230 lines
7.5 KiB
HTML
230 lines
7.5 KiB
HTML
<table class="table colsep rowsep table-striped">
|
|
<!--cq:include script="../../common/tablestack.jsp" /-->
|
|
|
|
<colgroup>
|
|
<col style="width: 25%" />
|
|
<col style="width: 75%" />
|
|
</colgroup>
|
|
<thead class="thead">
|
|
<tr class="row rowsep">
|
|
<th class="entry">
|
|
<div class="p"><b class="ph b">Issue ID</b></div>
|
|
</th>
|
|
<th class="entry">
|
|
<div class="p"><b class="ph b">Description</b></div>
|
|
</th>
|
|
</tr>
|
|
</thead>
|
|
|
|
<tbody class="tbody">
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b"> PAN-316911</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>VM-Series firewalls on Amazon Web Services (AWS) environments
|
|
only</tt
|
|
>) Fixed an issue where a newly bootstrapped firewall required a
|
|
management server restart, relicensing, or license push from Panorama
|
|
to invoke the device certificate.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-315176</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Added an enable and disable CLI command to address an issue where the
|
|
firewall experienced increased packet drops and slower performance
|
|
after an upgrade due to high burst traffic.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-314061</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where traffic was disrupted during IPSec rekey
|
|
operations due to a 2 second delay in sending the DELETE message for
|
|
the previous Security Association (SA) to the peer gateway after a new
|
|
SA was negotiated.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-313850</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>PA-1400 Series firewalls in HA configurations only</tt
|
|
>) Fixed an issue where a split-brain condition occurred and HA1/HA2
|
|
links went down while upgrading when the HA configuration used
|
|
dataplane interfaces for HA1 and a combination of HSCI and Ethernet
|
|
interfaces for HA2.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-313623</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where the
|
|
<span class="ph systemoutput">/opt/pancfg/mgmt/ssl/private/</span>
|
|
directory on Palo Alto Networks devices with TPM support became 100%
|
|
utilized due to an accumulation of undeleted
|
|
<span class="ph systemoutput">.pub_pem</span> files. This occurred
|
|
because executing the
|
|
<span class="ph systemoutput">show device-certificate status</span>
|
|
CLI command initiated a process that generated these files but failed
|
|
to remove them, which prevented the fetching of new device
|
|
certificates.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-311285</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Firewalls in HA conditions only</tt>) Fixed an
|
|
issue where a memory leak occurred related to the
|
|
<a
|
|
class="term"
|
|
href="#"
|
|
title=""
|
|
data-scope=""
|
|
data-format="dita"
|
|
data-type=""
|
|
target="_self"
|
|
>ospfd</a
|
|
>
|
|
process, which caused RAM usage to continuously increase on active
|
|
devices in an HA cluster until the device stopped responding, even
|
|
after an HA failover.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-308507</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">Panorama managed firewalls only</tt>) Fixed an
|
|
issue where the firewall intermittently failed to maintain active log
|
|
forwarding streams to Cortex Data Lake even when duplicate logging and
|
|
enhanced application logging were enabled.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-309300</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where management plane system resources configuration
|
|
size exceeded 28 MB for over 4 hours, and the following error message
|
|
was displayed:
|
|
<span class="ph systemoutput"
|
|
>Configuration size reaching device capacity limit</span
|
|
>.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-302654</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Firewalls in active/passive HA configurations only</tt
|
|
>) Fixed an issue where, when the HA configuration had multiple
|
|
logical routers, static or connected routes redistributed into OSPF
|
|
aged out in the LSDB, which caused the routes to be removed on peer
|
|
OSPF neighbors.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b"> PAN-300423</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Fixed an issue where Data Processing Cards (DPCs) installed in slots 5
|
|
and 6 remained stuck in a starting state with the error
|
|
<span class="ph uicontrol"
|
|
>Signal detected for port xeS5-DP0 but Link Down</span
|
|
>
|
|
alerts, which resulted in device instability.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-298617</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
Optimized the commit workflow to reduce the size of the effective
|
|
configuration, resulting in lower memory consumption.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row rowsep">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b">PAN-296202</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt"
|
|
>Firewalls in active/active HA configurations only</tt
|
|
>) Added a log enhancement to capture an issue where, when a commit
|
|
operation was in progress, newly deployed IP address tags that used
|
|
the XML API were not immediately reflected in address group
|
|
resolution, which delayed IP address mapping to address groups and
|
|
caused traffic to be incorrectly allowed or denied.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
|
|
<tr class="row">
|
|
<td class="entry">
|
|
<div class="p"><b class="ph b"> PAN-273158</b></div>
|
|
</td>
|
|
<td class="entry relcol">
|
|
<div class="p">
|
|
(<tt class="ph tt">PA-7000 Series firewalls only</tt>) Fixed an issue
|
|
where an incorrect ASIC configuration caused silent packet drops or
|
|
application slowness when receiving a mix of jumbo and non-jumbo
|
|
packets.
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|