1875 lines
72 KiB
HTML
1875 lines
72 KiB
HTML
<table class="table colsep rowsep table-striped">
|
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
|
|
|
<colgroup>
|
|
<col style="width: 34%" />
|
|
<col style="width: 66%" />
|
|
</colgroup>
|
|
<thead class="thead">
|
|
<tr class="row rowsep">
|
|
<th class="entry">
|
|
<div class="p"><b class="ph b">Issue ID</b></div>
|
|
</th>
|
|
<th class="entry">
|
|
<div class="p"><b class="ph b">Description</b></div>
|
|
</th>
|
|
</tr>
|
|
</thead>
|
|
|
|
<tbody class="tbody">
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">WF500-5632</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
The number of registered WildFire appliances reported in Panorama
|
|
(<span class="ph menucascade"
|
|
><span class="ph uicontrol">Panorama</span
|
|
><span class="ph uicontrol">Managed WildFire Appliances</span
|
|
><span class="ph uicontrol">Firewalls Connected</span
|
|
><span class="ph uicontrol">View</span></span
|
|
>) does not accurately reflect the current status of connected
|
|
WildFire appliances.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-260851</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
From the NGFW or Panorama CLI, you can override the existing
|
|
application tag even if Disable Override is enabled for the
|
|
application (<span class="ph menucascade"
|
|
><span class="ph uicontrol">Objects</span
|
|
><span class="ph uicontrol">Applications</span></span
|
|
>) tag.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-250062</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Device telemetry might fail at configured intervals due to bundle
|
|
generation issues.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-243951</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
On the Panorama management sever in an active/passive High
|
|
Availability (HA) configuration, managed devices (<span
|
|
class="ph menucascade"
|
|
><span class="ph uicontrol">Panorama</span
|
|
><span class="ph uicontrol">Managed Devices</span
|
|
><span class="ph uicontrol">Summary</span></span
|
|
>) display as <span class="ph systemoutput">out-of-sync</span> on the
|
|
passive HA peer when configuration changes are made to the SD-WAN
|
|
(<span class="ph menucascade"
|
|
><span class="ph uicontrol">Panorama</span
|
|
><span class="ph uicontrol">SD-WAN</span></span
|
|
>) configuration on the active HA peer.
|
|
</div>
|
|
<div class="p">
|
|
<b class="ph b">Workaround:</b> Manually synchronize the Panorama HA
|
|
peers.
|
|
</div>
|
|
<ol id="panos-known-issues-11.0.1_ol-o45_53l_w1c" class="ol">
|
|
<li class="li">
|
|
<div class="p">
|
|
Log in to the
|
|
<a
|
|
class="xref"
|
|
href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-web-interface"
|
|
title=""
|
|
data-scope="external"
|
|
data-format="html"
|
|
data-type=""
|
|
target="_blank"
|
|
>Panorama web interface</a
|
|
>
|
|
on the active HA peer.
|
|
</div>
|
|
</li>
|
|
<li class="li">
|
|
<div class="p">
|
|
Select <span class="ph uicontrol">Commit</span> and
|
|
<span class="ph uicontrol">Commit to Panorama</span> the SD-WAN
|
|
configuration changes on the active HA peer.
|
|
</div>
|
|
<div class="p">
|
|
On the passive HA peer, select
|
|
<span class="ph menucascade"
|
|
><span class="ph uicontrol">Panorama</span
|
|
><span class="ph uicontrol">Managed Devices</span
|
|
><span class="ph uicontrol">Summary</span></span
|
|
>
|
|
and observe that the managed devices are now
|
|
<span class="ph systemoutput">out-of-sync</span>.
|
|
</div>
|
|
</li>
|
|
<li class="li">
|
|
<div class="p">
|
|
Log in to the primary HA peer
|
|
<a
|
|
class="xref"
|
|
href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli"
|
|
title=""
|
|
data-scope="external"
|
|
data-format="html"
|
|
data-type=""
|
|
target="_blank"
|
|
>Panorama CLI</a
|
|
>
|
|
and trigger a manual synchronization between the active and
|
|
secondary HA peers.
|
|
</div>
|
|
<div class="p">
|
|
<span class="ph userinput"></span
|
|
><i class="ph i"
|
|
>request high-availability sync-to-remote running-config</i
|
|
>
|
|
</div>
|
|
</li>
|
|
<li class="li">
|
|
<div class="p">
|
|
Log back in to the active HA peer Panorama web interface and
|
|
select
|
|
<span class="ph menucascade"
|
|
><span class="ph uicontrol">Commit</span
|
|
><span class="ph uicontrol">Push to Devices</span></span
|
|
>
|
|
and <span class="ph uicontrol">Push</span>.
|
|
</div>
|
|
</li>
|
|
</ol>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-234408</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Enterprise DLP cannot detect and block non-file based traffic for
|
|
ChatGPT from traffic forwarded to the DLP cloud service from an NGFW.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-234015</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
The X-Forwarded-For (XFF) value is not displayed in traffic logs.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-242910</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
On the Panorama management server, Panorama administrators (<span
|
|
class="ph menucascade"
|
|
><span class="ph uicontrol">Panorama</span
|
|
><span class="ph uicontrol">Administrators</span></span
|
|
>) that are assigned a custom Panorama admin role (<span
|
|
class="ph menucascade"
|
|
><span class="ph uicontrol">Panorama</span
|
|
><span class="ph uicontrol">Admin Roles</span></span
|
|
>) with <span class="ph uicontrol">Push All Changes</span> enabled are
|
|
unable to push configuration changes to managed firewalls when
|
|
<span class="ph uicontrol">Managed Devices</span> and
|
|
<span class="ph uicontrol">Push For Other Admins</span> are disabled.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-241041</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
On the Panorama management server exporting template or template stack
|
|
variables (<span class="ph menucascade"
|
|
><span class="ph uicontrol">Panorama</span
|
|
><span class="ph uicontrol">Templates</span></span
|
|
>) in CSV format results in an empty CSV file.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-228515</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
The EleasticSearch SSH flaps on the M-600 appliance in Panorama or Log
|
|
Collector mode. This causes logs to not display on the Panorama
|
|
management server (<span class="ph menucascade"
|
|
><span class="ph uicontrol">Monitor</span
|
|
><span class="ph uicontrol">Logs</span></span
|
|
>) and the Log Collector health status (<span class="ph menucascade"
|
|
><span class="ph uicontrol">Panorama</span
|
|
><span class="ph uicontrol">Managed Collectors</span
|
|
><span class="ph uicontrol">Status</span></span
|
|
>) to display as degraded.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-228273</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
On the Panorama management server in FIPS-CC mode, the ElasticSearch
|
|
cluster fails to come up and the
|
|
<span class="ph systemoutput"
|
|
>show log-collector-es-cluster health</span
|
|
>
|
|
command displays the <span class="ph systemoutput">status</span> is
|
|
<span class="ph systemoutput">red</span>. This results in log
|
|
ingestion issues for Panorama in Panorama only or Log Collector mode.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-227344</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
On the Panorama management server, PDF Summary Reports (<span
|
|
class="ph menucascade"
|
|
><span class="ph uicontrol">Monitor</span
|
|
><span class="ph uicontrol">PDF Reports</span
|
|
><span class="ph uicontrol">Manage PDF Summary</span></span
|
|
>) display no data and are blank when predefined reports are included
|
|
in the summary report.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-225886</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
If you enable explicit proxy mode for the web proxy, intermittent
|
|
errors and unexpected TCP reconnections may occur.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-225337</b></div>
|
|
<div class="p">
|
|
<tt class="ph tt">This issue is now resolved. See</tt>
|
|
<a
|
|
class="xref"
|
|
href="/content/techdocs/en_US/pan-os/11-0/pan-os-release-notes/pan-os-11-0-4-known-and-addressed-issues/pan-os-11-0-4-addressed-issues.html"
|
|
title=""
|
|
data-scope="local"
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>PAN-OS 11.0.4 Addressed Issues</a
|
|
><tt class="ph tt">.</tt>
|
|
</div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
On the Panorama management server, the configuration push to a
|
|
multi-vsys firewall fails if you:
|
|
</div>
|
|
<ol id="panos-known-issues-11.0.1_ol_lgs_g4h_vyb" class="ol">
|
|
<li class="li">
|
|
<div class="p">
|
|
Create a <span class="ph uicontrol">Shared</span> and
|
|
vsys-specific device group configuration object with an indentical
|
|
name. For example, a
|
|
<span class="ph uicontrol">Shared</span> address object called
|
|
<span class="ph systemoutput">SharedAO1</span> and a vsys-specific
|
|
address object also called
|
|
<span class="ph systemoutput">SharedAO1</span>.
|
|
</div>
|
|
</li>
|
|
<li class="li">
|
|
<div class="p">
|
|
Reference the <span class="ph uicontrol">Shared</span> object in
|
|
another <span class="ph uicontrol">Shared</span> configuration.
|
|
For example, reference the
|
|
<span class="ph uicontrol">Shared</span> address object (<span
|
|
class="ph systemoutput"
|
|
>SharedAO1</span
|
|
>) in a <span class="ph uicontrol">Shared</span> address group
|
|
called <span class="ph systemoutput">SharedAG1</span>.
|
|
</div>
|
|
</li>
|
|
<li class="li">
|
|
<div class="p">
|
|
Use the <span class="ph uicontrol">Shared</span> configuration
|
|
object with the reference in a vsys-specific configuration. For
|
|
example, reference the
|
|
<span class="ph uicontrol">Shared</span> address group (<span
|
|
class="ph systemoutput"
|
|
>SharedAG1</span
|
|
>) in a vsys-specific policy rule.
|
|
</div>
|
|
</li>
|
|
</ol>
|
|
<div class="p">
|
|
<b class="ph b">Workaround:</b> Select
|
|
<span class="ph menucascade"
|
|
><span class="ph uicontrol">Panorama</span
|
|
><span class="ph uicontrol">Setup</span
|
|
><span class="ph uicontrol">Management</span></span
|
|
>
|
|
and edit the Panorama Settings to enable one of the following:
|
|
</div>
|
|
<ul id="panos-known-issues-11.0.1_ul_eyl_zph_vyb" class="ul">
|
|
<li class="li">
|
|
<div class="p">
|
|
<b class="ph b"
|
|
>Shared Unused Address and Service Objects with Devices</b
|
|
>—This options pushes all
|
|
<span class="ph uicontrol">Shared</span> objects, along with
|
|
device group specific objects, to managed firewalls.
|
|
</div>
|
|
<div class="p">
|
|
This is a global setting and applies to all managed firewalls, and
|
|
may result in pushing too many configuration objects to your
|
|
managed firewalls.
|
|
</div>
|
|
</li>
|
|
<li class="li">
|
|
<div class="p">
|
|
<b class="ph b"
|
|
>Objects defined in ancestors will take higher precedence</b
|
|
>—This option specifies that in the event of objects with the same
|
|
name, ancestor object take precedence over descendent objects. In
|
|
this case, the <span class="ph uicontrol">Shared</span> objects
|
|
take precedence over the vsys-specific object.
|
|
</div>
|
|
<div class="p">
|
|
This is a global setting and applies to all managed firewalls. In
|
|
the example above, if the IP address for the
|
|
<span class="ph uicontrol">Shared</span>
|
|
<span class="ph systemoutput">SharedAO1</span> object was
|
|
<span class="ph systemoutput">10.1.1.1</span> and the device group
|
|
specific <span class="ph systemoutput">SharedAO1</span> was
|
|
<span class="ph systemoutput">10.2.2.2</span>, the
|
|
<span class="ph systemoutput">10.1.1.1</span> IP address takes
|
|
precedence.
|
|
</div>
|
|
</li>
|
|
</ul>
|
|
<div class="p">
|
|
Alternatively, you can remove the duplicate address objects from the
|
|
device group configuration to allow only the
|
|
<span class="ph uicontrol">Shared</span> objects in your
|
|
configuration.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-223488</b></div>
|
|
<div class="p">
|
|
<tt class="ph tt">This issue is now resolved. See </tt
|
|
><a
|
|
class="xref"
|
|
href="/content/techdocs/en_US/pan-os/11-0/pan-os-release-notes/pan-os-11-0-3-known-and-addressed-issues/pan-os-11-0-3-addressed-issues.html"
|
|
title=""
|
|
data-scope="local"
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>PAN-OS 11.0.3 Addressed Issues</a
|
|
><tt class="ph tt">.</tt>
|
|
</div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Closed ElasticSearch shards are not deleted from the Panorama M-Series
|
|
and virtual appliance. This causes the ElasticSearch shard purging to
|
|
not work as expected, resulting in high disk usage.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-223365</b></div>
|
|
<div class="p">
|
|
<tt class="ph tt">This issue is now resolved. See </tt
|
|
><a
|
|
class="xref"
|
|
href="/content/techdocs/en_US/pan-os/11-0/pan-os-release-notes/pan-os-11-0-4-known-and-addressed-issues/pan-os-11-0-4-addressed-issues.html"
|
|
title=""
|
|
data-scope="local"
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>PAN-OS 11.0.4 Addressed Issues</a
|
|
><tt class="ph tt">.</tt>
|
|
</div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
The Panorama management server is unable to query any logs if the
|
|
ElasticSearch health status for any Log Collector (<span
|
|
class="ph menucascade"
|
|
><span class="ph uicontrol">Panorama</span
|
|
><span class="ph uicontrol">Managed Collector</span></span
|
|
>
|
|
is degraded.
|
|
</div>
|
|
<div class="p">
|
|
<b class="ph b">Workaround:</b>
|
|
<a
|
|
class="xref"
|
|
href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli"
|
|
title=""
|
|
data-scope="external"
|
|
data-format="html"
|
|
data-type=""
|
|
target="_blank"
|
|
>Log in to the Log Collector CLI</a
|
|
>
|
|
and restart ElasticSearch.
|
|
</div>
|
|
<!-- FM Dita Overlay for Code -->
|
|
<div class="code-wrap">
|
|
<pre
|
|
class="pre codeblock"
|
|
data-label="PRE CODEBLOCK"
|
|
><div style="display: inline;"><span class="ph systemoutput hljs language-undefined" data-highlighted="yes">admin</span><span class="ph userinput hljs language-apache" data-highlighted="yes"><span class="hljs-attribute">debug</span> elasticsearch es-restart <span class="hljs-literal">all</span></span></div></pre>
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-222586</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter
|
|
dropdown menus, Forward Methods, and Built-In Actions for Correlation
|
|
Log settings (<span class="ph menucascade"
|
|
><span class="ph uicontrol">Device</span
|
|
><span class="ph uicontrol">Log Settings</span></span
|
|
>) are not displayed and cannot be configured.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-222253</b></div>
|
|
<div class="p">
|
|
<tt class="ph tt">This issue is now resolved. See </tt
|
|
><a
|
|
class="xref"
|
|
href="/content/techdocs/en_US/pan-os/11-0/pan-os-release-notes/pan-os-11-0-5-known-and-addressed-issues/pan-os-11-0-5-addressed-issues.html"
|
|
title=""
|
|
data-scope="local"
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>PAN-OS 11.0.5 Addressed Issues</a
|
|
><tt class="ph tt">.</tt>
|
|
</div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
On the Panorama management server, policy rulebase reordering when you
|
|
<span class="ph uicontrol">View Rulebase by Groups</span> (<span
|
|
class="ph menucascade"
|
|
><span class="ph uicontrol">Policy</span
|
|
><span class="ph uicontrol"><policy-rulebase></span></span
|
|
>) does not persist if you reorder the policy rulebase by dragging and
|
|
dropping individual policy rules and then moving the entire tag group.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-221126</b></div>
|
|
<div class="p">
|
|
<tt class="ph tt">This issue is now resolved. See </tt
|
|
><a
|
|
class="xref"
|
|
href="/content/techdocs/en_US/pan-os/11-0/pan-os-release-notes/pan-os-11-0-3-known-and-addressed-issues/pan-os-11-0-3-addressed-issues.html"
|
|
title=""
|
|
data-scope="local"
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>PAN-OS 11.0.3 Addressed Issues</a
|
|
><tt class="ph tt">.</tt>
|
|
</div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Email server profiles (<span class="ph menucascade"
|
|
><span class="ph uicontrol">Device</span
|
|
><span class="ph uicontrol">Server Profiles</span
|
|
><span class="ph uicontrol">Email</span></span
|
|
>
|
|
and
|
|
<span class="ph menucascade"
|
|
><span class="ph uicontrol">Panorama</span
|
|
><span class="ph uicontrol">Server Profiles</span
|
|
><span class="ph uicontrol">Email</span></span
|
|
>) to forward logs as email notifications are not forwarded in a
|
|
readable format.
|
|
</div>
|
|
<div class="p">
|
|
<b class="ph b">Workaround:</b> Use a
|
|
<span class="ph uicontrol">Custom Log Format</span> to forward logs as
|
|
email notifications in a readable format.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-221015</b></div>
|
|
<div class="p">
|
|
<tt class="ph tt">This issue is now resolved. See</tt>
|
|
<a
|
|
class="xref"
|
|
href="/content/techdocs/en_US/pan-os/11-0/pan-os-release-notes/pan-os-11-0-4-known-and-addressed-issues/pan-os-11-0-4-addressed-issues.html"
|
|
title=""
|
|
data-scope="local"
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>PAN-OS 11.0.4 Addressed Issues</a
|
|
><tt class="ph tt">.</tt>
|
|
</div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
On M-600 appliances in Panorama or Log Collector mode, the
|
|
<span class="ph systemoutput">es-1</span> and
|
|
<span class="ph systemoutput">es-2</span> ElasticSearch processes fail
|
|
to restart when the M-600 appliance is rebooted. The results in the
|
|
Managed Collector <span class="ph systemoutput">ES</span> health
|
|
status (<span class="ph menucascade"
|
|
><span class="ph uicontrol">Panorama</span
|
|
><span class="ph uicontrol">Managed Collectors</span
|
|
><span class="ph uicontrol">Health Status</span></span
|
|
>) to be degraded.
|
|
</div>
|
|
<div class="p">
|
|
<b class="ph b">Workaround:</b>
|
|
<a
|
|
class="xref"
|
|
href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli"
|
|
title=""
|
|
data-scope="external"
|
|
data-format="html"
|
|
data-type=""
|
|
target="_blank"
|
|
>Log in to the Panorama or Log Collector CLI</a
|
|
>
|
|
experiencing degraded ElasticSearch health and restart all
|
|
ElasticSearch processes.
|
|
</div>
|
|
<!-- FM Dita Overlay for Code -->
|
|
<div class="code-wrap">
|
|
<pre
|
|
class="pre codeblock"
|
|
data-label="PRE CODEBLOCK"
|
|
><div style="display: inline;"><span class="ph systemoutput hljs language-undefined" data-highlighted="yes">admin></span><span data-outputclass="request" class="ph userinput hljs language-apache yay" data-highlighted="yes"><span class="hljs-attribute">debug</span> elasticsearch es-restart optional <span class="hljs-literal">all</span></span><div class="code-btn-container"><div class="alert alert-success copy-alert">Code copied to clipboard</div> <div class="alert alert-danger copy-fail-alert">Unable to copy due to lack of browser support.</div><button class="btn code-btn code-btn-bottom">Copy</button></div></div></pre>
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-220180</b></div>
|
|
<div class="p">
|
|
<tt class="ph tt">This issue is now resolved. See </tt
|
|
><a
|
|
class="xref"
|
|
href="/content/techdocs/en_US/pan-os/11-0/pan-os-release-notes/pan-os-11-0-3-known-and-addressed-issues/pan-os-11-0-3-addressed-issues.html"
|
|
title=""
|
|
data-scope="local"
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>PAN-OS 11.0.3 Addressed Issues</a
|
|
><tt class="ph tt">.</tt>
|
|
</div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Configured botnet reports (<span class="ph menucascade"
|
|
><span class="ph uicontrol">Monitor</span
|
|
><span class="ph uicontrol">Botnet</span></span
|
|
>) are not generated.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-220176</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PAN-OS 11.0.1-h2 hotfix</tt>) System process
|
|
crashes might occur with VoIP traffic when NAT is enabled with
|
|
Persistent Dynamic IP and Port settings.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-219644</b></div>
|
|
<div class="p">
|
|
<tt class="ph tt">This issue is now resolved. See </tt
|
|
><a
|
|
class="xref"
|
|
href="/content/techdocs/en_US/pan-os/11-0/pan-os-release-notes/pan-os-11-0-3-known-and-addressed-issues/pan-os-11-0-3-addressed-issues.html"
|
|
title=""
|
|
data-scope="local"
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>PAN-OS 11.0.3 Addressed Issues</a
|
|
><tt class="ph tt">.</tt>
|
|
</div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Firewalls forwarding logs to a syslog server over TLS (<span
|
|
class="ph menucascade"
|
|
><span class="ph uicontrol">Objects</span
|
|
><span class="ph uicontrol">Log Forwarding</span></span
|
|
>) use the default Palo Alto Networks certificate instead of the
|
|
custom certificate configured on the firewall.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-218521</b></div>
|
|
<div class="p">
|
|
<tt class="ph tt">This issue is now resolved. See </tt
|
|
><a
|
|
class="xref"
|
|
href="/content/techdocs/en_US/pan-os/11-0/pan-os-release-notes/pan-os-11-0-5-known-and-addressed-issues/pan-os-11-0-5-addressed-issues.html"
|
|
title=""
|
|
data-scope="local"
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>PAN-OS 11.0.5 Addressed Issues</a
|
|
><tt class="ph tt">.</tt>
|
|
</div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
The ElasticSearch process on the M-600 appliance in Log Collector mode
|
|
may enter a continuous reboot cycle. This results in the M-600
|
|
appliance becoming unresponsive, consuming logging disk space, and
|
|
preventing new log ingestion.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-217307</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
The following Security policy rule (<span class="ph menucascade"
|
|
><span class="ph uicontrol">Policies</span
|
|
><span class="ph uicontrol">Security</span></span
|
|
>) filters return no results:
|
|
</div>
|
|
<div class="p">
|
|
<span class="ph systemoutput">log-start eq no</span>
|
|
</div>
|
|
<div class="p"><span class="ph systemoutput">log-end eq no</span></div>
|
|
<div class="p"><span class="ph systemoutput">log-end eq yes</span></div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-216821</b></div>
|
|
<div class="p">
|
|
<tt class="ph tt">This issue is now resolved. See </tt
|
|
><a
|
|
class="xref"
|
|
href="/content/techdocs/en_US/pan-os/11-0/pan-os-release-notes/pan-os-11-0-2-known-and-addressed-issues/pan-os-11-0-2-addressed-issues.html"
|
|
title=""
|
|
data-scope="local"
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>PAN-OS 11.0.2 Addressed Issues</a
|
|
><tt class="ph tt">.</tt>
|
|
</div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
The <span class="ph systemoutput">reportd</span> process crashes after
|
|
you successfully upgrade an M-200 appliance to PAN-OS 10.2.4.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-216314</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Upon upgrade or downgrade to or from PAN-OS 10.1.9 or 10.1.9-h1,
|
|
offloaded application traffic sessions may disconnect after a period
|
|
of time even if a session is active. The disconnect occurs after the
|
|
application's default session timeout value is exceeded. This behavior
|
|
affects only PAN-OS 10.1.9 and 10.1.9-h1. If you are on PAN-OS 10.1.9
|
|
and 10.1.9-h1, please use the following workaround. If you have
|
|
already upgraded or downgraded to another PAN-OS version, use the
|
|
following workaround in that version.
|
|
</div>
|
|
<div class="p">
|
|
<b class="ph b">Workaround:</b> Run the CLI command
|
|
<span class="ph userinput"
|
|
>debug dataplane internal pdt fe100 csr wr_sem_ctrl_ctr_scan_dis
|
|
value 0</span
|
|
>
|
|
to set the value to zero (0).
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-216214</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
For Panorama-managed firewalls in an Active/Active High Availability
|
|
(HA) configuration where you configure the firewall HA settings (<span
|
|
class="ph menucascade"
|
|
><span class="ph uicontrol">Device</span
|
|
><span class="ph uicontrol">High Availability</span></span
|
|
>) in a template or template stack (<span class="ph menucascade"
|
|
><span class="ph uicontrol">Panorama</span
|
|
><span class="ph uicontrol">Templates</span></span
|
|
>), performing a local commit on one of the HA firewalls triggers an
|
|
HA config sync on the peer firewall. This causes the HA peer
|
|
configuration to go <span class="ph systemoutput">Out of Sync</span>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-215778</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
On the M-600 appliance in Management Only mode, XML API Get requests
|
|
for <span class="ph systemoutput">/config</span> fail with the
|
|
following error due to exceeding the
|
|
<a
|
|
class="xref"
|
|
href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/panorama-overview/centralized-firewall-configuration-and-update-management/total-configuration-size-for-panorama"
|
|
title=""
|
|
data-scope="external"
|
|
data-format="html"
|
|
data-type=""
|
|
target="_blank"
|
|
>total configuration size</a
|
|
>
|
|
supported on the M-600 appliance.
|
|
</div>
|
|
<!-- FM Dita Overlay for Code -->
|
|
<div class="code-wrap">
|
|
<pre
|
|
class="pre codeblock"
|
|
data-label="PRE CODEBLOCK"
|
|
><div style="display: inline;"><span class="ph systemoutput hljs language-bash" data-highlighted="yes">504 Gateway <span class="hljs-built_in">timeout</span></span></div></pre>
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-215082</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
M-300 and M-700 appliances may generate erroneous system logs (<span
|
|
class="ph menucascade"
|
|
><span class="ph uicontrol">Monitor</span
|
|
><span class="ph uicontrol">Logs</span
|
|
><span class="ph uicontrol">System</span></span
|
|
>) to alert that the M-Series appliance memory usage limits are
|
|
reached.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-213746</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
On the Panorama management server, the
|
|
<span class="ph uicontrol">Hostkey</span> displayed as
|
|
<span class="ph systemoutput">undefined undefined</span> if you
|
|
override an SSH Service Profile (<span class="ph menucascade"
|
|
><span class="ph uicontrol">Device</span
|
|
><span class="ph uicontrol">Certificate Management</span
|
|
><span class="ph uicontrol">SSH Service Profile</span></span
|
|
>) Hostkey configured in a Template from the Template Stack.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-213119</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
PA-5410 and PA-5420 firewalls display the following error when you
|
|
view the Block IP list (<span class="ph menucascade"
|
|
><span class="ph uicontrol">Monitor</span
|
|
><span class="ph uicontrol">Block IP</span></span
|
|
>):
|
|
</div>
|
|
<div class="p">
|
|
<span class="ph systemoutput"
|
|
>show -> dis-block-table is unexpected</span
|
|
>
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-212889</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
On the Panorama management server, different threat names are used
|
|
when querying the same threat in the Threat Monitor (<span
|
|
class="ph menucascade"
|
|
><span class="ph uicontrol">Monitor</span
|
|
><span class="ph uicontrol">App Scope</span
|
|
><span class="ph uicontrol">Threat Monitor</span></span
|
|
>) and <span class="ph uicontrol">ACC</span>. This results in the ACC
|
|
displaying
|
|
<span class="ph systemoutput">no data to display</span> when you are
|
|
redirected to the ACC after clicking a threat name in the Threat
|
|
Monitor and filtering the same threat name in the Global Filters.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-211531</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
On the Panorama management server, admins can still perform a selective
|
|
push to managed firewalls when
|
|
<span class="ph uicontrol">Push All Changes</span> and
|
|
<span class="ph uicontrol">Push for Other Admins</span> are disabled in
|
|
the admin role profile (<span class="ph menucascade"
|
|
><span class="ph uicontrol">Panorama</span
|
|
><span class="ph uicontrol">Admin Roles</span></span
|
|
>).
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-209937</b></div>
|
|
<div class="p">
|
|
<tt class="ph tt">This issue is now resolved. See </tt
|
|
><a
|
|
class="xref"
|
|
href="/content/techdocs/en_US/pan-os/11-0/pan-os-release-notes/pan-os-11-0-2-known-and-addressed-issues/pan-os-11-0-2-addressed-issues.html"
|
|
title=""
|
|
data-scope="local"
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>PAN-OS 11.0.2 Addressed Issues</a
|
|
><tt class="ph tt">.</tt>
|
|
</div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Certificate-based authentication for administrator accounts may be
|
|
unable to log into the Panorama or firewall web interface with the
|
|
following error:
|
|
</div>
|
|
<div class="p">
|
|
<span class="ph systemoutput"
|
|
>Bad Request - Your browser sent a request that this server could
|
|
not understand</span
|
|
>
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-208325</b></div>
|
|
<div class="p">
|
|
<tt class="ph tt">This issue is now resolved. See </tt
|
|
><a
|
|
class="xref"
|
|
href="/content/techdocs/en_US/pan-os/11-0/pan-os-release-notes/pan-os-11-0-2-known-and-addressed-issues/pan-os-11-0-2-addressed-issues.html"
|
|
title=""
|
|
data-scope="local"
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>PAN-OS 11.0.2 Addressed Issues</a
|
|
><tt class="ph tt">.</tt>
|
|
</div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
The following NextGen firewalls and Panorama management server models
|
|
are unable to automatically renew the device certificate (<span
|
|
class="ph menucascade"
|
|
><span class="ph uicontrol">Device</span
|
|
><span class="ph uicontrol">Setup</span
|
|
><span class="ph uicontrol">Management</span></span
|
|
>
|
|
or
|
|
<span class="ph menucascade"
|
|
><span class="ph uicontrol">Panorama</span
|
|
><span class="ph uicontrol">Setup</span
|
|
><span class="ph uicontrol">Management</span></span
|
|
>).
|
|
</div>
|
|
<ul id="panos-known-issues-11.0.1_ul_cnx_s4c_twb" class="ul">
|
|
<li class="li"><div class="p">M-300 and M-700</div></li>
|
|
<li class="li"><div class="p">PA-410 Firewall</div></li>
|
|
<li class="li"><div class="p">PA-415 and PA-445 Firewalls</div></li>
|
|
<li class="li">
|
|
<div class="p">PA-440, PA-450, and PA-460 Firewalls</div>
|
|
</li>
|
|
<li class="li"><div class="p">PA-1400 Series</div></li>
|
|
<li class="li"><div class="p">PA-3400 Series</div></li>
|
|
<li class="li">
|
|
<div class="p">PA-5410, PA-5420, and PA-5430 Firewalls</div>
|
|
</li>
|
|
<li class="li"><div class="p">PA-5440 Firewall</div></li>
|
|
<li class="li"><div class="p">PA-5450 Firewall</div></li>
|
|
</ul>
|
|
<div class="p">
|
|
<b class="ph b">Workaround:</b> Log in to the
|
|
<a
|
|
class="xref"
|
|
href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-cli-quick-start/get-started-with-the-cli/access-the-cli"
|
|
title=""
|
|
data-scope="external"
|
|
data-format="html"
|
|
data-type=""
|
|
target="_blank"
|
|
>firewall CLI</a
|
|
>
|
|
or
|
|
<a
|
|
class="xref"
|
|
href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli"
|
|
title=""
|
|
data-scope="external"
|
|
data-format="html"
|
|
data-type=""
|
|
target="_blank"
|
|
>Panorama CLI</a
|
|
>
|
|
and fetch the device certificate.
|
|
</div>
|
|
<!-- FM Dita Overlay for Code -->
|
|
<div class="code-wrap">
|
|
<pre
|
|
class="pre codeblock"
|
|
data-label="PRE CODEBLOCK"
|
|
><div style="display: inline;"><span class="ph systemoutput hljs language-undefined" data-highlighted="yes">admin></span><span class="ph userinput hljs language-nginx" data-highlighted="yes"><span class="hljs-attribute">request</span> certificate fetch</span></div></pre>
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-208189</b></div>
|
|
<div class="p">
|
|
<tt class="ph tt">This issue is now resolved. See </tt
|
|
><a
|
|
class="xref"
|
|
href="/content/techdocs/en_US/pan-os/11-0/pan-os-release-notes/pan-os-11-0-1-known-and-addressed-issues/pan-os-11-0-1-h2-addressed-issues.html"
|
|
title=""
|
|
data-scope="local"
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>PAN-OS 11.0.1-h2 Addressed Issues</a
|
|
><tt class="ph tt">.</tt>
|
|
</div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Traffic fails to match and reach all destinations if a Security policy
|
|
rule includes FQDN objects that resolve to two or more IP addresses.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-207770</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Data filtering logs (<span class="ph menucascade"
|
|
><span class="ph uicontrol">Monitor</span
|
|
><span class="ph uicontrol">Logs</span
|
|
><span class="ph uicontrol">Data Filtering</span></span
|
|
>) incorrectly display the traffic Direction as
|
|
<span class="ph systemoutput">server-to-client</span> instead of
|
|
<span class="ph systemoutput">client-to-server</span> for upload
|
|
traffic that matches Enterprise data loss prevention (DLP) data
|
|
patterns (<span class="ph menucascade"
|
|
><span class="ph uicontrol">Objects</span
|
|
><span class="ph uicontrol">DLP</span
|
|
><span class="ph uicontrol">Data Filtering Patterns</span></span
|
|
>) in an Enterprise DLP data filtering profile (<span
|
|
class="ph menucascade"
|
|
><span class="ph uicontrol">Objects</span
|
|
><span class="ph uicontrol">DLP</span
|
|
><span class="ph uicontrol">Data Filtering Profiles</span></span
|
|
>).
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-207733</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
When a DHCPv6 client is configured on HA Active/Passive firewalls, if
|
|
the DHCPv6 server goes down, after the lease time expires, the DHCPv6
|
|
client should enter SOLICIT state on both the Active and Passive
|
|
firewalls. Instead, the client is stuck in BOUND state with an IPv6
|
|
address having lease time 0 on the Passive firewall.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-207616</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
On the Panorama management server, after selecting managed firewalls
|
|
and creating a new <span class="ph uicontrol">Tag</span> (<span
|
|
class="ph menucascade"
|
|
><span class="ph uicontrol">Panorama</span
|
|
><span class="ph uicontrol">Managed Devices</span
|
|
><span class="ph uicontrol">Summary</span></span
|
|
>) the managed firewalls are automatically unselected and any new tag
|
|
created is applied to the managed firewalls for which you initially
|
|
created the new tag.
|
|
</div>
|
|
<div class="p">
|
|
<b class="ph b">Workaround:</b> Select and then unselect the managed
|
|
firewalls for which you created a new tag.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-207611</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
When a DHCPv6 client is configured on HA Active/Passive firewalls, the
|
|
Passive firewall sometimes crashes.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-207442</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
For M-700 appliances in an active/passive high availability (<span
|
|
class="ph menucascade"
|
|
><span class="ph uicontrol">Panorama</span
|
|
><span class="ph uicontrol">High Availability</span></span
|
|
>) configuration, the
|
|
<span class="ph systemoutput">active-primary</span> HA peer
|
|
configuration sync to the
|
|
<span class="ph systemoutput">secondary-passive</span> HA peer may
|
|
fail. When the config sync fails, the job Results is
|
|
<span class="ph systemoutput">Successful</span>
|
|
(<span class="ph uicontrol">Tasks</span>), however the sync status on
|
|
the <span class="ph uicontrol">Dashboard</span> displays as
|
|
<span class="ph systemoutput">Out of Sync</span> for both HA peers.
|
|
</div>
|
|
<div class="p">
|
|
<b class="ph b">Workaround</b>: Perform a local commit on the
|
|
<span class="ph systemoutput">active-primary</span> HA peer and then
|
|
synchronize the HA configuration.
|
|
</div>
|
|
<ol id="panos-known-issues-11.0.1_ol_aqy_kbp_qxb" class="ol">
|
|
<li class="li">
|
|
<div class="p">
|
|
<a
|
|
class="xref"
|
|
href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-web-interface"
|
|
title=""
|
|
data-scope="external"
|
|
data-format="html"
|
|
data-type=""
|
|
target="_blank"
|
|
>Log in to the Panorama web interface</a
|
|
>
|
|
of the <span class="ph systemoutput">active-primary</span> HA
|
|
peer.
|
|
</div>
|
|
</li>
|
|
<li class="li">
|
|
<div class="p">
|
|
Select <span class="ph uicontrol">Commit</span> and
|
|
<span class="ph uicontrol">Commit to Panorama</span>.
|
|
</div>
|
|
</li>
|
|
<li class="li">
|
|
<div class="p">
|
|
In the <span class="ph systemoutput">active-primary</span> HA peer
|
|
<span class="ph uicontrol">Dashboard</span>, click
|
|
<span class="ph uicontrol">Sync to Peer</span> in the High
|
|
Availability widget.
|
|
</div>
|
|
</li>
|
|
</ol>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-207040</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
If you disable Advanced Routing, remove logical routers, and downgrade
|
|
from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
|
|
commits fail and SD-WAN devices on Panorama have no Virtual Router
|
|
name.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-206913</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
When a DHCPv6 client is configured on HA Active/Passive firewalls,
|
|
releasing the IPv6 address from the client (using Release in the UI or
|
|
using the
|
|
<span class="ph systemoutput"
|
|
>request dhcp client ipv6 release all</span
|
|
>
|
|
CLI command) releases the IPv6 address from the Active firewall, but
|
|
not the Passive firewall.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-206909</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
The Dedicated Log Collector is unable to reconnect to the Panorama
|
|
management server if the
|
|
<span class="ph systemoutput">configd</span> process crashes. This
|
|
results in the Dedicated Log Collector losing connectivity to Panorama
|
|
despite the managed collector connection
|
|
<span class="ph systemoutput">Status</span> (<span
|
|
class="ph menucascade"
|
|
><span class="ph uicontrol">Panorama</span
|
|
><span class="ph uicontrol">Managed Collector</span></span
|
|
>) displaying <span class="ph systemoutput">connected</span> and the
|
|
managed colletor <span class="ph systemoutput">Health</span> status
|
|
displaying as healthy.
|
|
</div>
|
|
<div class="p">
|
|
This results in the local Panorama config and system logs not being
|
|
forwarded to the Dedicated Log Collector. Firewall log forwarding to
|
|
the disconnected Dedicated Log Collector is not impacted.
|
|
</div>
|
|
<div class="p">
|
|
<b class="ph b">Workaround:</b> Restart the
|
|
<span class="ph systemoutput">mgmtsrvr</span> process on the Dedicated
|
|
Log Collector.
|
|
</div>
|
|
<ol id="panos-known-issues-11.0.1_ol_pdy_4bm_lvb" class="ol">
|
|
<li class="li">
|
|
<div class="p">
|
|
<a
|
|
class="xref"
|
|
href="https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli"
|
|
title=""
|
|
data-scope="external"
|
|
data-format="html"
|
|
data-type=""
|
|
target="_blank"
|
|
>Log in to the Dedicated Log Collector CLI</a
|
|
>.
|
|
</div>
|
|
</li>
|
|
<li class="li">
|
|
<div class="p">
|
|
Confirm the Dedicated Log Collector is disconnected from Panorama.
|
|
</div>
|
|
<!-- FM Dita Overlay for Code -->
|
|
<div class="code-wrap">
|
|
<pre
|
|
class="pre codeblock"
|
|
data-label="PRE CODEBLOCK"
|
|
><div style="display: inline;"><span class="ph systemoutput hljs language-undefined" data-highlighted="yes">admin></span><span class="ph userinput hljs language-nginx" data-highlighted="yes"> <span class="hljs-attribute">show</span> panorama-status</span></div></pre>
|
|
<div class="p">
|
|
Verify the <span class="ph systemoutput">Connected</span> status
|
|
is <span class="ph systemoutput">no</span>.
|
|
</div>
|
|
</div>
|
|
</li>
|
|
<li class="li">
|
|
<div class="p">
|
|
Restart the <span class="ph systemoutput">mgmtsrvr</span> process.
|
|
</div>
|
|
<!-- FM Dita Overlay for Code -->
|
|
<div class="code-wrap">
|
|
<pre
|
|
class="pre codeblock"
|
|
data-label="PRE CODEBLOCK"
|
|
><div style="display: inline;"><span class="ph systemoutput hljs language-undefined" data-highlighted="yes">admin></span><span class="ph userinput hljs language-nginx" data-highlighted="yes"> <span class="hljs-attribute">debug</span> software restart process management-server</span></div></pre>
|
|
</div>
|
|
</li>
|
|
</ol>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-206416</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
On the Panorama management server, no data filtering log (<span
|
|
class="ph menucascade"
|
|
><span class="ph uicontrol">Monitor</span
|
|
><span class="ph uicontrol">Logs</span
|
|
><span class="ph uicontrol">Data Filtering</span></span
|
|
>) is generated when the managed firewall loses connectivity to the
|
|
following cloud services, and as a result fails to forward matched
|
|
traffic for inspection.
|
|
</div>
|
|
<ul id="panos-known-issues-11.0.1_ul_ffx_b53_kvb" class="ul">
|
|
<li class="li"><div class="p">DLP cloud service</div></li>
|
|
<li class="li">
|
|
<div class="p">
|
|
Advanced Threat Protection inline cloud analysis service
|
|
</div>
|
|
</li>
|
|
<li class="li">
|
|
<div class="p">Advanced URL Filtering cloud service</div>
|
|
</li>
|
|
</ul>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-206315</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-1420 firewall only</tt>) In an active/passive
|
|
high availability (HA) configuration, the
|
|
<span class="ph systemoutput">show session info</span> CLI command
|
|
shows that the passive firewall has packet rate and throughput values.
|
|
The packet rate and throughput of the passive firewall should be zero
|
|
since it is not processing traffic.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-205009</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-1420 firewall only</tt>) In an active/passive
|
|
high availability (HA) configuration, the
|
|
<span class="ph systemoutput">show interface all</span>,
|
|
<span class="ph systemoutput"
|
|
>show-high availability interface ha2</span
|
|
>, and
|
|
<span class="ph systemoutput">show high-availability all</span> CLI
|
|
commands display the HSCI port state as unknown on both the active and
|
|
passive firewalls.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-204689</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Upon upgrade to PAN-OS 11.0.1, the following GlobalProtect settings do
|
|
not work:
|
|
</div>
|
|
<ul id="panos-known-issues-11.0.1_ul_l1b_zqp_xwb" class="ul">
|
|
<li class="li">
|
|
<span class="ph menucascade"
|
|
><span class="ph uicontrol"
|
|
>Allow user to disconnect GlobalProtect App</span
|
|
><span class="ph uicontrol">Allow with Passcode</span></span
|
|
>
|
|
</li>
|
|
<li class="li">
|
|
<span class="ph menucascade"
|
|
><span class="ph uicontrol"
|
|
>Allow user to Disable GlobalProtect App</span
|
|
><span class="ph uicontrol">Allow with Passcode</span></span
|
|
>
|
|
</li>
|
|
<li class="li">
|
|
<span class="ph menucascade"
|
|
><span class="ph uicontrol"
|
|
>Allow User to Uninstall GlobalProtect App</span
|
|
><span class="ph uicontrol">Allow with Password</span></span
|
|
>
|
|
</li>
|
|
</ul>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-201910</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
PAN-OS security profiles might consume a large amount of memory
|
|
depending on the profile configuration and quantity. In some cases,
|
|
this might reduce the number of supported security profiles below the
|
|
stated maximum for a given platform.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-199557</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
On M-600 appliances in an Active/Passive high availability (HA)
|
|
configuration, the
|
|
<span class="ph systemoutput">configd</span> process restarts due to a
|
|
memory leak on the
|
|
<span class="ph systemoutput">Active</span> Panorama HA peer. This
|
|
causes the Panorama web interface and CLI to become unresponsive.
|
|
</div>
|
|
<div class="p">
|
|
<b class="ph b">Workaround:</b> Manually reboot the
|
|
<span class="ph systemoutput">Active</span> Panorama HA peer.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-197588</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
The PAN-OS ACC (Application Command Center) does not display a widget
|
|
detailing statistics and data associated with vulnerability exploits
|
|
that have been detected using inline cloud analysis.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-197419</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-1400 Series firewalls only</tt>) In
|
|
<span class="ph menucascade"
|
|
><span class="ph uicontrol">Network</span
|
|
><span class="ph uicontrol">Interface</span
|
|
><span class="ph uicontrol">Ethernet</span></span
|
|
>, the power over Ethernet (PoE) ports do not display a
|
|
<span class="ph uicontrol">Tag</span> value.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-197097</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Large Scale VPN (LSVPN) does not support IPv6 addresses on the
|
|
satellite firewall.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-196758</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
On the Panorama management server, pushing a configuration change to
|
|
firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
|
|
configurations for SD-WAN as being edited or deleted despite no edits
|
|
or deletions being made when you
|
|
<span class="ph uicontrol">Preview Changes</span> (<span
|
|
class="ph menucascade"
|
|
><span class="ph uicontrol">Commit</span
|
|
><span class="ph uicontrol">Push to Devices</span
|
|
><span class="ph uicontrol">Edit Selections</span></span
|
|
>
|
|
or
|
|
<span class="ph menucascade"
|
|
><span class="ph uicontrol">Commit</span
|
|
><span class="ph uicontrol">Commit and Push</span
|
|
><span class="ph uicontrol">Edit Selections</span></span
|
|
>).
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-196146</b></div>
|
|
<div class="p">
|
|
<tt class="ph tt">This issue is now resolved. See </tt
|
|
><a
|
|
class="xref"
|
|
href="/content/techdocs/en_US/pan-os/11-0/pan-os-release-notes/pan-os-11-0-5-known-and-addressed-issues/pan-os-11-0-5-addressed-issues.html"
|
|
title=""
|
|
data-scope="local"
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>PAN-OS 11.0.5 Addressed Issues</a
|
|
><tt class="ph tt">.</tt>
|
|
</div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
The VM-Series firewall on Azure does not boot up with a hostname
|
|
(specified in an init-cgf.txt or user data) when bootstrapped.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-195968</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-1400 Series firewalls only</tt>) When using the
|
|
CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
|
|
prints an error depending on whether an interface type was selected on
|
|
the non-PoE port or not. If an interface type, such as tap, Layer 2,
|
|
or virtual wire, was selected before PoE was configured, the error
|
|
message will not include the interface name (eg. ethernet1/4). If an
|
|
interface type was not selected before PoE was configured, the error
|
|
message will include the interface name.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-195342</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
On the Panorama management server, Context Switch fails when you try
|
|
to Context Switch from a managed firewall running PAN-OS 10.1.7 or
|
|
earlier release back to Panorama and the following error is displayed:
|
|
</div>
|
|
<div class="p">
|
|
<span class="ph systemoutput"
|
|
>Could not find start token '@start@'</span
|
|
>
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-194978</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-1400 Series firewalls only</tt>) In
|
|
<span class="ph menucascade"
|
|
><span class="ph uicontrol">Network</span
|
|
><span class="ph uicontrol">Interface</span
|
|
><span class="ph uicontrol">Ethernet</span></span
|
|
>, hovering the mouse over a power over Ethernet (PoE)
|
|
<span class="ph uicontrol">Link State</span> icon does not display
|
|
link speed and link duplex details.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-194424</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-5450 firewall only</tt>) Upgrading to PAN-OS
|
|
10.2.2 while having a log interface configured can cause both the log
|
|
interface and the management interface to remain connected to the log
|
|
collector.
|
|
</div>
|
|
<div class="p">
|
|
<b class="ph b">Workaround:</b> Restart the log receiver service by
|
|
running the following CLI command:
|
|
<!-- FM Dita Overlay for Code -->
|
|
<div class="code-wrap">
|
|
<pre
|
|
class="pre codeblock"
|
|
data-label="PRE CODEBLOCK"
|
|
><div style="display: inline;"><span class="ph userinput hljs language-nginx" data-highlighted="yes"><span class="hljs-attribute">debug</span> software restart process log-receiver</span></div></pre>
|
|
</div>
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-187685</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
On the Panorama management server, the Template Status displays no
|
|
synchronization status (<span class="ph menucascade"
|
|
><span class="ph uicontrol">Panorama</span
|
|
><span class="ph uicontrol">Managed Devices</span
|
|
><span class="ph uicontrol">Summary</span></span
|
|
>) after a bootstrapped firewall is successfully added to Panorama.
|
|
</div>
|
|
<div class="p">
|
|
<b class="ph b">Workaround:</b> After the bootstrapped firewall is
|
|
successfully added to Panorama,
|
|
<a
|
|
class="xref"
|
|
href="https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-web-interface.html"
|
|
title=""
|
|
data-scope="external"
|
|
data-format="html"
|
|
data-type=""
|
|
target="_blank"
|
|
>log in to the Panorama web interface</a
|
|
>
|
|
and select
|
|
<span class="ph menucascade"
|
|
><span class="ph uicontrol">Commit</span
|
|
><span class="ph uicontrol">Push to Devices</span></span
|
|
>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-187407</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
The configured Advanced Threat Prevention inline cloud analysis action
|
|
for a given model might not be honored under the following condition:
|
|
If the firewall is set to
|
|
<span class="ph uicontrol"
|
|
>Hold client request for category lookup </span
|
|
>and the action set to
|
|
<span class="ph uicontrol">Reset-Both</span> and the URL cache has
|
|
been cleared, the first request for inline cloud analysis will be
|
|
bypassed.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-186283</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Templates appear out-of-sync on Panorama after successfully deploying
|
|
the CFT stack using the Panorama plugin for AWS.
|
|
</div>
|
|
<div class="p">
|
|
<b class="ph b">Workaround</b>: Use
|
|
<span class="ph menucascade"
|
|
><span class="ph uicontrol">Commit</span
|
|
><span class="ph uicontrol">Push to Devices</span></span
|
|
>
|
|
to synchronize the templates.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-184708</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Scheduled report emails (<span class="ph menucascade"
|
|
><span class="ph uicontrol">Monitor</span
|
|
><span class="ph uicontrol">PDF Reports</span
|
|
><span class="ph uicontrol">Email Scheduler</span></span
|
|
>) are not emailed if:
|
|
</div>
|
|
<ul id="panos-known-issues-11.0.1_ul_bqh_5qx_rsb" class="ul">
|
|
<li class="li">
|
|
A scheduled report email contains a Report Group (<span
|
|
class="ph menucascade"
|
|
><span class="ph uicontrol">Monitor</span
|
|
><span class="ph uicontrol">PDF Reports</span
|
|
><span class="ph uicontrol">Report Group</span></span
|
|
>) which includes a SaaS Application Usage report.
|
|
</li>
|
|
<li class="li">
|
|
A scheduled report contains only a SaaS Application Usage Report.
|
|
</li>
|
|
</ul>
|
|
<div class="p">
|
|
<b class="ph b">Workaround:</b> To receive a scheduled report email
|
|
for all other PDF report types:
|
|
</div>
|
|
<ol id="panos-known-issues-11.0.1_ol_jgs_zqx_rsb" class="ol">
|
|
<li class="li">
|
|
Select
|
|
<span class="ph menucascade"
|
|
><span class="ph uicontrol">Monitor</span
|
|
><span class="ph uicontrol">PDF Reports</span
|
|
><span class="ph uicontrol">Report Groups</span></span
|
|
>
|
|
and remove all SaaS Application Usage reports from all Report
|
|
Groups.
|
|
</li>
|
|
<li class="li">
|
|
Select
|
|
<span class="ph menucascade"
|
|
><span class="ph uicontrol">Monitor</span
|
|
><span class="ph uicontrol">PDF Reports</span
|
|
><span class="ph uicontrol">Email Scheduler</span></span
|
|
>
|
|
and edit the scheduled report email that contains only a SaaS
|
|
Application Usage report. For the Recurrence, select
|
|
<span class="ph uicontrol">Disable</span> and click
|
|
<span class="ph uicontrol">OK</span>.
|
|
<div class="p">
|
|
Repeat this step for all scheduled report emails that contain only
|
|
a SaaS Application Usage report.
|
|
</div>
|
|
</li>
|
|
<li class="li">
|
|
<span class="ph uicontrol">Commit</span>.
|
|
<div class="p">
|
|
(<tt class="ph tt">Panorama managed firewalls</tt>) Select
|
|
<span class="ph menucascade"
|
|
><span class="ph uicontrol">Commit</span
|
|
><span class="ph uicontrol">Commit and Push</span></span
|
|
>
|
|
</div>
|
|
</li>
|
|
</ol>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-184406</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Using the CLI to add a RAID disk pair to an M-700 appliance causes the
|
|
dmdb process to crash.
|
|
</div>
|
|
<div class="p">
|
|
<b class="ph b">Workaround:</b> Contact customer support to stop the
|
|
dmdb process before adding a RAID disk pair to a M-700 appliance.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-183404</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Static IP addresses are not recognized when "and" operators are used
|
|
with IP CIDR range.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-182734</b></div>
|
|
<div class="p">
|
|
<tt class="ph tt">This issue is now resolved. See </tt
|
|
><a
|
|
class="xref"
|
|
href="/content/techdocs/en_US/pan-os/11-0/pan-os-release-notes/pan-os-11-0-2-known-and-addressed-issues/pan-os-11-0-2-addressed-issues.html"
|
|
title=""
|
|
data-scope="local"
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>PAN-OS 11.0.2 Addressed Issues</a
|
|
><tt class="ph tt">.</tt>
|
|
</div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
On an Advanced Routing Engine, if you change the IPSec tunnel
|
|
configuration, BGP flaps.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-181933</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
|
|
all of the cards may not receive all of the updates and the mappings
|
|
for the clients may become out of sync, which causes the firewall to
|
|
not correctly populate the Source User column in the session logs.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-171938</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
No results are displayed when you
|
|
<span class="ph uicontrol">Show Application Filter</span> for a
|
|
Security policy rule (<span class="ph menucascade"
|
|
><span class="ph uicontrol">Policies</span
|
|
><span class="ph uicontrol">Security</span
|
|
><span class="ph uicontrol">Application</span
|
|
><span class="ph uicontrol">Value</span
|
|
><span class="ph uicontrol">Show Application Filter</span></span
|
|
>).
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-164885</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
On the Panorama management server, pushes to managed firewalls (<span
|
|
class="ph menucascade"
|
|
><span class="ph uicontrol">Commit</span
|
|
><span class="ph uicontrol">Push to Devices</span></span
|
|
>
|
|
or <span class="ph uicontrol">Commit and Push</span>) may fail when an
|
|
EDL (<span class="ph menucascade"
|
|
><span class="ph uicontrol">Objects</span
|
|
><span class="ph uicontrol">External Dynamic Lists</span></span
|
|
>) is configured to
|
|
<span class="ph uicontrol">Check for updates</span> every 5 minutes
|
|
due to the commit and EDL fetch processes overlapping. This is more
|
|
likely to occur when multiple EDLs are configured to check for updates
|
|
every 5 minutes.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|