288</a
|
|
>
|
|
</li>
|
|
<li class="li">
|
|
<a
|
|
class="xref"
|
|
href="https://security.paloaltonetworks.com/CVE-2026-0286"
|
|
title=""
|
|
data-scope="external"
|
|
data-format="html"
|
|
data-type=""
|
|
target="_blank"
|
|
>CVE-2026-0286</a
|
|
>
|
|
</li>
|
|
<li class="li">
|
|
<a
|
|
class="xref"
|
|
href="https://security.paloaltonetworks.com/CVE-2026-0285"
|
|
title=""
|
|
data-scope="external"
|
|
data-format="html"
|
|
data-type=""
|
|
target="_blank"
|
|
>CVE-2026-0285</a
|
|
>
|
|
</li>
|
|
<li class="li">
|
|
<a
|
|
class="xref"
|
|
href="https://security.paloaltonetworks.com/CVE-2026-0280"
|
|
title=""
|
|
data-scope="external"
|
|
data-format="html"
|
|
data-type=""
|
|
target="_blank"
|
|
>CVE-2026-0280</a
|
|
>
|
|
</li>
|
|
<li class="li">
|
|
<a
|
|
class="xref"
|
|
href="https://security.paloaltonetworks.com/CVE-2026-0284"
|
|
title=""
|
|
data-scope="external"
|
|
data-format="html"
|
|
data-type=""
|
|
target="_blank"
|
|
>CVE-2026-0284</a
|
|
>
|
|
</li>
|
|
<li class="li">
|
|
<a
|
|
class="xref"
|
|
href="https://security.paloaltonetworks.com/CVE-2026-0281"
|
|
title=""
|
|
data-scope="external"
|
|
data-format="html"
|
|
data-type=""
|
|
target="_blank"
|
|
>CVE-2026-0281</a
|
|
>
|
|
</li>
|
|
</ul>
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-327009</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>all_task</a
|
|
>
|
|
process stopped responding.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-326677</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where a selective push from Panorama to the firewall
|
|
was successful even when applying rename operation failed in selective
|
|
push, which resulted in configurations on the firewall being deleted.
|
|
With this fix, the selective push will fail when applying rename
|
|
operation fails.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-326354</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>sslmgr</a
|
|
>
|
|
process stopped responding when attempting to display the OSCP host
|
|
cache.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-324370</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where IDE traffic did not function as expected when
|
|
both HTTP head insertion and DLP inspection were enabled.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-323485</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where multicast radio RTP based traffic was dropped
|
|
after an upgrade when the firewall performed Cloud Inline inspection,
|
|
which led to an exceeded session queue for Cloud Threat Detection.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-321816</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where processes stopped responding unexpectedly.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-321699</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where device telemetry intermittently failed to send
|
|
files, which resulted in critical alerts in system files.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-321527</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>PA-7500 firewalls in HA cluster configurations only</tt
|
|
>) Fixed an issue where, when one firewall suspended operations, the
|
|
other firewall also suspended operations instead of initiating a
|
|
failover, which resulted in a complete traffic outage.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-321516</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the dataplane restarted due to a race condition
|
|
in the dataplane cache infrastructure.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-321340</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Firewalls in FIPS mode only</tt>) Fixed an issue
|
|
where GlobalProtect unexpectedly prompted for RADIUS authentication
|
|
instead of client certificate authentication due to an OSCP validation
|
|
error and subsequent CRL verification failure, which led to
|
|
certificates being marked as invalid.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-321060</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where an ethernet interface remained in a down state
|
|
after repeated automated enable/disable cycles and required manual
|
|
intervention, which resulted in backup outages.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-320598</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where internal and external DNS names did not resolve
|
|
when connected to a GlobalProtect gateway.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-320245</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-7500 Series firewalls in vwire mode only</tt>)
|
|
Fixed an issue where Oracle application traffic was intermittently not
|
|
processed even though connected devices sent the traffic, which led to
|
|
service distruptions.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-319793</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after upgrading to PAN-OS 12.1.5, GlobalProtect
|
|
Clientless VPN failed to access JavaScripts.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-319504</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where telemetry data was not sent to the cloud due to
|
|
the firewall being unable to resolve the destination server's FQDN
|
|
even when a proxy server was configured. With this fix, the firewall
|
|
properly sends telemetry data through the configured proxy server
|
|
without requiring direct public DNS resolution for the telemetry
|
|
server's FQDN.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-319419</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Firewalls in active/passive HA configurations only</tt
|
|
>) Fixed an issue where active firewalls were unable to send device
|
|
telemetry data to CDL.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-319352</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall rebooted unexpectedly without any
|
|
configuration or power changes.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-319343</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Prisma Access Gateways only</tt>) Fixed an issue
|
|
where the global management plane stopped responding, which caused SSH
|
|
and HTML disconnections, HIP database lookup failures, and
|
|
significantly slower SCM commits. This occurred when egress IP allow
|
|
listing was enabled in SCM and changes were made to EDLs.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-319288</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where a DPC in Slot 4 restarted repeatedly, which
|
|
caused internal path monitoring failures and a failover event.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-319228</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where External Dynamic List (EDL) refresh and commit
|
|
operations remained in a pending state, which prevented any subsequent
|
|
operations from completing.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-318580</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where processes restarted and the firewall unexpectedly
|
|
rebooted when you configured a Security policy rule with
|
|
<span class="ph uicontrol">Source Device > quarantine</span>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-318382</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
|
|
issue where the secondary firewall remained at an
|
|
<span class="ph uicontrol">Initial</span> state after an upgrade.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-318120</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where SSL traffic was silently dropped when traffic was
|
|
processed by a Security policy with an Anti-Spyware profile that had
|
|
Inline cloud Analysis enabled for SSL C2 Detector with an action other
|
|
than allow or alert.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-318106</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where SCM did not update device telemetry for the
|
|
firewall after upgrading to an affected release.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-317755</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where selective push operations failed when
|
|
plugin configurations included access-domain or log-collector
|
|
references.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-317648</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>PA-5450 firewalls and PA-7000 Series firewalls with 100G NPCs
|
|
only</tt
|
|
>) Fixed an issue where intermittent packet loss occurred when
|
|
traversing the dataplane after upgrading the firewall. This occurred
|
|
when a dataplane HA interface was configured in an environment where
|
|
Slot 1 was unpopulated , which resulted in a wildcard entry being
|
|
created within the QMAP table.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-317614</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where high throughput and increased packet rates caused
|
|
high dataplane CPU usage.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-316435</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall restarted unexpectedly due to an OOM
|
|
condition after upgrading to an affected release.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-316120</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after Advanced Routing was enabled, the firewall
|
|
advertised routes to internal BGP neighbors with the original external
|
|
BGP next-hop address.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-315337</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where GlobalProtect throughput was reduced after an
|
|
upgrade.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-315326</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-7500 firewalls only</tt>) Fixed an issue where
|
|
zone protection threshold values per dataplane were unexpectedly low.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-315314</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, when a push operation from Panorama to the
|
|
firewall failed, accounting logs stopped forwarding.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-315160</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-7500 firewalls only</tt>) Fixed an issue where
|
|
internal path monitoring logs incorrectly reported internal path
|
|
monitoring failures when they did not occur.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-314776</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>configd</a
|
|
>
|
|
process stopped responding after pushing configuration changes from
|
|
Panorama to the firewall.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-314623</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Firewalls in active/passive HA configurations only</tt
|
|
>) Fixed an issue where, after a failover, routing information within
|
|
OSPF protocol was not correctly translated or propagated, which
|
|
affected network path convergence and FRR capabilities.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-314512</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the GlobalProtect portal became inaccessible when
|
|
the dataplane was configured with a DHCP assigned IP address.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-314104</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where running BCM counter commands from the
|
|
administrative shell did not consistently return output, and commands
|
|
to modify queue sizes did not take effect.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-313787</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where some system log filters with the
|
|
<span class="ph systemoutput">eventid</span> operator for a BGP event
|
|
did not work.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-313606</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama pushed commits took longer than expected
|
|
to complete without displaying an error message when committing due to
|
|
slow cloud-app compilation.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-313575</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where 10G connections on built-in RJ45 interfaces
|
|
(ethernet1/1 through ethernet1/5) intermittently experienced interface
|
|
flapping when connected to Cisco switchports.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-313523</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where generating a tech support file caused
|
|
GlobalProtect users to be forcibly logged out.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-313443</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where firewalls acting as an accumulation proxy sent a
|
|
server hello with an earlier TCP timestamp value than a preceding ACK
|
|
packet, which prevented successful session establishment. This
|
|
occurred when the client hello messages were split across multiple
|
|
network segments.
|
|
</div>
|
|
<div class="p">
|
|
To use this fix, run the CLI command
|
|
<span class="ph systemoutput"
|
|
>debug dataplane set ssl-decrypt accumulate-client-hello ts-relay
|
|
yes</span
|
|
>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-313218</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Added the following CLI commands to address QoS packet drops due to
|
|
bursty traffic:
|
|
</div>
|
|
<ul id="concept-nzg_cmn_vjc_ul-qzg_cmn_vjc" class="ul">
|
|
<li class="li">
|
|
<span class="ph systemoutput"
|
|
>debug dataplane set qos-setting qos-param qlimit 300</span
|
|
>
|
|
</li>
|
|
<li class="li">
|
|
<span class="ph systemoutput"
|
|
>debug dataplane set qos-setting qos-param red low 50 high
|
|
90</span
|
|
>
|
|
</li>
|
|
</ul>
|
|
<div class="p">
|
|
To utilize this fix, change the parameters, disable QoS, commit
|
|
changes, enable QOS, and then re-commit changes.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-313036</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall dataplane continuously accumulated
|
|
packets in the <span class="ph systemoutput">ctd_pkt_queue</span> and
|
|
packet buffers, which caused resource exhaustion and prematurely
|
|
terminated sessions.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-312442</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where 403 errors occurred when performing "show config
|
|
effective-running" API query after downgrading to an affected PAN-OS
|
|
release.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-312330</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Firewalls in active/passive HA configurations only</tt
|
|
>) Fixed an issue where the Clientless VPN applications failed to load
|
|
due to the firewall dataplane incorrectly processing session
|
|
information.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-312157</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, during a commit, the firewall intermittently
|
|
stopped sending SNMP messages, which caused interface counters to stop
|
|
updating for brief periods of time.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-311658</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>reportd</a
|
|
>
|
|
process stopped responding, which caused the firewall to reboot.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-311419</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the recommended filter for identifying traffic
|
|
from unidentified users in traffic logs reported an incorrectly low
|
|
number of results.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-310240</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where software packet buffers were completely utilized
|
|
when performing a Data Loss Prevention longevity test.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-308876</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where upgrades to managed firewalls from Panorama
|
|
failed.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-308775</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Firewalls in active/passive configurations only</tt
|
|
>) Fixed an issue where NTP status intermittently showed as rejected
|
|
on the active firewall, which prevented the firewalls from
|
|
synchronizing time.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-308444</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where pushing multiple policy rules failed when the
|
|
policy rules contained a large number of dynamic address object groups
|
|
or user groups.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-307190</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where LED indicators on combo ports remained off even
|
|
when the network link was active.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304360</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall did not redistribute its application
|
|
routes to BGP peers. This occurred in multi-mesh deployments with the
|
|
multi-cloud networking feature enabled.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295082</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the Panorama web interface where you were unable to
|
|
delete or change a logical router for tunnel, SD-WAN, VLAN, or
|
|
loopback interfaces under a template.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-289460</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the timestamp value in SNMPv3 trap headers was
|
|
incorrect.
|
|
</div>
|
|
<div class="p">
|
|
To use this fix, run the CLI command
|
|
<span class="ph systemoutput"
|
|
>debug log-receiver enginetime-from-snmptime yes</span
|
|
>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-286386</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where GlobalProtect users were unable to connect
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-285327</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where a memory leak occurred when processing device and
|
|
vsys tags.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-267067</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where VXLAN traffic failed and packet loss occurred in
|
|
networks sensors after upgrading to an affected release.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-240066</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed a duplicate MAC address issue where an ethernet interface sent
|
|
out Gratuitous ARP (GARP) messages for an IP address that was not
|
|
configured on it.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|