PAN-OS 12.1.9 Addressed Issues
Focus
Focus
Next-Generation Firewall

PAN-OS 12.1.9 Addressed Issues

Table of Contents

PAN-OS 12.1.9 Addressed Issues

Lists the addressed issues in PAN-OS 12.1.9.
The following table lists the addressed issues in PAN-OS 12.1.9.
Issue ID
Description
PAN-329834
Fixed an issue where a memory leak associated with some display CLI commands caused instability.
PAN-329180
Fixed an issue where Panorama did not automatically resume syslog forwarding over TCP after the syslog server became unavailable or was restarted.
PAN-328742
Fixed an issue where the dataplane silently dropped HTTP POST payloads, which disrupted application integrations. This occurred due to an internal error when processing XFF headers within the CTD engine.
PAN-327590
Fixed an issue where BFD sessions did not reestablish on the newly elected leader after a leader failover event that occurred when the previous leader node was suspended.
PAN-327460
Fixed an issue where a Commit and Push operation on Panorama did not successfully push configuration changes to Prisma Access endpoints. This occurred when the system reported that not all commit jobs were triggered. With this fix, Commit and Push operations now correctly apply configurations to Prisma Access.
PAN-326354
Fixed an issue where the sslmgr process stopped responding when attempting to display the OSCP host cache.
PAN-325613
(PA-7500 firewalls in HA cluster configurations only) Fixed an issue where interfaces intermittently remained offline after a cluster failover.
PAN-325002
(Google Cloud NGFW Enterprise VM-Series firewalls only) Fixed an issue where the HTTP2 threat logs did not include VPC ID, Security_key, and Endpoint ID.
PAN-324902
Fixed an issue where exporting Custom Reports to CSV failed with a UnicodeEncodeError message when report entries contained multibyte characters.
PAN-323249
(M-700 appliances only) Fixed an issue where the Elasticsearch processes repeatedly restarted and log collectors showed the Elasticsearch health status as red.
PAN-320345
Fixed an issue where the firewall repeatedly restarted when the monitored User-ID server became unreachable during Kerberos authentication connection attempts, which caused the authentication process to stop responding. On firewalls in HA configurations, both peer firewalls entered maintenance mode.
PAN-319838
Fixed an issue where SFP ports did not establish a link with a third-party peer device when forced speed was configured on the firewall and the peer device was set to nonegotiate.
PAN-319504
Fixed an issue where telemetry data was not sent to the cloud due to the firewall being unable to resolve the destination server's FQDN even when a proxy server was configured. With this fix, the firewall properly sends telemetry data through the configured proxy server without requiring direct public DNS resolution for the telemetry server's FQDN.
PAN-318580
Fixed an issue where processes restarted and the firewall unexpectedly rebooted when you configured a Security policy rule with Source Device > quarantine.
PAN-318382
(Firewalls in HA configurations only) Fixed an issue where the secondary firewall remained at an Initial state after an upgrade.
PAN-317598
(Firewalls in active/active HA configurations only) Fixed an issue where NAT failures occurred due to the IP pool not releasing unused resources in the Active Secondary firewall. This occurred because the secondary firewall attempts to release a Persistent DIPP NATed port that was originally allocated by the NAT policy from first firewall, leading to a ownership mismatch during the session teardown process.
PAN-317214
Fixed an issue where SNMP queries for TCP connections per second (CPS) metrics on single vsys firewalls returned inconsistent values.
PAN-316720
Fixed an issue on log collectors where Verify Update Server Identity was not consistently enabled and visible in the XML configuration after a configuration push from Panorama.
PAN-314776
Fixed an issue where the configd process stopped responding after pushing configuration changes from Panorama to the firewall.
PAN-314061
Fixed an issue where traffic was disrupted during IPSec rekey operations due to a 2 second delay in sending the DELETE message for the previous Security Association (SA) to the peer gateway after a new SA was negotiated.
PAN-313850
(PA-1400 Series firewalls in HA configurations only) Fixed an issue where a split-brain condition occurred and HA1/HA2 links went down while upgrading when the HA configuration used dataplane interfaces for HA1 and a combination of HSCI and Ethernet interfaces for HA2.
PAN-313218
Added the following CLI commands to address QoS packet drops due to bursty traffic:
  • debug dataplane set qos-setting qos-param qlimit 300
  • debug dataplane set qos-setting qos-param red low 50 high 90
To utilize this fix, change the parameters, disable QoS, commit changes, enable QOS, and then re-commit changes.
PAN-313190
(VM-Series firewalls only) Fixed an issue where content updates and configuration commits failed with the error message client device phase 1 failure error.
PAN-312685
Fixed an issue where committing a scheduled configuration push on Panorama caused the configd process to stop responding unexpectedly.
PAN-312330
(Firewalls in active/passive HA configurations only) Fixed an issue where the Clientless VPN applications failed to load due to the firewall dataplane incorrectly processing session information.
PAN-311988
(Firewalls in FIPS mode only) Fixed decryption issues that occurred after an upgrade to an affected release.
To enable this fix, run the CLI command debug dataplane set ssl-decrypt low-memory-throttle enable.
PAN-311624
Fixed an issue on Panorama where, when an Aggregate Ethernet interface was configured in override mode within a template stack, changing its management profile unexpectedly overrode other interface-specific variables.
PAN-310699
Fixed an issue where the firewall stripped the Authentication Key Identifier (AKID) from certificates using SSL decryption, which prevented clients from authenticating server certificates and resulted in decryption failures.
PAN-309306
Fixed a rare issue on Octeon Dataplane platforms where the firewall experienced an unexpected dataplane restart due to a race condition that occurred during session teardown for traffic undergoing software-based Content Threat detection.
PAN-308614
Fixed an issue where the mgmt process stopped responding after an upgrade during SSH Key Exchange verification.
PAN-302175
Fixed an issue where, after upgrading an LSVPN portal/gateway to an affected release, the portal was unable to issue and transfer certificates to the satellite firewalls, which led to repeated certificate requests and prevented the satellite firewalls from authenticating to the gateway.
PAN-297818
Fixed an issue on Panorama where exporting managed device information that included a PA-450R-5G appliance resulted in the Cellular Firmware field being exported into multiple cells.
PAN-252699
Fixed an issue where frequent session failures occurred due to CTD resource exhaustion.