Known Issues in Enterprise DLP Plugin 4.0.0
Focus
Focus
Enterprise DLP

Known Issues in Enterprise DLP Plugin 4.0.0

Table of Contents

Known Issues in Enterprise DLP Plugin 4.0.0

Known issues inEnterprise Data Loss Prevention (E-DLP) plugin 4.0.0

PAN-206186

This is addressed in PAN-OS 11.1.0 and Enterprise DLP plugin 5.0.
On rare occasions, the firewall fails to forward file uploads to the Box and Gmail web applications to the DLP cloud service for inspection. When this occurs, the show counter global | match wif command to display the firewall ctd-agent scanner displays ctd_wif_file_dlp_excluded .

PLUG-18987

This issue is addressed in Enterprise DLP plugin 5.0.6.
On rare occasions, you are unable to reset theEnterprise DLP plugin from the Panorama™ management server CLI and receive the following error:
DLP reset failure: must be str, not NoneType

PLUG-18713

This issue is addressed in Enterprise DLP plugin 3.0.10 and 5.0.6.
On the Panorama™ management server, Enterprise DLP might fail to delete a data pattern (ObjectsDLPData Filtering Pattern).

PLUG-17207

This issue is addressed in Enterprise DLP plugin 4.0.5 and 5.0.5.
The Enterprise Data Loss Prevention (E-DLP) plugin causes the Panorama management server post-commit operation to get stuck at 99%.

PLUG-15192

This issue is addressed in Enterprise DLP plugin 3.0.10.
The Panorama™ management server might fail to synchronize some data profiles created on Strata Cloud Manager and displays the following error:
Cannot update profile on Enforcer. Version passed to Enforcer must be equal to or greater than the onboard version.

PLUG-14534

This is addressed in Enterprise DLP plugin 3.0.7, 4.0.3, and 5.0.5
On the Panorama management server, the Enterprise DLP plugin fails to complete post commit tasks and causes all commits (CommitCommit to Panorama) to get stuck at 99%.

PLUG-14201

This is addressed in Enterprise DLP plugin 3.0.7, 4.0.3, and 5.0.1.
The Panorama management server is unable to a generate report if a data filtering log (MonitorLogsData Filtering) with Report ID of 0 for a DLP incident. A DLP Incident has a Report ID of 0 if the DLP cloud service was unable to scan the file.

PLUG-13729

This is addressed in Enterprise DLP plugin 4.0.3 and 5.0.1.
The Panorama management server is unable to synchronize new data profiles (ObjectsDLPData Filtering Profiles) from the DLP cloud service.

PLUG-11742

This issue is addressed in PAN-OS 11.1.0, 11.0.2, and 10.2.5.
Downgrading from PAN-OS 11.0 to PAN-OS 10.0 using Skip Software Version Upgrade results in commit failures for managed firewalls leveraging Enterprise data loss prevention (DLP) after successful downgrade to PAN-OS 10.1.
Workaround: Manually downgrade to each PAN-OS version in your downgrade path to PAN-OS 10.1.
  1. Downgrade Panorama and managed firewalls from PAN-OS 11.0 to the preferred PAN-OS 10.2 release.
  2. Downgrade Panorama and managed firewalls from PAN-OS 10.2 to the preferred PAN-OS 10.1 release.

PLUG-11423

This is addressed in Enterprise DLP plugin 4.0.1.
On the Panorama management server, modifying a data filtering pattern (ObjectsDLPData Patterns) that was cloned from a predefined data filtering pattern fails with the error regexes.

PLUG-6145

On the Panorama management server, you cannot create an admin role (PanoramaAdmin Roles) to control access to Enterprise Data Loss Prevention (DLP) filtering settings and snippet configuration (DeviceSetupDLP).

PAN-144897

Enterprise Data Loss Prevention (DLP) data profile Thread ID/Name filter is not available when you configure a custom report (ManageManage Custom Reports) on the Panorama management server or locally on a firewall leveraging Enterprise DLP.

PAN-144897

Enterprise Data Loss Prevention (DLP) data profile Thread ID/Name filter is not available when you configure a custom report (ManageManage Custom Reports) on the Panorama management server or locally on a firewall leveraging Enterprise DLP.

DSS-17763

On the Panorama management server, custom data profiles (ObjectsDLPData Filtering Profiles) are not synchronized to the DLP cloud service if you have an active CASB-X license. This prevents you being able to associate the data profile with a Security policy rule and displays the error Data Profile does not exist.
Workaround: Contact Palo Alto Networks Support to restore synchronization functionality between the DLP cloud service and Panorama.