6656 lines
214 KiB
HTML
6656 lines
214 KiB
HTML
<table class="table colsep rowsep table-striped">
|
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
|
|
|
<colgroup>
|
|
<col style="width: 25%" />
|
|
<col style="width: 75%" />
|
|
</colgroup>
|
|
<thead class="thead">
|
|
<tr class="row rowsep">
|
|
<th class="entry">
|
|
<div class="p"><b class="ph b">Issue ID</b></div>
|
|
</th>
|
|
<th class="entry">
|
|
<div class="p"><b class="ph b">Description</b></div>
|
|
</th>
|
|
</tr>
|
|
</thead>
|
|
|
|
<tbody class="tbody">
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-316911</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>VM-Series firewalls on Amazon Web Services (AWS) environments
|
|
only</tt
|
|
>) Fixed an issue where a newly bootstrapped firewall required a
|
|
management server restart, relicensing, or license push from Panorama
|
|
to invoke the device certificate.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-314142</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where establishing log forwarding connections to the
|
|
Strata Logging Service (SLS) took longer than expected, which resulted
|
|
in delayed log visibility on SLS.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-313623</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<span class="ph systemoutput">/opt/pancfg/mgmt/ssl/private/</span>
|
|
directory on Palo Alto Networks devices with TPM support became 100%
|
|
utilized due to an accumulation of undeleted
|
|
<span class="ph systemoutput">.pub_pem</span> files. This occurred
|
|
because executing the
|
|
<span class="ph systemoutput">show device-certificate status</span>
|
|
CLI command initiated a process that generated these files but failed
|
|
to remove them, which prevented the fetching of new device
|
|
certificates.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-313572</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
|
the dataplane restarted due to a segmentation fault.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-313258</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where PIM multicast routing failed on appliances with
|
|
advanced routing enabled.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-312706</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewalls restarted due to a function lacking
|
|
a NULL-pointer sanity check.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-312618</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall was unable to activate GlobalProtect
|
|
client software and displayed
|
|
<span class="ph systemoutput">SW LIMIT</span> messages related to
|
|
max-profiles and unsupported major and minor versions in the downgrade
|
|
list, which prevented successful software installation.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-311524</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where config-lock was not displayed on the web
|
|
interface.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-311412</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<span class="ph systemoutput">show advanced-routing resource</span>
|
|
CLI command failed to execute successfully when invoked through the
|
|
XML API and returned an error message.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-311261</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall generated duplicate URL Filtering
|
|
logs due to an error condition when the new XFF feature was enabled.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-311250</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Panorama appliances and Log Collectors only</tt>)
|
|
Fixed an issue where logs from multiple devices were not visible on
|
|
Panorama even though the Elasticsearch health status on the dedicated
|
|
Log Collectors appeared green.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-311074</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where GRE tunnels took significantly longer to
|
|
establish when the hold timer was configured to a value of 10 or
|
|
higher, which resulted in a tunnel requiring more successful keepalive
|
|
packets than expected to transition to an
|
|
<span class="ph uicontrol">Up</span> state.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-311073</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Panorama managed firewalls in HA configurations only</tt
|
|
>) Fixed an issue where firewalls incorrectly updated the modified
|
|
date and MD5 hash of policy rules during an HA sync commit job or a
|
|
subsequent local commit, even when no changes were made to the policy
|
|
rules.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-310868</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where PA Explicit proxy blocked ICMP packets from
|
|
flowing towards Envoy for Geneve due to the router not camping MSS
|
|
when the MTU was lower in the path.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-310499</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where, while configuring an an Application
|
|
Filter with Generative AI tags, the web interface did not retain
|
|
application exclusions that were added across multiple pages until you
|
|
clicked <span class="ph uicontrol">OK</span>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-310263</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
|
enabling TLS1.3 in a decryption profile prevented access to websites.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-309853</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Firewalls with FIPS-CC enabled only</tt>) Fixed an
|
|
issue where, when attempting to make changes to the GlobalProtect
|
|
portal, an error message was displayed and configuration updates
|
|
failed.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-309831</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where an AI Runtime Security Firewall rebooted when
|
|
processing Cursor traffic.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-309826</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
|
files from SSL decrypted sessions were incorrectly forwarded to the
|
|
WildFire cloud for analysis even when
|
|
<span class="ph uicontrol"
|
|
>Allow Forwarding of Decryption Content</span
|
|
>
|
|
was disabled.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-309459</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where on PA-5420 firewalls, configuring security rules
|
|
with a number of static IMSI/IMEI/NSSAI entries exceeding 5,000
|
|
resulted in a commit failure. This occurred because the firewall
|
|
incorrectly reported the maximum supported static IMSI/IMEI/NSSAI IDs
|
|
as 5,000 (as seen in the
|
|
<span class="ph systemoutput"
|
|
>cfg.mobile-nw-id.max-static-entries</span
|
|
>
|
|
system state variable), instead of the documented limit of 100,000 for
|
|
the platform.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-309392</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the scroll bar did not appear when editing
|
|
<span class="ph uicontrol">Destination Addresses</span> for Policy
|
|
Based forwarding policy rules.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-309379</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>logrcvr</a
|
|
>
|
|
process stopped responding on DPCs, which prevented logs from being
|
|
forwarded.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-309300</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where management plane system resources configuration
|
|
size exceeded 28 MB for over 4 hours, and the following error message
|
|
was displayed:
|
|
<span class="ph systemoutput"
|
|
>Configuration size reaching device capacity limit</span
|
|
>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-309258</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where you were unable to delete a HIP object with
|
|
<span class="ph uicontrol">OR</span> in the name, even though you were
|
|
able to successfully create and commit the object.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-309009</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where log ingestion stopped on the Elasticsearch
|
|
cluster when the number of open shards was significantly higher than
|
|
the number of data nodes.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-308902</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after upgrading to an affected release, the
|
|
firewall did not add mTLS websites that required client certificate
|
|
authentication via DN list to the ssl-decrypt exclude-cache list.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-308786</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue where
|
|
traffic log queries using the
|
|
<span class="ph systemoutput">device_name</span> filter returned no
|
|
results, and complex log queries that included negation operators
|
|
produced incorrect outputs.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-308727</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where traffic logs for
|
|
<span class="ph uicontrol">Remote Networks</span> displayed the source
|
|
zone as <span class="ph uicontrol">trust</span> instead of the remote
|
|
network name.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-308668</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Prisma Access Remote Network firewalls where high
|
|
CPU utilization caused slowness and command timeouts.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-308654</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the Elasticsearch Close Indices process closed
|
|
more indices than expected and dropped the number of open shards below
|
|
the minimum of 800 per Elasticsearch instance. This occurred because
|
|
the process did not correctly account for the number of Elasticsearch
|
|
instances when calculating the maximum number of allowed open shards.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-308606</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where traffic was blocked due to a mismatch between the
|
|
URL category specified in the Security policy rule and the URL filter
|
|
profile when custom URL categories with the same FQDN were configured.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-308468</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall rebooted due to the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>all_task</a
|
|
>
|
|
process restarting.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-308418</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, when Advanced DNS Security was enabled and
|
|
experienced unusually high loads, DNS resolution failures occurred
|
|
with the error
|
|
<span class="ph uicontrol">resources-unavailable</span>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-308377</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-7050 firewalls in HA configurations only</tt>)
|
|
Fixed an issue where the firewall reached 100% disk utilization due to
|
|
the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>logrcvr</a
|
|
>
|
|
process repeatedly restarting and dumping core files due to a blocked
|
|
hints processing thread, which caused a failover.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-308261</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall failed to send SNMPv3 traps when the
|
|
SNMP destination was configured with an FQDN that resolved to multiple
|
|
IP address through DNS load balancing.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-308085</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>VM-Series firewalls in Microsoft Azure environments only</tt
|
|
>) Fixed an issue where, after resizing the VM, the HA2 link became
|
|
unstable. Frequent keep-alive failures occurred, and HA2 keep-alive
|
|
packets were simultaneously transmitted to multiple destination MAC
|
|
addresses and the peer firewall's interface MAC). This issue occurred
|
|
on firewalls with Accelerated Networking enabled.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-308060</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Firewalls in active/active HA configurations only</tt
|
|
>) Fixed an issue where the BFD session went down and did not recover
|
|
even though the BGP remained in an established state, which caused the
|
|
firewall to cease route learning and advertisement with the peer, even
|
|
though BGP keep-alives were exchanged correctly.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-307901</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where a leak in decryption counters caused resource
|
|
exhaustion, which led to a GlobalProtect service outage.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-307893</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the Strata Cloud Manager (SCM) web interface
|
|
failed to fetch External Dynamic List (EDL) details from Prisma Access
|
|
and displayed the error message
|
|
<span class="ph systemoutput">Could not fetch the EDL main info</span
|
|
>. This occurred because the XML query returned an external list
|
|
authentication failed response when the EDL entry lacked a valid
|
|
certificate.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-307806</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after replacing the MPC (Management Processor
|
|
Card) on a firewall, the
|
|
<span class="ph systemoutput">logdb</span> process incorrectly wrote
|
|
logs to the root partition instead of the /opt/panlogs partition,
|
|
which led to high root partition usage and a non-functional state.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-307795</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama incorrectly generated system logs
|
|
indicating a lost connection to its peer after an upgrade even when
|
|
High Availability was not configured.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-307773</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where enabling Post-Quantum Pre-Shared Key
|
|
(PPK) within an IKE Gateway profile that was configured as a part of a
|
|
template stack failed or was inconsistent when attempted via the web
|
|
interface, even when the keys were properly configured.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-307714</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
|
insufficient i-node space was available on the sysroot0 partition.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-307702</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
|
|
issue where traffic passing through AE layer 2 interfaces was
|
|
interrupted during HA failovers.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-307597</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where BGP peering sessions between a hub firewall and a
|
|
satellite firewall over GlobalProtect LSVPN failed to connect.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-307453</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue for Panorama management servers where commit push
|
|
failed when
|
|
<span class="ph systemoutput">customer_info status</span> was a
|
|
<span class="ph systemoutput">failure</span> received from the
|
|
orchestrator, which prevented the system from processing and
|
|
validating the specified telemetry region correctly during the commit.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-307072</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where SNMP interface speed reporting incorrectly
|
|
identified 5Gbps interfaces as 1Gbps interfaces during an SNMP walk.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-307066</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where static DNS entries that were configured on the
|
|
firewall failed to resolve for client machines when DNS over TLS (DoT)
|
|
was enabled on the firewall DNS proxy for both client and server
|
|
settings.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-306934</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where traffic was unexpectedly blocked due to a
|
|
misconfiguration with an empty or invalid application filter. The
|
|
firewall incorrectly interpreted the empty filter as
|
|
<span class="ph uicontrol">match all cloud-apps</span>, which caused
|
|
the traffic to be denied.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-306903</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the firewall where, after upgrading, the system log
|
|
displayed the error message
|
|
<span class="ph uicontrol"
|
|
>Last config fetch FAILED. A commit is required for userid
|
|
functionality to work.</span
|
|
>
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-306886</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the root partition on the firewall or Panorama
|
|
management server filled up due to a file leak in the logging process.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-306884</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where after changing Panorama to logger mode, commits
|
|
failed due to the
|
|
<span class="ph uicontrol">panorama-admin</span> role assigned to
|
|
plugin management configuration users.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-306555</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall stopped responding, which led to
|
|
service outages.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-306502</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed two issues that impacted TLSv1.2 or earlier sessions when the
|
|
traffic matched a decryption policy rule with the no-decrypt action:
|
|
</div>
|
|
<ul class="ul">
|
|
<li class="li">
|
|
Connections failed when both HTTP header insertion (<span
|
|
class="ph uicontrol"
|
|
>Objects > Security Profiles > URL Filtering > HTTP
|
|
Header Insertion</span
|
|
>) and
|
|
<span class="ph uicontrol"
|
|
>Send handshake messages to CTD for inspection</span
|
|
>
|
|
(<span class="ph uicontrol"
|
|
>Device > Setup > Session > Decryption Settings > SSL
|
|
Decryption Settings</span
|
|
>) were enabled.
|
|
</li>
|
|
<li class="li">
|
|
New sessions failed due to software packet buffer resource
|
|
depletion, which occurred when
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>Log Successful SSL Handshake</a
|
|
>
|
|
was disabled in the decryption policy rule and the decryption
|
|
profile attached to the rule had both
|
|
<span class="ph uicontrol"
|
|
>Block sessions with expired certificates</span
|
|
>
|
|
and
|
|
<span class="ph uicontrol"
|
|
>Block sessions with untrusted issuers</span
|
|
>
|
|
disabled.
|
|
</li>
|
|
</ul>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-306451</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">VM-Series firewalls on AWS environments only</tt>)
|
|
Fixed an issue where, after upgrading the firewall to an affected
|
|
release, GlobalProtect clients did not connect with IPSec and instead
|
|
connected using SSL due to traffic flow being disabled when checking
|
|
for health check packets.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-306306</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Panorama appliances in FIPS-CC mode only</tt>)
|
|
Fixed interdevice TLS communication failures that occurred with RSA
|
|
and RSA-PSS signature algorithms across multiple layer 7 application
|
|
services.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-306226</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the TLS handshake did not complete and the
|
|
session did not go through. This occurred if the HTTP header insertion
|
|
applied to an HTTP CONNECT request passing through the firewall, the
|
|
scan-handshake feature was enabled, the session matched a decryption
|
|
policy rule with the decrypt action, and if the TLS client hello was
|
|
in a single packet and TLS 1.2 or below.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-306225</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the firewall where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>sslmgr</a
|
|
>
|
|
process memory utilization continually increased due to memory
|
|
fragmentation.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-306215</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where creating device groups in bulk via XML API took
|
|
significantly more time and the web interface stopped responding.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-306103</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-3400 and PA-5400 Series firewalls only</tt>)
|
|
Fixed an issue where the firewall dataplane frequently restarted when
|
|
lockless QoS was enabled
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305922</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where the CLI output for the running
|
|
configuration intermittently inserted
|
|
<span class="ph systemoutput">set template stack</span> commands
|
|
within certificate hash data.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305835</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where firewalls with Memory Integrity Checking
|
|
Architecture enabled rebooted unexpectedly due to accessing an invalid
|
|
memory address. This occurred because the forwarding data structure
|
|
index exceeded its designed limit.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305605</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where GlobalProtect gateway authentication failed due
|
|
to the firewall incorrectly bypassing SAML.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305557</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where LSVPN (Large Scale VPN) satellites failed to
|
|
authenticate to the gateway because the portal was providing a
|
|
zeroized certificate.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305552</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where DLP logs displayed an incorrect file type when
|
|
the firewall did not set the file type field.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305549</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall's service route functionality was
|
|
impacted due to a missing service route support code.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305502</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama was unable to forward logs to a syslog
|
|
server over TLSv1.3 when configured with SSL on a custom port. The
|
|
connection was established, but logs were not forwarded due to a
|
|
failure in the CRL check.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305412</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the Logging Service License Status displayed a
|
|
license failure when the license status transitioned from valid to
|
|
expired and then back to valid even when the connection to the
|
|
Security Logging Service (SLS) was working.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305411</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after creating a logical interface with an
|
|
assigned IP address and adding it to a virtual router, the connected
|
|
route for the interface did not appear in the
|
|
<span class="ph systemoutput">show routing route</span> CLI command
|
|
output. This occurred even when the interface was up and learning ARP
|
|
entries.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305374</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where the first letter of a custom URL
|
|
category was not displayed in generated reports.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305301</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the timing of GlobalProtect lifetime expiry or
|
|
inactivity logout notifications used for GlobalProtect SSL tunnels
|
|
could cause the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>pan_task</a
|
|
>
|
|
process to stop responding and the dataplane to restart.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305188</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where TLS connections failed to establish in asymmetric
|
|
routing environments if the Client Hello was split into multiple
|
|
segments and arrived out of order.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-305105</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where commits involving routing related network
|
|
configuration changes experienced slower than usual completion times
|
|
or remaining at 20% completion.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304840</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where multiple firewalls experienced high management
|
|
CPU utilization after upgrading to an affected release due to repeated
|
|
index regeneration occurring every 15 minutes, which caused periodic
|
|
CPU spikes above 90%.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304756</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where, after you disabled the shared
|
|
optimization feature, a full configuration push to multi-vsys devices
|
|
caused a validation error.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304746</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Panorama appliances and Panorama virtual appliances only</tt
|
|
>) Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>configd</a
|
|
>
|
|
process restarted when committing and pushing configuration for a new
|
|
WildFire cluster.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304718</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where OSPF and BGP outages occurred due to an
|
|
<span class="ph systemoutput">all_task</span> process restart during
|
|
clientless VPN content rewrite processing.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304696</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the Cloud User-ID connection timed out because
|
|
the firewall took too long to process the OCSP response.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304689</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where device group users were able to view
|
|
and commit configuration changes that had been created by Superusers
|
|
but not yet committed, even with access domains configured.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304636</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where BGP aggregate routes were not created and discard
|
|
routes were not installed in the routing table.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304576</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall entered a non-functional state due
|
|
to segmentation fault within the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>all_pktproc</a
|
|
>
|
|
process that was caused by a session that involved http2 cleartext
|
|
traffic.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304538</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where traffic logs did not populate the
|
|
<span class="ph uicontrol">Source EDL</span> or
|
|
<span class="ph uicontrol">Destination EDL</span> fields when traffic
|
|
matched a Security policy rule that used predefined external dynamic
|
|
lists.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304496</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after unregistering an IP tag and registering a
|
|
different IP tag for the same IP address via XML API, the dynamic
|
|
address group membership was not updated on the dataplane, which
|
|
resulted in Security policy rules being enforced incorrectly.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304397</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the web interface where you were unable to test the
|
|
SCP server connection for Scheduled Log Exports, and the error message
|
|
<span class="ph uicontrol">key is invalid</span> was displayed.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304229</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the Panorama web interface where you were unable to
|
|
disable <span class="ph uicontrol">Lifesize</span> (<span
|
|
class="ph uicontrol"
|
|
>Templates > Network > Network Profiles > IPSec
|
|
Crypto</span
|
|
>).
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304205</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where, after upgrading to an affected
|
|
release, a partial commit via the API did not push configuration
|
|
changes to managed firewalls, and a full commit was required to
|
|
synchronize the configuration.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304148</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where a large number of GlobalProtect users experienced
|
|
failed gateway pre-logins with the error
|
|
<span class="ph uicontrol">Failed to create SAML SSO request</span>
|
|
during peak login times.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304088</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where TCP traffic stopped working from Prisma Access
|
|
clients to TCP services behind the Service Connection (SC) after a
|
|
dataplane upgrade to PAN-OS 10.2.10-h26.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-304075</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall did not detect evasions due to TCP
|
|
checksum offloading not being enabled.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303959</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where traffic was incorrectly identified as
|
|
unknown-tcp/unknown-udp due to App-ID resource leak and eventually
|
|
dropped.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303954</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, when configuring Safenet HSMs in HA and
|
|
authentication HSM manually, the second HSM server failed to
|
|
authenticate due to the firewall overwriting the first HSM server's
|
|
certificate with the second HSM server's certificate.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303836</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where intermittent session-table resets on the AIRS VM
|
|
triggered packet drops, which led to packet loss in egress response
|
|
traffic.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303833</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama and managed devices incorrectly
|
|
displayed warning messages that indicated that an Advanced DNS
|
|
Security license and an Advanced Threat Prevention license were
|
|
required, even when a traditional DNS Security license was installed.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303826</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where scheduled software upgrades from the Software
|
|
Change Management (SCM) server to the firewall failed with a timeout
|
|
error during download.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303791</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where configuring a service route on a loopback
|
|
interface caused intermittent connectivity issues and disrupted
|
|
traffic due to the firewall being unable to resolve domain names.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303765</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where selective pushes failed when a
|
|
scheduled job was deleted from the Panorama configuration.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303745</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where inter-dataplane forwarding did not work for
|
|
sessions ingressing on Slot 2, which resulted in intermittent ping
|
|
failures to interfaces on Network Card 2 when traffic was forwarded to
|
|
Slot 3.
|
|
</div>
|
|
<div class="p">
|
|
Note: With this fix, after a slot restart, the global counter will
|
|
still show dot1q errors for a short period.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303722</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the firewall where configuring spyware and
|
|
vulnerability profiles in Security policy rules caused a memory leak
|
|
in the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>devsrvr</a
|
|
>
|
|
process with each configuration commit.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303671</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where third-party clients were unable to connect to the
|
|
GlobalProtect gateway after a successful login when the username was
|
|
entered in the domain\username format.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303663</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the firewall where SolarWinds monitoring systems
|
|
reported 100% usage for
|
|
<span class="ph systemoutput"
|
|
>Slot1 Data Processor-0 Hardware Packet Buffers</span
|
|
>
|
|
due to an inaccurate reported packet buffer.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303627</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after committing a configuration change, the
|
|
firewall experienced traffic issues,
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>pan_task</a
|
|
>
|
|
crashes, and LACP interface failures.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303559</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after manuallly creating a device telemetry
|
|
bundle, the
|
|
<span class="ph systemoutput">hour_cli_output.txt</span> file within
|
|
the bundle had a file size of 0 bytes. This occurred when checking the
|
|
bundle content after enabling device telemetry and setting the device
|
|
telemetry upload endpoint.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303508</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall failed to fetch the device
|
|
certificate during initial installation.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303487</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama appliances in FIPS-CC mode did not push
|
|
the configured values for
|
|
<span class="ph systemoutput">max-session-count</span> and
|
|
<span class="ph systemoutput">max-session-time</span> to managed
|
|
firewalls that were not in FIPS mode.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303390</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the firewall where the DNS cache capacity was set to
|
|
an incorrect value, which caused the firewall to repeatedly send DNS
|
|
requests for FQDN objects even after receiving valid responses. This
|
|
resulted in the firewall not storing DNS responses in the cache for
|
|
more than 10-15 seconds despite the minimum FQDN refresh interval
|
|
being set to a higher value.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303379</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<span class="ph systemoutput">show system resources</span> CLI command
|
|
displayed incorrect CPU usage values that did not add up to 100%.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303156</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the session timer for a custom application did
|
|
not transition from the initial 3-way handshake timer to the
|
|
application timeout when out-of-order 3-way handshake packets were
|
|
detected.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-303051</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where a memory leak occurred related to the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>reportd</a
|
|
>
|
|
process due to retaining memory that was temporarily used for report
|
|
generation instead of releasing the memory for reuse, which resulted
|
|
in continuous accumulation and memory exhaustion.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302983</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after committing changes on Panorama, a shared
|
|
post-rule moved to the end of the
|
|
<span class="ph systemoutput">post shared rulebase</span> on the
|
|
managed device instead of remaining at the top.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302927</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after upgrading Panorama, the
|
|
<span class="ph uicontrol">Push to Devices</span> option did not
|
|
display selected devices, and the
|
|
<span class="ph uicontrol">OK</span> and
|
|
<span class="ph uicontrol">Cancel</span> buttons did not function as
|
|
expected. Selecting
|
|
<span class="ph uicontrol">Push to Devices</span> did not populate any
|
|
results, and clicking <span class="ph uicontrol">OK</span> after
|
|
selecting a device under
|
|
<span class="ph uicontrol">Edit selections</span> did not work.
|
|
Despite this, selecting <span class="ph uicontrol">Push</span> or
|
|
<span class="ph uicontrol">Validate Device Group Push</span> still
|
|
pushed to the previously canceled, non-displayed devices.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302921</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<span class="ph systemoutput"
|
|
>set auth radius-require-msg-authentic yes</span
|
|
>
|
|
and
|
|
<span class="ph systemoutput"
|
|
>show auth radius-require-msg-authentic</span
|
|
>
|
|
CLI commands were unavailable on Log Collectors.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302834</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama did not display decryption logs after a
|
|
certain date due to the decryption index being purged.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302811</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
|
|
issue where network traffic was disrupted due to the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>all_pktproc</a
|
|
>
|
|
process repeatedly restarting, which caused an HA failover.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302767</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where IPv6 IPsec WAN support was not available in
|
|
Prisma Access.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302737</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where API key generation failed after renewing an
|
|
expired API certificate, and the system continued to use the expired
|
|
certificate.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302703</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Panorama virtual appliances only</tt>) Fixed an
|
|
issue where Panorama was inaccessible with the error message
|
|
<span class="ph systemoutput"
|
|
>Timed out while getting config lock</span
|
|
>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302567</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where firewalls incorrectly returned the message
|
|
<span class="ph uicontrol">API Error: Success</span> with the error
|
|
code 403 instead of the correct message
|
|
<span class="ph uicontrol">API Error: Invalid Credential</span>, when
|
|
Cisco-ISE server was used for MSCHAP-PEAP Radius auth.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302564</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the firewall where a path monitoring failure
|
|
occurred and caused the dataplane to restart.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302551</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall displayed as disconnected in the SLS
|
|
due to the serial number not being retrieved
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302428</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where daily scheduled report emails for
|
|
custom reports were delivered with no content and instead incorrectly
|
|
displayed the message
|
|
<span class="ph uicontrol">No matching data found</span>. With this
|
|
fix, the content is displayed correctly.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302317</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>all_task</a
|
|
>
|
|
process stopped responding after a commit, which cause the dataplane
|
|
to reboot repeatedly.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302254</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the web interface made calls to retrieve cloud
|
|
authentication service regions even when creating a non-cloud
|
|
authentication service profile.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302127</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Firewalls in active/active HA configurations only</tt
|
|
>) Fixed an issue where adding a 26th floating IP address to an
|
|
aggregate ethernet interface in one vsys caused IPSec tunnels on
|
|
another vsys to stop working due to rekeying. This occurred due to the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>routed</a
|
|
>
|
|
process not detecting the unchanged virtual address, uninstalling it,
|
|
and then reinstalling it, which ended the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>ikemgr</a
|
|
>
|
|
connection on the virtual address.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302085</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where network values were not displayed in Panorama
|
|
with the error message
|
|
<span class="ph uicontrol"
|
|
>There is no value for the selected item</span
|
|
>. This was due to the device group passing vsysName in Panorama.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301975</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
|
|
issue where the passive firewall incorrectly triggered PBP alerts even
|
|
with low packet rates.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301965</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where enabling Advanced Routing in a
|
|
template did not work.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301937</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Microsoft Defender for Cloud detected cleartext
|
|
SSH private keys in the /var/appweb and /etc/appweb directories on
|
|
PA-VM firewalls deployed in Azure.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301912</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama stopped responding when deploying
|
|
dynamic updates to managed devices.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301848</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where websites were incorrectly categorized with high
|
|
severity alerts (<span class="ph uicontrol"
|
|
>Monitoring > URL Filtering</span
|
|
>) even though they were assessed as low risk. This occurred due to
|
|
session information being unavailable during logging.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301828</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, when a firewall was managed by Strata Cloud
|
|
Manager and configured to use a proxy server for external connections,
|
|
the management server did not use the configured settings to connect
|
|
to the Cloud Management service.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301801</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Log Collectors where the Elasticsearch process
|
|
fluctuated intermittently between green and red states, which led to
|
|
interruptions in log collection. This issue occurred when the number
|
|
of shards exceeded the cluster's maximum supported threshold of
|
|
greater than 1000 shards per Elasticsearch instance.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301733</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<span class="ph systemoutput">show cloud-auth-service-regions</span>
|
|
CLI command took longer than expected to complete due to timeouts
|
|
while fetching Cloud Authentication Service (CAS) regions.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301691</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where BGP stopped responding with the error message
|
|
<span class="ph systemoutput">Too many open files</span> when pushing
|
|
1000 eBGP (External BGP) neighbor configurations. With this fix, the
|
|
number of file descriptors for the BGP process is increased from 1024
|
|
to 8192.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301662</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where direct application URLs for Clientless VPN did
|
|
not work on one device in a high availability (HA) pair because the
|
|
RelayState in the SAML assertion was not encoded by the firewall.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301653</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where DNS traffic sessions prematurely terminated with
|
|
the message
|
|
<span class="ph systemoutput">resources-unavailable</span>. This
|
|
occurred due to IPv4 fragmented DNS responses causing the Advanced DNS
|
|
Security module to incorrectly pack the DNS payload multiple times
|
|
when forwarding to the cloud for inspection.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301600</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the firewall where, after upgrading Panorama, OSPF
|
|
adjacencies remained in the exchange start state, which resulted in an
|
|
incomplete routing table.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301456</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where the
|
|
<span class="ph systemoutput">debug system reset-ztp</span> CLI
|
|
command was unavailable.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301430</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the web server did not specify the content type
|
|
in the header for font files, which could allow a browser to
|
|
misinterpret the content and potentially lead to cross-site scripting
|
|
(XSS) vulnerabilities.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301409</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama failed to perform a selective push to a
|
|
managed device when device tags were added or modified on the policy
|
|
rules. The selective push failed with the error message
|
|
<span class="ph systemoutput"
|
|
>Failed to generate selective push configuration. Schema validation
|
|
failed. Please try a full push</span
|
|
>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301386</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where BFD echo packets were dropped on Vwire interfaces
|
|
due to being incorrectly detected as a land attack when the source and
|
|
destination ports of the BFD packets were different.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301305</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
|
|
issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>all_task</a
|
|
>
|
|
process stopped responding and caused the passive firewall to reboot.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301290</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the Panorama web interface where a custom
|
|
administrator with device group and template permissions was unable to
|
|
upgrade devices to non-preferred releases due to the options to
|
|
uncheck base and preferred releases not being displayed.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301222</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where DNS Security logs incorrectly displayed a
|
|
sinkhole action for benign DNS categories due to the firewall saving
|
|
the drop or sinkhole action in session flags without discarding the
|
|
session.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301186</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the Panorama web interface where
|
|
<span class="ph uicontrol"
|
|
>Enable pushing device monitoring data to Panorama</span
|
|
>
|
|
was always checked, regardless of the actual configuration.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301113</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the XML API returned the error
|
|
<span class="ph systemoutput"
|
|
>Access to this vsys is unauthorized</span
|
|
>
|
|
when generating a report for a specific vsys, even when the
|
|
administrator had access to that vsys. This was due to the API session
|
|
not correctly populating the
|
|
<span class="ph systemoutput">vsysvector</span> field with the user's
|
|
allowed vsys.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301089</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Kubernetes pod health checks failed when the
|
|
pan-fw annotation was added. When the annotation was present, health
|
|
check traffic from the host's public IP address range to the pod CIDR
|
|
range was tunneled to the firewall by the pan-cni, which resulted in
|
|
asymmetric flows and no response from the pod endpoints.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301018</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where API queries for correlated category
|
|
logs incorrectly returned a count of 0.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-301014</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the GlobalProtect portal used an outdated
|
|
bootstrap version for clientless VPN.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300933</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where, after downgrading to an affected
|
|
release, the <span class="ph uicontrol">commit-all</span> operation
|
|
failed due to a missing downgrade script.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300922</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the syslog connection was handled by the syslog
|
|
forwarding thread.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300916</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama management servers failed to forward
|
|
syslog messages via TLS to a syslog server when DNS resolution for
|
|
IPv6 addresses failed, and the system did not automatically fall back
|
|
to IPv4.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300906</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where XML API commands failed with a
|
|
<span class="ph systemoutput">Method not found (policy_xml)</span>
|
|
error in dagger.log. The issue was due to missing XML-related
|
|
functions for inline-cloud-proxy.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300837</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where firewalls experienced multiple reboots due to the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>pan_task</a
|
|
>
|
|
process restarting with a SIGSEGV signal. This occurred because the
|
|
client-to-firewall side assumed TLS 1.3 for the firewall-server side.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300833</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the static default route remained active even
|
|
when the path or SaaS monitor was down when SD-WAN was used for local
|
|
internet breakout. This was due to missing validation handling in the
|
|
FRR routed code for link up/down status.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300671</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where traffic reports that were generated with
|
|
destination/source and destination/source hostnames were not displayed
|
|
in IPv4 format.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300664</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the Panorama and firewall web interface where
|
|
Applications pages became unresponsive after activating the SaaS
|
|
Inline license.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300638</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
|
the firewall stopped responding due to an out-of-bounds read when
|
|
parsing TLS 1.3 clientHello messages with large TLS clientHello
|
|
extensions where the
|
|
<span class="ph systemoutput">supported_versions</span> extension fell
|
|
outside the first TCP segment.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300637</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>VM-Series firewalls on Microsoft Azure environments only</tt
|
|
>) Fixed an issue where the firewall unexpectedly rebooted due to
|
|
repeated
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>varrcvr</a
|
|
>
|
|
process restarts.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300617</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the Elasticsearch cluster status displayed as red
|
|
due to unassigned shards, which prevented logs from updating.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300555</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
|
|
issue where the HA1-A interface reported an incorrect SNMP down value
|
|
even when the interface was physically up on the active firewall.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300548</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where using the IKEv2 multiplier setting for VPN
|
|
re-authentication resulted in the firewall not re-authenticating at
|
|
the expected intervals when both sides initiated rekeying. The
|
|
internal re-authentication counter incremented when the local side
|
|
triggered the rekey, but not when the peer side triggered it.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300423</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Data Processing Cards (DPCs) installed in slots 5
|
|
and 6 remained stuck in a starting state with the error
|
|
<span class="ph uicontrol"
|
|
>Signal detected for port xeS5-DP0 but Link Down</span
|
|
>
|
|
alerts, which resulted in device instability.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300280</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, on firewalls configured as an Area Border Router
|
|
(ABR) with a backbone area (0.0.0.0) and a stub area, external Type-5
|
|
Link State Advertisement (LSA) routes were not installed in the
|
|
routing table.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300186</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the GlobalProtect portal exposed the internal IP
|
|
address of the gateway when accessed via the SAML20/SP/ACS endpoint.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-300138</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where DNS queries stalled or repeatedly time out due to
|
|
multiple DNS responses with different CNAME values causing evasion
|
|
false positive alerts.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299915</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the Elasticsearch cluster health status displayed
|
|
as red on dedicated log collectors due to an expired Elasticsearch CC
|
|
certificate, which prevented log visibility from Panorama.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299815</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on multi-vsys firewalls where a host was not removed
|
|
from the quarantine list after receiving a redistribution message from
|
|
Panorama. This occurred when Panorama was configured to redistribute
|
|
quarantine messages to a firewall cluster, and the GlobalProtect
|
|
configuration and redistribution were built out in a vsys other than
|
|
vsys1.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299785</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-7500 and PA-5450 firewalls in FIPS-CC mode</tt>)
|
|
Fixed an issue where the affected firewalls would boot into
|
|
maintenance mode when a reboot was initiated from the web interface.
|
|
This was due to a device reboot triggering a power down to all slots,
|
|
leading to maintenance mode. A hard reboot would allow the firewall to
|
|
boot normally.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299772</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>VM-Series firewalls in active/passive configurations only</tt
|
|
>) Fixed an issue where, after an HA failover event, the newly active
|
|
firewall DHCP client interfaces failed to obtain IP addresses
|
|
automatically. This occurred because the DHCP client processes did not
|
|
initiate the necessary DHCP discover or renew requests
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299757</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Router Advertisements for IPv6 were not sent at
|
|
the configured time intervals.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299751</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall was unable to connect to the
|
|
Subscription License Service (SLS) due to a public and private key
|
|
pair mismatch with the device certificate.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299738</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where excessive dataplane debug logs were generated due
|
|
to the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>pan_task</a
|
|
>
|
|
process restarting, even without any dataplane debug logs or captures
|
|
being enabled by the administrator.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299706</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall repeatedly sent DNS requests for
|
|
FQDN objects despite even after receiving valid responses.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299705</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where API calls to commit changes on Panorama
|
|
intermittently failed when using the XML API with refresh=<span
|
|
class="ph systemoutput"
|
|
>no</span
|
|
>, which caused changes to not be applied to the partial-commit
|
|
configuration.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299622</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the MFA timestamp was not redistributed between
|
|
standalone firewalls behind an Azure load balancer after upgrading,
|
|
which resulted in users being prompted to reauthenticate multiple
|
|
times.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299615</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, when the Network Packet Broker feature was
|
|
enabled, forward TLS (non-decrypted) traffic was not working as
|
|
expected when there were segmented client hellos and a no-decrypt rule
|
|
existed. This issue occurred when Zone Protection profiles were
|
|
configured for trust/untrust zones but not attached to NPB zones.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299495</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<span class="ph systemoutput"
|
|
>show system setting ssl-decrypt certificate</span
|
|
>
|
|
CLI command did not display certificates when XML output was enabled.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299450</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where PAN-OS
|
|
<span class="ph systemoutput">logrotate</span> did not rotate large
|
|
log files until the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>cron.daily</a
|
|
>
|
|
process ran, which resulted in the root partition filling up.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299242</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall's SSL proxy sent an empty HTTP2
|
|
SETTINGS message to the client before confirming server support, which
|
|
caused some clients to incorrectly assume HTTP/2 support and not fall
|
|
back to HTTP/1.1. Additionally, the firewall dropped HTTP1.1 400 Bad
|
|
Request frames from the server, which prevented the client from
|
|
correctly detecting the lack of HTTP/2 support.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299228</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where a session process consumed excessive CPU
|
|
resources, even when Data Loss Prevention (DLP) was not enabled. This
|
|
occurred due to the active threat list being iterated twice when
|
|
active threats were present in the session.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299193</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the firewall where, after upgrading, autocommits
|
|
repeatedly failed until after a second reboot due to a timing issue
|
|
between content loading on the management plane card (MPC) and the log
|
|
receiver startup.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299161</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the bytes number overflowed for a specific
|
|
application, which caused Network Monitor graphs to display an
|
|
unexpectedly large volume of traffic.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-299027</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Panorama virtual appliances in Management Mode only</tt
|
|
>) Fixed an issue where a maximum configuration size of 120 was
|
|
incorrectly enforced instead of 150 MB.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298945</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where OSCP HTTP POST requests were not formatted
|
|
correctly, which caused failures with strict responders.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298929</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
|
|
issue where, after upgrading the ESXi host to version 8.0.3, the
|
|
firewall interface went down on the active firewall due to a behavior
|
|
change in ESXi 8.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298907</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on PA-VM in AWS where, in a two-arm deployment
|
|
integrated with Gateway Load Balancer (GWLB), the firewall did not
|
|
preserve the GENEVE source port for internet traffic, resulting in
|
|
increased latency. The fix ensures the firewall preserves the outer
|
|
UDP source port of GENEVE encapsulation when sending traffic back to
|
|
GWLB.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298872</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>PA-400 Series firewalls in HA configurations only</tt
|
|
>) Fixed an issue where ports went down after an HA failover.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298788</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the /pancfg partition on the Azure Cloud NGFW
|
|
reached 100% utilization, which caused commit failures.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298684</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where an Application Override policy rule was not
|
|
applied using an IPv4 source IP address with IPv6 enabled and
|
|
<span class="ph uicontrol">Network</span> >
|
|
<span class="ph uicontrol">Zones</span> >
|
|
<span class="ph uicontrol">Pre-NAT Identification</span> enabled.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298654</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall generated false positive threat logs
|
|
during updates to a large domain list (EDL) when a DNS lookup for a
|
|
domain being added or removed occurred during the update process. This
|
|
resulted in a threat log being generated for a different, unrelated
|
|
domain that remained on the list.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298617</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Optimized the commit workflow to reduce the size of the effective
|
|
configuration, resulting in lower memory consumption.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298460</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Panorama appliances in HA configurations on Microsoft Azure
|
|
environments only</tt
|
|
>) Fixed an issue on the web interface where the plugin versions that
|
|
were displayed when hovering the cursor over the Green Match icon were
|
|
inconsistent even though the Panorama web interface reported the
|
|
versions as matching.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298387</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the firewall where the source and destination NAT IP
|
|
addresses did not display in traffic and threat logs.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298288</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where traffic loss occurred when two aggregate ethernet
|
|
interfaces were configured as vwire with only one member link active
|
|
in the aggregate ethernet interface, which occurred due to an
|
|
incorrect logic in active port map of AE interfaces.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298279</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama administrators defined in a SAML
|
|
Identity Provider (IdP) were unable to authenticate if their username
|
|
exceeded 32 characters, and the system logs displayed the failed
|
|
authentication attempt with a truncated username.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298252</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Data Loss Prevention (DLP) inspection of chunked
|
|
transfer encoding over TLS resulted in incomplete file downloads on
|
|
Outlook Web App (OWA) due to the WIF page size limit, which led to
|
|
corrupted or incomplete PDF attachments.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298241</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the NAT IP address pool was exhausted, which led
|
|
to intermittent connectivity issues with call applications and
|
|
outbound call failures. This occurred due to the firewall not properly
|
|
releasing NAT dynamic ports back to the address pool.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298141</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall experienced recurring kernel
|
|
segfaults related to multiple processes, which led to a SIGSEGV error.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298000</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>useridd</a
|
|
>
|
|
process stopped responding after an upgrade, which led to high packet
|
|
buffer congestion and an OOM condition.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297976</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall experienced extended boot times
|
|
after a reboot due to the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>configd</a
|
|
>
|
|
process needing to rebuild the ACE catalog after detecting
|
|
discrepancies that were caused by duplicate application checking
|
|
between the ACE catalog and content.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297972</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where a dataplane crash occurred when traffic matched
|
|
Inline Cloud Analysis prefiltering signatures, even when Inline Cloud
|
|
Analysis features were not enabled.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297963</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where PA-400 Series firewalls were not properly caching
|
|
DNS responses for FQDN objects. The firewall was observed to
|
|
repeatedly send DNS requests for the same FQDN objects every 10-15
|
|
seconds, even after receiving valid responses, despite the minimum
|
|
FQDN refresh interval being set to a much higher value. This resulted
|
|
in excessive DNS queries originating from the firewall's management
|
|
interface.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297819</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall was unable to send device telemetry
|
|
files to Cortex Data Lake due to the firewall receiving an invalid
|
|
upload token.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297818</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where exporting managed device information
|
|
that included a PA-450R-5G appliance resulted in the
|
|
<span class="ph uicontrol">Cellular Firmware</span> field being
|
|
exported into multiple cells.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297797</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, during a refresh of a large External Dynamic
|
|
List (EDL), traffic that matched a domain on the list was incorrectly
|
|
identified as a different domain, which resulted in false positive
|
|
threat logs.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297796</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where the policy review feature in
|
|
<span class="ph uicontrol">Dynamic Updates</span> failed to display
|
|
Security policy rules when the device group was set to
|
|
<span class="ph uicontrol">All</span>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297782</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where reassociating a vsys from one device
|
|
group to another in a multi-vsys environment resulted in another vsys
|
|
from the same firewall being removed from the original device group.
|
|
This resulted in the device being moved into the
|
|
<span class="ph uicontrol">no device groups attached</span> group, a
|
|
superuser was required to manually reattach the device.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297775</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after upgrading to an affected PAN-OS release,
|
|
the Visible Virtual System field referenced the vsys name instead of
|
|
the vsys ID, which caused inter-vsys routing to fail. This occurred
|
|
when a vsys display name matched one of the vsys IDs. If you're using
|
|
a multivsys environment, you must upgrade your firewalls to a fixed
|
|
PAN-OS version. The best practice is to upgrade both the firewalls and
|
|
Panorama to a fixed PAN-OS version.
|
|
</div>
|
|
<div class="p">
|
|
If you don't upgrade Panorama to a fixed version, you'll encounter
|
|
PAN-245064, where a commit on a multivsys firewall fails with the
|
|
message
|
|
<span class="ph systemoutput"
|
|
>vsys name should end with a number vsys is invalid</span
|
|
>
|
|
after you
|
|
<span class="ph uicontrol">Export or push device config bundle</span>
|
|
from 11.1.1 Panorama.
|
|
</div>
|
|
<div class="p">
|
|
After you upgrade Panorama to a fixed version, you'll encounter
|
|
PAN-214177, which causes an
|
|
<span class="ph uicontrol">Export or Push device config bundle</span>
|
|
from Panorama to the firewall to fail. The workaround for PAN-214177
|
|
is to first push only the template configuration and then push the
|
|
device group configurations.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297774</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the web interface where the TLS Version was
|
|
misspelled as <span class="ph uicontrol">TLS Vesrion</span> (<span
|
|
class="ph uicontrol"
|
|
>Device > Server Profiles > Email</span
|
|
>).
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297761</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall incorrectly categorized some URLs as
|
|
not-resolved due to a conflict with Top Level Domain (TLD) data
|
|
handling in the PAN-DB URL cloud. This affected URLs under domains
|
|
marked as TLDs, which the firewall incorrectly assumed did not have
|
|
any category.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297749</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the redistribution agent status was blank on the
|
|
web interface on both the firewall and Panorama, even though the CLI
|
|
showed the agent as connected.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297708</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where a long-lived session with many Machine Learning
|
|
(ML) model triggers caused a memory leak of feature states associated
|
|
with the ML model runs. This resulted in Spyware_State failure
|
|
increases, allocation max outs, and impaired policy matching.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297610</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall became unresponsive after an upgrade
|
|
due to the <span class="ph systemoutput">fsck</span> command scanning
|
|
drive partitions in parallel with the root partition, which caused the
|
|
process to take an extended amount of time.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297609</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the CLI command
|
|
<span class="ph systemoutput"
|
|
>debug user-id refresh user-id agent all</span
|
|
>
|
|
failed with the error message
|
|
<span class="ph systemoutput"
|
|
>Invalid agent name. Agent name should be 1 to 31 characters
|
|
long.</span
|
|
>
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297540</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Panorama managed firewalls in HA configurations only</tt
|
|
>) Fixed an issue where the HA-Link-Monitor configuration pushed from
|
|
Panorama was converted to a local configuration on the peer device
|
|
after an HA sync, which caused subsequent Panorama pushes of link
|
|
monitor changes to be flagged as overwritten, and a forced template
|
|
push or manual clearing of the configuration on the firewall was
|
|
required.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297458</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>all_task_1</a
|
|
>
|
|
process crashed on the firewall when the wif service wasn't available
|
|
because the wif detection ID was not in the current service table.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297412</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
|
|
the firewall rebooted unexpectedly due to a negative decoded length.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297370</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where pushing a new object from Panorama to a Cloud
|
|
NGFW Device Group unexpectedly removed existing Panorama-pushed policy
|
|
rules, even though the
|
|
<span class="ph uicontrol">Push Preview</span> did not show any
|
|
deletions, which led to traffic disruptions.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297321</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Firewalls in active/active HA configurations only</tt
|
|
>) Fixed an issue where return packets from a phone gateway looped
|
|
between the HA pair instead of being encapsulated into the
|
|
GlobalProtect tunnel. This occurred when the inner session and the
|
|
outer IPSec tunnel terminated on different nodes, which led to
|
|
excessive retries and packet drops.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297320</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Panorama virtual appliances only</tt>) Fixed an
|
|
issue where scheduled configuration exports failed with an
|
|
<span class="ph systemoutput">invalid key</span> error when connecting
|
|
to a SCP server using non-default SCP port. Also, additional CLIs were
|
|
added to delete the known-hosts file.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297295</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>VM-Series firewalls in Microsoft Azure environments only</tt
|
|
>) Fixed an issue where the firewall repeatedly restarted due to high
|
|
packet rates on the synthetic path in DPDK mode.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297263</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-5220 firewalls only</tt>) Fixed an issue where
|
|
the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>ikemgr</a
|
|
>
|
|
process crashed intermittently, which caused IPSec tunnels to go down
|
|
randomly. With this fix, the IKE Security association data structures
|
|
are accessed in a thread-safe manner, and the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>ikemgr</a
|
|
>
|
|
process does not reference an invalid memory pointer during teardown
|
|
operations.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297005</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where exporting custom reports resulted in empty CSV
|
|
files.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296977</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the web interface became unresponsive when
|
|
attempting to view
|
|
<span class="ph uicontrol">Ethernet</span> interface details after
|
|
applying a filter in
|
|
<span class="ph uicontrol">Network > Interfaces</span>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296752</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-1410 Firewalls only</tt>) Fixed an issue where
|
|
the firewall experienced high management CPU usage and repeatedly
|
|
rebooted when attempting to retrieve SMART data.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296749</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where email alerts sent from the firewall were marked
|
|
as spam due to the EHLO header containing only the firewall hostname
|
|
and not the fully qualified domain name (FQDN).
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296694</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall rebooted due to the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>useridd</a
|
|
>
|
|
process repeatedly restarting during an IP-port data type writes to
|
|
the redis from multiple sources such as TSA or XML in a scale
|
|
environment.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296666</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Prisma Access gateways did not pass usernames to
|
|
the WildFire portal, which caused the
|
|
<span class="ph uicontrol">Recipient User ID</span> to display as
|
|
<span class="ph uicontrol">unknown</span> on
|
|
wildfire.paloaltonetworks.com, even when the username was present in
|
|
the gateway logs.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296635</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>reportd</a
|
|
>
|
|
process on passive Panorama management servers leaked memory due to
|
|
scheduled report handling from the Strata Logging Service (SLS). This
|
|
memory leak occurred daily, consuming available memory until the
|
|
process was restarted.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296616</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, when a PBF policy rule with a monitoring profile
|
|
was configured, the intermediate firewall dropped the PBF monitoring
|
|
traffic, which caused the PBF rule to remain disabled on the local
|
|
firewall.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296598</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where EAL logs were not forwarded to the IoT Security
|
|
dashboard when the proxy server password contained special characters.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296535</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the firewall where BGP peers disconnected when more
|
|
than 500 BGP neighbors were configured in a single Logical Router
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296490</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Firewalls with FIPS-CC mode enabled only</tt>)
|
|
Fixed an issue where Panorama on GCP lost access to management
|
|
interface after an hour of uptime.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296478</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after upgrading to PAN-OS 10.2.13-h10,
|
|
GlobalProtect Clientless VPN on PA-3250 firewalls failed to execute
|
|
JavaScript links, resulting in an authorization error. This occurred
|
|
because the firewall was incorrectly injecting text into URLs when
|
|
JavaScript buttons or dropdown menus were clicked within the
|
|
Clientless VPN portal.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296453</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where decryption exclusion lists were not working for
|
|
untrusted certificates, and SSL sessions were still being decrypted
|
|
even after adding them to the exclusion list. This occurred because
|
|
the firewall was not adding sessions to the exclude cache until after
|
|
receiving a non-RFC alert (BadCertificate) from the server. The fix
|
|
ensures that the first session is added to the exclude cache, allowing
|
|
subsequent sessions to skip decryption. This issue affects firewalls
|
|
configured as clients in server-client communication.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296452</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, when Panorama manages Prisma Access, filtering
|
|
GlobalProtect logs by IPv6 subnets displays all logs, including IPv4
|
|
logs.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296443</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
|
|
the firewall had a lower maximum capacity for DIPP translated IP
|
|
addresses than the PA-5260, which caused configuration commit errors
|
|
during migration. With this fix, the maximum capacity on PA-5450
|
|
firewalls has been increased to 8000.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296397</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the Panorama web interface where previewing changes
|
|
after a commit to shared objects were not accurately displayed in the
|
|
push scope.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296283</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, on hardware platforms with the SaaS inline
|
|
license, Additional Header Logging (AHL) hash table creation proceeded
|
|
even when the feature was disabled through the CLI, potentially
|
|
leading to crashes.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296224</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Firewalls in active/active HA configurations only</tt
|
|
>) Fixed an issue where adding a 26th floating IP address to an
|
|
aggregate interface on one vsys caused IPSec tunnels in another vsys
|
|
to stop working due to rekeying issues.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296208</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall did not accept address groups in the
|
|
filter condition of a Log Forwarding Match list.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296206</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall incorrectly routed external Type-5
|
|
Link State Advertisements (LSAs) within a stub area when the firewall
|
|
was configured as an Area Border Router (ABR) in a stub area and
|
|
learned about an external prefix from another ABR connected to the
|
|
backbone area.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296202</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Firewalls in active/active HA configurations only</tt
|
|
>) Added a log enhancement to capture an issue where, when a commit
|
|
operation was in progress, newly deployed IP address tags that used
|
|
the XML API were not immediately reflected in address group
|
|
resolution, which delayed IP address mapping to address groups and
|
|
caused traffic to be incorrectly allowed or denied.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296195</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, in an SD-WAN Branch Multi-VR environment, ping
|
|
traffic initiated from the firewall's internal interface resulted in
|
|
improper zone mapping during session setup, which resulted in the
|
|
firewall being unable to reach the internet. This occurred due to the
|
|
ingress zone being incorrectly used as the egress zone.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296020</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where commit operations failed during phase 1 when
|
|
configuring a non-default value for the Graceful Restart Hello Delay
|
|
due to an FRR parse error if the configured value was between 1 and 9.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295958</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where multicast output interfaces (OIFs) were missing
|
|
for up to 5 minutes after an HA failover or routing process restart,
|
|
which impacted new multicast sessions. This occurred due to an age-out
|
|
process triggered by unicast graceful restart conditions.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295951</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on firewalls in active/passive HA configurations where
|
|
CLI outputs incorrectly included XML formatting.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295944</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where static routes remained active in the FIB and RIB
|
|
even when the associated physical port interface was down, which
|
|
resulted in traffic being incorrectly routed through a non-operational
|
|
interface.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295899</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where DNS resolution failed on Linux machines running
|
|
GlobalProtect client version 6.2.6 when connected with DNS Security
|
|
enabled. This occurred because the firewall incorrectly discarded DNS
|
|
packets when processing multiple DNS requests or responses over the
|
|
same session, even when no malicious verdict was received.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295854</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall generated two URL logs for a single
|
|
session.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295838</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on IKEv1 tunnels where, if the peer IKE gateway was
|
|
unreachable, the IKE Phase-1 Security association (SA) was not cleared
|
|
by DPD until Phase-2 rekeying occurred or until it was manually
|
|
cleared via the CLI because the DPDs were not sent accurately
|
|
according to the configured interval due to a miscalculation of the
|
|
DPD timer. This resulted in the tunnel taking longer than expected to
|
|
recover.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295812</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the throughput data on the Switch Card Module
|
|
(SCM) was not accurately reported. This issue affected Standard SC
|
|
USABN and USABN-2 when using Direct-IO deployment.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295803</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Addressed a memory leak issue under sc3 and automatic commit recovery
|
|
(ACR) code path.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295802</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where a memory leak related to the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>configd</a
|
|
>
|
|
process occurred.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295796</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall intermittently failed to forward
|
|
VXLAN GARP packets, which led to connectivity issues for wireless
|
|
clients in environments that used VXLAN tunnels for wireless access
|
|
points.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295766</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">VM-Series firewalls in HA configurations only</tt>)
|
|
Fixed an issue where Panorama displayed incorrect packet buffer values
|
|
on the web interface and the CLI.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295728</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where configuring an OSPFv2 NSSA area range caused
|
|
OSPF-learned routes to become unreachable due to the incorrect
|
|
installation of a discard route when the NSSA range prefix matched an
|
|
existing OSPF route.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295662</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama displayed the URL instead of the file
|
|
name for vulnerability threat logs fetched from the Logging Service.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295644</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Strata Logging Service (SLS) log forwarding
|
|
streams intermittently displayed as inactive.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295586</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after committing changes to a Certificate
|
|
Profile or other global configurations without any making changes to
|
|
the virtual system (vsys), the Data Redistribution include/exclude
|
|
lists were ignored on the firewall. This resulted in the firewall
|
|
receiving and processing User-ID information from all sources.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295578</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where GlobalProtect HIP data file download and
|
|
installation failed with the error message
|
|
<span class="ph systemoutput"
|
|
>An error occurred while processing request. Please try again after
|
|
some time or contact support</span
|
|
>
|
|
or <span class="ph systemoutput">No ETAG from response</span> due to a
|
|
script exiting prematurely.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295560</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after upgrading Panorama and Log Collectors,
|
|
tunnel logs were not visible in Panorama or Splunk even though traffic
|
|
and threat logs were received.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295484</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where SD-WAN did not generate system logs with
|
|
timestamps and reasons for degradation of Direct Internet Access
|
|
paths.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295470</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the firewall where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>useridd</a
|
|
>
|
|
process continuously increased its memory consumption, which resulted
|
|
in an OOM condition that caused the firewall to restart.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295421</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the CLI command outputs incorrectly included XML
|
|
formatting tags.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295385</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where syslog forwarding dropped due to FQDN resolution
|
|
failures.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295342</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>pan_comm</a
|
|
>
|
|
process stopped responding due to insufficient time allocated to read
|
|
file descriptors when processing long messages.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295257</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after onboarding a firewall to Panorama, IPsec
|
|
tunnels displayed IKEv2 in Panorama, even though the tunnels were
|
|
configured with IKEv1 locally on the firewall.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295245</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>useridd</a
|
|
>
|
|
process stopped responding because the client was unavailable.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295240</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the source user field was intermittently missing
|
|
in traffic logs, even when the IP address-to-user mapping was
|
|
available. This occurred due to a race condition where the log
|
|
generation process preceded the creation of the IP address-to-user
|
|
mapping.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295221</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after upgrading Panorama and Log Collectors from
|
|
PAN-OS 10.2.9 to PAN-OS 11.1.6-h6, Traffic and Threat logs were not
|
|
forwarded to a Splunk server over UDP.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295185</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue where
|
|
a custom administrator role with the permission
|
|
<span class="ph uicontrol">Network > QoS (Read Only)</span> was
|
|
unable to create a QoS profile, even when the
|
|
<span class="ph uicontrol">Policies > QoS (Enabled)</span> and
|
|
<span class="ph uicontrol"
|
|
>Network Profiles > QoS Profile (Enabled)</span
|
|
>
|
|
permissions were also set.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-295095</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, when you used a syslog forwarding profile with
|
|
the CEF format, an additional string was appended to the end of the
|
|
log message when viewing the log entry from the Universal Forwarder
|
|
directory.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-294898</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue
|
|
where, when performing device software deployment to dedicated log
|
|
collectors, the <span class="ph uicontrol">Validate</span> option did
|
|
not display the required software versions. Additionally, attempting
|
|
to download images to multiple log collectors simultaneously failed.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-294893</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where firewalls with the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>Send handshake messages to CTD for inspection</a
|
|
>
|
|
setting enabled caused incorrect security policy rules to be matched
|
|
during the TLS handshake. Additionally, the expected response page for
|
|
blocked URLs was not displayed.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-294770</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Firewalls in active/passive HA configurations</tt>)
|
|
Fixed an issue on firewalls where, after failover, certain subnets
|
|
were missing from the Link State Database, which prevented OSPF routes
|
|
from being immediately learned due to a Type-7 to Type-5 LSA
|
|
translation conflict in the ABR when the same LSA was advertised by
|
|
two peers in the NSSA area.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-294524</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where firewalls and Panorama management servers were
|
|
unable to view or download WildFire reports from a WF-500 appliance,
|
|
resulting in a 401 error in the report tab.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-294379</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, when SD-WAN SaaS Application path monitoring
|
|
failed for all interfaces, the firewall stopped forwarding traffic
|
|
even if the ISP links and default gateway probing were still active.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-294307</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where a
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>configd</a
|
|
>
|
|
SIGSEGV crash occurred when renaming objects within policy rules,
|
|
objects, or zones.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-294191</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where BGP did not generate a system log when the number
|
|
of prefixes received from a peer exceeded the configured threshold,
|
|
even with the Address Family Identifier and Peer Group settings
|
|
configured to trigger a warning.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-294179</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where viewing, refreshing, and comparing config
|
|
versions in <span class="ph uicontrol">Config Audit</span> caused the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>configd</a
|
|
>
|
|
process to stop responding. If the page loaded successfully, some
|
|
commit versions displayed incorrect or missing data.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-294161</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall rebooted unexpectedly due to the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>useridd</a
|
|
>
|
|
process restarting and causing an HA failover. This occurred due to
|
|
the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>configd</a
|
|
>
|
|
process timing out when running the CLI command
|
|
<span class="ph systemoutput">show user user-id-agent config all</span
|
|
>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-294123</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall removed all Infrastructure and Audit
|
|
logs, as well as <span class="ph systemoutput">logdb</span> and search
|
|
engine quotas, when the configured retention period was reached
|
|
instead of only removing logs older than the configured retention
|
|
period.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293985</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue with the Panorama web interface where admin users were
|
|
unable to log in and received the error message
|
|
<span class="ph uicontrol">504: Gateway Timeout</span>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293953</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the cellular interface LED indicator incorrectly
|
|
displayed a green light when the cellular interface was down due to a
|
|
failed packet data session.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293879</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the firewall where the VM monitor source remained in
|
|
the <span class="ph uicontrol">Getting All</span> status, which
|
|
prevented dynamic address groups from updating IP addresses for new
|
|
EC2 instances. This issue occurred due to a race condition where two
|
|
threads that simultaneously retrieved IP address tag information from
|
|
AWS VM monitoring sources became stuck while reading the XML file.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293877</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Firewalls with Hub vsys (virtual system) configurations enabled
|
|
only</tt
|
|
>) Fixed an issue where, when using the Hub vsys feature to
|
|
redistribute Host Information Profiles (HIP) to a non-Hub vsys, HIP
|
|
policy enforcement failed intermittently on the active secondary
|
|
firewall. This occurred when traffic destined for specific non-Hub
|
|
vsys was routed to the active secondary, and the HIP query was not
|
|
triggered due to an incorrect check for the HIP mask in the Hub vsys.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293858</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the file URL was not displayed on SCM LogViewer
|
|
when a file was downloaded. This issue affected logs with a subtype of
|
|
'file'.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293848</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama failed to push the default value of
|
|
<span class="ph uicontrol">None</span> for the secondary NTP server
|
|
address to managed firewalls, resulting in a commit validation error.
|
|
This occurred even when configuring the secondary NTP server address
|
|
as <span class="ph uicontrol">None</span> in Panorama's web interface,
|
|
and affected both newly deployed and long-standing production
|
|
firewalls after upgrading.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293847</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where EAL logs for traffic matching the
|
|
intrazone-default security rule were not forwarded to the IoT Security
|
|
portal.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293825</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where packets with bad TCP checksums were transmitted
|
|
even when the
|
|
<span class="ph systemoutput">Strict TCP/IP checksum</span> option was
|
|
enabled.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293708</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>configd</a
|
|
>
|
|
process stopped responding when a partial revert operation was
|
|
performed on a newly added rule in a rulebase that was empty in the
|
|
running configuration.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293707</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>iotd</a
|
|
>
|
|
process failed to install DPI Cloud server FQDN due to a configuration
|
|
parsing failure, caused by the configuration XML memory buffer not
|
|
being NULL terminated. This resulted in the accumulation of EAL logs
|
|
and DLP forwarding being stopped.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293686</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where importing a device state file was incorrectly
|
|
allowed during an existing commit job.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293673</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall stopped all tasks due to an OOM
|
|
condition caused by a scheduled log export using FTP to an external
|
|
FTP server.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293644</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
|
|
issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>configd</a
|
|
>
|
|
process stopped responding during an External Dynamic List (EDL)
|
|
refresh.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293574</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where Global Find returned incomplete and
|
|
inconsistent search results.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293561</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where users with a custom role-based administrator role
|
|
were unable to download the GlobalProtect client application via the
|
|
web interface even when the
|
|
<span class="ph uicontrol">GlobalProtect Client</span> option was
|
|
enabled in the admin role profile.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293533</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, in KVM environments, traffic did not work as
|
|
expected on Mellanox CX5 interfaces during multinic runs.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293511</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where renaming a BGP filtering profile in Panorama does
|
|
not update the corresponding BGP peer group in the virtual router,
|
|
leading to commit failures.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293440</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where setting the
|
|
<span class="ph systemoutput">logdb-quota</span> for the
|
|
<span class="ph systemoutput">desum</span> log type to
|
|
<span class="ph systemoutput">0</span> caused the /opt/panlogs
|
|
partition to reach capacity.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293428</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the interval of IKEv1 Dead Peer Detection (DPD)
|
|
R-U-THERE packets did not correspond to the configured value in the
|
|
IKE Gateway profile due to using the value configured for retry
|
|
instead.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293297</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where a full push to device groups was
|
|
initiated instead of a selective push when using
|
|
<span class="ph uicontrol">Commit and Push Changes Made By</span> in
|
|
the commit and push.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293281</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the reported throughput and packet rate were
|
|
higher than the actual interface traffic due to a double counting
|
|
error.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293033</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where
|
|
<span class="ph uicontrol">Push</span> was disabled during a Selective
|
|
Push operation.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-292980</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the web interface where the
|
|
<span class="ph uicontrol">Connected</span> status for a User-ID agent
|
|
in a non-User-ID Hub vsys displayed as blank if the same agent was
|
|
also configured in a User-ID Hub vsys.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-292752</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where a command injection vulnerability could occur due
|
|
to improper input sanitization.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-292580</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue where
|
|
the software deployment validation process did not display the
|
|
required software version for dedicated log collectors (DLCs), and
|
|
downloading software images to multiple DLCs failed.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-292539</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">CN-Series firewalls only</tt>) Fixed an issue where
|
|
the firewall generated incomplete or corrupted tech support files
|
|
(TSF) due to high disk usage on the management plane.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-292529</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where HA configuration synchronization failed between
|
|
HA firewalls due to an empty interface node present only in the
|
|
passive firewall's running-config.xml file.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-292471</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the default route (0.0.0.0/0) advertised via the
|
|
<span class="ph uicontrol">Originate Default Route</span> in BGP AFI
|
|
profiles did not appear in the output of the
|
|
<span class="ph systemoutput"
|
|
>show advanced-routing bgp peer advertised-routes</span
|
|
>
|
|
CLI command, even though it was being sent to the BGP peer.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-292447</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama did not display data in the
|
|
<span class="ph uicontrol">Feature Adoption</span> tab in Strata Cloud
|
|
Manager due to the system creating and deleting a CLI user for each
|
|
interval instead of reusing a permanent CLI user for telemetry.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-292393</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where TFTP file transfers intermittently timed out in
|
|
active-active HA pairs when the TFTP control channel was processed by
|
|
one firewall and the data channel was processed by the other. This
|
|
occurred because the firewall receiving the data channel failed to
|
|
match the predicted session due to asynchronous processing of HA
|
|
messages.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-292285</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Firewalls in active/passive HA configurations only</tt
|
|
>) Fixed an issue where network outages of approximately 30 seconds
|
|
occurred after a failover due to a delay in establishing the BGP
|
|
connection between the new active firewall and one of its peers and a
|
|
second delay in advertising prefixes learned from the firewall to
|
|
another peer.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-292242</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on M-200 and logging appliances where traffic logs were
|
|
intermittently truncated when forwarded using a TCP syslog
|
|
configuration. This issue occurred during the log forwarding stage due
|
|
to intermittent syslog drops caused by exceeding the forwarding queue
|
|
capacity.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-292228</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after configuring dual stack GlobalProtect with
|
|
both IPv4 and IPv6 address pools, IPv6 return traffic was dropped with
|
|
the error message
|
|
<span class="ph systemoutput"
|
|
>flow-basic error; packet dropped, tunnel resolution failure</span
|
|
>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-292079</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue where
|
|
the data on scheduled SaaS Application Usage Reports was different
|
|
than the data on on-demand reports generated via
|
|
<span class="ph uicontrol">Run Now</span>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-292019</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the Panorama web interface where cloud applications
|
|
were not displayed under
|
|
<span class="ph uicontrol">Objects > Applications</span> after a
|
|
new content upgrade and Cloud App Catalog download, and were only
|
|
visible in application groups, security policy rules, and the CLI.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291984</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where SSH/SFTP traffic was intermittently blocked by
|
|
URL filtering due to the firewall incorrectly applying URL categories
|
|
from previous sessions.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291945</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on PA-5220 firewalls where denied traffic logs
|
|
incorrectly displayed a byte count of 0. This occurred because the
|
|
bytes_sent value was stored in the most significant bits of
|
|
u_bytes_sent, resulting in a zero value when a small value was
|
|
assigned to u_bytes_sent.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291940</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall established multiple TCP connections
|
|
to a syslog server, which caused logs to be dropped. This occurred
|
|
because the firewall established a new TCP session for each transfer
|
|
and the sessions were not closed, which resulted in a continuous
|
|
increase in connections over time.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291915</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the firewall where the PDT process experienced a
|
|
memory leak due to frequent dumping of fabric traffic statistics,
|
|
which resulted in high CPU utilization and instability.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291804</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where deleting objects resulted in errors
|
|
indicating references in Security policy rules.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291792</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-7050 firewalls on vwire instances only</tt>)
|
|
Fixed an issue where Bidirectional Forwarding Detection (BFD) echo
|
|
packets were dropped due to the firewall dropping packets with the
|
|
same source and destination IP addresses.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291781</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where the CLI command
|
|
<span class="ph systemoutput">show ntp</span> displayed the error
|
|
message
|
|
<span class="ph systemoutput"
|
|
>server error: op command for client dagger timed out as client is
|
|
not available</span
|
|
>
|
|
even when connectivity to the NTP server was active.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291716</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where during a commit, the firewall experienced an
|
|
out-of-memory (OOM) condition due to a memory leak and displayed an
|
|
error message. This issue caused the device to stop responding and
|
|
reboot unexpectedly.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291661</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama appliances and Log Collectors where, after
|
|
an upgrade, Elasticsearch intermittently entered into a Red state
|
|
before automatically recovering.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291653</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the GlobalProtect host ID field was
|
|
intermittently blank in traffic logs on Prisma Access, even when the
|
|
user was connected and had the correct host ID information. This
|
|
occurred when the IP address to host ID entry expired and the entry
|
|
was re-inserted without the dataplane flag being set.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291650</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall rebooted unexpectedly due to an OOM
|
|
condition.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291635</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where cookie surrogate cache entries remained
|
|
unresolved after an
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>idmgr</a
|
|
>
|
|
process reset due to the request not being retransmitted. This
|
|
occurred because the timestamp in the cache entry was refreshed even
|
|
when the UID was 0, which prevented the retransmission of the request
|
|
if the initial response was not received.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291247</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where checksum values changed when downloading files
|
|
through TFTP on firewalls using subinterfaces.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291174</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Real Time Streaming Protocol (RTSP) video streams
|
|
did not work when connected through GlobalProtect due to the firewall
|
|
blocking 200 OK responses. This occurred because of incorrect NAT
|
|
translations for the 200 OK message from the server.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291067</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>devsrvr</a
|
|
>
|
|
process periodically exceeded its virtual memory limit and restarted,
|
|
which led to intermittent outages.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291009</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after a web server returned a 401 or 403 error,
|
|
the firewall was unable to decrypt HTTP/2 traffic, and the firewall
|
|
rejected all subsequent streams from the client.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-290954</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the web server used a low HTTP Strict Transport
|
|
Security (HSTS) max-age value of 86400 seconds for the
|
|
log.query.expression.js.php page.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-290948</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the proxy hid the Cache-Control header, which
|
|
prevented context switching.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-290938</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where multiple memory leaks occurred related to the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>configd</a
|
|
>
|
|
process.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-290851</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the Agent User Override Key was incorrectly
|
|
available for configuration on Panorama management servers when
|
|
running in FIPS-CC mode.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-290783</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<span class="ph systemoutput">debug dataplane nat sync-ippool</span>
|
|
command may not accurately account for all allocated ports or
|
|
display/sync leaks when multiple NAT rules use the same IP pool. This
|
|
could result in inaccurate reporting of leaked ports. The fix modifies
|
|
the implementation to directly compare the original pool against the
|
|
temporary pool across all vsys.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-290728</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where modifying an interface IP address on an existing
|
|
vsys caused a default <span class="ph uicontrol">vsys1</span> to be
|
|
created, which led to commit failures due to the maximum supported
|
|
number of vsys being reached.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-290681</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama and Panorama managed firewalls where
|
|
template settings reverted during a device group push when
|
|
<span class="ph uicontrol">Include Device and Network Templates</span>
|
|
was checked, even if no changes were made to the template. This caused
|
|
the SAML IDP server profile certificate to revert to an older, invalid
|
|
certificate, and resulted in GlobalProtect users being unable to
|
|
authenticate via SAML.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-290665</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue with firewalls enabled with Security profiles where
|
|
certain traffic conditions caused high dataplane CPU utilization and
|
|
packet buffer exhaustion, which caused LACP flapping conditions.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-290663</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Panorama managed firewalls in HA configurations only</tt
|
|
>) Fixed an issue where the firewall did not enforce serial number
|
|
validation during HA deployment or replacement, which resulted in
|
|
pairs being established even when the serial numbers configured on
|
|
Panorama did not not match the serial number of the devices.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-290640</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>VM-Series firewalls on Microsoft Azure environments in HA
|
|
configurations only</tt
|
|
>) Fixed an issue where, when an interface was configured with IPv6,
|
|
the firewall displayed the message
|
|
<span class="ph uicontrol">Unknown error</span> during validation
|
|
after the client secret expired, which caused DNS resolution to fail
|
|
when resolving FQDNs and HA failovers to occur.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-290449</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, when multiple scheduled vulnerability reports
|
|
were sent in the same email, only the first attached report was
|
|
displayed.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-290157</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>configd</a
|
|
>
|
|
process stopped responding when filtering in the
|
|
<span class="ph uicontrol">Config Audit</span> window, which caused
|
|
Panorama to restart unexpectedly.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-289852</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where websites did not load when accumulation proxy was
|
|
enabled.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-289757</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where policy rule imports were blocked when
|
|
<span class="ph uicontrol">any</span> was in the source device column,
|
|
which prevented the use of inbound policy rule recommendations.
|
|
Additionally, when the source profile name was missing for inbound
|
|
behaviors, a default policy rule name was not able to be generated.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-289736</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where partial-revert operations were taking a long
|
|
time, causing config lock timeout issues and resulting in frequent
|
|
error messages being displayed:
|
|
<span class="ph uicontrol"
|
|
>Timed out while getting config lock. Please try again.</span
|
|
>
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-289723</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall web interface continuously loaded
|
|
and not display any output when viewing the Route Table or FIB table
|
|
(<span class="ph uicontrol">More Runtime Stats</span>). This issue
|
|
occurred when L3 configurations were added to ethernet and AE
|
|
interfaces.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-289706</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>authd</a
|
|
>
|
|
process crashed intermittently on VM-Series firewalls due to
|
|
authentication sequence failures. The crashes occurred during memory
|
|
management operations within a library while releasing memory to its
|
|
central cache.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-289578</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama managed firewalls where the source user,
|
|
source device vendor, source MAC address, and OS version information
|
|
were not visible in traffic logs and SCM when the user and device
|
|
access control lists were empty.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-289249</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where a memory leak occurred on the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>reportd</a
|
|
>
|
|
process when a WildFire update was initiated while device telemetry
|
|
data collection was in progress. This resulted in an OOM condition.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-289067</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after upgrading Panorama in a High Availability
|
|
(HA) pair, the configuration logs stopped synchronizing from the
|
|
primary Panorama to the secondary Panorama. This issue occurred
|
|
because the log forwarding flag was permanently disabled due to the
|
|
connection state not being active when the
|
|
<span class="ph systemoutput">log-fwd-ctrl</span> message was
|
|
received.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-288938</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the Panorama web interface where the search bar
|
|
suddenly was not displayed, or the filter/clear filter icon moved to
|
|
the left of the search bar.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-288869</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where custom administrators with visibility into
|
|
specific vsys logs were able to view logs for all vsys.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-288388</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after an EDL certificate update or repository
|
|
migration, authentication failures caused the firewall to not fall
|
|
back to the last successfully cached EDL entries, which led to policy
|
|
rules that referenced the EDL to not be enforced.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-288381</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where data interfaces unexpectedly went down and then
|
|
up after an HA failover, which caused intermittent traffic disruption.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-288175</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Addressed a stack buffer overflow memory leak under plugin management
|
|
code path.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-288141</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<span class="ph systemoutput">debug data-plane sync ippool</span> CLI
|
|
command did not work for Per Destination IP Pool (PDIPP) and caused a
|
|
memory leak.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-288139</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall incorrectly identified ports as
|
|
leaking when the session was not active even though the ports were
|
|
allocated.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-287803</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, after upgrading firewalls to PAN-OS 11.1.6-h1,
|
|
certain websites weren't accessible when the accumulation proxy was
|
|
enabled. The proxy did not use the same DF bit state as the original
|
|
traffic, causing it to be fragmented and dropped elsewhere in the
|
|
network.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-287782</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where firewalls configured in vwire mode modified DSCP
|
|
values from AF11 to CS0 on traffic passing through the firewall, even
|
|
when QoS policy rules and DSCP rewrite settings were not configured.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-287713</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where, after uninstalling a plugin, commit
|
|
validation failed with the error message
|
|
<span class="ph systemoutput"
|
|
>interface '-' is not a valid reference</span
|
|
>
|
|
due to cloud service plugin configuration errors.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-287693</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama did not use the configured proxy
|
|
settings to check WildFire private cloud content and instead connected
|
|
directly to the WildFire device using the management interface. This
|
|
occurred even when
|
|
<span class="ph uicontrol">Use Proxy Settings for Private Cloud</span>
|
|
was enabled.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-287599</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the prefix value for a BGP neighbor caused the
|
|
firewall to leak routes to a different BGP peer.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-287581</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Firewalls in active/passive HA configurations only</tt
|
|
>) Fixed an issue where the firewall did not process and transmit HA
|
|
path monitoring probes received from another HA cluster when the
|
|
firewall acted as a gateway for internal monitoring IP addresses used
|
|
in the HA path monitoring group, which caused HA flapping due to path
|
|
monitoring failures.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-287392</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed the issue on the web interface where
|
|
<span class="ph uicontrol">ACC</span> graphs displayed
|
|
<span class="ph uicontrol">No data to display</span> when a filter was
|
|
applied to <span class="ph uicontrol">Source IP</span> or
|
|
<span class="ph uicontrol">Destination IP</span>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-287387</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where API jobs failed with the error
|
|
message
|
|
<span class="ph systemoutput"
|
|
>Server error: Timed out while getting config lock</span
|
|
>. This occurred due to slow set request performance when setting a
|
|
large number of address objects in a single set call.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-287165</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on the firewall CLI where autocomplete did not work for
|
|
zones in the
|
|
<span class="ph systemoutput">clear session all</span> CLI command.
|
|
Additionally, the CLI was unable to clear sessions for a specific IP
|
|
subnet.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-287086</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where PA-3420 firewalls experienced unexpected reboots
|
|
due to the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>all_task_7</a
|
|
>
|
|
process crashing with signal 6, leading to a non-functional state.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-287034</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where sequence numbers were skipped for all types of
|
|
logs on the firewall due to audit logs being generated but not written
|
|
to disk when Audit Tracking was enabled.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-286865</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, when you upgraded log collectors via Panorama
|
|
(<span class="ph uicontrol">Device Deployment</span>), the software
|
|
installation on the log collector remained at 0%.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-286297</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall did not respond to ARP requests when
|
|
a subinterface was configured with source address translation using
|
|
the <span class="ph uicontrol">Translated Address</span> option.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-285758</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall web interface became unresponsive
|
|
while adding a description that contained 1062 bytes of character data
|
|
in a Security policy rule instead of displaying an error message when
|
|
the description exceeded the maximum allowed length.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-285208</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall did not automatically recover after
|
|
a machine check exception (MCE) occurred.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-285181</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the wifclient ran out of memory when Enhanced
|
|
Application Logging was enabled and a sudden traffic increase caused a
|
|
surge in EAL messages sent through WIF.
|
|
</div>
|
|
<div class="p">
|
|
To use this fix, run the CLI command
|
|
<span class="ph codeph">debug iot eal memory-gc native</span>
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-285169</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where Kerberos superusers were unable to
|
|
edit policy rules because the target device tab was grayed out.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-284801</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the OpenConfig plugin was automatically installed
|
|
on VM Panorama and firewalls after upgrading.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-284417</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where proxied traffic was shown as decrypted even when
|
|
no applicable decryption policy rule was configured. Additionally, the
|
|
<span class="ph systemoutput">show session</span> CLI command and the
|
|
session browser web interface incorrectly displayed cleartext proxy
|
|
sessions as decrypted.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-283704</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the PAN-OS DoS protection feature by default
|
|
blacklisted specific IP addresses, which caused outbound traffic
|
|
domain resolution to fail for clusters.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-283311</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where log forwarding to all syslog servers failed if
|
|
one syslog server that used TLS as the protocol became unreachable.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-283237</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where traffic logs incorrectly displayed the action as
|
|
<span class="ph uicontrol">allow</span> for traffic matching a
|
|
Security policy rule configured with the action set to
|
|
<span class="ph uicontrol">deny</span>. This issue occurred due to the
|
|
child session being used for policy rule lookup when a configuration
|
|
update triggered a rematch if the FTP-data application was not in the
|
|
rule.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-283101</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
|
|
issue where the
|
|
<span class="ph systemoutput">show wildfire status</span> CLI command
|
|
displayed an incorrect maximum file size of 4 KB for WildFire script
|
|
uploads even though the configured value was different.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-283053</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall experienced high disk space
|
|
utilization, which caused the firewall to become non-functional.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-282961</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall rebooted unexpectedly after a commit
|
|
due to a memory leak related to the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>rasmgr</a
|
|
>
|
|
process and displayed the error message
|
|
<span class="ph systemoutput"
|
|
>Management server failed to send phase 1 to client l2ctrld</span
|
|
>
|
|
before rebooting.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-282956</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on firewalls running PAN-OS 11.1 and later PAN-OS
|
|
releases where the portal and gateway configuration view did not
|
|
display rows and columns.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-282687</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where performing a selective revert of
|
|
configuration changes resulted in all configuration changes being
|
|
reverted.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-281721</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall generated high-severity system
|
|
alerts indicating that the configuration size exceeded the maximum
|
|
recommended size, even when the configuration size was within the
|
|
expected limits.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-281588</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where packet buffer depletion occurred due to the a
|
|
high number of
|
|
<span class="ph systemoutput">tcp_pkt_queued</span> packets when Jumbo
|
|
was enabled.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-280917</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where the WildFire cloud URL contained an
|
|
extra period character, which prevented the retrieval of WildFire
|
|
analysis reports.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-280536</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where firewalls that were connected to the same Cloud
|
|
Identity Engine displayed inconsistent group membership information,
|
|
with some firewalls showing only a subset of users belonging to a
|
|
group. This occurred due to a full or incremental group sync failure.
|
|
</div>
|
|
<div class="p">
|
|
This fix introduces a retry mechanism for failed group queries to the
|
|
Cloud Identity Engine. To use this feature, run the following CLI
|
|
commands.
|
|
</div>
|
|
<div class="p">
|
|
To enable the retry mechanism:
|
|
<span class="ph systemoutput">debug user-id dscd retry-enable on</span
|
|
>.
|
|
</div>
|
|
<div class="p">
|
|
To set the retry time:
|
|
<span class="ph systemoutput"
|
|
>debug user-id dscd retry-time set-time <1-10></span
|
|
>. The default value is 5 seconds.
|
|
</div>
|
|
<div class="p">
|
|
To set the number of retry attempts:
|
|
<span class="ph systemoutput"
|
|
>debug user-id dscd retry attempts set-attempts <3-10></span
|
|
>. The default value is 5 attempts.
|
|
</div>
|
|
<div class="p">
|
|
To disable the retry mechanism:
|
|
<span class="ph systemoutput"
|
|
>debug user-id dscd retry-enable off</span
|
|
>.
|
|
</div>
|
|
<div class="p">
|
|
Additionally, a system log is now generated when a group sync fails,
|
|
and you are able to monitor the group sync status with the following
|
|
CLI commands:
|
|
</div>
|
|
<ul class="ul">
|
|
<li class="li">
|
|
<span class="ph systemoutput"
|
|
>show user group count list cloud-identity-engine</span
|
|
>
|
|
</li>
|
|
<li class="li">
|
|
<span class="ph systemoutput"
|
|
>show user group count name <group_name></span
|
|
>
|
|
</li>
|
|
</ul>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-279699</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on M-600 line cards where the /var/log/messages file
|
|
flooded with
|
|
<span class="ph systemoutput"
|
|
>i40e 0000:81:00.1: ARQ: Unknown event 0x0000 ignored</span
|
|
>
|
|
messages, causing the root partition to fill up and prevent PAN-OS
|
|
upgrades.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-278688</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where DNS Security threat logs were not displayed on
|
|
the firewall when packet capture was enabled and the domain name
|
|
length was 62 characters.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-278611</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where software images were not purged from
|
|
the /opt/pancfg/mgmt/sw-images folder.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-277971</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the PA-5220 firewall reports inaccurate NetFlow
|
|
statistics for DNS flows after upgrading to PAN-OS 10.2.13.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-277178</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where you were unable to delete a shared
|
|
object due to the rulebase incorrectly referencing the shared object
|
|
instead of the device group-specific object when the name was used.
|
|
</div>
|
|
<div class="p">
|
|
To use this fix, delete the original shared object after cloning it to
|
|
a device group with the same name.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-276525</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Resolved multiple issues affecting IPSec tunnels using NAT Traversal
|
|
(NAT-T) when a Dynamic NAT policy was configured (including Dynamic
|
|
NAT or DIPP). During rekey events, tunnels could go down or flap due
|
|
to incorrect session handling. This issue impacted both cluster and
|
|
standalone deployments.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-275050</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the Japanese translation for the URL filtering
|
|
option to add a trailing slash to entries and the device license
|
|
status error was incorrect.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-274484</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where commits failed when
|
|
<span class="ph uicontrol">Data Services</span> was in a Service route
|
|
configuration was configured with the
|
|
<span class="ph uicontrol">MGMT</span> interface.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-273487</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>distributord</a
|
|
>
|
|
process restarted on firewalls in multi-vsys environments with User-ID
|
|
configured and Panorama as a redistribution client. This occurred when
|
|
a large volume of IP address-to-user mappings were learned.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-273158</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-7000 Series firewalls only</tt>) Fixed an issue
|
|
where an incorrect ASIC configuration caused silent packet drops or
|
|
application slowness when receiving a mix of jumbo and non-jumbo
|
|
packets.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-273028</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where manual SCP exports from firewalls in FIPS mode
|
|
were successful to SCP servers that were not FIPS-compliant. This
|
|
occurred because the manual SCP process did not enforce FIPS security
|
|
checks.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-272432</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama and Cortex Data Lake (CDL) logs
|
|
displayed incorrect interface names without node IDs for cluster
|
|
firewalls.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-272245</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>dnsproxy</a
|
|
>
|
|
process stopped responding due to memory corruption caused by a race
|
|
condition when the allow list downloading was impacted by a
|
|
configuration change.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-271507</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
|
|
the DPC on slot 3 intermittently stopped responding due an
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>all_pktproc</a
|
|
>
|
|
restart.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-271239</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where searching for the GlobalProtect client version
|
|
browser in Panorama logs returned no results.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-268038</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<span class="ph systemoutput">routed</span> process on Orion-ZTNA NGFW
|
|
Connectors stopped responding when a destination FQDN path monitor
|
|
configuration was present and the
|
|
<span class="ph systemoutput">show routing path-monitor</span> CLI
|
|
command was executed due to the CLI command handler dereferencing a
|
|
null pointer without proper validation.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-267965</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Firewalls on Amazon Web Services (AWS) environments only</tt
|
|
>) Fixed an issue where newly bootstrapped firewalls sent an
|
|
incorrect, non-DHCP-assigned hostname to the SNMP server. This
|
|
occurred because the SNMP process referred to a configuration file
|
|
that was not updated due to a missing configuration commit.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-267614</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the Panorama web interface was slower than
|
|
expected due to high CPU utilization on the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>mongodb</a
|
|
>
|
|
process.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-267450</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>reportd</a
|
|
>
|
|
process stopped responding with a SIGSEGV at
|
|
<span class="ph systemoutput">schedule_report_es_response</span>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-266843</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on airgapped firewalls where cloud connection errors
|
|
flooded the system logs.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-265744</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall repeatedly generated false critical
|
|
alerts due to an Intel firmware issue.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-264762</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall showed the status of SFP+ interfaces
|
|
as not up, or up but not configured, when a PAN-SFP-PLUS-SR cable was
|
|
connected.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-263691</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall rebooted unexpectedly due to a
|
|
memory leak in the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>all_task</a
|
|
>
|
|
process.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-262353</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, when Panorama was upgraded but log collectors
|
|
were on an earlier version, logs from a log collector group were not
|
|
viewable on a Panorama.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-259853</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, when the DHCP server was enabled for
|
|
GlobalProtect, the commit error message was not properly displayed
|
|
when <span class="ph uicontrol">Any</span> was selected as the source
|
|
interface in the service router configuration (<span
|
|
class="ph uicontrol"
|
|
>Device > Setup > Service > Service Router
|
|
Configuration</span
|
|
>).
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-259785</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>devsrvr</a
|
|
>
|
|
process restarted and created a core dump because two threads did not
|
|
terminate correctly.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-255879</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<span class="ph uicontrol">threat name</span> on the firewall report
|
|
PDF was blank.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-253504</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where commits did not return an error message when an
|
|
invalid Log Forwarding Filter was configured.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-250339</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Added an improvement to automatically clean up idle HTTP connection
|
|
pools to address an issue where idle connection pools accumulated when
|
|
a circuit breaker limit was reached, which caused client requests to
|
|
fail with a 503
|
|
<span class="ph systemoutput">no_healthy_upstream</span> error.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-248913</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the Elasticsearch client certificate was not auto
|
|
renewed, which caused it to enter a Red state, and logs were not
|
|
displayed in Panorama.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-242952</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where high SSL traffic depleted flex memory, which
|
|
prevented the firewall from revalidating SSLVPN client CAs during
|
|
configuration pushes.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-238208</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall API returned inconsistent responses
|
|
to a failed call using a valid API key. With this fix, the firewall
|
|
returns the error
|
|
<span class="ph uicontrol">Session is invalid</span> if the session is
|
|
not available for the cookie.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-237294</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the interface rate counter intermittently went to
|
|
zero frequently.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-209516</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, when creating an interface, an error occurred
|
|
when you clicked <span class="ph uicontrol">OK</span> without
|
|
providing a value in the <span class="ph uicontrol">Tag</span> field
|
|
even though the field was not displayed as mandatory.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-185731</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall was unable to parse the URL path and
|
|
host when the host header was located in a different packet, which
|
|
resulted in the firewall not logging the URL path in the first packet.
|
|
</div>
|
|
<div class="p">
|
|
The fix is disabled by default. The following CLI commands can be used
|
|
to enable/disable the feature:
|
|
<ul id="panos-addressed-issues-11.2.11_ul-imr_phd_s3c" class="ul">
|
|
<li class="li">
|
|
<span class="ph systemoutput"
|
|
>set system setting ctd url-crosspkt-host-path-caching
|
|
enable</span
|
|
>
|
|
</li>
|
|
<li class="li">
|
|
<span class="ph systemoutput"
|
|
>set system setting ctd url-crosspkt-host-path-caching
|
|
disable</span
|
|
>
|
|
</li>
|
|
<li class="li">
|
|
<span class="ph systemoutput"
|
|
>set system setting ctd url-crosspkt-host-path-caching
|
|
default</span
|
|
>
|
|
</li>
|
|
</ul>
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|