: Known Issues in Enterprise DLP Plugin 4.0.0
Focus
Focus

Known Issues in Enterprise DLP Plugin 4.0.0

Table of Contents

Known Issues in Enterprise DLP Plugin 4.0.0

Known issues in Enterprise DLP Plugin 4.0.0

PAN-206186

On rare occasions, the firewall fails to forward file uploads to the Box and Gmail web applications to the DLP cloud service for inspection. When this occurs, the
show counter global | match wif
command to display the firewall ctd-agent scanner displays
ctd_wif_file_dlp_excluded
.

PLUG-14534

This is addressed in Enterprise DLP plugin 4.0.3 and 3.0.7.
On the Panorama management server, the Enterprise DLP plugin fails to complete post commit tasks and causes all commits (
Commit
Commit to Panorama
) to get stuck at 99%.

PLUG-14201

This is addressed in Enterprise DLP plugin 3.0.7, 4.0.3, and 5.0.1.
The Panorama management server is unable to a generate report if a data filtering log (
Monitor
Logs
Data Filtering
) with Report ID of
0
for a DLP incident. A DLP Incident has a Report ID of
0
if the DLP cloud service was unable to scan the file.

PLUG-13729

This is addressed in Enterprise DLP plugin 4.0.3 and 5.0.1.
The Panorama management server is unable to synchronize new data profiles (
Objects
DLP
Data Filtering Profiles
) from the DLP cloud service.

PLUG-13111

This issue is addressed in Enterprise DLP 3.0.6.
On the Panorama management server, the list of predefined URL categories are not displayed for a data profile configured for non-file inspection (
Objects
DLP
Data Filtering Profiles
<select a data profile>
URL Category List Excluded From
).

PLUG-11851

On the Panorama management server, an outdated default DLP block response page is displayed when traffic matches a data filtering profile with the Action set to
Block
when leveraging Enterprise DLP.

PLUG-11750

After you upgrade the Panorama management server and managed firewalls leveraging Enterprise DLP from PAN-OS 10.1.7 to PAN-OS 11.0, data filtering logs (
Monitor
Logs
Data Filtering
) display
DLP Skipped; possible config er
as the Reason for Action despite the firewall taking the correct action for matched traffic.

PLUG-11742

This issue is addressed in PAN-OS 11.1.0, 11.0.2, and 10.2.5.
Downgrading from PAN-OS 11.0 to PAN-OS 10.0 using Skip Software Version Upgrade results in commit failures for managed firewalls leveraging Enterprise data loss prevention (DLP) after successful downgrade to PAN-OS 10.1.
Workaround:
Manually downgrade to each PAN-OS version in your downgrade path to PAN-OS 10.1.
  1. Downgrade Panorama and managed firewalls from PAN-OS 11.0 to the preferred PAN-OS 10.2 release.
  2. Downgrade Panorama and managed firewalls from PAN-OS 10.2 to the preferred PAN-OS 10.1 release.

PLUG-11423

On the Panorama management server, modifying a data filtering pattern (
Objects
DLP
Data Patterns
) that was cloned from a predefined data filtering pattern fails with the error
regexes
.

PLUG-6145

On the Panorama management server, you cannot create an admin role (
Panorama
Admin Roles
) to control access to Enterprise Data Loss Prevention (DLP) filtering settings and snippet configuration (
Device
Setup
DLP
).

PAN-144897

Enterprise Data Loss Prevention (DLP) data profile
Thread ID/Name
filter is not available when you configure a custom report (
Manage
Manage Custom Reports
) on the Panorama management server or locally on a firewall leveraging Enterprise DLP.

Recommended For You