Files
firewallissues/reference/PAN-OS/addressed/10.2.16-h6.html
T
2026-05-18 08:30:46 -05:00

451 lines
14 KiB
HTML

<table class="table colsep rowsep">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 46.728971962616825%" />
<col style="width: 53.27102803738318%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">Issue ID</th>
<th class="entry">Description</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-304756</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where, after you disabled the shared
optimization feature, a full configuration push to multi-vsys devices
caused a validation error.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297775</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to an affected PAN-OS release,
the Visible Virtual System field referenced the vsys name instead of
the vsys ID, which caused inter-vsys routing to fail. This occurred
when a vsys display name matched one of the vsys IDs. If you're using
a multivsys environment, you must upgrade your firewalls to a fixed
PAN-OS version. The best practice is to upgrade both the firewalls and
Panorama to a fixed PAN-OS version.
</div>
<div class="p">
If you don't upgrade Panorama to a fixed version, you'll encounter
PAN-245064, where a commit on a multivsys firewall fails with the
message
<span class="ph systemoutput"
>vsys name should end with a number vsys is invalid</span
>
after you
<span class="ph uicontrol">Export or push device config bundle</span>
from Panorama.
</div>
<div class="p">
After you upgrade Panorama to a fixed version, you'll encounter
PAN-214177, which causes an
<span class="ph uicontrol">Export or Push device config bundle </span
>from Panorama to the firewall to fail. The workaround for PAN-214177
is to first push only the template configuration and then push the
device group configurations.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-297349</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the MIB ID returned an incorrect value via SNMP.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-294770</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in active/passive HA configurations</tt>)
Fixed an issue on firewalls where, after failover, certain subnets
were missing from the Link State Database, which prevented OSPF routes
from being immediately learned due to a Type-7 to Type-5 LSA
translation conflict in the ABR when the same LSA was advertised by
two peers in the NSSA area.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-293673</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped all tasks due to an OOM
condition caused by a scheduled log export using FTP to an external
FTP server.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-292539</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">CN-Series firewalls only</tt>) Fixed an issue where
the firewall generated incomplete or corrupted tech support files
(TSF) due to high disk usage on the management plane.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291716</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where during a commit, the firewall experienced an
out-of-memory (OOM) condition due to a memory leak and displayed an
error message. This issue caused the device to stop responding and
reboot unexpectedly.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-291288 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted unexpectedly due to a
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process restart related to page allocation failures.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-289239</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a new virtual system (vsys) was
automatically created with the name of a device group.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-288097</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where on the firewall where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>routed</a
>
process stopped responding after changing the MTU or any link state
parameters when OSPF and PIM were enabled on the same interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-287734</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the error message
<span class="ph uicontrol">Scan ERR: Internal Err 1002</span> was
generated unexpectedly when WIF shared memory use was high.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286615</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall double-freed shared memory when the
shared memory usage reached 100% when sending large payloads. This
occurred when DLP, Advanced Advanced Threat Protection (ATP), Advanced
WildFire (AWF), or Advanced URL Filtering were enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-286231</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a simultaneous selective push from Panorama to
multiple firewalls with different base configurations resulted in
configuration corruption, which caused the firewall to go down.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-285208</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not automatically recover after
a machine check exception (MCE) occurred.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-284067</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a cumulative memory leak in the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
process that occurred whenever the CLI command
<span class="ph systemoutput"
>show running application statistics</span
>
was issued. This memory leak would gradually consume system memory and
produce an OOM condition, causing the firewall to reboot.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-284003</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where clients did not receive a valid response when
searching a website due to a compression error.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-280536</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls that were connected to the same Cloud
Identity Engine displayed inconsistent group membership information,
with some firewalls showing only a subset of users belonging to a
group.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279901</b></div>
</td>
<td class="entry relcol">
<div class="p">
An issue was fixed where the firewall dropped fragmented TLS
ClientHello packets, which blocked access to certain websites. This
occurred because the packets arrived truncated, in varying sizes and
orders, and the firewall's heuristics failed to handle them correctly.
</div>
<div class="p">
To enable this fix, run:
<span class="ph systemoutput"
>debug dataplane set ssl-decrypt accumulate-client-hello disjoined
yes</span
>
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279500</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TLS connections failed to establish in asymmetric
routing environments if the firewall did not see server-to-client
(s2c) packets of the TLS handshake.
</div>
<div class="p">
To use this fix, run the following CLI command:
<span class="ph systemoutput"
>debug dataplane set ssl-decrypt accumulate-client-hello
asym-disable yes</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279364</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls with multiple NICs only</tt>)
Fixed an issue were the queue count in the task dump displayed an
incorrect number of queues for SR-IOV interfaces due to the queue
mapping logic incorrectly using a non-multi-NIC function.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-278288 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IPv6 BGP peering established between virtual
routers even without dataplane connectivity. This occurred because the
firewall used the kernel for lookups instead of the dataplane.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-276484 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not display license information for
Cloud NGFW firewalls under (<span class="ph uicontrol"
>Device Deployment &gt; Licenses</span
>) due to the inability to perform batch-license refreshes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267614</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama web interface was slower than
expected due to high CPU utilization on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>mongodb</a
>
process.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-231386</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding during certificate verification.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-202905</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall web interface where the
<span class="ph uicontrol">Next Hop</span> value was not displayed in
the static route configuration, the
<span class="ph uicontrol">admin-dist</span> values were empty, and
the path-monitor parameters were not listed in the management server
web interface when the firewall was configured in FRR mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-191026</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">debug log receiver statistics</span> CLI
command did not display entries for hipmatch logs.
</div>
</td>
</tr>
</tbody>
</table>