PAN-OS 8.1.7 Addressed Issues
Table of Contents
Expand All
|
Collapse All
Next-Generation Firewall Docs
-
PAN-OS 11.1 & Later
- PAN-OS 11.1 & Later
- PAN-OS 11.0 (EoL)
- PAN-OS 10.2
- PAN-OS 10.1
- PAN-OS 10.0 (EoL)
- PAN-OS 9.1 (EoL)
- Cloud Management of NGFWs
-
- Management Interfaces
-
- Launch the Web Interface
- Use the Administrator Login Activity Indicators to Detect Account Misuse
- Manage and Monitor Administrative Tasks
- Commit, Validate, and Preview Firewall Configuration Changes
- Commit Selective Configuration Changes
- Export Configuration Table Data
- Use Global Find to Search the Firewall or Panorama Management Server
- Manage Locks for Restricting Configuration Changes
-
-
- Define Access to the Web Interface Tabs
- Provide Granular Access to the Monitor Tab
- Provide Granular Access to the Policy Tab
- Provide Granular Access to the Objects Tab
- Provide Granular Access to the Network Tab
- Provide Granular Access to the Device Tab
- Define User Privacy Settings in the Admin Role Profile
- Restrict Administrator Access to Commit and Validate Functions
- Provide Granular Access to Global Settings
- Provide Granular Access to the Panorama Tab
- Provide Granular Access to Operations Settings
- Panorama Web Interface Access Privileges
-
- Reset the Firewall to Factory Default Settings
-
- Plan Your Authentication Deployment
- Pre-Logon for SAML Authentication
- Configure SAML Authentication
- Configure Kerberos Single Sign-On
- Configure Kerberos Server Authentication
- Configure TACACS+ Authentication
- Configure TACACS Accounting
- Configure RADIUS Authentication
- Configure LDAP Authentication
- Configure Local Database Authentication
- Configure an Authentication Profile and Sequence
- Test Authentication Server Connectivity
- Troubleshoot Authentication Issues
-
- Keys and Certificates
- Default Trusted Certificate Authorities (CAs)
- Certificate Deployment
- Configure the Master Key
- Export a Certificate and Private Key
- Configure a Certificate Profile
- Configure an SSL/TLS Service Profile
- Configure an SSH Service Profile
- Replace the Certificate for Inbound Management Traffic
- Configure the Key Size for SSL Forward Proxy Server Certificates
-
- HA Overview
-
- Prerequisites for Active/Active HA
- Configure Active/Active HA
-
- Use Case: Configure Active/Active HA with Route-Based Redundancy
- Use Case: Configure Active/Active HA with Floating IP Addresses
- Use Case: Configure Active/Active HA with ARP Load-Sharing
- Use Case: Configure Active/Active HA with Floating IP Address Bound to Active-Primary Firewall
- Use Case: Configure Active/Active HA with Source DIPP NAT Using Floating IP Addresses
- Use Case: Configure Separate Source NAT IP Address Pools for Active/Active HA Firewalls
- Use Case: Configure Active/Active HA for ARP Load-Sharing with Destination NAT
- Use Case: Configure Active/Active HA for ARP Load-Sharing with Destination NAT in Layer 3
- HA Clustering Overview
- HA Clustering Best Practices and Provisioning
- Configure HA Clustering
- Refresh HA1 SSH Keys and Configure Key Options
- HA Firewall States
- Reference: HA Synchronization
-
- Use the Dashboard
- Monitor Applications and Threats
- Monitor Block List
-
- Report Types
- View Reports
- Configure the Expiration Period and Run Time for Reports
- Disable Predefined Reports
- Custom Reports
- Generate Custom Reports
- Generate the SaaS Application Usage Report
- Manage PDF Summary Reports
- Generate User/Group Activity Reports
- Manage Report Groups
- Schedule Reports for Email Delivery
- Manage Report Storage Capacity
- View Policy Rule Usage
- Use External Services for Monitoring
- Configure Log Forwarding
- Configure Email Alerts
-
- Configure Syslog Monitoring
-
- Traffic Log Fields
- Threat Log Fields
- URL Filtering Log Fields
- Data Filtering Log Fields
- HIP Match Log Fields
- GlobalProtect Log Fields
- IP-Tag Log Fields
- User-ID Log Fields
- Decryption Log Fields
- Tunnel Inspection Log Fields
- SCTP Log Fields
- Authentication Log Fields
- Config Log Fields
- System Log Fields
- Correlated Events Log Fields
- GTP Log Fields
- Audit Log Fields
- Syslog Severity
- Custom Log/Event Format
- Escape Sequences
- Forward Logs to an HTTP/S Destination
- Firewall Interface Identifiers in SNMP Managers and NetFlow Collectors
- Monitor Transceivers
-
- User-ID Overview
- Enable User-ID
- Map Users to Groups
- Enable User- and Group-Based Policy
- Enable Policy for Users with Multiple Accounts
- Verify the User-ID Configuration
-
- App-ID Overview
- App-ID and HTTP/2 Inspection
- Manage Custom or Unknown Applications
- Safely Enable Applications on Default Ports
- Applications with Implicit Support
-
- Prepare to Deploy App-ID Cloud Engine
- Enable or Disable the App-ID Cloud Engine
- App-ID Cloud Engine Processing and Policy Usage
- New App Viewer (Policy Optimizer)
- Add Apps to an Application Filter with Policy Optimizer
- Add Apps to an Application Group with Policy Optimizer
- Add Apps Directly to a Rule with Policy Optimizer
- Replace an RMA Firewall (ACE)
- Impact of License Expiration or Disabling ACE
- Commit Failure Due to Cloud Content Rollback
- Troubleshoot App-ID Cloud Engine
- Application Level Gateways
- Disable the SIP Application-level Gateway (ALG)
- Maintain Custom Timeouts for Data Center Applications
-
- Decryption Overview
-
- Keys and Certificates for Decryption Policies
- SSL Forward Proxy
- SSL Forward Proxy Decryption Profile
- SSL Inbound Inspection
- SSL Inbound Inspection Decryption Profile
- SSL Protocol Settings Decryption Profile
- SSH Proxy
- SSH Proxy Decryption Profile
- Profile for No Decryption
- SSL Decryption for Elliptical Curve Cryptography (ECC) Certificates
- Perfect Forward Secrecy (PFS) Support for SSL Decryption
- SSL Decryption and Subject Alternative Names (SANs)
- TLSv1.3 Decryption
- High Availability Not Supported for Decrypted Sessions
- Decryption Mirroring
- Configure SSL Forward Proxy
- Configure SSL Inbound Inspection
- Configure SSH Proxy
- Configure Server Certificate Verification for Undecrypted Traffic
- Post-Quantum Cryptography Detection and Control
- Enable Users to Opt Out of SSL Decryption
- Temporarily Disable SSL Decryption
- Configure Decryption Port Mirroring
- Verify Decryption
- Activate Free Licenses for Decryption Features
-
- Policy Types
- Policy Objects
- Track Rules Within a Rulebase
- Enforce Policy Rule Description, Tag, and Audit Comment
- Move or Clone a Policy Rule or Object to a Different Virtual System
-
- External Dynamic List
- Built-in External Dynamic Lists
- Configure the Firewall to Access an External Dynamic List
- Retrieve an External Dynamic List from the Web Server
- View External Dynamic List Entries
- Exclude Entries from an External Dynamic List
- Enforce Policy on an External Dynamic List
- Find External Dynamic Lists That Failed Authentication
- Disable Authentication for an External Dynamic List
- Register IP Addresses and Tags Dynamically
- Use Dynamic User Groups in Policy
- Use Auto-Tagging to Automate Security Actions
- CLI Commands for Dynamic IP Addresses and Tags
- Application Override Policy
- Test Policy Rules
-
- Network Segmentation Using Zones
- How Do Zones Protect the Network?
-
PAN-OS 11.1 & Later
- PAN-OS 11.1 & Later
- PAN-OS 11.0 (EoL)
- PAN-OS 10.2
- PAN-OS 10.1
-
- Tap Interfaces
-
- Layer 2 and Layer 3 Packets over a Virtual Wire
- Port Speeds of Virtual Wire Interfaces
- LLDP over a Virtual Wire
- Aggregated Interfaces for a Virtual Wire
- Virtual Wire Support of High Availability
- Zone Protection for a Virtual Wire Interface
- VLAN-Tagged Traffic
- Virtual Wire Subinterfaces
- Configure Virtual Wires
- Configure a PPPoE Client on a Subinterface
- Configure an IPv6 PPPoE Client
- Configure an Aggregate Interface Group
- Configure Bonjour Reflector for Network Segmentation
- Use Interface Management Profiles to Restrict Access
-
- DHCP Overview
- Firewall as a DHCP Server and Client
- Firewall as a DHCPv6 Client
- DHCP Messages
- Dynamic IPv6 Addressing on the Management Interface
- Configure an Interface as a DHCP Server
- Configure an Interface as a DHCPv4 Client
- Configure an Interface as a DHCPv6 Client with Prefix Delegation
- Configure the Management Interface as a DHCP Client
- Configure the Management Interface for Dynamic IPv6 Address Assignment
- Configure an Interface as a DHCP Relay Agent
-
- DNS Overview
- DNS Proxy Object
- DNS Server Profile
- Multi-Tenant DNS Deployments
- Configure a DNS Proxy Object
- Configure a DNS Server Profile
- Use Case 1: Firewall Requires DNS Resolution
- Use Case 2: ISP Tenant Uses DNS Proxy to Handle DNS Resolution for Security Policies, Reporting, and Services within its Virtual System
- Use Case 3: Firewall Acts as DNS Proxy Between Client and Server
- DNS Proxy Rule and FQDN Matching
-
- NAT Rule Capacities
- Dynamic IP and Port NAT Oversubscription
- Dataplane NAT Memory Statistics
-
- Translate Internal Client IP Addresses to Your Public IP Address (Source DIPP NAT)
- Create a Source NAT Rule with Persistent DIPP
- PAN-OS
- Strata Cloud Manager
- Enable Clients on the Internal Network to Access your Public Servers (Destination U-Turn NAT)
- Enable Bi-Directional Address Translation for Your Public-Facing Servers (Static Source NAT)
- Configure Destination NAT with DNS Rewrite
- Configure Destination NAT Using Dynamic IP Addresses
- Modify the Oversubscription Rate for DIPP NAT
- Reserve Dynamic IP NAT Addresses
- Disable NAT for a Specific Host or Interface
-
- Network Packet Broker Overview
- How Network Packet Broker Works
- Prepare to Deploy Network Packet Broker
- Configure Transparent Bridge Security Chains
- Configure Routed Layer 3 Security Chains
- Network Packet Broker HA Support
- User Interface Changes for Network Packet Broker
- Limitations of Network Packet Broker
- Troubleshoot Network Packet Broker
-
- Enable Advanced Routing
- Logical Router Overview
- Configure a Logical Router
- Create a Static Route
- Configure BGP on an Advanced Routing Engine
- Create BGP Routing Profiles
- Create Filters for the Advanced Routing Engine
- Configure OSPFv2 on an Advanced Routing Engine
- Create OSPF Routing Profiles
- Configure OSPFv3 on an Advanced Routing Engine
- Create OSPFv3 Routing Profiles
- Configure RIPv2 on an Advanced Routing Engine
- Create RIPv2 Routing Profiles
- Create BFD Profiles
- Configure IPv4 Multicast
- Configure MSDP
- Create Multicast Routing Profiles
- Create an IPv4 MRoute
-
-
PAN-OS 8.1 (EoL)
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 11.0 (EoL)
- PAN-OS 10.2
- PAN-OS 10.1
- PAN-OS 10.0 (EoL)
- PAN-OS 9.1 (EoL)
- PAN-OS 9.0 (EoL)
- PAN-OS 8.1 (EoL)
- Cloud Management and AIOps for NGFW
-
-
- App-ID Changes in PAN-OS 8.1
- Authentication Changes in PAN-OS 8.1
- Content Inspection Changes in PAN-OS 8.1
- GlobalProtect Changes in PAN-OS 8.1
- User-ID Changes in PAN-OS 8.1
- Panorama Changes in PAN-OS 8.1
- Networking Changes in PAN-OS 8.1
- Virtualization Changes in PAN-OS 8.1
- Appliance Changes in PAN-OS 8.1
- Associated Software and Content Versions
- Limitations
-
- PAN-OS 8.1.26-h1 Addressed Issues
- PAN-OS 8.1.26 Addressed Issues
- PAN-OS 8.1.25-h3 Addressed Issues
- PAN-OS 8.1.25-h2 Addressed Issues
- PAN-OS 8.1.25-h1 Addressed Issues
- PAN-OS 8.1.25 Addressed Issues
- PAN-OS 8.1.24-h2 Addressed Issues
- PAN-OS 8.1.24-h1 Addressed Issues
- PAN-OS 8.1.24 Addressed Issues
- PAN-OS 8.1.23-h1 Addressed Issues
- PAN-OS 8.1.23 Addressed Issues
- PAN-OS 8.1.22 Addressed Issues
- PAN-OS 8.1.21-h3 Addressed Issues
- PAN-OS 8.1.21-h2 Addressed Issues
- PAN-OS 8.1.21-h1 Addressed Issues
- PAN-OS 8.1.21 Addressed Issues
- PAN-OS 8.1.20-h1 Addressed Issues
- PAN-OS 8.1.20 Addressed Issues
- PAN-OS 8.1.19 Addressed Issues
- PAN-OS 8.1.18 Addressed Issues
- PAN-OS 8.1.17 Addressed Issues
- PAN-OS 8.1.16 Addressed Issues
- PAN-OS 8.1.15-h3 Addressed Issues
- PAN-OS 8.1.15 Addressed Issues
- PAN-OS 8.1.14-h2 Addressed Issues
- PAN-OS 8.1.14 Addressed Issues
- PAN-OS 8.1.13 Addressed Issues
- PAN-OS 8.1.12 Addressed Issues
- PAN-OS 8.1.11 Addressed Issues
- PAN-OS 8.1.10 Addressed Issues
- PAN-OS 8.1.9-h4 Addressed Issues
- PAN-OS 8.1.9 Addressed Issues
- PAN-OS 8.1.8-h5 Addressed Issues
- PAN-OS 8.1.8 Addressed Issues
- PAN-OS 8.1.7 Addressed Issues
- PAN-OS 8.1.6-h2 Addressed Issues
- PAN-OS 8.1.6 Addressed Issues
- PAN-OS 8.1.5 Addressed Issues
- PAN-OS 8.1.4-h2 Addressed Issues
- PAN-OS 8.1.4 Addressed Issues
- PAN-OS 8.1.3 Addressed Issues
- PAN-OS 8.1.2 Addressed Issues
- PAN-OS 8.1.1 Addressed Issues
- PAN-OS 8.1.0 Addressed Issues
End-of-Life (EoL)
PAN-OS 8.1.7 Addressed Issues
PAN-OS® 8.1.7 addressed issues
Issue ID | Description |
---|---|
WF500-4093 | Fixed an issue on a WF-500 appliance cluster
where a firewall failed to join the cluster with a large data set
of previously processed files. |
PAN-113536 | Fixed an issue where the automatic refresh
of external dynamic lists (EDLs) did not update the URL or Domain
EDLs. |
PAN-112540 | Fixed an issue on a VM-Series firewall where
traffic stopped processing and resumed processing only after the
firewall was restarted. |
PAN-112428 | (Panorama™ running PAN-OS® 8.1.6 only)
Fixed an intermittent issue where autocommits failed and Panorama
stopped displaying device groups when managing a WildFire® appliance
running PAN-OS 8.1.5 or an earlier PAN-OS 8.1 release. |
PAN-112305 | Fixed an issue where source URLs (ObjectsExternal Dynamic Lists<EDL-name>Create
ListSource URL),
which contained double escape characters caused external dynamic
list entries to display incorrect values in the policies. |
PAN-112098 | Fixed an intermittent issue on a firewall
where outbound traffic failed with an error message: (proxy decrypt failure)
when configured with HTTP Header Insertion (ObjectsSecurity ProfilesURL Filtering<Filter-name>HTTP
Header Insertion). |
PAN-111866 | Fixed an issue where the push scope selection
on the Panorama web interface displayed incorrectly even though
the commit scope displayed as expected. This issue occurred when
one administrator made configuration changes to separate device
groups or templates that affected multiple firewalls and a different
administrator attempted to push those changes. |
PAN-111817 | Fixed an intermittent issue on Panorama
M-Series and virtual appliances where elastic search queries to
Cortex Data Lake did not display logs. |
PAN-111638 | Fixed an issue where the external dynamic
list did not update after a scheduled refresh of the list. |
PAN-111593 | (PA-3200 Series and PA-5200 Series firewalls
only) Fixed an issue where a firewall dropped generic routing
encapsulation (GRE) version 1 traffic. |
PAN-110526 | Fixed an issue where Captive Portal authentication
required two log-in attempts when the authentication sequence was
configured as an authentication profile. |
PAN-110341 | Fixed an issue where the firewall sent RIP
updates more frequently than expected. |
PAN-110293 | Fixed an issue where GTP-U traffic dropped
when the GTP tunnel endpoint ID (TEID) was not updated correctly
during a GTP-C update. |
PAN-110262 | Fixed an issue on VM-Series firewalls Dynamic
Address Groups did not display all the tags and labels for registered
IPs. |
PAN-109668 | A security related fix was made to limit
the amount of information returned from an API call error message. |
PAN-109506 | Fixed an issue where a process (useridd)
stopped responding when the firewall received excessive Security
Assertion Markup Language (SAML) requests received. |
PAN-109336 | (PA-500 and PA-800 Series firewalls
only) Fixed an issue where commits failed after you imported
a device state from Panorama the template configuration referenced
Bidirectional Forwarding Detection (BFD). |
PAN-109187 | Fixed an issue where an administrator with
a custom configuration role could not export reports. |
PAN-109096 | Fixed an issue where the firewall did not
remove the 4-Byte AS Format number when Remove Private
AS was enabled. |
PAN-109003 | Fixed an issue on Panorama M-Series and
virtual appliances where a process (configd) stopped
responding during a local commit. |
PAN-108990 | Fixed an intermittent issue on a firewall
where configuring Force Template Values (NetworkInterfacesCommitPush to DevicesTemplates) deleted the zone
assigned to an interface. |
PAN-108642 | Fixed an issue where P2MP OSPF static neighbor
did not display in the run-time neighbor table. |
PAN-108542 | Fixed an issue where the DHCP client interface
was configured with an incorrect subnet mask value instead of the
value provided by DHCP option 1. |
PAN-108374 | Fixed an issue on GlobalProtect™ where you
were unable to authenticate when the domain name included the ampersand
( & ) character. |
PAN-108123 | Fixed an issue where applications took longer
than expected to load when accessed through a Clientless VPN. |
PAN-107989 | Fixed an issue where the Strict IP Address
Check incorrectly triggered when you enabled ECMP (Network >Virtual RoutersAddRouter settingsECMP). |
PAN-107922 | Fixed an issue on a VM-Series firewall where
packet sizes more than 1,500 bytes caused the firewall to stop transmitting
and receiving packets. |
PAN-107848 | Fixed an issue where commits failed after
a BGP aggregate route configuration modification. |
PAN-107729 | Fixed an issue on a VM-Series firewall where
the PCI-PT interface did not receive VLAN tagged traffic after a
system boot up. |
PAN-107659 | (PA-5000 Series firewalls only)
Fixed an issue where extra byte (1 to 7) padding were appended to
the initial SYN and UDP packets, which caused the server to stop
responding. |
PAN-107636 | (Panorama M-Series and virtual appliances
only) Fixed a rare issue where the web interface did not display
new logs as expected because Elasticsearch (ES) stopped working
when the Raid drives reached maximum capacity and the purge script
to remove old ES indices failed to execute and make room for new
indices. However, this issue also resulted in creation of new ES
indices that were empty because the appliance could not read or
write to them. With this fix, old indices are purged as expected;
however, empty ES indices created before you upgraded to this release
with this fix are not removed as expected (see known issue PAN-114041). |
PAN-107607 | Fixed an issue where the test security-policy-match XML
API command returned invalid XML responses. |
PAN-107240 | Fixed an issue where you were unable to
retrieve the external dynamic list for URLs that included the ampersand
( & ) character in the URL string. |
PAN-107120 | Fixed an intermittent issue on a firewall
where the (all_pktproc) stopped responding and caused
the dataplane to restart. |
PAN-107006 | Fixed an issue where you were unable to
search for service objects by destination port numbers. |
PAN-106963 | Fixed an issue where the firewall did not
display the full URL information in the URL Filtering log (MonitorURL Filtering)
after a (“ ’\r’ “) return character. |
PAN-106922 | A security-related fix was made to address
a denial of service (DoS) vulnerability in PAN-OS SNMP (CVE-2018-18065
/ PAN-SA-2019-0007). |
PAN-106865 | Fixed an issue where DNS proxy memory leaks
occurred during the FQDN refresh process. |
PAN-106857 | Fixed an issue where the dataplane restarted
due to an internal path monitoring failure caused by large SSL decrypted
file transfer sessions. |
PAN-106724 | Fixed an intermittent issue on a firewall
where the log receiver leaked memory after 24 hours of runtime,
which caused the firewall to stop responding. |
PAN-106548 | Fixed an issue where MIB attributes caused
MIB compilation failures when using a third-party compiler. |
PAN-106426 | Fixed an issue where GlobalProtect did not
authenticate and displayed the following error message: search failed 32. |
PAN-106356 | Fixed an issue where you could not log in
to GlobalProtect from a mobile device when the mobile ID contained
a hyphen (-) character in the mobile
ID string. |
PAN-106274 | Fixed an issue on a firewall where a Layer
2 interface that contained a VLAN sub-interface in conjunction with
policy based forwarding (PBF) caused the firewall to forward the
return traffic to the incorrect web interface. |
PAN-105966 | A security-related fix was made to address
the Linux Kernel Local Privilege Escalation vulnerability (CVE-2018-14634
/ PAN-SA-2019-0006). |
PAN-105849 | A security-related fix was made to address
an issue with the wf_curl.log file
in WF-500 appliances (WildFire). |
PAN-105792 | Fixed an issue where NetFlow server profile
traffic did not route over IPSec tunnels when the service route
was configured to use the dataplane interface. |
PAN-105747 | Fixed an issue where correlated events forwarded
as email alerts displayed the incorrect date and time. |
PAN-105684 | Fixed an issue on a firewall in a high availability
(HA) active/passive configuration where OSPF and BGP running on
an Aggregate Ethernet (AE) interface with LACP enabled took longer
than expected to restart after a failover. |
PAN-104866 | Fixed an issue on a VM-Series firewall where
the dataplane interface continuously flapped when PCI passthrough was
enabled with DPDK. |
PAN-104738 | Fixed an intermittent issue where octet
values were incorrect for random flows in the NetFlow traffic. |
PAN-104466 | Fixed an issue on a VM-50 firewall where
an out-of-memory event caused the firewall to restart. |
PAN-104354 | Fixed an issue in an HA active/passive configuration
where the passive firewall ran a configuration out-of-sync after
a restart. |
PAN-104263 | Fixed an issue where the real-time clock
(RTC) battery voltage exceeded the maximum threshold value. |
PAN-104078 | Fixed an issue where BGP conditional advertisements
did not respond, the BGP conditional advertisements did not match
the suppress condition policy even when the prefix in the non-exist
filter condition matched. |
PAN-103857 | Fixed an issue in an HA active/passive configuration
where a suspended firewall processed traffic. |
PAN-103497 | Fixed an issue on PA-3200 Series firewalls
where an SNMP OID (sysObjectID) reported the incorrect
model (for example, PA-2020 instead of PA-3260). |
PAN-103285 | Fixed an issue where an API call (show system disk details),
responded with the following error message: An error occurred. See dagger.log for information. |
PAN-103225 | Fixed an issue on Panorama M-Series and
virtual appliances where the Task Manager did not display progress
after you pushed a configuration to a firewall. |
PAN-103140 | Fixed an issue where a newly deployed VM-Series
firewall in the VMware NSX environment did not display on the summary
web interface (PanoramaSummary)
after a partial commit. |
PAN-103023 | Fixed an intermittent issue where a job
type (content) caused a firewall configuration failure
and the firewall to stop responding. |
PAN-102745 | Fixed an intermittent issue on a firewall
where a commit and FQDN refresh took longer than expected. |
PAN-102526 | Fixed an issue on Panorama M-Series and
virtual appliances where disk quota edits failed and resulted in
the following error message: quota-settings -> disk-quota is invalid. |
PAN-101527 | Fixed an issue on a PA-5200 Series firewall
where enhanced small form-factor pluggable (SFP+) ports were unable
to detect link-fault events on the transmission side. |
PAN-101451 | Fixed an issue where SNMP queries displayed
incorrect values. |
PAN-101365 | Fixed an intermittent issue where the session
ID did not clear when the session ID was set to 0. |
PAN-101341 | Fixed an issue where administrators configured
with Device Group and Template Admin type
were unable to perform a global search and returned the following
message: Unauthorized request. |
PAN-101224 | Fixed an intermittent issue on VM-Series
firewalls in an AWS environment where packets were dropped due to
a longer than expected delay in transmission. |
PAN-101068 | Fixed an issue where the object identifier
(OID) ifAdminStatus incorrectly displayed "up"
when it was configured to be configured "down." |
PAN-100761 | A security-related fix was made to address
a development configuration file issue. |
PAN-100408 | Fixed an issue where the IPv6 flow label
was set to 0 when decryption was configured, which caused the firewall
to drop IPv6 traffic during the SSL handshake. |
PAN-98420 | Fixed an issue on Panorama M-Series and
virtual appliances where TCP port 28 was accessible on management
plane. |
PAN-98128 | Fixed an issue where SYN-ACK packets with
low time-to-live (TTL) values were sent, which caused a connection
failure. |
PAN-97385 | An enhancement was made to enable you to
monitor connections between a firewall and Cortex Data Lake on the
web interface. |
PAN-96344 | Fixed an issue on a firewall where TCP reset
packets were sent even after you set the vulnerability profile action
to drop the packets. |
PAN-96038 | (PA-200 <N/A in 9.0>, PA-220, and
PA-220R firewalls only) Fixed an issue with the Ethernet driver
that caused the firewall to reboot when experiencing heavy broadcast
traffic on the management interface. |
PAN-95034 | Fixed an issue where a firewall stopped
responding when a NAT Dynamic IP and Port (DIPP) was configured
as a NAT dynamic IP fallback. |
PAN-94342 | Fixed an issue where the GlobalProtect Gateway
host information profile (HIP) notification operation failed to
execute and returned the following message: GP-EX-GW-21 -> hip-notification - > win-fw-is-not-enable -> not-match-message -> message is invalid. |
PAN-84670 | Fixed an issue where firewalls that were
not configured to decrypt HTTPS services and applications traffic
allowed users without valid authentication timestamps to access
those resources regardless of Authentication Policy settings. To
prevent such access, either configure the firewall to decrypt traffic
or run the debug device-server cp-deny-encrypted on command
and execute the commit force CLI command
(this command will persist across reboots). |
PAN-82421 | Fixed an issue where the new connection
did not get established after you changed the IP address of a log
collector. |