Known Issues in Enterprise DLP Plugin 3.0.9
Focus
Focus
Enterprise DLP

Known Issues in Enterprise DLP Plugin 3.0.9

Table of Contents

Known Issues in Enterprise DLP Plugin 3.0.9

Known issues in Enterprise Data Loss Prevention (E-DLP) plugin 3.0.9.

PLUG-15645

This issue is addressed in Enterprise DLP plugin 4.0.4 and 5.0.2.
Enterprise Data Loss Prevention (E-DLP) continues to forward traffic to the DLP cloud service for inspection when even after a data profile (ObjectsDLPData Filtering Profiles) are removed from a Security policy rule (PoliciesSecurity).

PLUG-13729

This is addressed in Enterprise DLP plugin 4.0.3 and 5.0.1.
The Panorama management server is unable to synchronize new data profiles (ObjectsDLPData Filtering Profiles) from the DLP cloud service.

PLUG-11447

On the Panorama management server, data filtering profiles (ObjectsDLPData Filtering Profiles) with the .gzip file type specified do not display after you install the latest Apps & Threats dynamic update version (PanoramaDevice DeploymentsDynamic Updates). This results in commit failures if the data filtering profile is associated with a Security policy rule (PoliciesSecurity).
Workaround: If installing the latest Apps & Threats dynamic update is required, remove the impacted data filtering profiles from Security policy rules or modify the specified file types.

PLUG-11851

On the Panorama management server, an outdated default DLP block response page is displayed when traffic matches a data filtering profile with the Action set to Block when leveraging Enterprise DLP.

PLUG-6254

Firewalls leveraging Enterprise Data Loss Prevention (DLP) do not display the Enterprise DLP data filtering profiles (ObjectsDLPData Filtering Profiles) or Enterprise DLP Settings (DeviceSetupDLP), and cannot be overridden locally on the firewall.

PLUG-6145

On the Panorama management server, you cannot create an admin role (PanoramaAdmin Roles) to control access to Enterprise Data Loss Prevention (DLP) filtering settings and snippet configuration (DeviceSetupDLP).

PAN-144897

Enterprise Data Loss Prevention (DLP) data profile Thread ID/Name filter is not available when you configure a custom report (ManageManage Custom Reports) on the Panorama management server or locally on a firewall leveraging Enterprise DLP.

DSS-17763

On the Panorama management server, custom data profiles (ObjectsDLPData Filtering Profiles) are not synchronized to the DLP cloud service if you have an active CASB-X license. This prevents you being able to associate the data profile with a Security policy rule and displays the error Data Profile does not exist.
Workaround: Contact Palo Alto Networks Support to restore synchronization functionality between the DLP cloud service and Panorama.