PAN-OS 12.1.10 Addressed Issues
Focus
Focus
Next-Generation Firewall

PAN-OS 12.1.10 Addressed Issues

Table of Contents

PAN-OS 12.1.10 Addressed Issues

Lists the addressed issues in PAN-OS 12.1.10.
The following table lists the addressed issues in PAN-OS 12.1.10.
Issue ID
Description
Fixes were made to address the following CVEs:
PAN-334722
Fixed an issue where the firewall introduced out-of-order packet delivery for certain data streams, which resulted in clients receiving data in an incorrect sequence.
PAN-332247
Fixed an issue where the proxy generated HTTP 503 errors for multiple URLs, which prevented users from connecting to servers. With this fix, the proxy now functions as expected.
PAN-331856
Fixed an issue where the firewall unexpectedly terminated the DNS proxy process when it received TCP/53 DNS queries on an interface configured for DNS proxy, which led to repeated firewall reboots and temporary unavailability of the web interface. With this fix, the firewall processes TCP/53 DNS queries without interruption.
PAN-330000
Fixed an issue where SNMPv3 communication would fail after an upgrade from PAN-OS 11.1 to PAN-OS 12.1.6 when using SHA-512 authentication and AES-256 privacy. With this fix, SNMPv3 communication functions as expected after the upgrade.
PAN-329809
Fixed an issue where testing an SCP server connection from the Panorama web interface returned an error instead of prompting to allow the host key, which prevented the successful establishment of the connection. With this fix, the system now correctly prompts to allow the host key.
PAN-329793
Fixed an issue where the characters in PDF Summary Reports did not display correctly when the Locale was set as Japanese, Korean, Simplified Chinese, or Traditional Chinese.
PAN-329637
Fixed an issue where the push scope window did not display the target devices when attempting to push configurations from Panorama, which required manual selection of templates or device groups. With this fix, the push scope window now correctly populates with the intended push scope.
PAN-329550
Fixed an issue where the firewall experienced unexpected process terminations, which resulted in an HA failover and led to the dataplane becoming unresponsive.
PAN-329407
Fixed an issue where the cellular interface did not come up and entered a Dead Zone state after an upgrade due to the management plane losing communication with the modem hardware. With this fix, the cellular interface came up by having an expected APN name based on the SIM card carrier.
PAN-329359
Fixed an issue where the Panorama web interface showed blank Host Information Profile (HIP) Match log entries when opened in Detailed Log View. With this fix, the Detailed Log View now displays the expected information for HIP Match logs.
PAN-328145
Fixed an issue where a firewall functioning as an Area Border Router did not correctly translate NSSA Type-7 LSAs to Type-5 LSAs when OSPF neighbors set the Nt bit in the NSSA Area, and routes were not advertised to upstream OSPF neighbors in the backbone area, which resulted in traffic being silently discarded.
PAN-325724
Fixed an issue where importing PKCS12 certificates failed with the error Import of certificate and private-key failed. Failed to extract certificate.
PAN-325151
Fixed an issue where a system log was not generated when the proxy reached its session limit.
PAN-324652
Fixed an issue where selective configuration pushes from Panorama failed after an upgrade, which caused shared policy rules to go out of sync. With this fix, selective configuration pushes complete successfully and policies remain in sync.
PAN-322398
Fixed an issue where the firewall sent a BFD admin down message during an NGFW cluster failover, which caused BGP sessions to terminate and routes to be lost.
PAN-320324
Fixed an issue where incorrect source region information appeared in GlobalProtect logs, which occurred because the location service lookup did not consistently return region information for public IP addresses. With this fix, accurate source region information is consistently displayed.
PAN-319352
Fixed an issue where the firewall rebooted unexpectedly without any configuration or power changes.
PAN-314826
Fixed an issue where the system failed to alert you when indices were created before their corresponding templates loaded, which could lead to unexpected data handling. With this fix, the system now proactively identifies and alerts you to these situations.
PAN-314825
Fixed an issue where GlobalProtect user authentication with certificates from a new Public Key Infrastructure (PKI) would not succeed when Certificate Revocation List (CRL) checking was enabled. This occurred because the firewall did not properly retrieve the CRL from the new PKI's Distribution Point URL. With this fix, the firewall now successfully retrieves CRLs, allowing GlobalProtect users to authenticate correctly with certificates from new PKIs.
PAN-314104
Fixed an issue where running BCM counter commands from the administrative shell did not consistently return output, and commands to modify queue sizes did not take effect.
PAN-313393
Fixed an issue where, after you configured a proxy server, External Dynamic Lists (EDL) and system software checks did not function concurrently. This occurred when you configured service routes for Palo Alto Networks services, which caused either EDL updates or system software checks to fail, depending on the specific service route configuration. With this fix, both EDL updates and system software checks correctly utilize the configured proxy server.
PAN-312157
Fixed an issue where, during a commit, the firewall intermittently stopped sending SNMP messages, which caused interface counters to stop updating for brief periods of time.
PAN-310627
Fixed an issue where Inline Cloud Analyzer (ICA) did not correctly apply custom URL categories configured as exceptions for traffic detection. With this fix, ICA correctly applies the configured custom URL category exceptions.
PAN-308812
Fixed an issue where firewalls using the Real-Time update setting for WildFire intermittently generated system alerts indicating a failure to connect to the WildFire real-time cloud. With this fix, these alerts are no longer generated.
PAN-307590
Fixed an issue where some FQDNs could not be resolved by the firewall. This occurred even when your configured Domain Name System (DNS) servers successfully returned valid IP addresses for the FQDNs. With this fix, the firewall correctly processes DNS responses and resolves FQDNs as expected.
PAN-286889
Fixed an issue where a website would intermittently fail to load in Mozilla Firefox after authentication when AURL inline cloud was active, which was caused by an interaction with the inline cloud analysis process. With this fix, websites now load consistently.
PAN-216054
Fixed an issue that caused the firewall fan speed to increase while it was idle.