Prisma Agent 26.4 Known Issues
Focus
Focus
Prisma Agent

Prisma Agent 26.4 Known Issues

Table of Contents

Prisma Agent 26.4 Known Issues

Review the known issues in Prisma Agent 26.4.
Prisma Agent version 26.4 has the following known issues.

Prisma Agent 26.4 (Linux) Known Issues

Issue IDDescription
PANG-15306
DNS-over-TCP to any upstream server is not exempt from fail-safe enforcement when the tunnel is down. This can occur regardless of whether IPv4 or IPv6 DNS servers are configured, whenever the system resolver uses TCP, such as when a UDP DNS response is truncated or TCP is otherwise required.
Workaround: Configure the system resolver to prefer IPv4 DNS servers.
PANG-15265
On Linux endpoints, container-to-container traffic on Podman networks and Docker bridge networks with names that do not start with br-, docker, or virbr is tunneled through Prisma Agent instead of bypassed as local LAN traffic. This includes Podman's default bridge network and any custom-named bridge network.
PANG-15263
On Linux endpoints, containers that were running while the tunnel was connected may experience a 5-second delay on DNS lookups after the Prisma Agent service is restarted while disconnected. DNS resolution returns to normal after the agent reconnects and disconnects again normally.
PANG-15262
On Linux endpoints, two issues occur when switching between network interfaces. When you disconnect from a wired network while Wi-Fi is also connected, the agent may remain in "Connected internally" status even though the internal network is no longer reachable. When you connect to a wired network from Wi-Fi, the user location is not re-detected and forwarding profile rules scoped to that location are not applied.
Workaround: Run pacli traffic user-location refresh or manually reconnect to re-detect user location.
PANG-15254
On Linux endpoints, after you disconnect from a Prisma Access gateway behind a Network Load Balancer (NLB), the gateway may continue to show you as connected. The logout request times out because it is sent to an internal tunnel address that is no longer reachable after the tunnel closes.
PANG-15246
On Linux endpoints, if your sign-in to the endpoint management portal falls back to SAML authentication after a certificate attempt, subsequent gateway connections skip the PKCS#11 PIN prompt and send no client certificate. Gateways that require a client certificate reject the connection. This behavior persists across service restarts until you sign out and sign back in.
PANG-15244
On Linux endpoints, when the authentication mode requires a client certificate with SAML fallback and no certificate is present, clicking the session expiry banner to re-authenticate displays a "Certificate validation failed" error instead of opening the SAML browser flow. Re-authentication cannot be completed from the session expiry banner.
Workaround: Sign out and sign back in to re-authenticate.
PANG-15238
On Fedora and RHEL Linux endpoints on private IP networks, connecting in "Best Gateway Available" mode may immediately fail and return a Disconnected state. Connecting to a specific gateway by name succeeds.
Workaround: Connect to a specific gateway by name instead of using Best Available.
PANG-15231
On KDE desktops, session timeout notifications may remain visible in the notification center after you sign out. Additionally, "Unable to Connect" error notifications accumulate as separate entries in the notification center rather than replacing each other, requiring you to dismiss each one individually.
PANG-15166
On KDE desktops, when MFA is required to access a protected resource, clicking OK in the MFA dialog closes the dialog but does not automatically bring a browser window to the foreground.
Workaround: If a browser window is already open, switch to it to complete MFA. If no browser is open, it launches automatically.
PANG-15148
On Linux endpoints, the active gateway tunnel may disconnect and reconnect repeatedly during normal use, even when the network connection is working. The agent incorrectly interprets a single transient network check failure as a full loss of connectivity and tears down the tunnel unnecessarily.
PANG-15130
On Linux endpoints, when a forwarding profile uses user-location rules, the first connection opened immediately after the agent detects the user location may be routed to the wrong destination. Subsequent connections to the same destination are routed correctly.
PANG-15102
On Linux endpoints, upgrading from Prisma Agent 26.3 to 26.4.0.35 while the tunnel is connected may leave network routing and DNS configuration in an inconsistent state. After the upgrade, DNS resolution may stop working. The agent interface may also become unresponsive during the upgrade process.
Workaround: Restart the system after upgrading to restore network connectivity and DNS resolution.
PANG-15088
On Linux endpoints, if the system was connected to an internal network before entering sleep mode for more than 30 minutes, the agent does not reconnect automatically after the system wakes and moves to an external network.
Workaround: Manually reconnect by clicking Connect in the Prisma Agent interface or running pacli connect.
PANG-15077
On Linux endpoints, when a PKCS#11 or TPM client certificate with a PIN is used for authentication, the agent cannot reconnect automatically after a reboot or service restart. You must enter the certificate PIN each time the system restarts.
PANG-15070
On Linux endpoints, if you change the system color scheme between dark and light mode while an MFA authentication dialog is open, the dialog retains its original colors and does not update to match the new theme.
PANG-15069
On Linux endpoints, running sudo pacli switchto PAA to switch from GlobalProtect to Prisma Agent always returns an error and leaves both agents disabled. The endpoint has no active tunnel until you manually re-enable Prisma Agent.
PANG-15041
On Linux endpoints, TPM2 PKCS#11 tokens created using tpm2_ptool without specifying a custom path are stored in the user's personal directory and are not visible to Prisma Agent. The agent service runs as root and reads the system-wide token store at /etc/tpm2_pkcs11 instead.
Workaround: Create TPM2 tokens in the system-wide store as root, or set the tpm_store_path configuration value to point to your token store location:
sudo tpm2_ptool init --path /etc/tpm2_pkcs11
PANG-15021
On RHEL 9.8 x86_64 endpoints, the Prisma Agent interface does not support dark mode.
PANG-14994
On Linux endpoints, when you authenticate using a client certificate, the session expiry notification banner is not displayed before your session times out. The session expires without warning and you are disconnected.
PANG-14966
On Linux endpoints, if you initially authenticated using SAML and later added client certificates to the system certificate store, clicking the session expiry banner to re-authenticate fails with a certificate error. The session expiry banner is disabled after the failure and cannot be used to retry authentication.
Workaround: Sign out and sign back in to re-authenticate with your client certificate.
PANG-14957
On Linux endpoints connecting to on-premises GlobalProtect gateways running PAN-OS 12.1.x, the tunnel may disconnect approximately every 60 seconds with a "Login failed: invalid gateway auth token" error. The agent reconnects automatically but disconnects again at the same interval.
PANG-14954
On Linux endpoints, the first connection attempt after restarting the Prisma Agent service may return to a disconnected state with no error message displayed due to a stale cached token. A second connection attempt completes successfully.
Workaround: Click Connect or Log In a second time to complete the connection.
PANG-14581
On Linux endpoints, the first connection attempt to an IPv6 address using a literal IP address fails immediately when the tunnel is disconnected or when the address is covered by a Direct forwarding rule. Subsequent connection attempts to the same address succeed. Connections to hostnames are not affected. Applications that retry automatically, such as browsers, are not affected; command-line tools and scripts that dial IPv6 literal addresses directly without retrying will encounter the failure.
PANG-14518
On Linux endpoints, rapidly switching between gateways may briefly put the agent in a Disconnected state before it reconnects to the selected gateway. The agent recovers automatically.