Files
firewallissues/reference/PAN-OS/addressed/11.2.3.html
T

1817 lines
52 KiB
HTML

<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263387</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall web interface was blank after
logging in.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263226</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where decryption based traffic failed on Explicit Proxy
nodes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262593</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic to websites failed on the Google Chrome
web browser on Secure Web Gateway (SWG) nodes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262287</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where dereferencing a NULL pointer that occurred when
App-ID stopped responding caused the firewall to restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262013</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Prisma Access mobile users did not receive
<span class="ph uicontrol">no such name</span> DNS responses from the
firewall and were timed out.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261991</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic that did not match a decryption policy
rule, or matched a no-decrypt policy rule, failed when accumulation
proxy was enabled and a Zone Protection profile was configured with
syn-cookies enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261917</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where websites with a no-decrypt policy rule were
decrypted in the traffic log when using a Google Chrome browser with
PQC enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261797</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where fragmented IP packets were dropped silently.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261270</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall decremented the TTL/Hop limit for
BGPv6 packets by 1 after IPSec decryption.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260059</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">Device Telemetry Regions</span> did not
show up with the latest content due to content files not being parsed
for the region list when Telemetry was turned off.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259964</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was not able to handle a high
traffic load, which caused some logs to be lost.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259769</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect portal was not accessible via a
web browser and displayed the error
<span class="ph systemoutput">ERR_EMPTY_RESPONSE</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259733</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a custom report was not deleted on Panorama when
expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259480</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>varrcvr</a
>
process stopped responding after running out of memory due to how the
process queued and dequeued files for WildFire file forwarding when a
WildFire Analysis Security profile was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259473</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
the chassis shut down when FAN1 was removed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259151</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where unused objects were pushed to the firewall, which
caused configuration pushes to fail with the error
<span class="ph systemoutput"
>Number of address groups exceed platform capacity</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-258442</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where changes made to the split tunnel configuration on
the Prisma Access gateway were not reflected on the GlobalProtect
client.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257957</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls and Panorama appliances in FIPS-CC mode only</tt
>) Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>authd</a
>
process restarted if RADIUS PAP/CHAP authentication was used.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257925</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">CN-Series firewalls only</tt>) Fixed an issue where
the CLI command
<span class="ph systemoutput">show system setting ctd state</span> did
not work as expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257624</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall web interface was blank after
logging in.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257615</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where logs did not display or displayed
intermittently on the web interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257563</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
component for SASE and MCW displayed incorrect zones in the traffic
flow.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257515</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Possible Domain Fronting Detection for HTTP/2
generated false positives. With this change, domain fronting is
limited to HTTP/1.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257462</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>varrcvr</a
>
process where the management plane CPU was higher than expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257432</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process stopped responding, which caused a log query issue.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257390</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5250 firewalls only</tt>) Fixed an issue where
the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process stopped responding due to a segmentation fault.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257355</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a false positive HTTP/TLS evasion alert was
generated when the domain had DNS load balance.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257197</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where <span class="ph systemoutput">ifType</span> and
<span class="ph systemoutput">ifSpeed</span> were not populated in
asynchronous mode of SNMP operations.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256939</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where disk space was low in
<span class="ph systemoutput">/opt/pancfg/</span>, which caused
dynamic content installation to fail.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256765</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were unable to push variables from Panorama
in service routes for non-cluster templates.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256738</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls in HA configurations only</tt>)
Fixed an issue where BGP routes from the active firewall were lost
when the passive firewall was rebooted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256666</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding when
<span class="ph uicontrol">Commit and Push</span> operations were
performed on multiple device groups.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256385</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">CN-Series firewalls only</tt>) Fixed an issue where
communication was broken between the management plane and the
dataplane when Anti-Spyware profiles were configured in a Security
policy rule.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256327</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Panorama virtual appliances on Microsoft Azure environments
only</tt
>) Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logd</a
>
process repeatedly restarted due to a buffer overflow when generating
a traffic summary from a traffic log.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256249</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface that occurred when changing the
pre-shared key to a variable (<span class="ph uicontrol"
>Network &gt; Network Profiles &gt; IKE Gateways</span
>).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256223</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where device telemetry log collection filled the root
partition.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256181</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the management interface and front panel port
interface statistics were not populated in asynchronous mode of SNMP
operations.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255895</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama administrators with the
<span class="ph uicontrol">Panorama Administrator</span> dynamic
administrator type were not able to create or modify BGP timer
profiles or BGP dampening profiles.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255820</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the WildFire signature generation check box in
Panorama did not register a change in the configuration.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255711</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall displayed a malformed request error
when selecting a custom format and clicking
<span class="ph uicontrol">OK</span> on the configuration window due
to the log type
<span class="ph uicontrol">Correlation</span> incorrectly being
displayed (<span class="ph uicontrol"
>Device &gt; Log Setting - Correlation &gt; Syslog Server Profile
&gt; Custom Log Format &gt; Correlation</span
>).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255611</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where newly added routes were not
automatically sorted based on subnets when added to a redistribution
profile.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255441</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where BGP-ARE routes were not advertised due to a peer
route map filter.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255396</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when using serial number and IP address
authentication, and multiple gateways were configured, the portal
returned the last gateway in the list and disregarded the satellite
assignment by serial number.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255391</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to filter logs using the
ISO 8601 timestamp format after upgrading to PAN-OS 11.0.4 or a later
release.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255266</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were unable to clone a template stack with
the Pre-Shared Key variable.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255252</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama administrators with the type Dynamic
were unable to create, modify, or delete BGP Dampening profiles.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-255163</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">CN-Series firewalls only</tt>) Fixed an issue where
the system database key that stored the configuration status of the
dataplane pod was not updated frequently.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254826</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding when processing
traffic.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254629</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Management Processing Card where excessive logs
were generated for an error.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254621</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall frequently rebooted due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>brdagent</a
>
process not responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254577</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a core file was created on the Log Forwarding
Card (LFC) due to a third-party software issue.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254425</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not restrict port 9905 to
<span class="ph systemoutput">localhost</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254423</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where custom role-based admin users with
read-only access were able to make changes to configurations.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254422</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall required a restart when an SD-WAN
policy rule was pushed from Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254411</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding, which caused
<span class="ph uicontrol">ERR_CONNECTION_REFUSED</span> error
messages to be displayed in admin sessions.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254373</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not handle error code 500
responses from the WildFire cloud correctly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254241</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding due to a high
number of SD-WAN probes being sent.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254181</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">CN-Series firewalls only</tt>) Fixed an issue where
firewall pods and application pods repeatedly restarted.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-253829</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the CLI command
<span class="ph systemoutput">show running security-policy</span>
timed out when the Security policy was large.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253819</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a
<span class="ph uicontrol">User Activity Report</span> was not
generated by <span class="ph uicontrol">Run Now</span> or not emailed
through the <span class="ph uicontrol">Email Schedule</span> when the
locale setting was not English.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253452</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect users were unable to connect to the
GlobalProtect gateway and received the error
<span class="ph systemoutput">Gateway does not exist</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253317</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Microsoft Azure environments only</tt
>) Fixed an issue where you were unable to log in to the firewall
after a private data reset.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252867</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an incorrect memory reference in an IoT API
caused the <span class="ph systemoutput">wifclient</span> process to
stop responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252517</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SNMP failed to respond to multiple Object
Identifier (OID) queries in a single SNMP GET request.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-252411</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when log files were purged from the rollup
summary logs, the summary report still used the rollup summary data,
which resulted in the summary report displaying less data.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-251909</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a Panorama pushed configuration failed to commit
on the firewall due to the address object referenced by the interface
not being shared with the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-251732</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Oracle traffic over generic routing encapsulation
(GRE) was dropped when the traffic passed through the firewall using
ttunnel content inspection (TCI).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-251676</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama appliances in large-scale deployments where
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process core files consumed more space in the /opt/panlogs partition
than was available.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-251661</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory overwrite occurred during HTTP/2 header
inflation.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-251656</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where enabling lockless QoS caused traffic disruptions.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-251655</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped forwarding files to the
WildFire cloud and a restart of the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>varrcvr</a
>
process was required.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-251446</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a critical system log was generated for a SAML
authenticated user whose username length was greater than 32
characters.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-251047</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process logs were flooded with an error message related to service
profiles.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250948</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issues where GlobalProtect on Microsoft Windows devices did
not attempt CNAME resolution for sinkhole.paloaltonetworks.com.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250909</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when creating a Security policy rule via the
CLI, validation was not implemented and the same object was able to be
referenced in the policy twice.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250787</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where network issues between the firewall and the log
collector caused
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process memory exhaustion.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250597</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Global Find for a Panorama pushed shared address
object displayed <span class="ph uicontrol">Others</span> in the
results.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250462</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the session logout time for the firewall was
incorrect when viewing via context switch from Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250419</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where XML API explorer inserted a plus (+) character in
the Xpath when a space was used in the object name.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250405</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">CN-Series firewalls only</tt>) Fixed an issue on
the firewall where
<span class="ph systemoutput">websrvr</span> related messages
displayed repeatedly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250311</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the domain was not mapped when using certificate
profile authentication on GlobalProtect.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250258</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where the Certificate Name character
limit was 31 characters instead of 63 characters.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250127</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where commits failed with the error message
<span class="ph systemoutput">set is not allowed</span> when
<span class="ph uicontrol">default originate</span> was enabled with a
route map that included a set action.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250024</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process where you were unable to log in to Panorama via the web
interface and received a 500 error.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250021</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">Change Summary</span> and
<span class="ph uicontrol">Preview Changes</span> displayed
inconsistent information when changing an admin user password.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250005</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Advanced Routing migration script did not
migrate BGP import policy rules correctly when the policy rule was
configured with an exact match condition.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-249855</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dropped the active source of the
Multicast source via MSDP when they were not received from the MSDP
peer firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-249404</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where the commit lock for
a device group and template with the same name was not visible.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-249266</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>config</a
>
process virtual memory was exceeded due to delays in post-commit
processing.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-248975</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where no content was
displayed after logging in.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-248841</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the SSL response time was not displayed in the
GlobalProtect log.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-248542</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the NPB policy type was missing from
configuration policy updates, which caused error messages to
incorrectly display in the system logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-248211</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where commits failed when Advanced Routing
was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-248130</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph uicontrol">AND</span> operation under a Dynamic
Address Group comparison did not work after upgrading the AWS plugin
to 3.0.1.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-247857</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7050 firewalls in HA configurations only</tt>)
Fixed an issue on the firewall where a dataplane process restarted
when updating the routing table.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-247754</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where successful
<span class="ph uicontrol">Commit and Push</span> operations performed
by SAML authenticated users were not reflected on the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-247575</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the error message
<span class="ph systemoutput"
>import of &lt;issuecert&gt; failed. Please check the validity of
the key pair and try again</span
>
for unmatched keys for EC certificates.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-247426</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a proxy server was used for External Dynamic List
communication even when the dataplane interface was configured through
service routes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-247257</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process stopped responding, which caused the firewall to reboot.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-247230</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the syslog forwarding configuration did not
include the full path for Security policy rules.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-246772</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where the dataplane went down due to a
path monitor failure caused by an out-of-memory (OOM) condition
related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-246769</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where deny logs were not displayed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-246220</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a dynamic peer connection was rejected when using
an FQDN for the peer address.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-246056</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where single TLS session packets were sent to multiple
firewalls when off-loading was enabled and ECMP was disabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-245892</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Log Filtering (<span class="ph uicontrol"
>Monitor &gt; Logs</span
>) was slower than expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-245556</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dropped VxLAN packets via v-wire
after upgrading to PAN-OS 10.1.10 or a later release, which impacted
SMB traffic and resulted in silent packet drops.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-244746</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where changes committed on Panorama were not reflected
on the firewall after a successful push.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-243957</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall TLS/SSL service profile exclusion
settings were not correctly applied on the captive portal.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-243387</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where sessions ended with the message
<span class="ph uicontrol">resources-unavailable</span> when traffic
hit a Security profile.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-243240</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the using QoS caused packet buffer utilization to
increase exponentially and the
<span class="ph systemoutput">PKI POOL DFLT</span> pool depleted until
a reboot was performed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-243098</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with corrupted images when SSL decryption and Security
profiles were configured.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-243081</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where log filtering with special
characters in the username incorrectly returned results.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-242958</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall intermittently logged
<span class="ph systemoutput">connect-agent-failure</span> messages
for service connection instances due to bi-directional host ID
redistribution.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-242331</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Prisma Access remote network firewalls
intermittently created incorrect user-to-IP-address mappings.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-242147</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-1410 firewalls only</tt>) Fixed an issue where
the firewall did not block STP packets when the ports on the connected
routers were in access mode.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-241781</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where partial
<span class="ph systemoutput">commit</span> and
<span class="ph systemoutput">commit-all</span> operations took more
time than expected to create the job ID.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-241044</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic was denied by the interzone-default
policy rule when a Security policy rule with an FQDN destination was
configured.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-239246</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the CLI command
<span class="ph systemoutput"
>debug user-id dump hip-based-profile-database-entry</span
>
returned an incorrect value in the output for the
<span class="ph systemoutput">total size of hip reports</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-237582</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where logs were intermittently missing on the log
collector due to missing aliases for some indices.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-236497</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to purge expired GTP-U
sessions that remained as allocated sessions even after the TTL was
expired.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-235110</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-220 firewalls only</tt>) Fixed an issue where
the web interface did not load after an upgrade.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-234560</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the daily summary report displayed IPv6 addresses
instead of IPv4 addresses.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-232550</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SNMPv3 authentication failed when using SHA-512
Auth protocol.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-231642</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where users that were
logged in through multiple sessions were able to see an active lock on
only one session.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-230326</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Network Packet Broker (NPB) user interface
was incorrectly displayed on unsupported platforms.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-226785</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where accessing websites with HTTP to HTTPS redirect
failed via explicit proxy.
</div>
</td>
</tr>
</tbody>
</table>