Prisma Access
Prisma Access Addressed Issues
Table of Contents
Expand All
|
Collapse All
Prisma Access Docs
-
- 6.1 Preferred and Innovation
- 6.0 Preferred and Innovation
- 5.2 Preferred and Innovation
- 5.1 Preferred and Innovation
- 5.0 Preferred and Innovation
- 4.2 Preferred
- 4.1 Preferred
- 4.0 Preferred
- 3.2 Preferred and Innovation
-
-
- 4.0 & Later
- Prisma Access China
-
-
Prisma Access Addressed Issues
Lists the known issues in Prisma Access6.1.0.
The following table lists the issues addressed in Prisma Access 6.1.0.
Addressed Issues in Prisma Access 6.1.1
|
Issue ID
|
Description
|
|---|---|
| CYR-62527 | Fixed an issue where syslog config filters out NAT tunnel alerts to be sent out to Strata Logging Service. |
| CYR-62135 | Fixed an issue where, in a multitenant Panorama managed Prisma Access deployment, internal host detection could not be configured by device group and template admin users. |
| CYR-60959 | Fixed an issue where, when enabling Private Application Access in Explicit Proxy and ZTNA Connector is also configured, an error message displayed that there was not a service connection deployed. |
| CYR-59967 | Fixed an issue where, for RN-HP sites in OCI regions, maximum bandwidth per tunnel supported is 2Gbps because of OCI limiting per-flow traffic from their side. |
| CYR-58965 | Fixed an issue where Panorama did not send the onboarding commit job to the back end when onboarding Service Connections, requiring a secondary push to properly trigger the commit job for Service Connections. |
| CYR-54776 | Fixed an issue where BGP filtering was enabled on a Panorama in a multi-tenant deployment that had no supertenant. BGP filtering is not supported on a Panorama in a multi-tenant deployment that has no supertenant. |
| CYR-55477 | Fixed an issue where, when using a site-based license, the allocated and available bandwidth for remote networks was incorrectly shown as 0 in the Panorama status page. |
Addressed Issues in Prisma Access 6.1.0-h6
|
Issue ID
|
Description
|
|---|---|
| CYR-66462 | Fixed an issuer where, for the NGFW connector to work in staging and production environments, customers must use Cloud Service Plugin version 6.1.0-ch48 only. |
| CYR-66281 | Fixed an issue where SPNs were not appearing on the SD-WAN UI because of a Cloud Service Plugin issue. |
| CYR-64827 | Fixed an issue to remove bad import for get_rn_to_ep_ip_list.py. |
| CYR-64328 | Fixed an issue where these special characters are
blocked from plugin Colo-Connect configurations: ' - Single Quote
" - Double Quote \ - Backslash ; -
Semicolon – Double dash # -Hash /* ... */
-C-style comment 0x00 \x00 / Forward
slash NULL |
| CYR-63235 | Fixed an issue where, if the Panorama device is in multitenant mode, the Cloud Services plugin validation fails when an IPv6 address is configured for tunnel monitoring in the service connection's IPsec tunnel template. |
| CYR-61262 | Fixed a logging issue for commit validation on the Panorama plugin to show the total number of Trusted Source IP Addresses instead of the total number of object entries. |
Addressed Issues in Prisma Access 6.1.0-h5
|
Issue ID
|
Description
|
|---|---|
| CYR-65646 | Fixed an issue where, in the Panorama Explicit Proxy configuration UI, the "Enable Prisma Access Browser" toggle is not visible. |
| CYR-65009 | Fixed an issue where users with the Device Group and Template role cannot push commit for Prisma Access after upgrading to CSP 5.2.0-h69. The user can now commit and push the configuration changes. |
| CYR-54503 | Fixed an issue where domain configurations were not applied to mobile users during a partial commit on Panorama, while the same configurations were successfully applied to remote networks. |
Addressed Issues in Prisma Access 6.1.0-h4
|
Issue ID
|
Description
|
|---|---|
| CYR-63880 | Fixed an issue where a new GlobalProtect app could not be activated in Panorama. |
| CYR-63785 | Fixed an issue where, for Panorama Site-Based License tenants, only 4 sites were displayed on Branch Sites pages. With this fix, up to 25 sites are displayed per page. |
| CYR-63697 | Fixed an issue where commit validation did not fail when Remote Network was configured with ECMP Load Balancing with Symmetric Return and was enabled with no ECMP link. |
| CYR-63690 | Fixed an issue where a "Failed to load mobile user gateways" error occurred during mobile user onboarding for setups with high subtenant counts. |
| CYR-63656 | Fixed an issue where, for Panorama site-based license tenants, if the site was configured in an edge location, the compute location name was displayed on the Branch Sites page instead of edge location name. |
| CYR-62342 | Fixed an issue where the user was unable to configure Quality of Service (QoS) for specific compute locations such as Sweden. |
| CYR-61254 | Fixed an issue where Prisma Access multitenancy managed through Panorama could be enabled for new deployments. For more information, see the EOL announcement at https://www.paloaltonetworks.com/services/support/end-of-life-announcements. |
| CYR-60685 | Fixed an issue where plugin validation failed after reducing the Aggregate Bandwidth allocation for the US-East location. |
| CYR-60070 | Fixed an issue where all Panorama environments were not required to have the device certificate installed. |
| CYR-59382 | Fixed an issue where, when onboarding a legacy (non-remote network high performance) site on Panorama, commit fails because of a missing QoS profile. |
| CYR-56776 | Fixed an issue where users need to block "Allow all IPs and Auth bypass *.*" in Explicit Proxy configuration. |
| CYR-44968 | Fixed an issue where Prisma Access no longer validates the 30-minute maximum limit for automatic VPN restoration when you enable IP Optimization. |
Addressed Issues in Prisma Access 6.1.0-h2
|
Issue ID
|
Description
|
|---|---|
| CYR-62135 | Fixed an issue where, in a multitenant Panorama managed Prisma Access deployment, internal host detection could not be configured by device group and template admin users. |
| CYR-61659 | Fixed an issue where, before changing the infrastructure subnet, administrators were not provided a message indicating that a maintenance window and a TAC case is required. |
| CYR-61474 | Fixed an issue where the Explicit Proxy feature in Prisma Access displayed "Prisma Access Browser" instead of "Prisma Browser". |
| CYR-61443 | Fixed an issue where, under the OnboardingService Connection area in Strata Cloud Manager, when Colo-Connect service connections are onboarded, the BGP-specific column that includes overlay BGP status and peer RIB and routing table information displayed a pop-up window with an error that the BGP status couldn't be found. |
| CYR-60959 | Fixed an issue where, when enabling Private Application Access in Explicit Proxy and ZTNA Connector is also configured, an error message displayed that there was not a service connection deployed. |
| CYR-59412 | Fixed an issue where serviceability commands did not yield any output in a tenant that had Dynamic Privilege Access enabled. |
| CYR-54776 | Fixed an issue where BGP filtering was enabled on a Panorama in a multi-tenant deployment that had no supertenant. BGP filtering is not supported on a Panorama in a multi-tenant deployment that has no supertenant. |
| CYR-52444 | Fixed an issue where, in a multitenant Panorama Managed Prisma Access deployment, the BGP Filtering feature was supported only on a parent Tenant and was not supported on sub-tenants. |
Addressed Issues in Prisma Access 6.1.0-h1
|
Issue ID
|
Description
|
|---|---|
| CYR-61065 | Fixed an issue where a Panorama local commit failed with a validation error: Failed Plugin Validation error after a Cloud Services Plugin upgrade. |
| CYR-60869 | Fixed an issue where the export operation failed to download the Remote Network configuration from Panorama. |
| CYR-60105 | Fixed an issue where the Panorama one-time password (OTP) workflow for a new deployment failed from the UI. |
| CYR-59494 | Fixed an issue where the list of Remote Networks on the Remote Networks status page displayed a count of 0. |
| CYR-58530 | Fixed an issue on Panorama where you could not update hypervisor profile fields when an on-premises deployment was pending. |
| CYR-55824 | Fixed an issue where the Panorama UI did not allow BGP configuration for the passive tunnel in an Active/Passive tunnel configuration. |
| CYR-54007 | Fixed an issue where, after reducing the Remote Network's aggregate bandwidth from a Safari browser, the browser fails to display the list of unused SPN names that will be released. |
Addressed Issues in Prisma Access 6.1.0
|
Issue ID
|
Description
|
|---|---|
|
CYR-58852
|
Fixed an issue where Panorama commit validation workflows would
fail if a tenant's licenses had the "no_limit" string under the
service_connection local service chain information in the
license_capabilities. This occurred because the system was
attempting to convert the string to an integer.
|
|
CYR-58332
|
Fixed an issue where commits to GlobalProtect gateways failed
with a validation error related to the `max-version` setting in
the SSL-TLS service profile.
|
|
CYR-58134
|
Fixed an issue where upgrading the cloud_services plugin from
version 5.1.0-39 to 6.0.0-11 on Panorama automatically disabled
the "Enable Private App Access" option. When this configuration
was pushed to Prisma Access, it caused an outage to critical
internal applications.
|
|
CYR-57700
|
Fixed an issue where any changes to the Cloud Services Plugin
onboarding configuration on Panorama resulted in an error when
the 'DEFAULT' config was missing in the GlobalProtect
portal.
|
|
CYR-57636
|
Fixed an issue where Panorama could not display bandwidth usage
statistics for remote networks in the tenant status view when
managing Prisma Access with multitenancy enabled.
|
|
CYR-55432
|
Fixed an issue where Internal Host Detection (IHD) details were
grayed out during Mobile User onboarding.
|
|
CYR-54503
|
Fixed an issue where domain configurations were not applied to
mobile users during a partial commit on Panorama, while the same
configurations were successfully applied to remote networks.
|
|
CYR-53941
|
Fixed an issue where, when onboarding remote networks using
configuration import in a multitenant deployment, an import
error was seen.
|
|
CYR-51619
|
Fixed an issue where, after creating a new regional IP pool for
IP the pool group 31 region, a 'blank ip pool' message was
received in the Cloud services plugin UI.
|
|
CYR-49944
|
Fixed an issue where a secondary DNS server was configured, which
is not allowed.
|