Files
firewallissues/reference/PAN-OS/addressed/11.2.7-h10.html
T

301 lines
9.6 KiB
HTML

<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-310868</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where PA Explicit proxy blocked ICMP packets from
flowing towards Envoy for Geneve due to the router not camping MSS
when the MTU was lower in the path.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-307901</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a leak in decryption counters caused resource
exhaustion, which led to a GlobalProtect service outage.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-306502</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed two issues that impacted TLSv1.2 or earlier sessions when the
traffic matched a decryption policy rule with the no-decrypt action:
</div>
<ul class="ul">
<li class="li">
Connections failed when both HTTP header insertion (<span
class="ph uicontrol"
>Objects &gt; Security Profiles &gt; URL Filtering &gt; HTTP
Header Insertion</span
>) and
<span class="ph uicontrol"
>Send handshake messages to CTD for inspection</span
>
(<span class="ph uicontrol"
>Device &gt; Setup &gt; Session &gt; Decryption Settings &gt; SSL
Decryption Settings</span
>) were enabled.
</li>
<li class="li">
New sessions failed due to software packet buffer resource
depletion, which occurred when
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>Log Successful SSL Handshake</a
>
was disabled in the decryption policy rule and the decryption
profile attached to the rule had both
<span class="ph uicontrol"
>Block sessions with expired certificates</span
>
and
<span class="ph uicontrol"
>Block sessions with untrusted issuers</span
>
disabled.
</li>
</ul>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-306103</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-3400 and PA-5400 Series firewalls only</tt>)
Fixed an issue where the firewall dataplane frequently restarted when
lockless QoS was enabled
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-303959</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic was incorrectly identified as
unknown-tcp/unknown-udp due to App-ID resource leak and eventually
dropped.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-302767</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IPv6 IPsec WAN support was not available in
Prisma Access.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-301222</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DNS Security logs incorrectly displayed a
sinkhole action for benign DNS categories due to the firewall saving
the drop or sinkhole action in session flags without discarding the
session.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-300638</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the firewall stopped responding due to an out-of-bounds read when
parsing TLS 1.3 clientHello messages with large TLS clientHello
extensions where the
<span class="ph systemoutput">supported_versions</span> extension fell
outside the first TCP segment.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-297295</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls in Microsoft Azure environments only</tt
>) Fixed an issue where the firewall repeatedly restarted due to high
packet rates on the synthetic path in DPDK mode.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-295803</b></div>
</td>
<td class="entry relcol">
<div class="p">
Addressed a memory leak issue under sc3 and automatic commit recovery
(ACR) code path.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-294488</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where certificate data was missing in decryption logs
for <span class="ph uicontrol">No decrypt</span> policy rules and
TLS1.2 traffic after upgrading, and the
<tt class="ph tt">Subject Common Name</tt>,
<span class="ph uicontrol">Issuer Common Name</span>,
<span class="ph uicontrol">Certificate Start Date</span>,<span
class="ph uicontrol"
>
Certificate End Date</span
>, <span class="ph uicontrol">Certificate Serial Number</span>, and
<span class="ph uicontrol">Certificate Fingerprint</span> fields were
blank in the decryption logs.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-283563</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect gateway firewall intermittently
failed to assign an IP address to GlobalProtect clients from the DHCP
server, even after successfully receiving a DHCP offer. This occurred
when the DHCP retry and timeout settings were overwritten due to
parsing results being stored in the same variable, which caused the
last gateway configuration to take effect.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271438</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall calculated available memory
incorrectly on CENTOS devices, which caused the firewall to display
high memory usage alerts even when sufficient memory was available.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-267328</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding, which caused the firewall to stop
processing traffic.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259853</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the DHCP server was enabled for
GlobalProtect, the commit error message was not properly displayed
when <span class="ph uicontrol">Any</span> was selected as the source
interface in the service router configuration (<span
class="ph menucascade"
><span class="ph uicontrol">Device</span
><span class="ph uicontrol">Setup</span
><span class="ph uicontrol">Service</span
><span class="ph uicontrol"
>Service Router Configuration</span
></span
>).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-258039</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall displayed the incorrect rule name
when a threat log was generated for Inline Cloud Analyzed CMD
Injection Traffic Detection.
</div>
</td>
</tr>
</tbody>
</table>