Files
firewallissues/reference/PAN-OS/addressed/12.1.8.html
T

3217 lines
107 KiB
HTML

<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row">
<th class="entry">
<div class="p">Issue ID</div>
</th>
<th class="entry">
<div class="p">Description</div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-327009</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-326677</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a selective push from Panorama to the firewall
was successful even when applying rename operation failed in selective
push, which resulted in configurations on the firewall being deleted.
With this fix, the selective push will fail when applying rename
operation fails.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-325903</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading Panorama, a custom admin role
with Object Level Changes disabled did not automatically populate
out-of-sync firewalls in the push scope.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-325890</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where licenses were not installed after bootstrapping a
VM-Series firewall in an air-gapped environment.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-325120</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue on PA-415, PA-415-5G, PA-445, PA-455, and PA-455-5G
platforms where certain PAN-OS versions caused intermittent
connectivity failures on the Eth1/1 data port and loss of power on PoE
ports.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-324966</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where you were unable to view new
or modified App-IDs under
<span class="ph uicontrol">Review Policy</span> or
<span class="ph uicontrol">Review Apps</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-324370</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IDE traffic did not function as expected when
both HTTP head insertion and DLP inspection were enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-324275</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where requesting logging service forwarding
certification information via the CLI did not work.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-324014</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where logging disks were reported with a byte size of
zero in the system status even when they were properly mounted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-323974</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were unable to add logging drives to the
firewall, and validation errors occurred when pushing configurations
from Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-323862</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SAML re-authentication failed when both IP
address-to-user mapping and session cookies expired simultatneously.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-323825</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Panorama appliances in Microsoft Azure environments only</tt
>) Fixed an issue where Panorama continuously displayed disk-related
read/write errors in the console logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-323809</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where attempting to generate a ticket for the
GlobalProtect portal caused Panorama to restart unexpectedly with the
error message <span class="ph systemoutput">tpl is invalid</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-323485</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where multicast radio RTP based traffic was dropped
after an upgrade when the firewall performed Cloud Inline inspection,
which led to an exceeded session queue for Cloud Threat Detection.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-323243</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding occurred when a Security policy rule was
updated or refreshed in the web interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-322815</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Microsoft Azure environments only</tt
>) Fixed an issue where the firewall entered maintenance mode after
enabling FIPS-CC mode and rebooted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-322681</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the PDF Summary Reports were not generated
correctly after upgrading to an affected release.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-322630</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IKE gateways were not visible within Panorama
Templates under
<span class="ph uicontrol">Network Profiles</span> from a custom
administrator role after upgrading to an affected PAN-OS release.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-322402</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where ACC reports for a duration of seven or more days
did not fully load or displayed partial information.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-322390</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Enhanced Application Logging status in the
Logging Service Status dashboard displayed as gray and indicated 0/0
connections, even though EAL logs were successfully forwarded to
Cortex XDR.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-322325</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-3400, PA-5400, PA-5500, and PA-5500l platforms with dedicated
log interfaces only</tt
>) Fixed an issue where email forwarding failed silently when the SMTP
gateway was reachable only via the log-interface, even when test
emails were forwarded successfully.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-321937</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an expired SD-WAN license caused SD-WAN tunnels
to become unavailable, which resulted in traffic interruptions. With
this fix, the device provides logs and commit messages about expired
licenses.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-321816</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where processes stopped responding unexpectedly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-321699</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where device telemetry intermittently failed to send
files, which resulted in critical alerts in system files.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-321527</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-7500 firewalls in HA cluster configurations only</tt
>) Fixed an issue where, when one firewall suspended operations, the
other firewall also suspended operations instead of initiating a
failover, which resulted in a complete traffic outage.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-321516</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the dataplane restarted due to a race condition
in the dataplane cache infrastructure.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-321340</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in FIPS mode only</tt>) Fixed an issue
where GlobalProtect unexpectedly prompted for RADIUS authentication
instead of client certificate authentication due to an OSCP validation
error and subsequent CRL verification failure, which led to
certificates being marked as invalid.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-321222</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were unable to create an HTTP server profile
an API key certificate was configured. This occurred because the
generated API key exceeded the maximum character limit.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-321150</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the interface remained down after an upgrade.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-321084</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls on ESXi platforms only</tt>)
Fixed an issue where enabling link monitoring caused the
<span class="ph systemoutput">brdagent</span> process to stop
responding, which caused system instability, interface outages,
split-brain conditions in HA pairs, and a reboot during failover.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-321081</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">Log Quotas</span> incorrectly displayed a
value that was higher than possible.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-320598</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where internal and external DNS names did not resolve
when connected to a GlobalProtect gateway.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-320420</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput"
>show running resource-monitor ingress-backlogs</span
>
API call returned an unexpected error instead of the expected resource
monitoring information.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-320290</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where ACC reports did not display data under the
<span class="ph uicontrol">Area</span> and
<span class="ph uicontrol">Column</span> graphs. This occurred when
the report included dates prior to March 8.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-320245</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7500 Series firewalls in vwire mode only</tt>)
Fixed an issue where Oracle application traffic was intermittently not
processed even though connected devices sent the traffic, which led to
service distruptions.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-319798</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Panorama virtual appliances in AWS environments only</tt
>) Fixed an issue where logging disks failed to mount or reported an
unknown file system type.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-319793</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to PAN-OS 12.1.5, GlobalProtect
Clientless VPN failed to access JavaScripts.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-319557</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where graphical counters did not display correctly in
the control plane or dataplane monitor logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-319481</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where system logs did not display the
firewall serial numbers when Panorama retrieved logs from the SLS.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-319419</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/passive HA configurations only</tt
>) Fixed an issue where active firewalls were unable to send device
telemetry data to CDL.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-319335</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not follow configured management
proxy settings for OCSP and CRL queries, and instead reverted to
default configurations after a process restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-319288</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a DPC in Slot 4 restarted repeatedly, which
caused internal path monitoring failures and a failover event.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-319266</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Cloud IPS only</tt>) Increased scale limit for zone
mappings.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-319228</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where External Dynamic List (EDL) refresh and commit
operations remained in a pending state, which prevented any subsequent
operations from completing.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-319136</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall generated high-severity system log
alerts due to a certificate trust issue during SSL handshakes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-318990</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>GlobalProtect dual-profile MacOS/Windows deployments only</tt
>) Fixed an issue where GlobalProtect commit warnings incorrectly
flagged SAML
<span class="ph uicontrol">default browser</span> mismatches between
authentication profiles and agent configurations.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-318949</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where irrelevant error messages related to IoT devices
filled the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-318784</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped processing traffic and all
VPN tunnels went down even when the firewall remained in an active
state, and the CLI became unresponsive.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-318619</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Geneve ingress traffic did not use the correct
public IP address for return traffic.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-318567</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the OpenConfig plugin stopped working after a
configuration update.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-318288</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic initiated from Microsoft Azure to an
on-premises firewall was not decrypted, which caused the firewall to
drop the traffic. This occurred due to the firewall incorrectly
identifying SPI values.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-318275</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the firewall became unresponsive and did not automatically reboot,
which led to prolonged outages. With this fix, the Linux kernel
configuration will trigger a system panic and reboot.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-318120</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SSL traffic was silently dropped when traffic was
processed by a Security policy with an Anti-Spyware profile that had
Inline cloud Analysis enabled for SSL C2 Detector with an action other
than allow or alert.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-318106</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SCM did not update device telemetry for the
firewall after upgrading to an affected release.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-318030</div></td>
<td class="entry relcol">
<div class="p">
<tt class="ph tt">VM-Series firewalls in Hyper-V only</tt>) Fixed an
issue where the throughput was reported to be twice as high as the
actual traffic rate.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-317867</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama became inaccessible and a manual reboot
was required to restore access. This occurred due rapid increase in
memory usage on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process, which led to OOM events.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-317858</div></td>
<td class="entry relcol">
<div class="p">
Added a CLI command to address an issue where ethernet trailer padding
was not removed during IPv4-to-IPv6 packet translation. This occurred
when the original packet contained ethernet trailers and the
translated packet exceeded the minimum MTU.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-317772</div></td>
<td class="entry relcol">
<div class="p">
Added a fix to improve performance in lossy network conditions.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-317755</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where selective push operations failed when
plugin configurations included access-domain or log-collector
references.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-317749</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the commit scope preview for a vsys incorrectly
displayed configuration changes made in other vsys, even when the
commit only applied changes to the intended vsys.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-317614</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where high throughput and increased packet rates caused
high dataplane CPU usage.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-317600</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
issue where autocommit operations took longer than expected to
complete when the firewalls were configured with multiple vsys and
EDLs. This occurred because the firewalls were unable to reach the DNS
server during the autocommit process.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-317583</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue with intermittent ICMP ping drops and packet loss in
traffic flows between a hub and branch after upgrading to an affected
PAN-OS release due to incorrect SD-WAN path monitor state.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-317548</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an IMA violation occurred when Panorama accessed
GRUB during the installation process, which caused upgrades from
PAN-OS 12.1.4 to PAN-OS 12.1.5 to fail.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-317466</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SIP sessions stopped progressing after the
firewall received fragmented packets, fragmented at header field.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-317372</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where custom administrators received an
<span class="ph uicontrol">access denied</span> error when attempting
to view specific policy rule details from the
<span class="ph uicontrol">Rule Shadow</span> tab after a push from
Panorama, even when the administrator had permissions to view Security
policy rules.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-317215</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on ESXi with Intel E810 NICs using PCI
passthrough</tt
>) Fixed an issue where the
<span class="ph systemoutput">brdagent</span> process became
unresponsive during data port initialization, which resulted in system
instability, interface outages, HA split-brain conditions, and
unexpected reboots during failover.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-317177</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue on firewalls in DHCP Client mode where, after upgrading
to an affected release, the SNMP process unexpectedly restarted after
a commit, which led to false interface flap notifications on SNMP
managers.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-317133</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were unable to generate a ticket for the
GlobalProtect portal.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-317068</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where you were able to
enable IPv6 for IKE gateways and IPSec tunnels even when IPv6 WAN was
disabled, which resulted in an invalid configuration. To utilize this
fix, upgrade to the latest Panorama plugin.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-316978</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where system log error messages were displayed after
every firewall reboot, even when the firewall functioned correctly
after the reboot.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-316937</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect users intermittently received
incorrect private IP addresses after connecting to a gateway behind a
Network Load Balancer (NLB).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-316911</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Amazon Web Services (AWS) environments
only</tt
>) Fixed an issue where a newly bootstrapped firewall required a
management server restart, relicensing, or license push from Panorama
to invoke the device certificate.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-316856</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an error message displayed when attempting to
delete the Logging Service certificate or view the Logging Service
customer information.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-316761</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process timeout errors occurred during a manual management server
restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-316740</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to an affected release, HCE
profiles exceeded the maximum character length when generated
automatically, which caused subsequent commit operations to fail with
a validation error. This occurred when HIP objects were associated
with HIP profiles prior to the upgrade.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-316718</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped forwarding logs or
generating system and configuration logs to Panorama after restarting
the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>mgmtsrvr</a
>
process.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-316631</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue BGP sessions experienced short disruptions across all
peers, interfaces, and slots when a multicast event persisted longer
than the NGP negotiated hold timers.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-316605</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where HIP redistribution to remote network nodes from
external gateways resulted in a large amount of error messages in
User-ID logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-316556</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a race condition between the session ager and
packet processing resulted in memory corruption and caused the
pan_task process to stop responding, which resulted in the firewall
becoming unresponsive
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-316435</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall restarted unexpectedly due to an OOM
condition after upgrading to an affected release.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-316433</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where the last digit of entries in
policy rule descriptions were truncated.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-316263</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an incorrect validation error was displayed,
falsely indicating that IKE Gateway and IPSec tunnel names can begin
with a numeral
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-316120</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after Advanced Routing was enabled, the firewall
advertised routes to internal BGP neighbors with the original external
BGP next-hop address.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-316106</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances in Log Collector mode only</tt
>) Fixed an issue where commit validation failed after an upgrade when
the previous configuration included a
<span class="ph systemoutput">shared-optimization</span> setting.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-316070</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a BGP peer automatically established a BGP
connection after manually adding it via the CLI when Advanced Routing
was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-315965</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue to address TCP proxy fast recovery behavior to follow
RFC 5681.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-315964</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where you were unable to sort an
AS path list by its sequencing number (**Network &gt; Routing &gt;
Routing Profiles &gt; Filters &gt; Filters AS Path Access List*).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-315958</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-1410 firewalls only</tt>) Fixed an issue where
the SaaS Quality Profile HTTP/HTTPS monitoring feature failed to send
probes due to the firewall being unable to determine the correct
egress interface and source IP address for the monitoring probes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-315913</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after a User-ID restart on a redistribution
firewall, some expiring IP tag entries became permanent instead of
aging out as intended, which affected Dynamic Address Group policy
rule enforcement.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-315912</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Maximum Segment Size (MSS) rewrite
functionality for packets ingressing through SD-WAN interfaces on
firewalls was not optimized.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-315424</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the BGP peer filter match condition incorrectly
identified neighbors in the Advanced routing Engine, which led to
incorrect Logical Preference assignments and illogical path
selections. This occurred when a BGP Inbound Route Map was configured
to prioritize a path from a specific peer by setting its
<span class="ph uicontrol">Local Reference</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-315337</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect throughput was reduced after an
upgrade.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-315326</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7500 firewalls only</tt>) Fixed an issue where
zone protection threshold values per dataplane were unexpectedly low.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-315314</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when a push operation from Panorama to the
firewall failed, accounting logs stopped forwarding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-315176</div></td>
<td class="entry relcol">
<div class="p">
Added an enable and disable CLI command to address an issue where the
firewall experienced increased packet drops and slower performance
after an upgrade due to high burst traffic.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-315160</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7500 firewalls only</tt>) Fixed an issue where
internal path monitoring logs incorrectly reported internal path
monitoring failures when they did not occur.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-315134</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after an upgrade,
<span class="ph uicontrol">IoT Devices &gt; Asset Inventory</span> did
not display device data even though the system reported a total count
of devices.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-315005</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where configured RIPv2 timer parameters were not
applied when the profile was configured with custom update, expire,
and delete values, and the system continued to use the default timer
settings, which caused unexpected route removal and network
disconnections.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-314873</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall intermittently stopped forwarding
traffic to the internet.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-314823</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the management interface became unresponsive when
attempting to untag an IP address via the web interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-314818</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dropped IPv6 packets after enabling
<span class="ph uicontrol">Strict IP Check</span> under
<span class="ph uicontrol">Zone Protection</span> in an SD-WAN
configuration.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-314764</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a shared object appeared in the push scope during
every push to devices even when it was not applicable to the committed
changes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-314752</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where, after removing a scheduled
configuration push, Panorama still initiated the push at its
previously scheduled time.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-314724</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the OpenConfig plugin was unavailable for
installation after installing PAN-OS due to the plugin package not
being included in the PAN-OS software bundle.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-314712</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7500 Series firewalls only</tt>) Fixed an issue
where the source IP Dynamic Address Group mappings were intermittently
not displayed under
<span class="ph uicontrol">Monitor &gt; Traffic logs</span>. This
occurred even when dynamic address groups were updated via XML API
without an expiry time and no unregister requests were observed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-314630</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall repeatedly rebooted and entered
maintenance mode, and a factory reset was required.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-314623</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/passive HA configurations only</tt
>) Fixed an issue where, after a failover, routing information within
OSPF protocol was not correctly translated or propagated, which
affected network path convergence and FRR capabilities.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-314512</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect portal became inaccessible when
the dataplane was configured with a DHCP assigned IP address.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-314477</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where committing configuration changes failed due to
the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>routed</a
>
process not responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-314435</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where custom application
tags for cloud applications were not consistently displayed in the
Application Filter or application details even though the tags were
configured via CLI and successfully enforced traffic blocking policy
rules.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-314398</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-7500 firewalls in a cluster configuration only</tt
>) Fixed an issue where the firewall was unable to establish a TCP
connection to CDL endpoints, which prevented forwarding of traffic,
system, configuration, and threat logs to the CDL.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-314385</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in active/passive HA clusters only</tt>)
Fixed an issue where high dataplane CPU usage occurred and traffic
offloading decreased when a failover occurred from the active firewall
to the passive firewall, and then back to the active firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-314372</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when SSL Inbound Decryption was enabled, the
inbound SMTP email delivery to an internal mail server failed due to
the firewall silently dropping application packets containing SMTP
commands after successful decryption.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-314365</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process stopped responding for traffic containing multiple XFF headers
when URL XFF header logging was enabled along with additional XFF
header logging, which caused subsequent commits to fail.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-314319</div></td>
<td class="entry relcol">
<div class="p">
Added a CLI command to enable and disable AHO software offload
optimization.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-314300</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall continued to send LLDP learned
information via SNMP for an interface even after disabling LLDP on
that interface. This occurred when a third-party tool polled SNMP and
it received outdated topology information.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-314223</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama web interface did not display all
Security policy rules when using a Chromium-based browser, and you
were unable to scroll to the bottom of the page to view the complete
list.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-314201</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue on PAN-OS 12.1 releases where intermittent traffic
drops occurred over IPSec VPN tunnels to third-party firewalls during
the IPSec rekey due to the firewall failing to inform the peer to
delete the old SA after moving to the new one.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-314147</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SSL traffic was dropped on SD-WAN DIA interfaces
with member having different MTU.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-314142</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where establishing log forwarding connections to the
Strata Logging Service (SLS) took longer than expected, which resulted
in delayed log visibility on SLS.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-314126</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where session rematch did not properly apply updated
Security policy rules to existing traffic flows after committing
changes, which caused traffic to still be allowed when a new Security
policy was set to <span class="ph uicontrol">Deny</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-314020</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not decapsulate GENEVE packets
when DNS Security retransmitted a DNS query after receiving a verdict
from the cloud.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-314018</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls in AWS environments only</tt>)
Fixed an issue where the decrypt mirror port did not function
expected, which prevented decrypted traffic from reaching the intended
destination collector.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-313976</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where traffic, URL, and unified log entries
were duplicated, which led to inaccurate Security logging after
applying a time filter for the previous 6 hours.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-313828</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not forward traffic due to
memory issues on a forwarding component.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-313827</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory leak occurred related to the
<span class="ph systemoutput">reportd</span> process when custom
reports were run via API.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-313787</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where some system log filters with the
<span class="ph systemoutput">eventid</span> operator for a BGP event
did not work.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-313779</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7500 Series only</tt>) Fixed an issue where the
<span class="ph systemoutput"
>request high-availability session-reestablish</span
>
CLI command did not work due to encryption not being supported on HA1
and HA1-backup interfaces.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-313700</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an unexpected reboot occurred when Inline Cloud
Analysis was enabled in an Anti-Spyware and Vulnerability profile.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-313623</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">/opt/pancfg/mgmt/ssl/private/</span>
directory on Palo Alto Networks devices with TPM support became 100%
utilized due to an accumulation of undeleted
<span class="ph systemoutput">.pub_pem</span> files. This occurred
because executing the
<span class="ph systemoutput">show device-certificate status</span>
CLI command initiated a process that generated these files but failed
to remove them, which prevented the fetching of new device
certificates.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-313606</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama pushed commits took longer than expected
to complete without displaying an error message when committing due to
slow cloud-app compilation.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-313575</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where 10G connections on built-in RJ45 interfaces
(ethernet1/1 through ethernet1/5) intermittently experienced interface
flapping when connected to Cisco switchports.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-313572</div></td>
<td class="entry relcol">
<div class="p">
<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
the dataplane restarted due to a segmentation fault.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-313523</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where generating a tech support file caused
GlobalProtect users to be forcibly logged out.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-313494</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where ARP entries remained in a
<span class="ph uicontrol">complete</span> state with a TTL of 0 on
the active-secondary node, which prevented affected devices from
reliably communicating when traffic routes routed through that node.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-313443</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls acting as an accumulation proxy sent a
server hello with an earlier TCP timestamp value than a preceding ACK
packet, which prevented successful session establishment. This
occurred when the client hello messages were split across multiple
network segments.
</div>
<div class="p">
To use this fix, run the CLI command
<span class="ph systemoutput"
>debug dataplane set ssl-decrypt accumulate-client-hello ts-relay
yes</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-313258</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where PIM multicast routing failed on appliances with
advanced routing enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-313216</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls with Prisma Access incorrectly
displayed some traffic as unsanctioned in traffic logs for cloud
applications that were tagged as
<span class="ph systemoutput">sanctioned</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-313193</div></td>
<td class="entry relcol">
<div class="p">
<tt class="ph tt">Firewalls in Layer 2 mode only</tt>) Fixed an issue
where the new sessions were not able to be established due to the
firewall intermittently dropping valid MAC address entries for
specific VLANs when a manual switchover sent a high volume of traffic
to the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-313048</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the BGP default route was lost from the
forwarding table during a failover, which caused a temporary service
interruption.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-313036</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dataplane continuously accumulated
packets in the <span class="ph systemoutput">ctd_pkt_queue</span> and
packet buffers, which caused resource exhaustion and prematurely
terminated sessions.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-312706</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewalls restarted due to a function lacking
a NULL-pointer sanity check.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-312697</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls intermittently failed to send all logs
to the SLS.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-312618</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to activate GlobalProtect
client software and displayed
<span class="ph systemoutput">SW LIMIT</span> messages related to
max-profiles and unsupported major and minor versions in the downgrade
list, which prevented successful software installation.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-312514</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where correlation logs were not forwarded via syslog or
email.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-312354</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Captive Portal authentication redirects failed
for HTTPS traffic when a user attempted to access internal HTTPS
websites via URL, which led to
<span class="ph uicontrol">ERR_CONNECTION_RESET</span> error messages
in the browser with SSL decryption and CTD handshake inspection
enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-312277</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after manually restarting the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>mgmtsrvr</a
>
process caused the firewall to stop generating or forwarding system
and configuration logs to Panorama, and a reboot was required to
restore logging functionality.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-312267</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall lost its MAC entry which caused IPv6
traffic sessions to become unresponsive or drop. This occurred when
PBF rules were configured with symmetric return and
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>no-pbf</a
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-312156</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls did not correctly apply SD-WAN policy
rules, which caused traffic to be incorrectly routed via local
breakout instead of VPN backhaul.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-311938</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where autocommits failed after an upgrade due to
configuration memory allocation issues and 100% policy rule cache
usage when both DNS Rewrite and URL Custom Category Match were
configured.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-311658</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process stopped responding, which caused the firewall to reboot.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-311512</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where HIP (Host Information Profile) reports were
blocked on GlobalProtect when
<span class="ph uicontrol"
>Authentication Cookie Usage Restrictions</span
>
was enabled and the Prisma Access Agent protocol was in use. This
occurred because the system failed to correctly process HIP messages
that were relayed via IPSec tunnels with a Virtual IP as the source,
leading to their rejection.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-311456</div></td>
<td class="entry relcol">
<div class="p">
Enhanced the SCP-based export script by adding comprehensive logging
to identify and diagnose the root cause for failed or incomplete
traffic log exports.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-311449</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where global search did not return comprehensive
results after an upgrade and only displayed top-level objects.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-311419</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the recommended filter for identifying traffic
from unidentified users in traffic logs reported an incorrectly low
number of results.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-311412</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">show advanced-routing resource</span>
CLI command failed to execute successfully when invoked through the
XML API and returned an error message.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-311352</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue in SD-WAN deployments where DIA traffic was disrupted
when DIA AnyPath was enabled during path transitions from the SD-WAN
VIF to the physical interface. With this fix, the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>drop the packet even on zone change</a
>
configuration is not needed to prevent interrupted DIA traffic during
path switching.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-311285</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory leak occurred related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>ospfd</a
>
process, which caused RAM usage to continuously increase until the
device stopped responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-311261</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall generated duplicate URL Filtering
logs due to an error condition&nbsp;when the new XFF feature was
enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-311250</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances and Log Collectors only</tt>)
Fixed an issue where logs from multiple devices were not visible on
Panorama even though the Elasticsearch health status on the dedicated
Log Collectors appeared green.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-311248</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the ABR failed to translate and advertise the
default route (0.0.0.0/0) from an OSPF NSSA area into the OSPF
backbone area as a Type-5 LSA.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-311218</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a system health check Security policy
rule was applied to <span class="ph uicontrol">any</span> zones
instead of <span class="ph uicontrol">Public</span> or
<span class="ph uicontrol">Private</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-311205</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where XML queries failed when you attempted to compare
configuration versions.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-311166</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted unexpectedly to the
<span class="ph systemoutput">all_task_1</span> process repeatedly
restarting.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-311113</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to clear sessions using
the CLI command
<span class="ph systemoutput">clear session all filter rule</span>
when the specified rule name exceeded 32 characters, even though the
limit is 63 characters.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-311098</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls entered a nonfunctional state due to L7
running out of resources due to a high volume of traffic.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-311074</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GRE tunnels took significantly longer to
establish when the hold timer was configured to a value of 10 or
higher, which resulted in a tunnel requiring more successful keepalive
packets than expected to transition to an
<span class="ph uicontrol">Up</span> state.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-311040</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding and caused the firewall to reboot
unexpectedly.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-310851</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls experienced
<span class="ph systemoutput">snmpd</span> log flooding with messages
such as
<span class="ph systemoutput"
>update_ifTable_utilization_rates(pan_interfacecache.c:1720): Last
time is 0 for dedicated-ha2.</span
>, which caused the <span class="ph systemoutput">snmpd</span> log to
overflow and be cleared every five minutes. This occurred because the
<span class="ph systemoutput">snmpd</span> process attempted to
calculate interface utilization rates without first verifying if the
interface had valid
<span class="ph systemoutput">sysd</span> configuration data, as the
code incorrectly assumed all interfaces in the MIB would possess valid
<span class="ph systemoutput">sysd</span> data.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-310743</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were unable to change an administrator's
authentication profile to <span class="ph uicontrol">None</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-310526</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where you were unable to download cellular firmware
through Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-310473</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where committing configuration changes to an Advanced
Logical router caused a 20-30 second loss of management access in the
firewall when IPv4 and IPv6 default static routes were configured with
identical attributes including interface, next-hop, and metrics, which
triggered an unnecessary routing table refresh.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-310472</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where checkboxes for
<span class="ph uicontrol">default information originate</span> and
ABR in OSPF NSSA configurations were automatically enabled which
resulted in unexpected configuration changes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-310452</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a configuration setting was not reset to its
default value after an upgrade, which caused pre-checks and
post-checks to fail.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-310362</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where IPv6 Routed HA did not function correctly when
the HA1 (control link) was configured with an IPv6 routed connection.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-310267</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a process stopped responding during Go garbage
collection (GC).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-310240</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where software packet buffers were completely utilized
when performing a Data Loss Prevention longevity test.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-309960</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory leak related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process on the passive device led to an OOM condition.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-309944</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an error message was incorrectly displayed
instead of a debug message.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-309927</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the
<span class="ph systemoutput">multi-clone</span> XML API operation
reported a successful configuration change even when the specific
device group did not exist.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-309828</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after a firewall serial number was updated via
Panorama, a subsequent policy rule push from Panorama incorrectly
deleted target policy rules from managed firewalls with the updated
serial numbers.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-309676</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a database component unexpectedly
stopped when Panorama was deployed using an .ova file or
upgraded/downgraded to an affected PAN-OS version. This occurred due
to a required directory not being created during the initial
provisioning workflow. With this fix, the necessary directory is
created automatically during deployment.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-309493</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the URL cloud connection was impacted, which
caused a traffic outage.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-309300</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where management plane system resources configuration
size exceeded 28 MB for over 4 hours, and the following error message
was displayed:
<span class="ph systemoutput"
>Configuration size reaching device capacity limit</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-308928</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where OSPF routes did not install correctly when you
performed a traffic switch between firewalls with the Advanced Routing
Engine enabled, which led to routing instability.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-308876</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where upgrades to managed firewalls from Panorama
failed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-308775</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in active/passive configurations only</tt
>) Fixed an issue where NTP status intermittently showed as rejected
on the active firewall, which prevented the firewalls from
synchronizing time.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-308732</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Multi-vsys firewalls only</tt>) Fixed an issue
where GlobalProtect clients were unable to use custom source region
objects for gateway selection criteria due to region objects defined
in Panorama not being correctly recognized or displayed in the
GlobalProtect Portal configuration.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-308711</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where superusers with read-only privileges on Panorama
were unable to execute
<span class="ph systemoutput">show device-certificate</span> CLI
commands.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-308651</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall web interface where the TLSv1.3_Default
certificate setting and SSL/TLS profile were not displayed."
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-308563</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where multiple
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
processes attempted to clear the packet queue of the same session.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-308507</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama managed firewalls only</tt>) Fixed an
issue where the firewall intermittently failed to maintain active log
forwarding streams to Strata Logging Service (SLS) even when duplicate
logging and enhanced application logging were enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-308461</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the CLI command
<span class="ph systemoutput"
>request system software download to-version &lt;version&gt;</span
>
failed to download multiple software images due with a
<span class="ph systemoutput"
>Download terminated due to timeout</span
>
error message.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-308444</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where pushing multiple policy rules failed when the
policy rules contained a large number of dynamic address object groups
or user groups.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-308418</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when Advanced DNS Security was enabled and
experienced unusually high loads, DNS resolution failures occurred
with the error
<span class="ph uicontrol">resources-unavailable</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-308377</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-7000 Series firewalls with an LFC in HA configurations only</tt
>) Fixed an issue where the firewall reached 100% disk utilization due
to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process repeatedly restarting and dumping core files due to a blocked
hints processing thread, which caused a failover.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-308261</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall failed to send SNMPv3 traps when the
SNMP destination was configured with an FQDN that resolved to multiple
IP address through DNS load balancing.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-307937</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where the global filter set in
<span class="ph uicontrol">ACC &gt; Threat Activity</span> did not
apply when you navigated to the
<span class="ph uicontrol">Network Activity</span> tab.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-307773</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where enabling Post-Quantum Pre-Shared Key
(PPK) within an IKE Gateway profile that was configured as a part of a
template stack failed or was inconsistent when attempted via the web
interface, even when the keys were properly configured.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-307717</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where administrators were unable to
override SNMP setup configurations within device groups due to the
configured override not being retained.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-307618</div></td>
<td class="entry relcol">
<div class="p">
Added a debug CLI command to address where remote networks for Prisma
Access tenants randomly dropped monitoring packets from peer devices,
which caused tunnels to be marked as down. This occurred when a CPU
core suddenly experienced high utilization.
</div>
<div class="p">
To utilize this fix, run
<span class="ph systemoutput"
>debug dataplane set ssl-decrypt use-new-peek-window yes</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-307491</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall entered maintenance mode after a
reboot when ZTP was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-307470</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an External Dynamic List (EDL) fetch with an
invalid certificate was skipped on newly provisioned GlobalProtect
gateway instances.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-306533</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where system logging for NTP events was delayed by
approximately 15 minutes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-306356</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process on a firewall stopped responding due to a document node being
unexpectedly freed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-306217</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where scheduled reports with specific
queries did not include any data.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-305950</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when attempting to install software upgrades on
managed firewalls via
<span class="ph uicontrol">Device Deployments</span>, Panorama
incorrectly reported that the firewalls did not have valid support
licenses.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-305619</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where HTTP management access appeared to fail and
incorrectly displayed the error message
<span class="ph uicontrol">Error 503: Service Unavailable</span> even
though it functioned correctly as allowed. This occurred when an
interface was configured with an address object.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-305369</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dropped packets due to an invalid
interface when attempting to ping the next-hop gateway from a VLAN
interface due to the firewall incorrectly resolving the ARP for the
gateway on an unintended interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-305240</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where User-ID redistribution clients experienced delays
in establishing initial communication with the redistribution server,
which caused connection timeouts.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-304718</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where OSPF and BGP outages occurred due to an
<span class="ph systemoutput">all_task</span> process restart during
clientless VPN content rewrite processing.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-304360</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not redistribute its application
routes to BGP peers. This occurred in multi-mesh deployments with the
multi-cloud networking feature enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-303662</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where PA-455 firewalls running PAN-OS 11.2.4-h7
intermittently failed to generate system logs and trigger an HA
failover when a link-monitored interface was unplugged, despite the
interface's status being reflected as down on the GUI.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-303173</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in Advanced Routing mode only</tt>) Fixed
an issue where OSPF sessions using MD5 authentication experienced
intermittent flapping due to out-of-order packets.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-302855</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where multiple processes restarted which caused the
firewall to become unstable when processing traffic.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-302834</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not display decryption logs after a
certain date due to the decryption index being purged.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-302512</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Log Collectors in HA configurations only</tt>)
Fixed an issue where log collectors displayed a disconnected inter-log
collector status.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-302387</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where on PA-7500 firewalls, SNMP incorrectly reported
the administrative and operational status of High Speed Chassis
Interconnect (HSCI) interfaces as down, even when the interfaces were
physically up. Additionally, interface counters for these interfaces
displayed all zeroes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-302150</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue where
you were unable to successfully configure log collector groups due to
the master node settings not populating automatically.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-301513</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama managed multi-vsys firewalls where, when
the shared-to-shared feature was enabled, shared objects reverted to
an older configuration after a selective push to a vsys.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-300617</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Elasticsearch cluster status displayed as red
due to unassigned shards, which prevented logs from updating.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-300615</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_comm</a
>
process stopped after multiple content versions were installed and the
memory limits were reached.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-300445</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall downloaded an Antivirus package but
did not automatically install it.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-300423</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Data Processing Cards (DPCs) installed in slots 5
and 6 remained stuck in a starting state with the error
<span class="ph uicontrol"
>Signal detected for port xeS5-DP0 but Link Down</span
>
alerts, which resulted in device instability.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-298960</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall continuously rebooted when the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process repeatedly restarted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-298788</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the /pancfg partition on the Azure Cloud NGFW
reached 100% utilization, which caused commit failures.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-298252</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Data Loss Prevention (DLP) inspection of chunked
transfer encoding over TLS resulted in incomplete file downloads on
Outlook Web App (OWA) due to the WIF page size limit, which led to
corrupted or incomplete PDF attachments.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-297819</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to send device telemetry
files to Cortex Data Lake due to the firewall receiving an invalid
upload token.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-296635</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process on passive Panorama management servers leaked memory due to
scheduled report handling from the Strata Logging Service (SLS). This
memory leak occurred daily, consuming available memory until the
process was restarted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-296246</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where policy cache corruption led to unexpected policy
rule behavior or operational instability. This occurred when an
internal system process restarted while a commit was in progress or
when a commit operation failed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-295806</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where memory leaks on the
<span class="ph systemoutput">configd</span> process occurred due to a
hash insert operation failing during connection management and SSL
connections.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-295082</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where you were unable to
delete or change a logical router for tunnel, SD-WAN, VLAN, or
loopback interfaces under a template.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-295047</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>staticd</a
>
process stopped responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-294998</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the LogDB incorrectly reported that the database
quota for <span class="ph systemoutput">extpcap</span> logs was
reached.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-294434</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where memory leaks occurred. These leaks were caused by
two distinct scenarios: the failure to deallocate memory for a nodeset
when a new nodeset was assigned to the same variable, and the failure
to free a UUID hash table during error conditions.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-293586</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama virtual appliances only</tt>) Introduced a
CLI command to increase the limit of user types from 1 million to 3.6
million.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-292447</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not display data in the
<span class="ph uicontrol">Feature Adoption</span> tab in Strata Cloud
Manager due to the system creating and deleting a CLI user for each
interval instead of reusing a permanent CLI user for telemetry.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-292220</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Status LED on PA-7500 SFCs did not work.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-292191</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dropped packets related to call
recording and voice calls, which resulted in communication failures,
retransmissions, and disconnected calls. This occurred when the
firewall was positioned between a Private Branch Exchange and an AES
server and users registered phones across different data centers.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-291785</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-291284</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where single-session IPSec VPN traffic was distributed
across multiple member interfaces of a Link Aggregation Group
configured with LACP. This resulted in packet reordering and loss,
which impacted VPN performance.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-290712</div></td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7500 Firewalls in cluster mode only</tt>) Fixed
an issue where the firewall incorrectly advertised BGP routes back to
the external BGP peer, which resulted in routing inefficiency.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-289578</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama managed firewalls where the source user,
source device vendor, source MAC address, and OS version information
were not visible in traffic logs and SCM when the user and device
access control lists were empty.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-289460</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the timestamp value in SNMPv3 trap headers was
incorrect.
</div>
<div class="p">
To use this fix, run the CLI command
<span class="ph systemoutput"
>debug log-receiver enginetime-from-snmptime yes</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-287280</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a
<span class="ph systemoutput">configd</span> crash occurred when the
<span class="ph uicontrol">Policies &gt; Security</span> view was
updated or refreshed in the web interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-283704</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the PAN-OS DoS protection feature by default
blacklisted specific IP addresses, which caused outbound traffic
domain resolution to fail for clusters.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-282335</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where firewalls in a cluster experienced approximately
50% packet loss on IPSec NATT tunnels when tunnel acceleration was
enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-280196</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue in Prisma Access environments where the firewall
matched a HIP object but not on the HIP profile that contained the
object.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-274622</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where GlobalProtect
client images were not exported via SCP.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-273805</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SAML authentication for GlobalProtect failed when
the GlobalProtect portal was accessed externally on a non-standard
port.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-273028</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where manual SCP exports from firewalls in FIPS mode
were successful to SCP servers that were not FIPS-compliant. This
occurred because the manual SCP process did not enforce FIPS security
checks.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-272175</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where session rematch caused ACE cloud application
traffic to match the wrong policy.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-266843</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue on airgapped firewalls where cloud connection errors
flooded the system logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-264762</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall showed the status of SFP+ interfaces
as not up, or up but not configured, when a PAN-SFP-PLUS-SR cable was
connected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-264349</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Management Processor Card (MPC) on modular
firewalls became unresponsive when a disk drive entered a low-power
state and failed to wake up.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-260661</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where daily email reports generated from the custom
report did not display the report details in PDF or CSV files.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry"><div class="p">PAN-250445</div></td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DLP logs accumulated in the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
cache when using DLP in mirror mode.
</div>
</td>
</tr>
</tbody>
</table>