400 lines
12 KiB
HTML
400 lines
12 KiB
HTML
<table class="table colsep rowsep table-striped">
|
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
|
|
|
<colgroup>
|
|
<col style="width: 50%" />
|
|
<col style="width: 50%" />
|
|
</colgroup>
|
|
<thead class="thead">
|
|
<tr class="row rowsep">
|
|
<th class="entry">Issue ID</th>
|
|
<th class="entry">Description</th>
|
|
</tr>
|
|
</thead>
|
|
|
|
<tbody class="tbody">
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-321340</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Firewalls in FIPS mode only</tt>) Fixed an issue
|
|
where GlobalProtect unexpectedly prompted for RADIUS authentication
|
|
instead of client certificate authentication due to an OSCP validation
|
|
error and subsequent CRL verification failure, which led to
|
|
certificates being marked as invalid.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-319288</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where a DPC in Slot 4 restarted repeatedly, which
|
|
caused internal path monitoring failures and a failover event.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-318580</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where processes restarted and the firewall unexpectedly
|
|
rebooted when you configured a Security policy rule with
|
|
<span class="ph uicontrol">Source Device > quarantine</span>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-317755</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Panorama where selective push operations failed when
|
|
plugin configurations included access-domain or log-collector
|
|
references.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-317466</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where SIP sessions stopped progressing after the
|
|
firewall received fragmented packets, fragmented at header field.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-316556</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where a race condition between the session ager and
|
|
packet processing resulted in memory corruption and caused the
|
|
pan_task process to stop responding, which resulted in the firewall
|
|
becoming unresponsive
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-315337</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where GlobalProtect throughput was reduced after an
|
|
upgrade.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-315314</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where, when a push operation from Panorama to the
|
|
firewall failed, accounting logs stopped forwarding.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-315160</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-7500 firewalls only</tt>) Fixed an issue where
|
|
internal path monitoring logs incorrectly reported internal path
|
|
monitoring failures when they did not occur.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-314623</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Firewalls in active/passive HA configurations only</tt
|
|
>) Fixed an issue where, after a failover, routing information within
|
|
OSPF protocol was not correctly translated or propagated, which
|
|
affected network path convergence and FRR capabilities.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-313827</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where a memory leak occurred related to the
|
|
<span class="ph systemoutput">reportd</span> process when custom
|
|
reports were run via API.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-313606</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Panorama pushed commits took longer than expected
|
|
to complete without displaying an error message when committing due to
|
|
slow cloud-app compilation.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-311658</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>reportd</a
|
|
>
|
|
process stopped responding, which caused the firewall to reboot.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-311248</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the ABR failed to translate and advertise the
|
|
default route (0.0.0.0/0) from an OSPF NSSA area into the OSPF
|
|
backbone area as a Type-5 LSA.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-310240</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where software packet buffers were completely utilized
|
|
when performing a Data Loss Prevention longevity test.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-309853</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Firewalls with FIPS-CC enabled only</tt>) Fixed an
|
|
issue where, when attempting to make changes to the GlobalProtect
|
|
portal, an error message was displayed and configuration updates
|
|
failed.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-308775</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Firewalls in active/passive configurations only</tt
|
|
>) Fixed an issue where NTP status intermittently showed as rejected
|
|
on the active firewall, which prevented the firewalls from
|
|
synchronizing time.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-308668</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue on Prisma Access Remote Network firewalls where high
|
|
CPU utilization caused slowness and command timeouts.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-297819</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall was unable to send device telemetry
|
|
files to Cortex Data Lake due to the firewall receiving an invalid
|
|
upload token.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-293142</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where firewall components became unresponsive during
|
|
sustained operation.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-291660</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the firewall incorrectly reported the speed of
|
|
25G interfaces as 1G when queried using SNMP for the ifHighSpeed OID.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-289460</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the timestamp value in SNMPv3 trap headers was
|
|
incorrect.
|
|
</div>
|
|
<div class="p">
|
|
To use this fix, run the CLI command
|
|
<span class="ph systemoutput"
|
|
>debug log-receiver enginetime-from-snmptime yes</span
|
|
>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-282335</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where firewalls in a cluster experienced approximately
|
|
50% packet loss on IPSec NATT tunnels when tunnel acceleration was
|
|
enabled.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-280536</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where firewalls that were connected to the same Cloud
|
|
Identity Engine displayed inconsistent group membership information,
|
|
with some firewalls showing only a subset of users belonging to a
|
|
group. This occurred due to a full or incremental group sync failure.
|
|
</div>
|
|
<div class="p">
|
|
This fix introduces a retry mechanism for failed group queries to the
|
|
Cloud Identity Engine. To use this feature, run the following CLI
|
|
commands.
|
|
</div>
|
|
<div class="p">
|
|
To enable the retry mechanism:
|
|
<span class="ph systemoutput">debug user-id dscd retry-enable on</span
|
|
>.
|
|
</div>
|
|
<div class="p">
|
|
To set the retry time:
|
|
<span class="ph systemoutput"
|
|
>debug user-id dscd retry-time set-time <1-10></span
|
|
>. The default value is 5 seconds.
|
|
</div>
|
|
<div class="p">
|
|
To set the number of retry attempts:
|
|
<span class="ph systemoutput"
|
|
>debug user-id dscd retry attempts set-attempts <3-10></span
|
|
>. The default value is 5 attempts.
|
|
</div>
|
|
<div class="p">
|
|
To disable the retry mechanism:
|
|
<span class="ph systemoutput"
|
|
>debug user-id dscd retry-enable off</span
|
|
>.
|
|
</div>
|
|
<div class="p">
|
|
Additionally, a system log is now generated when a group sync fails,
|
|
and you are able to monitor the group sync status with the following
|
|
CLI commands:
|
|
</div>
|
|
<ul id="pan_os_11_1_10_h28_addressed_issues_ul-kk4_jh5_pjc" class="ul">
|
|
<li class="li">
|
|
<span class="ph systemoutput"
|
|
>show user group count list cloud-identity-engine</span
|
|
>
|
|
</li>
|
|
<li class="li">
|
|
<span class="ph systemoutput"
|
|
>show user group count name <group_name></span
|
|
>
|
|
</li>
|
|
</ul>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-213491</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the management CPU was high, which caused the web
|
|
interface to be slower than expected.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|