PAN-OS 8.1.5 Addressed Issues
PAN-OS® 8.1.5 addressed issues
Fixed an issue where WF-500 appliances displayed the wrong WildFire® content version
show system infoafter a WildFire content update.
Fixed an issue where after upgrading from PAN-OS® 8.1.3 to 8.1.4 the CLI two-factor administrator authentication failed.
Fixed an issue where firewalls failed to establish IKE phase 1 or phase 2 when you specified Diffie-Hellman (DH)
Fixed an issue on Panorama™ M-Series and virtual appliances where after you make a change to a template and attempt to push to a target device, the device does not appear in the Push Scope Selection list (
Push to Devices
Fixed an issue on PA-3200 Series firewalls where packets dropped when a VSS-Monitoring Ethernet trailer was being appended by an external device.
Fixed an issue where PA-800 Series firewalls intermittently restarted due to a kernel error.
Fixed an issue on a PA-3200 Series firewall where the dataplane failed due to an internal path monitoring failure.
Fixed an issue where hardware packet buffers gradually depleted when LLDP packets created locally were sent to a down interface within an Aggregate Ethernet (AE) interface.
Fixed an intermittent issue where newly created IPSec Tunnels (
) did not activate.
Fixed an issue on PA-800 Series firewalls where a kernel memory spike caused the firewall to restart.
Fixed an intermittent issue on Panorama M-Series and virtual appliances where an address object referenced in the address group was allowed to be deleted without a reference error which caused commits to fail.
Fixed an issue with Panorama where administrators were unable to use the web interface to acquire a commit or configuration lock for device groups.
Fixed an issue on Panorama M-Series and virtual appliances where the Dynamic Address Group lists did not display and displayed the following error message:
Command failed with no output.
Fixed an intermittent issue where the dataplane restarted while processing SMTP traffic.
Fixed an issue on Panorama managed devices where the green Template Values Exist indicator incorrectly displayed after you closed any interface settings (
) even when you did not make any changes.
Fixed an issue where the HTTP header insertion entries caused the dataplane to restart.
Fixed an issue on Panorama management server when using Microsoft Azure or Amazon AWS where the management interface settings (
) is disabled.
Fixed an issue where a GTP PDP update did not update the GTP-U session which caused subsequent GTP traffic to drop.
Fixed an intermittent issue where the
replace deviceCLI command caused the configuration lock to stop responding.
Fixed and issue where the template stack retains the dynamic update schedule information after you remove it.
Fixed an issue where a firewall blocked SMTP traffic when processing ZIP files due to too many packet-process loops.
Fixed an issue where the LDAP Service Route Configuration (
) did not respond when
Service Route Configuration
Customizewas selected and
non-management interfaceswere enabled.
A security-related fix was made to address the FragmentSmack vulnerability (CVE-2018-5391 / PAN-SA-2018-0012).
Fixed an issue where SSL enabled applications accessed through a GlobalProtect™ Clientless VPN caused buffer leaks.
PA-5250, PA-5260, “PA-5280-8.1-only”, PA-5000 Series, and PA-7000 Series firewalls only) Fixed an intermittent issue where GlobalProtect SSL sessions that were enforcing client certificate authentication failed to resume and caused an authentication failure.
Fixed an issue on Panorama virtual appliances in a high availability (HA) configuration where the elastic search script failed to identify the master node due to case sensitivity in the serial number that caused log-replication failures when you enabled log redundancy.
Fixed an issue where installing path monitoring for static route on a satellite in a Large Scale VPN (LSVPN) infrastructure failed.
Fixed an issue where the Panorama Controller did not display all
commit-alljobs for Panorama Nodes (
) and the Panorama Controller did not push those missing jobs during a Push to Devices action when the associated Panorama Node was running a PAN-OS 8.1 release.
Fixed an issue where the firewall did not correctly process OSPF link-state updates which caused the firewall to send incorrect updates externally, which resulted in ARP broadcasts that contained incorrect source MAC and source IP addresses.
The following PA-7000 Series NPCs only: PA-7000-20G-NPC, PA-7000-20GQ-NPC, PA-7000-20GXM-NPC, PA-7000-20GQXM-NPC) Fixed an issue where an egress buffer overflow that impacted internal packet path monitoring caused a high availability (HA) failover. Additionally, enhancements were made to flow control communication between the traffic manager and flow engine components to improve system stability during periods of heavy traffic.
Fixed an issue where the EDL and FQDN address objects in the security and NAT policies displayed 0.0.0.0, which caused traffic to fail to match the policy.
Fixed an issue on Panorama M-Series and virtual appliances where after you configured the Authentication fields (
) for the GlobalProtect gateway template stack, the saved configuration did not get applied.
Fixed an issue where after a redistribution profile was added, the OSPF configured with an authentication profile flapped.
Fixed an issue with firewalls in a high availability (HA) active/passive configuration where the firewall processed traffic in a suspended state.
Fixed an issue where SNMP polling displayed incorrect values, which caused authentication failures each time you restarted the firewall.
Fixed an intermittent issue where SSL decryption caused Content-ID™ to block files received over SMTP.
Fixed an issue where User Principal Names (UPN) which begin with the "at" ( @ ) character caused User-ID™ to fail.
Fixed an intermittent issue where a commit error occurred when an Aggregate Ethernet (AE) sub-interface was configured as the destination interface in a QoS policy rule.
Fixed an issue where Dynamic Updates pushed from Panorama to the Firewall displayed an incorrect
Fixed an issue on a PA-5200 Series firewall in a high availability (HA) active/active configuration with a virtual wire (vwire) subinterface where session setup packets sent to peer firewalls were sent back as HA2/HA3 race conditions, which caused an increase in packet descriptors and traffic to stop responding.
Fixed an issue where exporting a device state (
) from Panorama failed to import to the firewall.
Fixed an issue where a scheduled external dynamic list refresh displayed incorrect update values.
VM-Series firewalls in a high availability (HA) configuration only) Fixed an issue when the management interface used DHCP Client-IP assignment where the automatic commits failed after multiple PAN-OS upgrade and downgrade cycles.
Fixed an issue on Panorama M-Series and virtual appliances in a high availability (HA) active/passive configuration where the passive firewall failed to connect to a newly deployed firewall with the following error message:
vm-cfg: failed to process registration from svm device. vm-state: active.
Fixed an intermittent issue on a firewall where Dead Peer Detection (DPD) (
) was enabled and failed during IKE negotiations.
Fixed and issue on a firewall where a Device Group was selected, the App Scope Network Monitor report (
) failed to display data.
App Scope >
Fixed an issue where a failed commit or commit validation followed by a non-user-committed event (such as an FQDN refresh, an external dynamic list refresh, or an antivirus update) resulted in an unexpected change to the configuration that caused the firewall to drop traffic.
Fixed an issue where obsolete IPv6 host entries were not purged and remained in a
REACHABLEstate, which caused new entries to fail.
Fixed an intermittent issue on a PA-7000 Series firewall where auto-commits prematurely executed before all Network Processing Cards (NPCs) were detected and ready.
Fixed an issue on PA-7000 Series firewalls in a high availability (HA) active/active configuration where after a HA failover event the IP address rule list continuously duplicated entries and resulted in slow response times from the firewall and, eventually, caused the Network Processing Cards (NPCs) to restart.
Fixed an issue on Panorama M-Series and virtual appliances where Push Scope Selection (
) selected firewalls not in the hierarchy of the firewall you selected.
Push to Devices
Fixed an issue where Commit and Push (
) failed and displayed the following validation error:
Commit and Push
log-settings profiles match-list send-email is not a valid referencewhen you attempted to import a firewall configuration to Panorama.
Fixed an issue where SNMP Object identifier queries for
hrStorageAllocationUnitsreturned negative values.
Fixed an issue where SaaS application usage reports were empty when you used special characters in naming zones.
Fixed an issue on a PA-7000 Series firewall where the Network Processing Card (NPC) rebooted due to a memory allocation issue.
Fixed an issue where a change in user-mapping information prevented the host information profile (HIP) from updating.
Fixed an issue where a firewall in a high availability (HA) active/passive configuration did not send the Bidirectional Forwarding Detection (BFD)
administrator downstatus after a manual failover.
Fixed an issue where the destination NAT (DNAT) using a dynamic IP address caused the dataplane to fail.
PA-5250, PA-5260, and PA-5280 firewalls only) Fixed an issue where, when you deployed the firewall in a network that uses Dynamic IP and Port (DIPP) NAT translation with PPTP, client systems were limited to using a translated IP address-and-port pair for only one connection.
Fixed an issue in a high availability (HA) active/passive configuration where the hardware offload feature attempted to reinstall IPSec sessions for individual packets, which caused additional dataplane CPU loads on both the active and passive firewalls.
Fixed an issue on Panorama M-Series and virtual appliances where a qualifier configured for a custom application signature displayed the following error message:
Fixed an issue where the Captive Portal configured with RADIUS authentication failed when a username contained the "at" ( @ ) character.
Fixed an issue where firewalls did not purge files automatically as expected, which caused WildFire updates to fail.
Fixed an intermittent issue on Panorama M-Series and virtual appliances where GlobalProtect Gateway Configuration (
) responded with the following message:
Fixed an issue where the firewall dropped IPv6 ping packets, which caused high availability (HA) path monitoring to fail.
Fixed an issue on a firewall configured with RADIUS where the default timeout setting failed after an administrator entered credentials through the web interface.
Fixed an issue where the firewall incorrectly forwarded packets to upstream devices when it had no ARP entry for the destination IP address, which resulted in traffic outages caused by source MAC addresses that did not get updated as expected.
Fixed an issue on a PA-5000 Series firewall where SNMP values for received and transmitted bytes for Aggregate Ethernet (AE) subinterfaces returned incorrect values.
Fixed an issue on Panorama M-Series and virtual appliances in a high availability (HA) active/passive configuration where after you delete a plugin from both firewalls the configuration synchronization failed.
PAN-OS 8.0.8 and later releases only) Fixed an issue where administrator setting did not change when appropriate after you imported a configuration.
Fixed an issue where you could not set the Captive Portal session timeout (
) to 60 seconds or longer without causing a browser redirect.
Fixed an issue on Panorama management server in a high availability (HA) active/passive configuration where a Commit (
) caused the firewalls to restart.
Commit to Panorama
Fixed an issue Panorama M-Series and virtual appliances with the characteristic
) enabled caused all Device Groups entries not to display.
Fixed an issue where the firewall took longer than expected to update a URL category.
Fixed an issue on a PA-5000 Series firewall in a QoS configuration where the setting did not re-apply after the dataplane restarted.
A security-related fix was made to the way the Linux kernel handles exceptions associated with MOV to SS and POP to SS instructions (CVE-2018-8897).
Fixed an issue where license keys with special characters caused rebooting to fail.
A security-related fix was made to prevent modification of attributes in a SAML Response packet.
Fixed an issue where the command
delete report custom scope shared report-namedid not delete the files in the directory and displayed the following error message:
Server error : unable to remove directory for.
Fixed an intermittent issue where the firewall did not rotate error logs correctly, which caused disk space issues.
Fixed an issue where the static route was not reinstalled if you modified the path-monitoring hold time while the timer was active.
Fixed an issue on Panorama M-Series and virtual appliances where one template is selected to display a list of templates displayed.
Fixed an issue on VM-Series firewalls where the bootstrap in GCP failed when a software image was provided, which caused GCP to time out before media availability was provided.
Fixed an issue where administrators with predefined roles and permission to save configuration changes were not able to save their changes.
Fixed an intermittent issue on a PA-7000 Series firewall where the GlobalProtect LSVPN tunnel monitoring failed during re-key, which caused satellites to disconnect.
Fixed an issue where a firewall did not apply the configured NAT policy during a predicted RTSP session.
Fixed an issue where Commits failed when custom role-based administrators made changes to Managed Collectors (
Fixed an intermittent issue on a VM-Series firewall in a VMware NSX environment where the firewall stopped passing traffic.
Fixed an issue where administrators with Device Group and Template access were not able to modify the QoS interface (
Fixed an issue on a Panorama M-Series and virtual appliances where firewalls redeployed to a NSX environment, the Device State (
) displayed a
Deactivatedstatus due to the firewalls being deployed with previously assigned authorization codes.
Firewall gets the same serial number after getting redeployed in NSX environment where Panorama still think that newly deployed firewalls are de-activated because of it has a serial number used in the past.
Fixed an issue where a memory leak caused an out-of-memory (OOM) error.
Fixed an intermittent issue where VPN tunnels terminated due to IKE manager failures.
Fixed an intermittent issue where the threat log displayed unrelated URLs in the file name column.
Fixed an issue where the
show running ippoolcommand stopped responding due to a conflict with packet processing and caused the Aggregate Ethernet (AE) interface to flap.
A security-related fix was made to SAML authentication.
Recommended For You
Recommended videos not found.