Files
firewallissues/reference/PAN-OS/addressed/11.1.13-h2.html
T

631 lines
19 KiB
HTML

<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-314319</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall experienced increased packet drops
and slower performance after an upgrade due to high burst traffic.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"></b></div>
</td>
<td class="entry relcol">
<div class="p"></div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-313572</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the dataplane restarted due to a segmentation fault.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-312706</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewalls restarted due to a function lacking
a NULL-pointer sanity check.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-311524</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where config-lock was not displayed on the web
interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-311250</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances and Log Collectors only</tt>)
Fixed an issue where logs from multiple devices were not visible on
Panorama even though the Elasticsearch health status on the dedicated
Log Collectors appeared green.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-311073</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Panorama managed firewalls in HA configurations only</tt
>) Fixed an issue where firewalls incorrectly updated the modified
date and MD5 hash of policy rules during an HA sync commit job or a
subsequent local commit, even when no changes were made to the policy
rules.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-308786</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue where
traffic log queries using the
<span class="ph systemoutput">device_name</span> filter returned no
results, and, additionally complex log queries that included negation
operators produced incorrect outputs.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-308654</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Elasticsearch Close Indices process closed
more indices than expected and dropped the number of open shards below
the minimum of 800 per Elasticsearch instance. This occurred because
the process did not correctly account for the number of Elasticsearch
instances when calculating the maximum number of allowed open shards.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-307702</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
issue where traffic passing through AE layer 2 interfaces was
interrupted during HA failovers.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-307597</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where BGP peering sessions between a hub firewall and a
satellite firewall over GlobalProtect LSVPN failed to connect.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-306555</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding, which led to
service outages.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-306451</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls on AWS environments only</tt>)
Fixed an issue where, after upgrading the firewall to an affected
release, GlobalProtect clients did not connect with IPSec and instead
connected using SSL due to traffic flow being disabled when checking
for health check packets.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-305700</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a reboot loop occurred when OSPF interfaces were
configued with a link type of
<span class="ph uicontrol">point-to-point</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-305552</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DLP logs displayed an incorrect file type when
the firewall did not set the file type field.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-304746</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Panorama appliances and Panorama virtual appliances only</tt
>) Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process restarted when committing and pushing configuration for a new
WildFire cluster.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-304718</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where OSPF and BGP outages occurred due to an
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process restart during clientless VPN content rewrite processing.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-304696</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Cloud User-ID connection timed out because
the firewall took too long to process the OCSP response.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-304576</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall entered a non-functional state due
to segmentation fault within the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process that was caused by a session that involved http2 cleartext
traffic
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-303745</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where inter-dataplane forwarding did not work for
sessions ingressing on Slot 2, which resulted in intermittent ping
failures to interfaces on Network Card 2 when traffic was forwarded to
Slot 3. Note: With this fix, after a slot restart, the global counter
will still show dot1q errors for a short period.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-303722</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where configuring spyware and
vulnerability profiles in Security policy rules caused a memory leak
in the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
process with each configuration commit.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-301731</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the firewall was unable to establish an SCM
connection due to the discovery service returning a 404 error when the
device was not yet known to the service, the firewall did not retry
the attempt as expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-300664</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama and firewall web interface where
Applications pages became unresponsive after activating the SaaS
Inline license.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-299705</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where API calls to commit changes on Panorama
intermittently failed when using the XML API with refresh=<span
class="ph systemoutput"
>no</span
>, which caused changes to not be applied to the partial-commit
configuration.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-299495</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput"
>show system setting ssl-decrypt certificate</span
>
CLI command did not display certificates when XML output was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-298945</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where OSCP HTTP POST requests were not formatted
correctly, which caused failures with strict responders.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b"> PAN-297540 </b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Panorama managed firewalls in HA configurations only</tt
>) Fixed an issue where the HA-Link-Monitor configuration pushed from
Panorama was converted to a local configuration on the peer device
after an HA sync, which caused subsequent Panorama pushes of link
monitor changes to be flagged as overwritten, and a forced template
push or manual clearing of the configuration on the firewall was
required.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-296694</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process repeatedly restarting during an IP-port data type writes to
the redis from multiple sources such as TSA or XML in a scale
environment.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-295803</b></div>
</td>
<td class="entry relcol">
<div class="p">
Addressed a memory leak issue under sc3 and automatic commit recovery
(ACR) code path.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-295802</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory leak related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process occurred.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-294379</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when SD-WAN SaaS Application path monitoring
failed for all interfaces, the firewall stopped forwarding traffic
even if the ISP links and default gateway probing were still active.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-292306</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>authd</a
>
process stopped handling RADIUS authentication requests and required a
restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-290938</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where multiple memory leaks occurred related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-288175</b></div>
</td>
<td class="entry relcol">
<div class="p">
Addressed a stack buffer overflow memory leak under plugin management
code path.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-287159</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where file uploads to Dropbox stalled when using a
PA-CPT device with MLC2 and DLP Mirror mode enabled for HTTP2 traffic.
This occurred because the proxy was unable to decrement packet counts
properly when the queue was large, resulting in a receive window size
of 0 for the parent session.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279364</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls with multiple NICs only</tt>)
Fixed an issue were the queue count in the task dump displayed an
incorrect number of queues for SR-IOV interfaces due to the queue
mapping logic incorrectly using a non-multi-NIC function.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-278688</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DNS Security threat logs were not displayed on
the firewall when packet capture was enabled and the domain name
length was 62 characters.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-274742</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the <span class="ph systemoutput">task-queue dump</span> CLI command
returned incorrect information in multi-nic mode.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259785</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
process restarted and created a core dump because two threads did not
terminate correctly.
</div>
</td>
</tr>
</tbody>
</table>