Files
firewallissues/reference/PAN-OS/addressed/11.2.4-h6.html
T

560 lines
16 KiB
HTML

<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-284036</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-450R and PA-450R-5G firewalls only</tt>) Fixed
an issue where the maximum temperature threshold and shutdown
threshold were not set correctly.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-282236</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where large IPv6 packets were reassembled incorrectly
on the firewall when the packets arrived fragmented over an IPv4
tunnel.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-282206</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where configuring Secure Web Gateway (SWG) in
<span class="ph uicontrol">no-auth</span> mode led to latency when no
decryption policy rules or
<span class="ph uicontrol">No-decrypt</span> policy rules were
present.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-282022</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed the support limitation for the Panorama M-600 and M-700
appliances.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-280471</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where navigating
<span class="ph uicontrol">Panorama &gt; Monitor &gt; Logs</span> was
slower than expected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279746</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SMTP packets were not sent out when the Client
Hello arrived at the firewall in multiple out-of-order segments and
the traffic was not subject to SSL decryption.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279197</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-450R-5G firewalls only</tt>) Fixed an issue
where the firewall stopped responding and displayed the error message
`Thermal temperature exceeds system threshold! Shutting down NOW` even
when the firewall was within the threshold.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-278684</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-445 firewalls only</tt>) Fixed an issue where
the firewall did not properly power cycle during a reboot.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-278296</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the system MAC address of the aggregate interface
was the same on the active firewall and the passive firewall after an
upgrade.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-276546</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a session lost the PBF rule mapping after a
configuration change or commit.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-275905</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama web interface was slower than
expected and Elasticsearch CPU usage was high.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273949</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall generated the following error
message in the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>snmpd</a
>
logs:
<span class="ph systemoutput"
>pan_get_keystr_from_cryptod(pan_snmpinterface.c:181): Key
X2F1dGhfa2V5 import from cryptod failed.</span
>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273026</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic logs did not display correctly when
filters were applied.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273021</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where 25G port links did not come up due to a change in
the handling of 25G DAC modules.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272849</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where log forwarding to a UDP syslog server stopped
when an unreachable TCP syslog server was configured and applied.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272538</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding during a commit-all validation when there
were uncommitted changes and
<span class="ph systemoutput">share-unused-objects-with-devices</span>
was set to off.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272085</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall might crash and reboot when DoH is
enabled for DNS Security and multiple DoH transactions are sent in a
single HTTP/1 connection.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271912</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding when filtering in the configuration audit
window after upgrading to PAN-OS 11.1.3.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271351</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-0116"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-0116</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270224</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where indices were not opened after a query.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269956</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process stopped responding, which caused internal path monitor
failures.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269291</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the scheduled report generation script did not
return debug information.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269106</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">wifclient</span> stopped responding
during server certificate verification for MICA gRPC connections and
caused the dataplane to restart when using a cloud-based ML detection
engine (MICA). On certain platforms, this caused the firewall to
reboot periodically.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269091</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>varrcvr</a
>
process stopped responding.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268501</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to generate a TSF file
due to a full root partition.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267430</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama was unable to return logs for queries
that were longer than 64,000 characters.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-265179</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a kernel race condition caused the firewall to
reboot with a kernel panic.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-263208</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5440 and PA-5445 firewalls only</tt>) Fixed an
issue where interrupts were generated at a certain packet rate, and
dataplane processes missed heartbeats, which caused the dataplane to
go down.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-262383</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to decompress the HTTP2
header, which caused the session to be classified as unknown-tcp
instead of web-browsing.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261739</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls in Microsoft Azure environments only</tt
>) Fixed an issue where the firewall displayed 0 for the physical port
counters read from MAC.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261484</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where DPDK allocated twice the amount
of memory as requested for pre-allocation.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-258736</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where policy rule configurations pushed from Panorama
were not reflected on the firewall if the rule had 63 characters.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-258570</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall might reboot unexpectedly due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>varrcvr</a
>
process progressively using more memory when WildFire file forwarding
is handling PE files.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-257619</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the
<span class="ph uicontrol">Task Manager</span> took longer than
expected to display managed firewall report tasks.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-257028 </b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/passive HA configurations only</tt
>) Fixed an issue where firewalls entered a non-functional state and
displayed the error message
<span class="ph systemoutput"
>Dataplane down: path monitor failure during the fail-over</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-255323</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7050 firewalls only</tt>) Fixed an issue where
the Network Processing Card (NPC), Data Processing Card (DPC), and Log
forwarding Card (LFC) remained in a starting state after an unexpected
power cycle.
</div>
</td>
</tr>
</tbody>
</table>