Known Issues in SD-WAN Plugin 3.5
Focus
Focus
SD-WAN

Known Issues in SD-WAN Plugin 3.5

Table of Contents

Known Issues in SD-WAN Plugin 3.5

Known issues in SD-WAN 3.5.
The following list includes all known issues that impact an SD-WAN 3.5 release. This list includes both outstanding issues and issues that are addressed, as well as known issues that apply more generally or that are not identified by a specific issue ID. Refer to PAN-OS Release Notes for additional known issues affecting SD-WAN Plugin 3.5.

PAN-327372

Description of PAN-327372.
When you change the maximum or minimum bandwidth values for an interface or tunnel in an SD-WAN interface profile, Panorama does not generate a configuration diff for the change. As a result, pushing the configuration from Panorama does not update the bandwidth settings on the firewall.
Workaround: After saving the bandwidth change, toggle (enable, then disable, or disable, then enable) the error correction profile and push the configuration from Panorama to the firewall.

PAN-326579

Description of PAN-326579.
Fixed an issue where a segmentation fault in SD-WAN path monitoring policy connection map processing caused repeated dataplane crashes, exhausting restart attempts and triggering an unexpected system reboot. On High Availability Active/Passive deployments, this resulted in an HA failover and a brief disruption to production traffic.
This issue is addressed in SD-WAN plugin 3.5.0.
- PAN-OS 12.2.2 or later versions

PAN-325076

Description of PAN-325076.
Fixed an issue where, on High Availability Active/Passive deployments, the SD-WAN plugin incorrectly interpreted an HA failover event as a topology change and triggered an unnecessary commit that tore down and recreated VPN tunnel interfaces while sessions were still active. In PAN-OS 11.1.14, active sessions referencing the deleted interfaces triggered a segmentation fault in the dataplane fast path, causing repeated firewall reboots and further HA failovers.
This issue is addressed in SD-WAN plugin 3.5.0.
- PAN-OS 12.2.2 or later versions

PAN-321937

Description of PAN-321937.
Fixed an issue where an expired SD-WAN license caused SD-WAN tunnels to become unavailable, which resulted in traffic interruptions. With this fix, the device provides logs and commit messages about expired licenses.
This issue is addressed in SD-WAN plugin 3.5.0.
- PAN-OS 12.2.2 or later versions

PAN-317583

Description of PAN-317583.
Fixed an issue with intermittent ICMP ping drops and packet loss in traffic flows between a hub and branch after upgrading to an affected PAN-OS release due to incorrect SD-WAN path monitor state.
This issue is addressed in SD-WAN plugin 3.4.3 and 3.5.0.
- PAN-OS 12.1.8 or later versions
- PAN-OS 12.2.2 or later versions

PAN-315958

Description of PAN-315958.
Fixed an issue where the SaaS Quality Profile HTTP/HTTPS monitoring feature failed to send probes due to the firewall being unable to determine the correct egress interface and source IP address for the monitoring probes.
This issue is addressed in SD-WAN plugin 3.4.3 and 3.5.0.
- PAN-OS 12.1.8 or later versions
- PAN-OS 12.2.2 or later versions

PAN-315912

Description of PAN-315912.
Fixed an issue where the Maximum Segment Size (MSS) rewrite functionality for packets ingressing through SD-WAN interfaces on firewalls was not optimized.
This issue is addressed in SD-WAN plugin 3.5.0.
- PAN-OS 12.2.2 or later versions

PAN-314818

Description of PAN-314818.
Fixed an issue where the firewall dropped IPv6 packets after enabling Strict IP Check under Zone Protection in an SD-WAN configuration.
This issue is addressed in SD-WAN plugin 3.4.3 and 3.5.0.
- PAN-OS 12.1.8 or later versions
- PAN-OS 12.2.2 or later versions

PAN-314147

Description of PAN-314147.
Fixed an issue where SSL traffic was dropped on SD-WAN DIA interfaces with member having different MTU.
This issue is addressed in SD-WAN plugin 3.4.3 and 3.5.0.
- PAN-OS 12.1.8 or later versions
- PAN-OS 12.2.2 or later versions

PAN-312156

Description of PAN-312156.
Fixed an issue where firewalls did not correctly apply SD-WAN policy rules, which caused traffic to be incorrectly routed via local breakout instead of VPN backhaul.
This issue is addressed in SD-WAN plugin 3.4.3 and 3.5.0.
- PAN-OS 12.1.8 or later versions
- PAN-OS 12.2.2 or later versions

PAN-308564

Description of PAN-308564.
Fixed an issue where packets were dropped on SD-WAN interfaces when a proxy was enabled due to an MTU inconsistency where the firewall failed to rewrite the maximum segment size in SYN/ACK packets based on the SD-WAN virtual interface MTU.
This fix does not apply when the traffic egress interface is SD-WAN Direct Internet Access (DIA) interface and proxy is enabled.
This issue is addressed in SD-WAN plugin 3.5.0.
- PAN-OS 12.2.2 or later versions

PAN-306794

Description of PAN-306794.
Fixed an issue where SD-WAN did not generate system logs with timestamps and reasons for degradation of Direct Internet Access paths.
This issue is addressed in SD-WAN plugin 3.5.0.
- PAN-OS 12.2.2 or later versions

PAN-305411

Description of PAN-305411.
Fixed an issue where, after creating a logical interface with an assigned IP address and adding it to a virtual router, the connected route for the interface did not appear in the `show routing route` CLI command output. This occurred even when the interface was up and learning ARP entries.
This issue is addressed in SD-WAN plugin 3.5.0.
- PAN-OS 12.2.2 or later versions

PAN-300216

Description of PAN-300216.
Fixed an issue where, when SD-WAN Direct Internet Access was configured and traffic traversed the cellular interface without a NAT policy rule, intermittent cellular modem connectivity issues occurred, which caused the firewall to disconnect and reconnect to the cellular network.
To use this fix, run the CLI command set session teardown-upon-fwd-zonechange yes.
This issue is addressed in SD-WAN plugin 3.5.0.
- PAN-OS 12.2.2 or later versions

PAN-296195

Description of PAN-296195.
Fixed an issue where, in an SD-WAN Branch Multi-VR environment, ping traffic initiated from the firewall's internal interface resulted in improper zone mapping during session setup, which resulted in the firewall being unable to reach the internet. This occurred due to the ingress zone being incorrectly used as the egress zone.
This issue is addressed in SD-WAN plugin 3.5.0.
- PAN-OS 12.2.2 or later versions

PAN-295484

Description of PAN-295484.
Fixed an issue where SD-WAN did not generate system logs with timestamps and reasons for degradation of Direct Internet Access paths.
This issue is addressed in SD-WAN plugin 3.5.0.
- PAN-OS 12.2.2 or later versions

PAN-294379

Description of PAN-294379.
Fixed an issue where, when SD-WAN SaaS Application path monitoring failed for all interfaces, the firewall stopped forwarding traffic even if the ISP links and default gateway probing were still active.
This issue is addressed in SD-WAN plugin 3.5.0.
- PAN-OS 12.2.2 or later versions

PLUG-21340

Description of PLUG-21340.
Panorama now includes a preventative fix to ensure tunnel IP addresses remain synchronized. As part of this fix, the following CLI command is deprecated: debug plugins sd_wan drop-config-cache.
Workaround
To resolve the synchronization issue, first perform a configuration push to the affected Branch node to generate the new tunnel monitor IP address. Once the push is complete, identify the new tunnel monitor IP address and manually enter it into the BGP Peer IP field for the corresponding peer in the Panorama Cloud Services plugin. Finally, perform a configuration push to the Remote Network (RN) to align the settings and restore connectivity.
This issue is addressed in SD-WAN plugin 3.0.9-h1, 3.4.2, 3.3.4 and 3.5.0.
- PAN-OS 12.2.2 or later versions