PAN-OS 12.1.7-h5 Addressed Issues
Focus
Focus
Next-Generation Firewall

PAN-OS 12.1.7-h5 Addressed Issues

Table of Contents

PAN-OS 12.1.7-h5 Addressed Issues

Lists the addressed issues in PAN-OS 12.1.7-h5.
The following table lists the addressed issues in PAN-OS 12.1.7-h5.
Issue ID
Description
Fixes were made to address the following CVEs:
PAN-334722
Fixed an issue where the firewall introduced out-of-order packet delivery for certain data streams, which resulted in clients receiving data in an incorrect sequence.
PAN-329637
Fixed an issue where the push scope window did not display the target devices when attempting to push configurations from Panorama, which required manual selection of templates or device groups. With this fix, the push scope window now correctly populates with the intended push scope.
PAN-329359
Fixed an issue where the Panorama web interface showed blank Host Information Profile (HIP) Match log entries when opened in Detailed Log View. With this fix, the Detailed Log View now displays the expected information for HIP Match logs.
PAN-329180
Fixed an issue where Panorama did not automatically resume syslog forwarding over TCP after the syslog server became unavailable or was restarted.
PAN-327590
Fixed an issue where BFD sessions did not reestablish on the newly elected leader after a leader failover event that occurred when the previous leader node was suspended.
PAN-325903
Fixed an issue where, after upgrading Panorama, a custom admin role with Object Level Changes disabled did not automatically populate out-of-sync firewalls in the push scope.
PAN-325724
Fixed an issue where importing PKCS12 certificates failed with the error Import of certificate and private-key failed. Failed to extract certificate.
PAN-325613
(PA-7500 firewalls in HA cluster configurations only) Fixed an issue where interfaces intermittently remained offline after a cluster failover.
PAN-324652
Fixed an issue where selective configuration pushes from Panorama failed after an upgrade, which caused shared policy rules to go out of sync. With this fix, selective configuration pushes complete successfully and policies remain in sync.
PAN-323249
(M-700 appliances only) Fixed an issue where the Elasticsearch processes repeatedly restarted and log collectors showed the Elasticsearch health status as red.
PAN-322398
Fixed an issue where the firewall sent a BFD admin down message during an NGFW cluster failover, which caused BGP sessions to terminate and routes to be lost.
PAN-321699
Fixed an issue where device telemetry intermittently failed to send files, which resulted in critical alerts in system files.
PAN-319838
Fixed an issue where SFP ports did not establish a link with a third-party peer device when forced speed was configured on the firewall and the peer device was set to nonegotiate.
PAN-318120
Fixed an issue where SSL traffic was silently dropped when traffic was processed by a Security policy with an Anti-Spyware profile that had Inline cloud Analysis enabled for SSL C2 Detector with an action other than allow or alert.
PAN-318106
Fixed an issue where SCM did not update device telemetry for the firewall after upgrading to an affected release.
PAN-316721
Fixed an issue where multiple EDL fetches were queued and did not complete.
PAN-314776
Fixed an issue where the configd process stopped responding after pushing configuration changes from Panorama to the firewall.
PAN-314630
Fixed an issue where the firewall repeatedly rebooted and entered maintenance mode, and a factory reset was required.
PAN-312685
Fixed an issue where committing a scheduled configuration push on Panorama caused the configd process to stop responding unexpectedly.
PAN-309676
Fixed an issue on Panorama where a database component unexpectedly stopped when Panorama was deployed using an .ova file or upgraded/downgraded to an affected PAN-OS version. This occurred due to a required directory not being created during the initial provisioning workflow. With this fix, the necessary directory is created automatically during deployment.
PAN-308775
(Firewalls in active/passive configurations only) Fixed an issue where NTP status intermittently showed as rejected on the active firewall, which prevented the firewalls from synchronizing time.
PAN-308444
Fixed an issue where pushing multiple policy rules failed when the policy rules contained a large number of dynamic address object groups or user groups.