Red Hat SATELLITE 5.0.0 RELEASE NOTES Manual de usuario Pagina 18

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 52
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 17
18 PAN-OS 6.1 Release Notes Palo Alto Networks
Known Issues PAN-OS 6.1 Release Information
66233
When HTTP header logging is enabled in the URL Filtering profile, two issues can be seen:
the URL logging rate is reduced or HTTP headers are not logged to the URL Filtering logs
when the traffic rate is high. The second issue can cause a delay in receiving headers,
resulting in missing HTTP header information.
65824
Unused NAT IP address pools are not cleared after a single commit, so a commit might
possibly fail if the cache of unused pools, existing used pools, and the new pools together
exceed the memory limit.
Workaround: commit a second time, which clears the old pool allocation.
64658
When setting up or modifying a DoS protection profile, you can set a maximum number of
concurrent sessions for traffic that matches the DoS profile. The maximum concurrent limit
of sessions for the PAN-OS 6.1.0 release is 65,535. Following an upgrade to PAN-OS 6.1.0,
check that the
Maximum Concurrent Sessions you have configured is less than 65,535
(
Objects > DoS Protection > DoS Protection Profile > Resources Protection). You will not
be able to commit configuration changes if the Maximum Concurrent Sessions field was set
to a value higher than 65,535 while running a previous release version. Enter a value for this
field that is less than 65,535 in order to continue to commit configuration changes following
the upgrade.
63962
Configurations pushed from Panorama 6.1 to firewalls running PAN-OS versions 6.0.0 to
6.0.3 will fail to commit due to an unexpected
Rule Type error. This is because the new
Rule Type setting in security policy rules was not included in the upgrade transform and
therefore the new rule types are not recognized on the devices.
63524
When you perform a template commit to a PA-200 firewall, the operation fails if you
changed the vsys1 display name on the firewall using the CLI command
set display-name
<name>
.
Workaround: leave the display name at its default value (vsys1) or, if you already changed it,
reset it to the default value.
63186
If you perform a factory reset on a Panorama virtual appliance and configure the serial
number, logging does not work until you reboot Panorama or run the CLI command debug
software restart management-server.
60229
A cached web page maybe accessible to a user, even if the URL category is blocked by policy.
However, if the user uses the links on the web page to request additional content from the
blocked category, the request will be successfully blocked by policy.
58260
If a HA failover happens on Panorama at the time that the NSX Manager is deploying the
NSX edition firewall, the licensing process fails with the error:
vm-cfg: failed to
process registration from svm device. vm-state: active
.
Workaround: Delete the unlicensed instance of the VM-Series firewall on each ESXi host
and then redeploy the Palo Alto Networks NGFW service from the NSX Manager.
49322
After you configure Panorama M-100 appliances for high availability and synchronize the
configuration, the Log Collector of the passive peer cannot connect to the active peer until
you reboot the passive peer.
40436
PAN-OS does not update FQDN entries unless you enable the DNS Proxy caching option.
Issue Identifier Issue Description
Vista de pagina 17
1 2 ... 13 14 15 16 17 18 19 20 21 22 23 ... 51 52

Comentarios a estos manuales

Sin comentarios