Files
firewallissues/reference/PAN-OS/addressed/10.2.5.html
T
aaron.axvig b36247faf4
Test and deploy / deploy (push) Successful in 29s
Added remaining PAN-OS 10.2 reference files
2026-07-29 12:45:46 -05:00

3258 lines
96 KiB
HTML

<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p">
<b class="ph b"><b class="ph b">PAN-231823</b></b>
</div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2024-5916"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2024-5916</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-227179</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where routes were not updated in the forwarding table.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-225340</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect users were unable to connect after
upgrading to PAN-OS 10.2.4 due to an incorrect client authentication
configuration being selected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-225183</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SSH tunnels were unstable due to ciphers used as
part of the high availability SSH configuration.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-224273</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">debug dataplane pow status</span> CLI
command did not display extended NIC statistics.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-223501</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-5200 Series and PA-7000 Series firewalls only</tt
>) Fixed an issue where diagnostic information for the dataplane in
the dp-monitor.log file was not complete.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-223317</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SSL traffic failed with the error message:
<span class="ph systemoutput">Error: General TLS protocol error</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-223185</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>distributord</a
>
process stopped responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-222712</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed a low frequency
DPC restart issue.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-221984</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls in Microsoft Azure environments only</tt
>) Fixed an issue where an interface went down after a hotplug event
and was only recoverable by restarting the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-221881</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where log ingestion to Panorama failed, which resulted
in missing logs under the
<span class="ph uicontrol">Monitor</span> tab.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-221836</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where improper SNI detection caused incorrect URL
categorization.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-221708</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where temporary files remained under
<span class="ph systemoutput">/opt/pancfg/tmp/sw-images/</span> even
after manually uploading the content or AV file to the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-221647</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph uicontrol">Apps seen</span> value was not reflected on
Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-220910</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an internal management plane NIC caused a kernel
panic when doing a transmit due to the driver reinitializing under
certain failure or change conditions on the same interface during
transmit.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-220899</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were unable to choose the manual
GlobalProtect gateway.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-220747</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where logs were not visible after restarting the log
collector.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-220626</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where system warning logs were written every 24 hours.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-220448</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect client connection remained at
the prelogin stage when Kerberos SSO failed and was unable to fall
back to the realm authentication.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-220401</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, during a reboot, an unexpected error message was
displayed that the syslog configuration file format was too old.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-220281</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7080 firewalls only</tt>) Fixed an issue where
auto-committing changes after rebooting the Log Forwarding Card (LFC)
caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process to fail to read the configuration file.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-219690</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect authentication failed when
authentication was SAML with CAS and the portal was resolved with
IPv6.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-219686</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a device group push operation from Panorama
failed with the following error on managed firewalls:
<span class="ph systemoutput"
>vsys &lt;vsys1&gt; plugins unexpected here vsys is invalid Commit
failed</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-219659</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where root partition frequently filled up and the
following error message was displayed:
<span class="ph systemoutput"
>Disk usage for / exceeds limit, xx percent in use, cleaning
filesystem</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-219640</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a transformation migration script error caused a
commit failure with the error message
<span class="ph systemoutput">user-id-agent unexpected here</span>.
This occurred after upgrading the firewall from a PAN-OS 9.1 release
to a PAN-OS 10.0 release.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-219573</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where tag names did not correctly display special
characters.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-219508</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series, PA-400 Series, PA-1400, PA-3400, and PA-5400 Series
firewalls only</tt
>) Fixed an issue where Bidirectional Forwarding Detection (BFD)
packets experienced a delay in processing, which caused the BFD
connection to flap.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-219498</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph uicontrol">Threat ID/Name</span> detail in Threat logs
was not included in syslog messages sent to Splunk.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-219351</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process stopped responding during Layer 7 processing.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-219253</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after making changes in a template, the
<span class="ph uicontrol">Commit and Push</span> option was grayed
out.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-218947</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where logs were not displayed in Elasticsearch under
ingestion load.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-218697</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the ElasticSearch status frequently changed to
red or yellow after a PAN-OS upgrade.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-218644</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall generated incorrect VSA attribute
codes when radius was configured with EAP-based authentication
protocols.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-218620</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where scheduled configuration exports and SCP server
connection testing failed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-218404</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>ikemgr</a
>
stopped responding due to receiving
<span class="ph systemoutput">CREATE_CHILD</span> messages with a
malformed SA payload.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-218335</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with hardware destination MAC filtering on the Log
Processing Card (LPC) that caused the logging card interface to be
susceptible to unicast flooding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-218318</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall changed the time zone automatically
instead of retrieving the correct time zone from the NTP server.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-218264</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-3400 and PA-1400 Series firewalls only</tt>)
Fixed an issue where packet drops occurred due to slow servicing of
internal hardware queries.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-218151</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a configuration push to a new firewall did not
work and displayed validation errors.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-218107</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with ciphers used for SSH tunnels where packet lengths
were too large, which made the SSH tunnel unstable.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-218001</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-400 Series firewalls only</tt>) Fixed an issue
where shut down commands rebooted the system instead of correctly
triggering a shutdown.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-217681</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue caused by out of order TCP segments where the TCP
retransmission failed when the TCP segment had the FIN flag and the
TCP data was truncated.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-217582</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Google Cloud Platform environments only</tt
>) Fixed an issue where firewalls failed to load the virtual machine
information source configuration.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-217581</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not initiate scheduled log
uploads to the FTP server.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-217489</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with firewalls in active/passive HA configurations
where the passive firewall MAC flapping occurred when the passive
firewall was rebooted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-217465</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama web interface became unresponsive
and displayed the error message
<span class="ph uicontrol">504 Gateway Not Reachable</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-217431</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-5400 Series firewalls with DPC (Data Processing Cards) only</tt
>) Fixed an issue with slot 2 DPCs where URL Filtering did not work as
expected after upgrading to PAN-OS 10.1.9.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-217284</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an intermittent issue where an LACP flap occurred when the LACP
transmission rate was set to <span class="ph uicontrol">Fast</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-217169</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the logrcvr stopped forwarding logs to the syslog
server after a restart or crash.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-216996</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where multiple User-ID alerts were generated every 10
minutes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-216957</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where allow list checks in an authentication profile
did not work if the group Distinguished Name contains the ampersand (
&amp; ) character.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-216913</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls in Microsoft Azure environments only</tt
>) Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>brdagent</a
>
process stopped responding due to missed heartbeats, which caused the
firewall to reboot. This occurred when the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>brdagent</a
>
process and DPDK-managed ports became out of sync after the Azure
infrastructure triggered a hotplug event.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-216821</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process stopped responding after upgrading an M-200 appliance to
PAN-OS 10.2.4.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-216662</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a custom Antispyware profile did not open and
displayed the following error message:
<span class="ph systemoutput"
>The server is not responding. Please wait and try your operation
again later</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-216366</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when custom signatures used a certain syntax,
false positives were generated on devices on a PAN-OS 10.0 release.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-216360</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where
<span class="ph uicontrol">No Default Selections</span> under
<span class="ph uicontrol">Push to Devices</span> was intermittently
deselected after performing a commit operation.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-216170</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-400 Series firewalls in HA configurations only</tt
>) Fixed an issue where an HA switchover took longer than expected to
bring up ports on the newly active firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-216054</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue that caused the firewall's fan speed to increase while
it was idle.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-216048</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when upgrading from a PAN-OS 9.1 release to a
PAN-OS 10.0 release, commits failed with the error message:
<span class="ph systemoutput">hip profiles unexpected here</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-216043</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where wifclient stopped responding due to shared memory
corruption.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-215911</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue that resulted in a race condition, which caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process to stop responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-215808</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to PAN-OS 10.1, the log
forwarding rate toward the syslog server was reduced. With this fix,
the overall log forwarding rate has also been improved.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-215780</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where changes to Zone Protection profiles made via XML
API were not reflected in the zone protection configuration.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-215778</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where API Get requests for
<span class="ph systemoutput">/config</span> timed out due to
insufficient buffer size.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-215655</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after a multidynamic group push, Security policy
rules with the target device tag were added to a firewall that did not
have the tag.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-215503</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a memory-related issue where the
<span class="ph systemoutput">MEMORY_POOL</span> address was mapped
incorrectly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-215496</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where 100G ports did not come up with BIDI QSFP
modules.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-215338</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5400 Series firewalls only</tt>) Fixed an issue
where the inner VLAN tag for Q-in-Q traffic was stripped when
forwarding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-215317</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the dataplane stopped responding unexpectedly
with the error message
<span class="ph systemoutput">comm exited with signal of 10</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-215066</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where push scope rendering caused the
<span class="ph uicontrol">Commit and Push</span> or
<span class="ph uicontrol">Push to Devices</span> operation window to
hang for several minutes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-215058</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a memory leak related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logdb</a
>
process.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-214990</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewall copper ports flapped intermittently when
device telemetry was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-214815</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SNMP queries were not replied to due to an
internal process timeout.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-214753</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where retrieving WildFire Analysis reports when
choosing WildFire log entries under
<span class="ph uicontrol">Detailed Log View</span> displayed the
error
<span class="ph systemoutput"
>Fetching WildFire server xxx report failed!</span
>
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-214727</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory leak related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process resulted in an OOM condition, which caused the process to stop
responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-214669</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where FIN and RESET packets were sent in reverse order.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-214201</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after exporting custom reports to CSV format,
the letter <span class="ph uicontrol">b</span> appeared at the
beginning of each column.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-214187</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where superreaders were able to execute the
<span class="ph systemoutput">request restart system</span> CLI
command.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-214026</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when using an ECMP
<span class="ph systemoutput">weighted-round-robin</span> algorithm,
traffic was not redistributed among the links proportionally as
expected from the configuration.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-213949</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the VPN responder stopped responding when it
received a CREATE_CHILD message with no security association (SA)
payload.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-213942</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-400 Series firewalls</tt>) Fixed an issue where
the firewall required an explicit allow rule to forward broadcast
traffic.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-213932</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when an incorrect log filter was configured, the
commit did not fail.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-213931</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process cache was not in sync with the mapping on the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-213746</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the Hostkey displayed as
<span class="ph uicontrol">undefined</span> if an SSH Service Profile
Hostkey configured in a template from the template stack was
overridden.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-213463</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5200 Series firewalls only</tt>) Fixed an issue
where unplugging a PAN-SFP-CG transceiver from an interface with its
link speed setting set to 1000 caused the firewall to incorrectly read
that interface as up.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-213296</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Single Log-out (SLO) was not correctly triggered
from the firewall toward the client, which caused the client to not
initiate the SLO request toward the identity provider (IdP). This
resulted in the IdP not making the SLO callback to the firewall to
remove the user.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-213162</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an SD-WAN object was not displayed under a child
device group.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-213077</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>sysdagent</a
>
process stopped responding, which caused interfaces and the subsequent
connections behind them to fail.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-213060</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not show the target under the
<span class="ph uicontrol">Entities</span> column.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-212978</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding when executing an
SD-WAN debug CLI command.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-212889</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where different threat names were used when
querying a threat under
<span class="ph uicontrol">Threat Monitor</span> (<span
class="ph uicontrol"
>Monitor &gt; App Scope</span
>) and the ACC. This resulted in the ACC displaying no data after
clicking a threat name in
<span class="ph uicontrol">Threat Monitor</span> and filtering it in
the global filters.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-212859</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">pan_task</span> stopped responding
briefly during a commit due to a contention with
<span class="ph systemoutput">brdagent</span> updating the
configuration.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-212848</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where attempting to change the disk-usage cleanup
threshold to 90 resulted in the error message
<span class="ph systemoutput"
>Server error : op command for client dagger timed out as client is
not available</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-212726</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where RTP/RTCP packets were dropped for SIP calls by
SIP ALG when the source NAT translation type was persistent
<span class="ph uicontrol">Dynamic IP And Port</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-212577</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5200 Series and PA-7080 firewalls only</tt>)
Fixed an issue where commits took longer than expected when more than
45,000 Security policy rules were configured.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-212576</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewall HA clusters in active/active
configurations with Advanced Routing enabled did not relay to ping
requests sent to a virtual IP address.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-212530</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on log collectors where root partition reached 100%
utilization.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-212057</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Advanced Threat Prevention caused SSL delays when
no URL licenses were present.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-211997</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where large OSPF control packets were fragmented, which
caused the neighborship to fail.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-211887</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama that caused recently committed changes to
not be displayed when previewing the changes to push to device groups.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-211843</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where renaming a Zone Protection profile failed with
the error message
<span class="ph systemoutput">Obj does not exist.</span>
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-211602</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when viewing a WildFire Analysis report via the
web interface, the
<span class="ph uicontrol">detailed log view</span> was not accessible
if the browser window was resized.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-211575</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a local commit on Panorama remained at 99% for
longer than expected before completing.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-211519</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where RTP/RTCP packets were dropped for SIP calls by
SIP ALG when the source NAT translation type was persistent
<span class="ph uicontrol">Dynamic IP And Port</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-211441</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a memory leak issue related to SSL crypto operations that
resulted in failed commits.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-211422</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput"
>show session packet-buffer-protection buffer-latency</span
>
CLI command randomly displayed incorrect values.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-211398</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where dataplane processes stopped responding when
handling HTTP/2 streams.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-211191</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall restarted after initiating a
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>mgmtsrvr</a
>
process restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-211041</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama virtual appliances only</tt>) Fixed an
issue where DHCP assigned interfaces did not send
<span class="ph systemoutput"
>ICMP unreachable - Fragmentation needed</span
>
messages when the received packets were higher than the maximum
transmission unit (MTU).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210921</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances in Legacy Mode only</tt>) Fixed
an issue where
<span class="ph uicontrol">Blocked Browsing Summary by Website</span>
in the user activity report contained scrambled characters.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210883</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SSL proxy traffic was dropped when DoS zone
protection was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210740</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a memory leak issue related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>slotd</a
>
process.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210738</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where fragmented UDP packets were dropped.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210736</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where configuration changes related to the SSH service
profile were not reflected when pushed from Panorama. With this fix,
the deletion of ciphers, MAC, and kex fields of SSH server profiles
and HA profiles won't clear the values under template stacks and will
retain the values configured from templates.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210661</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls disconnected from
<span class="ph">Strata Logging Service</span> after renewing the
device certificate.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210640</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where applications were not displayed after
authenticating into the clientless VPN.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210563</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where Security policy rules with a
<span class="ph uicontrol">Tag</span> target did not appear in the
pre-rule list of a Dynamic Address Group that was part of the tag.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210511</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama commits failed due to an invalid
community value error.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210502</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama was unable to convert to PAN-OS 9.1
syntax for WF-500 appliances.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210456</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where high latency occurred on PA-850-ZTP when SSL
decryption was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210452</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where application PCAP was not generated when Security
policy rules were used as a filter.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210451</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not send the source IP address
of the user to the RADIUS server with the
<span class="ph systemoutput"
>set authentication radius-vsa-on client-source-ip</span
>
CLI command.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210429</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the HTTP service failed to come up on DHCP dataplane interfaces after
rebooting the firewall, which resulted in health-check failure on
HTTP/80 with a 503 error code on the public load balancer.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210397</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where VM-Series firewalls in HA
configurations hosted on Amazon Web Services (AWS) were not displayed
under <span class="ph uicontrol">Deploy Master Key</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210364</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where high latency was observed when accessing internal
web applications, which interrupted development activities related to
the web server.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210325</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where the configuration log always
displayed commit-all operations as successful even when the commit
failed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210216</b></div>
</td>
<td class="entry relcol">
<div class="p">
A debug command was added to address an issue with firewalls in high
availability configurations.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210158</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">CN-Series firewalls only</tt>) Fixed an issue where
the dataplane stopped responding after a container restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-210000</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when traffic and Threat logs exceeded the
threshold of 90% total allowed size, alarms were not generated for
other log types.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-209937</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where certificate-based authentication for
administrators were unable to log in to the Panorama or firewall web
interface and received the following error message:
<span class="ph systemoutput"
>Bad Request - Your browser sent a request that this server could
not understand</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-209930</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where cloned rules pushed from Panorama were not shown
on the managed firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-209872</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where dataplane ports responded to ICMP requests fewer
than 64 bytes with nonzero padding bytes in the ICMP response.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-209696</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where link-local address communication for IPv6, BFD,
and OSPFv3 neighbors was dropped when IP address spoofing check was
enabled in a Zone Protection profile.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-209683</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama was unable to retrieve IP
address-to-username mapping from a firewall on a PAN-OS 8.1 release.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-209617</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with firewalls in active/passive HA configurations
where the passive firewall created an incorrect SCTP association due
to the HA sync messages from the active firewall having an incorrect
value.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-209585</b></div>
</td>
<td class="entry relcol">
<div class="p">
The Palo Alto Networks QoS implementation now supports a new QoS mode
called lockless QoS for PA-3400, PA-5410, PA-5420, PA-5430, and
PA-5440 firewalls. For firewalls with higher bandwidth QoS
requirements, the lockless QoS dedicates cores to the QoS function
that improves QoS performance, resulting in improved throughput and
latency.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-209501</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect
<span class="ph systemoutput">logdb</span> quota was not displayed in
the
<span class="ph systemoutput">show system logdb quota</span> output.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-209375</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where log filtering did not work as
expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-209172</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to handle GRE packets for
Point-to-Point Tunneling Protocol (PPTP) connections.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-209108</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a Panorama in Management Only mode was unable to
display logs from log collectors due to missing schema files.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-208902</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when a client sent a TCP/FIN packet, the
firewall displayed the end reason as
<span class="ph systemoutput">aged-out</span> instead of
<span class="ph systemoutput">tcp-fin</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-208792</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where authentication failed when the service route for
RADIUS traffic was configured as
<span class="ph uicontrol">use default</span> for IPv4 addresses and
included the dataplane interface as the destination route.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-208567</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with email formatting where, when a scheduled email
contained two or more attachments, only one attachment was visible.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-208343</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where telemetry regions were not visible on Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-208325</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-5400 Series, PA-3400 Series, and PA-400 Series only</tt
>) Fixed an issue where the firewall was unable to automatically renew
the device certificate.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-208316</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where user-group names were unable to be configured as
the source user via the
<span class="ph systemoutput">test security-policy-match</span>
command.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-208201</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where the modified date and time was
incorrectly updated after a commit operation, PAN-OS upgrade, or
reboot.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-208198</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with firewalls in active/passive HA configurations
where, after rebooting the passive firewall, interfaces were briefly
shown as powered up, and then shown as down or shutdown.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-208187</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where REST API requests did not work for GlobalProtect
gateway tunnels.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-208090</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the ACC report did not display data when querying
the filter for the fields <span class="ph uicontrol">Source</span> and
<span class="ph uicontrol">Destination IP</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-208039</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7000 Series firewalls with SMC-B only</tt>)
Fixed an issue where the details of configuration changes were not
included in configuration logs on the syslog server.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207842</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where WildFire Analysis reports were not visible when
the WF-500 appliance was on private cloud.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207741</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Large Scale VPN (LSVPN) Portal authentication
failed with the error
<span class="ph systemoutput"
>invalid http response. return error(Authentication failed; Retry
authentication</span
>
when the satellite connected to more than one portal.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207700</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">show system info</span> and
<span class="ph systemoutput">show system ztp status</span> CLI
commands displayed a different Zero Touch Provisioning (ZTP) status if
a firewall upgrade was initiated from Panorama before the initial
commit push succeeded.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207661</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with firewalls in active/active HA configurations where
the virtual floating IP address configuration under a Panorama
template was overridden and displayed
<span class="ph systemoutput">From Template Override: undefined</span>
as a source.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207604</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where system logs continuously generated the log
message
<span class="ph systemoutput"
>Not enough space to load content to SHM</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207457</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the MLAV allow list did not work for some types
of traffic.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-207240</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>mprelay</a
>
repeatedly restarted, which caused commits to remain at 70% before
failing with the error message
<span class="ph systemoutput"
>A communication error happened during the configuration commit to
the data plane, please try again</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206765</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where log forwarding filters involving negation did not
work.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206640</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">ikemgr</span> process stopped
responding, which caused IPSec tunnels to go down.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206396</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where HIP report flip and HIP check failed when a user
was part of multiple user groups with different domains.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206391</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where shared objects were seen under the push scope
with every configuration push.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206333</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph uicontrol">Include/Exclude IP</span> filter under
<span class="ph uicontrol">Data Distribution</span> did not work
correctly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206278</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a critical system log was generated when the boot
drive for PA-7000 Series firewall Switch Management Cards (SMCs)
failed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-206221</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where scheduled configuration pushes with
<span class="ph uicontrol">Include Device and Network Templates</span>
selected did not work.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205513</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the stats dump file generated by Panorama for a
device firewall differed from the stats dump file generated by the
managed device.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205369</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where connections to
<span class="ph">Strata Logging Service</span> were initialized from
the firewall even when
<span class="ph">Strata Logging Service</span> forwarding was
disabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-205086</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DNS Security categories were able to be deleted
from spyware profiles.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204718</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5200 Series firewalls only</tt>) Fixed an issue
where, after upgrading to PAN-OS 10.1.6-h3, a TACACS user login
displayed the following error message during the first login attempt:
<span class="ph systemoutput"
>Could not chdir to home directory /opt/pancfg/home/user: Permission
denied</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204683</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where logs were unable to be generated due to old logs
not getting purged and
<span class="ph systemoutput">/opt/panlogs</span> reaching over 100%
usage.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204530</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where giving up FTP or SCP sessions for log export took
longer than expected after a failure to export the log when one of the
destination hosts designated in the scheduled log export was
unresponsive.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204420</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">WF-500 appliances only</tt>) Fixed an issue where,
after an upgrade to a PAN-OS 10.1 release, SNMP traps were not sent to
the SNMP server. This occurred due to SNMP trap server settings not
being enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204233</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the firewall received a 513 error from the
WildFire cloud, the firewall attempted to repeatedly send the same
file.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-204215</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-7000 Series firewalls with Log Processing Cards (LPCs) only</tt
>) Fixed an issue where performing a commit operation resulted in the
following error messages:
<span class="ph systemoutput"
>log forwarding is setup for data but log-card interface is not
setup</span
>
or
<span class="ph systemoutput"
>log forwarding is setup for traffic but log-card interface is not
setup</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-203791</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-3400 and PA-5400 Series firewalls only</tt>)
Fixed an issue where the log type correlation was not configurable and
displayed as
<span class="ph uicontrol">$.Format.Correlation</span> (<span
class="ph uicontrol"
>Device &gt; Server Profile &gt; syslog &gt;&lt;Profile-name&gt;
&gt; Customer log format &gt; log type</span
>).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-203655</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where enabling
<span class="ph uicontrol">event-specific traps</span> (<span
class="ph uicontrol"
>Device &gt; Setup &gt; Operations &gt; Miscellaneous &gt; SNMP
Setup</span
>), the new deviating device system logs included incorrect
information.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-203611</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where URL categorization was not recognized for URLs
that contained more than 100 characters.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-203222</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where commit-all operations took longer than expected
due to cURL failures and timeouts related to external dynamic list
retrieval.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-203168</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the WIF state was not cleaned up promptly after
usage, which caused allocation failure. This fix increased the
<span class="ph systemoutput">wif_state</span> quota.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202981</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where global find did not return results
for existing universally unique identifiers (UUID).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202963</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the system log message
<span class="ph systemoutput"
>dsc HA state is changed from 1 to 0</span
>
was generated with the severity
<span class="ph uicontrol">High</span>. With this fix, the severity
was changed to <span class="ph uicontrol">Info</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202524</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the session ID was missing in the session details
section of the
<span class="ph systemoutput">ingress-backlogs</span> XML API output.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-202516</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding if it received an
illegal packet with SRC port = 0 encapsulated within a VXLAN packet.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-201855</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after cloning a template, a certificate with the
block private key option enabled was corrupted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-201721</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with firewalls in HA configurations where HA setup
generated the error
<span class="ph systemoutput">mismatch due to device update</span>
during a content update even though the version was the same.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-201515</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with the web interface where the cursor disappeared
under the <span class="ph uicontrol">Policies</span> and
<span class="ph uicontrol">Objects</span> tabs on the search bar if
the cursor was moved quickly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-201466</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the system log generated on GlobalProtect
satellite did not provide the reason for failures to connect to the
GlobalProtect portal or gateway.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-200757</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with client certificate generation on Panorama, which
resulted in a firewall being unable to connect to a log collector.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-200394</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after a push from Panorama to one or more device
groups in a multi-vsys environment, vulnerability profile exceptions
were not seen on all firewalls.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-199819</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, if a decryption profile allowed TLS1.3, but the
server only supported TLS1.2, and the cipher used by the first
connection to the server was a CBC SHA2 cipher suite, the connection
failed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-199687</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where content updates failed when using prelicensed
keys during the bootstrap process.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-199557</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where virtual memory usage exceeded the set
limit, which caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process to restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-198453</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were unable to resize the
<span class="ph uicontrol">Description</span> pop-up window (<span
class="ph uicontrol"
>Policies &gt; Security &gt; Prerules</span
>).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-198050</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph systemoutput"
>Connection to update server is successful</span
>
messages displayed even when connections failed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197493</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where having multiple terminal service agents with the
same hostname caused the firewall to reboot.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197467</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the WildFire
<span class="ph uicontrol">Test-Configuration</span> feature did not
work as expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-197388</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the firewall forwarded Threat logs via
email, the email client truncated the sender and recipient email
addresses when they were put between angle brackets (&lt;, &gt;).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196956</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where URL Filtering logs did not display matching
entries when filtered by device name.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196923</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the interface option did not have a source
address in the cURL command, which caused a DNS lookup error and
resulted in DNS lookup failing for device Telemetry.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196597</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>dnsproxyd</a
>
process stopped responding due to corruption.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196417</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7000 Series firewalls only</tt>) Fixed an issue
where firewalls experienced slow SNMP responses, which caused the SNMP
server to time out before polling completion.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-196345</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where scheduled dynamic content updates failed to be
retrieved by managed firewalls from Panorama when connectivity was
slow.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195788</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where zip files did not download when applying Security
inspection and the following error message displayed:
<span class="ph systemoutput">resources-unavailable</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195439</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls in Microsoft Azure environments only</tt
>) Fixed an issue where the dataplane interface status went down after
a hotplug event triggered by Azure infrastructure.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-195251</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IPSec tunnel re-key generated the critical log
message <span class="ph systemoutput">tunnel-status-up</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-193521</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol"
>Panorama &gt; Device &gt; Deployment &gt; Software</span
>
did not display software after running
<span class="ph uicontrol">check now</span> for managed devices.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-190903</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where MAC addresses in threat capture were swapped
between the source MAC and destination MAC addresses.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-190435</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after committing a configuration change, the
<span class="ph uicontrol">Task Manager</span> commit
<span class="ph uicontrol">Status</span> went directly from 0% to
<span class="ph uicontrol">Completed</span> instead of reflecting the
accurate commit job process.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-190055</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the firewall did not follow the set Jumbo MTU value.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189442</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process stopped responding, which caused the firewall to reboot.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189423</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where exporting correlation logs generated an empty
file.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-189328</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic belonging to the same session was sent
out from different ECMP enabled interfaces.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-187989</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a user who did not have permissions of other
access domains were able to view the commit and configuration lock.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-186956</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SD-WAN DIA VIF did not become active if default
gateways for member interfaces did not respond to pings.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-186182</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where software buffer 3 was depleted when URL proxy was
enabled and SSL sessions were decrypted to inject the block page. This
issue occurred when an HTTP/2 block page was displayed for a large
POST request.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-185249</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">Template Stack</span> overrides (<span
class="ph uicontrol"
>Dynamic Updates &gt; App &amp; Threats &gt; Schedule</span
>) were not able to be reverted via the web interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-185135</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Kernel-based Virtual Machine (KVM) only</tt
>) Fixed an issue where the physical port counters (including SNMP) on
the dataplane interfaces increased when DPDK was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-184630</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TLS clients, such as those using OpenSSL 3.0,
enforced the TLS renegotiation extension (RFC 5746).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-183297</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the firewall received a large amount of
user information, the firewall was unable to output IP
address-to-username mapping information via XML API.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-182960</b></div>
</td>
<td class="entry relcol">
<div class="p">
Additional error logs were added for an issue where, when multiple
Panorama web interface sessions were opened, active lock did not show
up on the web interface for any session.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-182734</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, on an Advanced Routing Engine, BGP peering
flapped after a commit.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-180082</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where errors in
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>brdagent</a
>
logs caused dataplane path monitoring failure.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-177227</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Amazon Web Services environments only</tt
>) Fixed an issue where traffic sent from a GENEVE tunnel to the
firewall was dropped if the firewall attempted to encapsulate traffic
into an IPSec tunnel.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-176412</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where changing the password of a local database user
did not work.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-172977</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where session offloading did not occur on a tap
interface under a high packet load.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-172600</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the CLI command
<span class="ph systemoutput">show rule-hit-count</span> did not
provide all details of the rule from the device group.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-169586</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where scheduled log view reports in emails didn't match
the monitor page query result for the same time interval.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-168102</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the API format to check heap usage of a node
showed a JSON error.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-160633</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls
only</tt
>) Fixed an issue where the dataplane restarted repeatedly due to an
internal path monitoring failure until a power cycle.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-151692</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a permission issue where a Panorama administrator was unable to
download or install Dynamic Updates (<span class="ph uicontrol"
>Panorama &gt; Device Deployment</span
>).
</div>
</td>
</tr>
</tbody>
</table>