Files
firewallissues/reference/PAN-OS/addressed/11.2.10-h7.html
T
2026-05-15 09:34:02 -05:00

1148 lines
41 KiB
HTML

<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 34%" />
<col style="width: 66%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-314201</b></div>
<div class="p">
<tt class="ph tt">This issue is now resolved. See </tt
><a
class="xref"
href="/content/techdocs/en_US/ngfw/release-notes/12-1/pan-os-12-1-6-known-and-addressed-issues/pan-os-12-1-6-addressed-issues.html"
title=""
data-scope="local"
data-format="dita"
data-type=""
target="_self"
>PAN-OS 12.1.6 Addressed Issues</a
>
</div>
</td>
<td class="entry relcol">
<div class="p">
On firewalls running PAN-OS 12.1, IPsec VPN tunnels to third-party
peer devices may experience intermittent traffic loss during rekey
operations. When a new Security Association (SA) forms before the old
SA expires, traffic may stop flowing until the older SA naturally
expires or you manually clear it. During this time, the output of show
vpn ipsec-sa may show two SAs for the same proxy ID. This issue
primarily affects tunnels to third-party peer devices and does not
occur with Palo Alto Networks to Palo Alto Networks tunnels.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Manually clear the affected Security
Association using the command
<span class="ph userinput"
>clear vpn ipsec-sa tunnel &lt;tunnel-name&gt;</span
>
to restore connectivity.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-313623</b></div>
</td>
<td class="entry relcol">
<div class="p">
On firewalls with TPM (Trusted Platform Module) support, device
certificate renewals may fail due to a disk partition being full. This
latter occurs because temporary files aren't being deleted during
device certificate status checks.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-312706</b></div>
<div class="p">
<tt class="ph tt">This issue is now resolved. See </tt
><a
class="xref"
href="/content/techdocs/en_US/ngfw/release-notes/12-1/pan-os-12-1-5-known-and-addressed-issues/pan-os-12-1-5-addressed-issues.html"
title=""
data-scope="local"
data-format="dita"
data-type=""
target="_self"
>PAN-OS 12.1.5 Addressed Issues</a
>.
</div>
</td>
<td class="entry relcol">
<div class="p">
Firewalls may restart unexpectedly due to an internal error in content
inspection processing. This issue can occur when the firewall is
performing antivirus scanning, URL filtering, or WildFire analysis.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-309604</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5500 series only</tt>) In some rare cases, the
front panel PSU status LED might show amber, even when the LEDs on the
PSU show green.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-309602</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5500 series only</tt>) When the firewall is
initially powered on, the FAN-0 LED does not turn on. The fan
functions correctly, but the LED doesn't reflect the status.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Remove and reinsert the fan to turn on
the LED.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-308564</b></div>
</td>
<td class="entry relcol">
<div class="p">
Packets are dropped on SD-WAN interfaces if they require fragmentation
for an interface but have the
<span class="ph uicontrol">Don't Fragment (DF)</span> bit set. This
results in unexpected packet drops. This affects client to server
sessions when using SD-WAN for NGFW.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Allow fragmenting packets with DF bit
set (<span class="ph userinput"
>debug dataplane set ip4-ignore-df yes</span
>).
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-308507</b></div>
<div class="p">
<tt class="ph tt">This issue is now resolved. See </tt
><a
class="xref"
href="/content/techdocs/en_US/ngfw/release-notes/12-1/pan-os-12-1-6-known-and-addressed-issues/pan-os-12-1-6-addressed-issues.html"
title=""
data-scope="local"
data-format="dita"
data-type=""
target="_self"
>PAN-OS 12.1.6 Addressed Issues</a
>.
</div>
</td>
<td class="entry relcol">
<div class="p">
Strata Logging Service (SLS) log-forwarding streams intermittently
show as inactive. When checking the status of log-forwarding
connections, one or more streams are reported as inactive. Restarting
the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>log-receiver</a
>
process temporarily resolves the issue, but the streams become
inactive again after approximately 1-2 hours. This intermittent
inactivity results in log loss.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-307702</b></div>
<div class="p">
<tt class="ph tt">This issue is now resolved. See </tt
><a
class="xref"
href="/content/techdocs/en_US/ngfw/release-notes/12-1/pan-os-12-1-5-known-and-addressed-issues/pan-os-12-1-5-addressed-issues.html"
title=""
data-scope="local"
data-format="dita"
data-type=""
target="_self"
>PAN-OS 12.1.5 Addressed Issues</a
>.
</div>
</td>
<td class="entry relcol">
<div class="p">
When LACP pre-negotiation is enabled on firewalls in HA
configurations, traffic passing through aggregate Ethernet (AE)
interfaces may be interrupted for several minutes during HA failovers.
This occurs because the suspended (formerly active) firewall continues
to forward packets for active sessions even after the failover
completes, causing MAC address flapping on neighboring switches.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-305880</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7500 firewalls only</tt>) Intermittent internet
connectivity failures on the logging interface might trigger a
dataplane disconnect from Strata Logging Service (SLS) and WildFire
cloud.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-305301</b></div>
<div class="p">
<tt class="ph tt">This issue is now resolved. See </tt
><a
class="xref"
href="/content/techdocs/en_US/ngfw/release-notes/12-1/pan-os-12-1-5-known-and-addressed-issues/pan-os-12-1-5-addressed-issues.html"
title=""
data-scope="local"
data-format="dita"
data-type=""
target="_self"
>PAN-OS 12.1.5 Addressed Issues</a
>.
</div>
</td>
<td class="entry relcol">
<div class="p">
The timing of GlobalProtect lifetime expiry or inactivity logout
notifications used for GlobalProtect SSL tunnels may cause the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process to stop responding and the dataplane to restart.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Select
<span class="ph uicontrol"
>Network &gt; GlobalProtect &gt; Gateways &gt;
&lt;gateway-config&gt; &gt; Agent &gt; &lt;agent-config&gt; &gt;
Connection Settings</span
>
and change the value of both
<span class="ph uicontrol">Notify Before Lifetime Expires (min)</span>
and
<span class="ph uicontrol"
>Notify Before Inactivity Logout (min)</span
>
to 0.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-304718</b></div>
<div class="p">
<tt class="ph tt">This issue is now resolved. See </tt
><a
class="xref"
href="/content/techdocs/en_US/ngfw/release-notes/12-1/pan-os-12-1-5-known-and-addressed-issues/pan-os-12-1-5-addressed-issues.html"
title=""
data-scope="local"
data-format="dita"
data-type=""
target="_self"
>PAN-OS 12.1.5 Addressed Issues</a
>.
</div>
</td>
<td class="entry relcol">
<div class="p">
When using GlobalProtect Clientless VPN, the firewall may restart
unexpectedly, causing routing protocol (OSPF and BGP) outages. This
issue occurs during web content processing for clientless VPN
sessions.
</div>
<div class="p">
<b class="ph b">Workaround:</b> To prevent this issue until you can
upgrade to a fixed release, disable clientless VPN in your
GlobalProtect portal configuration.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-304576</b></div>
<div class="p">
<tt class="ph tt">This issue is now resolved. See </tt
><a
class="xref"
href="/content/techdocs/en_US/ngfw/release-notes/12-1/pan-os-12-1-5-known-and-addressed-issues/pan-os-12-1-5-addressed-issues.html"
title=""
data-scope="local"
data-format="dita"
data-type=""
target="_self"
>PAN-OS 12.1.5 Addressed Issues</a
>.
</div>
</td>
<td class="entry relcol">
<div class="p">
Traffic interruption may occur when inspection of HTTP/2 traffic is
enabled.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Disable HTTP/2 server push using the
<span class="ph userinput"
>set deviceconfig setting http2 server-push no</span
>
CLI command.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-303959</b></div>
<div class="p">
<tt class="ph tt">This issue is now resolved. See </tt
><a
class="xref"
href="/content/techdocs/en_US/ngfw/release-notes/12-1/pan-os-12-1-5-known-and-addressed-issues/pan-os-12-1-5-addressed-issues.html"
title=""
data-scope="local"
data-format="dita"
data-type=""
target="_self"
>PAN-OS 12.1.5 Addressed Issues</a
>.
</div>
</td>
<td class="entry relcol">
<div class="p">
Traffic that is incorrectly identified as unknown-tcp/unknown-udp
eventually drops due to an App-ID resource limitation issue.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-303663</b></div>
<div class="p">
<tt class="ph tt">This issue is now resolved. See </tt
><a
class="xref"
href="/content/techdocs/en_US/ngfw/release-notes/12-1/pan-os-12-1-5-known-and-addressed-issues/pan-os-12-1-5-addressed-issues.html"
title=""
data-scope="local"
data-format="dita"
data-type=""
target="_self"
>PAN-OS 12.1.5 Addressed Issues</a
>.
</div>
</td>
<td class="entry relcol">
<div class="p">
After upgrading to an affected release, SNMP monitoring systems such
as SolarWinds may report 100% usage for hardware packet buffers on
PA-3400 Series and PA-5450 firewalls, even when the firewall is idle
and packet buffer utilization is normal. The packet buffer utilization
oid is fixed to not show incorrect values.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300850</b></div>
</td>
<td class="entry relcol">
<div class="p">
Manual scheduling of cloud verdicts is required if a new host in an
Host Compliance Service-enabled environment has a refresh event entry
without a corresponding update event entry.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300809</b></div>
</td>
<td class="entry relcol">
<div class="p">
Host Compliance Service connectivity will not work if it is connected
with management IP which is configured with DHCP mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300677</b></div>
</td>
<td class="entry relcol">
<div class="p">
Panorama cannot display Threat log entries (<b class="ph b"
>Monitor &gt; Logs &gt; Threat</b
>) when the managed log collector is running a lower PAN-OS release
than Panorama.
</div>
<div class="p">
Workaround: Upgrade the log collectors to the same version as
Panorama.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300671</b></div>
<div class="p">
<tt class="ph tt">This issue is now resolved. See </tt
><a
class="xref"
href="/content/techdocs/en_US/ngfw/release-notes/12-1/pan-os-12-1-5-known-and-addressed-issues/pan-os-12-1-5-addressed-issues.html"
title=""
data-scope="local"
data-format="dita"
data-type=""
target="_self"
>PAN-OS 12.1.5 Addressed Issues</a
>.
</div>
</td>
<td class="entry relcol">
<div class="p">
Traffic reports that display destination/source IP addresses or
destination/source hostnames may incorrectly show IPv4 addresses in
IPv6 format (for example, ::ffff:x.x.x.x). This issue affects both
custom reports and scheduled reports, including PDF exports.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300627</b></div>
</td>
<td class="entry relcol">
<div class="p">
AutoCommit fails when the Traffic Object is used on AI Runtime
Security, which consequently impacts the workloads that utilize
overlapping subnets.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300483</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7500 firewall only</tt>) Enabling FIPS-CC mode
causes the firewall to go into maintenance mode.
</div>
<div class="p">
<b class="ph b">Workaround</b>: After the firewall goes into
maintenance mode, perform an additional reboot. The firewall will
successfully start up in FIPS-CC mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300467</b></div>
</td>
<td class="entry relcol">
<div class="p">
WildFire WF-500 appliances running PAN-OS 10.x or PAN-OS 11.x cannot
be managed by Panorama running PAN-OS 12.1.2 due to connectivity
issues.
</div>
<div class="p">
<b class="ph b">Workaround:</b> Upgrade your WildFire appliances to
PAN-OS 12.1.2 or later.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300407</b></div>
</td>
<td class="entry relcol">
<div class="p">
The Release Note URL column in the Panorama &gt; Plugins page is
empty.
</div>
<div class="p">
Release Notes for the plugins are available in the
<a
class="xref"
href="https://docs.paloaltonetworks.com/plugins/vm-series-and-panorama-plugins-release-notes"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>plugins release notes</a
>
or in their individual product release notes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300230</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">NGFW Cluster</tt>) In an NGFW cluster, your pings
to the HSCI-B link might fail, even when the link indicates it is up.
In the event that the HSCI-A link is brought down or unplugged, the
cluster node will transition to failed state, avoiding split brain as
both HSCI links are down in this case.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Reboot the cluster node to resolve the
HSCI-B ping issue.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300192</b></div>
</td>
<td class="entry relcol">
<div class="p">
If the Host Compliance Service is configured with a service route
pointing to an unreachable IP address, the
<span class="ph systemoutput">gp_broker</span> process may stop
working when you enable-disable the Host Compliance Service.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300114</b></div>
</td>
<td class="entry relcol">
<div class="p">
VM entered maintenance mode during a downgrade from version 12.1.2 to
11.2.7, when executed through the CLI.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Download and install the required
version of PAN-OS through the UI instead of the CLI.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300069</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-410 firewall only</tt>) Loading a saved config
file can take up to 5 minutes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300053</b></div>
</td>
<td class="entry relcol">
<div class="p">
When you use the CLI command
<span class="ph userinput">request system fqdn refresh</span> to
trigger another IP address resolution of configured FQDN entries, the
firewall might get into an error state where the DNS Proxy cache
received and stored a new IP address for a particular FQDN entry via
this command. However, the Device-Server (and the Security rule) still
have the old IP address for that FQDN entry.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Avoid using the CLI command:
<span class="ph userinput">request system fqdn refresh</span>. Use the
following command instead (for a particular domain-name or an entire
list):
<span class="ph userinput"
>clear dns-proxy cache all domain-name &lt;domain_name&gt;</span
>. To correct the error state where the DNS Proxy cache and
Device-Server and Security rule are already storing different IP
addresses, use the following CLI command:
<span class="ph userinput"
>debug device-server dump fqdn type resync vsys &lt;vsys_name&gt;
fqdn-name &lt;domain_name&gt;</span
>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-300025</b></div>
</td>
<td class="entry relcol">
<div class="p">
If Azure hotplug events occur, the firewall may experience a
<span class="ph userinput">brdagent</span> crash and data interfaces
may transition to an unknown state, leading to traffic disruption.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Reboot the VM if the
<span class="ph userinput">brdagent</span> crash does not trigger a
device reboot.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-299562</b></div>
</td>
<td class="entry relcol">
<div class="p">
SSL proxy sessions fail when clients send a Client Hello with TLSv1.2
and TLSv1.3, and exclusively prefer the secp192 elliptic curve.
</div>
<div class="p">
<b class="ph b">Workaround</b>: To address this, configure a
decryption profile to use TLSv1.2 as the maximum supported TLS
version. Then, apply this profile to the decryption policy rules for
the affected clients and servers. This enables the client to modify
its preferred curves, facilitating successful session establishment.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">PAN-299387</b></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">NGFW Cluster</tt>) When an NGFW cluster has only
one firewall node present and powered up, that node is stuck in
UNKNOWN state after you reboot it and it comes back up. The issue
occurs in two scenarios:
</div>
<ul id="panos-known-issues-12.1.4_ul-pfz_hyt_tgc" class="ul">
<li class="li">
When there is only one node configured in the cluster (no peer is
available or configured).
</li>
<li class="li">
When the peer device in the cluster is completely powered down or
unable to autonegotiate its connected HSCI ports. That is, two nodes
are in the cluster, but only one node is booting up while the other
remains down completely.
</li>
</ul>
<div class="p">
The expected behavior is that if no peer device is available (at a
port autonegotiation or link level for HSCI-A or HSCI-B), then a
cluster device should go to INITIAL state, followed by ONLINE state
(and not remain in UNKNOWN state).
</div>
<div class="p">
<b class="ph b">Workaround</b>: To avoid this issue, connect the
HSCI-A to HSCI-B in loopback to create a link partner.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">PAN-299229</b></td>
<td class="entry relcol">
<div class="p">
On PA-5400 Series and PA-7500 Series firewalls, if you run certain
types of CLI commands during or shortly after a commit, the commands
will time out. The types of CLI commands impacted by this issue are
IoT, Cloud-User-ID, and App-ID Cloud Engine CLI commands.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Don't execute IoT, Cloud-User-ID, or
App-ID Cloud Engine CLI commands during or shortly after a commit on a
PA-5400 Series or PA-7500 Series firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">PAN-299170</b></td>
<td class="entry relcol">
<div class="p">
The remediation link included in the generated PDF of an upgrade check
report might be pruned due to a text length limitation of the export
function. The link remains fully functional and works correctly on the
Panorama web interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">PAN-299114</b></td>
<td class="entry relcol">
<div class="p">
After you enable the
<span class="ph uicontrol"
>Enable Duplicate Logging (Cloud and On-Premise) </span
>setting on a firewall, clicking
<span class="ph uicontrol">Status for Cloud Logging</span>, does not
display the logging service connection status.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">PAN-298540</b></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5500 Series firewalls only</tt>) The
<span class="ph uicontrol">Monitor</span> tab in the Web Interface
does not display a pop-up to indicate that high-speed log forwarding
is enabled and that logs are only viewable from Panorama.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">PAN-298083</b></td>
<td class="entry relcol">
<div class="p">
After you change the system mode on an M-700 appliance from Panorama
mode to PAN-DB private cloud mode, the
<span class="ph codeph">snmpd</span> process fails to work.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">PAN-298047</b></td>
<td class="entry relcol">
<div class="p">
In an AI Runtime Security environment, the Azure Container outbound
traffic does not seem to be functional and the egress traffic is being
misdirected to an incorrect cluster node port.
</div>
</td>
</tr>
<tr class="row">
<td class="entry"><b class="ph b">PAN-297772</b></td>
<td class="entry relcol">
<div class="p">
When an Intel e810 NIC is configured in SR-IOV mode, sharing Virtual
Functions (VFs) among multiple HSF cluster nodes and subsequently
rebooting a cluster node while traffic is active may result in traffic
disruption on other HSF cluster nodes utilizing the same NIC. It is
recommended to refrain from sharing Intel e810 VFs across cluster
nodes and to allocate one VF per Intel e810 PF.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297610</b></div>
<div class="p">
<tt class="ph tt">This issue is now resolved. See </tt
><a
class="xref"
href="/content/techdocs/en_US/ngfw/release-notes/12-1/pan-os-12-1-5-known-and-addressed-issues/pan-os-12-1-5-addressed-issues.html"
title=""
data-scope="local"
data-format="dita"
data-type=""
target="_self"
>PAN-OS 12.1.5 Addressed Issues</a
>.
</div>
</td>
<td class="entry relcol">
<div class="p">
A firewall may become unresponsive after an upgrade due to the `fsck`
command scanning drive partitions in parallel with the root partition,
causing the process to take an extended amount of time.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297114</b></div>
</td>
<td class="entry relcol">
<div class="p">
After successfully generating a health check report for managed
firewalls from Panorama, the progress bar does not appear and the
latest health check reports are not displayed (<span
class="ph uicontrol"
>Panorama &gt; Device Deployment &gt; Upgrade Check</span
>).
</div>
<div class="p">
<b class="ph b">Workaround</b>: Manually refresh the page to see the
latest reports.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p">
<b class="ph b">PAN-295803</b
><tt class="ph tt">This issue is now resolved. See </tt
><a
class="xref"
href="/content/techdocs/en_US/ngfw/release-notes/12-1/pan-os-12-1-5-known-and-addressed-issues/pan-os-12-1-5-addressed-issues.html"
title=""
data-scope="local"
data-format="dita"
data-type=""
target="_self"
>PAN-OS 12.1.5 Addressed Issues</a
>
</div>
</td>
<td class="entry relcol">
<div class="p">
A <span class="ph codeph">configd</span> memory leak occurs post
commit (during Panorama connectivity check), potentially leading to
OOM (out of memory condition) and device reboot.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-294687</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">NGFW Clusters</tt>) In an NGFW cluster, the leader
can't retrieve the HIP Report from Panorama, nor synchronize it to the
non-leader nodes. Unlike HA Active/Passive mode, both leader and
non-leader nodes receive traffic in cluster mode. If the relevant HIP
Report is missing, policies involving HIP may not work properly. The
expected behavior is that when a non-leader node receives related
traffic, it should request the corresponding HIP Report from the
leader.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-293754</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">NGFW Clusters</tt>) Firewalls in an NGFW cluster
indicate they are in ONLINE state even though their configurations are
different (they aren't synchronized).
</div>
<div class="p">
<b class="ph b">Workaround</b>: Push the configuration from Panorama
to all cluster members at the same time; don't push to an individual
firewall. If a cluster member isn't connected to Panorama during the
push, the push will fail to the disconnected firewall, but will
succeed to all connected firewalls.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-293718</b></div>
</td>
<td class="entry relcol">
<div class="p">
When high speed logging is enabled on a PA-5560 device, the expected
warning message is not displayed on the web interface. This prevents
administrators from being notified that logs can only be viewed from
Panorama.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-292601</b></div>
</td>
<td class="entry relcol">
<div class="p">
PAN-OS 12.1.2 and later 12.1 releases support a Load Balanced DNS
configuration for an address object. If there are two address objects
with same FQDN, but one object has Load Balanced DNS enabled and other
object has Load Balanced DNS disabled, then the policy match for the
removed IP addresses doesn't work as expected.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Enable (or disable) Load Balanced DNS
consistently for an FQDN that is used with multiple address objects.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-290692</b></div>
</td>
<td class="entry relcol">
<div class="p">
In Host Compliance Service, when you create a 'Shared' type Host
Compliance Object for the 'Disk-Encryption' category, the State
drop-down is automatically selected and cannot be edited. However, you
can change the state later by editing the object, if required.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-289524</b></div>
</td>
<td class="entry relcol">
<div class="p">
In PAN-OS 12.1.2 and later 12.1 releases, PAN-OS can obtain resolved
IP addresses from a Load balanced DNS server and use them in a policy
match. However, this functionality does not work as intended when the
DNS cache reuse flag is enabled. When the DNS cache reuse flag is
enabled, the DNS resolution works as if the Load balanced DNS flag
(for an Address object) is disabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286496</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">NGFW Clusters</tt>) URL-continue and override
continue selections will function like a general URL-block action.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-283429</b></div>
</td>
<td class="entry relcol">
<div class="p">
When you use custom certificates for the connection between Panorama
and a log collector, the automated renewal for the predefined
ElasticSearch certificates gets disrupted.
</div>
<div class="p">
<b class="ph b">Workaround</b>: Remove the custom certificates before
the ElasticSearch certificates expire. This allows the system to
correctly identify and renew the predefined ElasticSearch
certificates. After the renewal is complete, re-install the custom
certificates.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-283053</b></div>
<div class="p">
<tt class="ph tt">This issue is now resolved. See </tt
><a
class="xref"
href="/content/techdocs/en_US/ngfw/release-notes/12-1/pan-os-12-1-5-known-and-addressed-issues/pan-os-12-1-5-addressed-issues.html"
title=""
data-scope="local"
data-format="dita"
data-type=""
target="_self"
>PAN-OS 12.1.5 Addressed Issues</a
>.
</div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7000 Series with Log Forwarding Card only</tt>)
When the firewall is configured to forward logs to an external log
collector or Strata Logging Service, the firewall root partition may
reach high disk utilization, which can cause the firewall to become
non-functional. This occurs when the log collector is temporarily
unavailable or unable to process logs at the rate the firewall is
sending them.
</div>
<div class="p">
<b class="ph b">Workaround:</b> To help prevent this issue, ensure
network connectivity between the firewall and log collector is stable
and verify that the log collector has sufficient capacity to handle
the volume of logs generated by your deployment.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-237106</b></div>
</td>
<td class="entry relcol">
<div class="p">
LSVPN satellite certificates may be generated with serial numbers
exceeding 40 hexadecimal characters. This causes certificate
revocation and deletion operations to fail with the following error
messages:
</div>
<ul id="panos-known-issues-12.1.4_ul-t2x_dxs_wgc" class="ul">
<li class="li">
<span class="ph systemoutput"
>db-serialno can be at most 40 characters</span
>
</li>
<li class="li">
<span class="ph systemoutput">db-serialno is invalid</span>
</li>
</ul>
<b class="ph b">Workaround:</b>
<div class="p">
To resolve this issue, use the following CLI commands with the LSVPN
satellite serial number to manually delete or revoke the affected
certificates:
</div>
<div class="p">
<b class="ph b">Delete certificate information</b>:<span
class="ph userinput"
>delete sslmgr-store certificate-info portal name
<var class="keyword varname">&lt;name&gt;</var> serialno
<var class="keyword varname">&lt;satellite_serial&gt;</var></span
>
</div>
<div class="p">
<b class="ph b">Revoke satellite certificates</b>:<span
class="ph userinput"
>delete sslmgr-store satellite-info-revoke-certificate portal
<var class="keyword varname">&lt;name&gt;</var> serialno
<var class="keyword varname"
>&lt;list_of_satellite_serials&gt;</var
></span
>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PLUG-21065</b></div>
</td>
<td class="entry relcol">
<div dir="ltr" class="p">
In a PA-VM or AI Runtime Security environment, it is observed that the
Software Firewall Orchestration plugin deployed with a VM-Flex license
and configured with 8-14 GB of memory may encounter traffic
disruptions when jumbo frames are enabled. It is recommended to
disable jumbo frames on these lower-end VMs in version 12.1.2 by
executing the command: set system setting jumbo-frame off.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PLUG-19238</b></div>
</td>
<td class="entry relcol">
<div class="p">
Enabling Advanced Routing through bootstrap on VM-Series and Prisma
AIRS is not supported.
</div>
<b class="ph b">Workaround</b>: After the firewall boots up, enable
advanced routing using the CLI command set device-management
general-settings advance-routing yes or enable
<a
class="xref"
href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-networking-admin/advanced-routing/enable-advanced-routing"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>advanced routing</a
>
through the UI.
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">DRS-6556</b></div>
</td>
<td class="entry relcol">
<div class="p">
For Host Compliance Service, while configuring Mappings &amp; Tags in
CIE and when you click on the
<span class="ph uicontrol">HIP Report</span> tab, the following error
message is displayed even when the response is successful:
</div>
<div class="p">
<span class="ph uicontrol">getaddrinfo ENOTFOUND null</span>
</div>
</td>
</tr>
</tbody>
</table>