<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is Pan OS 3.1.4 stable? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-pan-os-3-1-4-stable/m-p/17204#M12561</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://support.paloaltonetworks.com/index.php?option=com_pan&amp;amp;task=view_releasenotes&amp;amp;vn=3.1.4&amp;amp;ut=sw&amp;amp;ct=&amp;amp;prod=panos&amp;amp;plat=2000"&gt;https://support.paloaltonetworks.com/index.php?option=com_pan&amp;amp;task=view_releasenotes&amp;amp;vn=3.1.4&amp;amp;ut=sw&amp;amp;ct=&amp;amp;prod=panos&amp;amp;plat=2000&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of course there are known issues in 3.1.4 too, check that document.&amp;nbsp; Some of these probably impact you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Addressed Issues in 3.1.4.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The following issues have been addressed in this release:&lt;BR /&gt;• [21676] PA-2000 series devices may become unresponsive.&lt;BR /&gt;• [21641] An admin with the device administrator role cannot create local users.&lt;BR /&gt;• [21620] URL category does not show up properly when logs are forwarded via syslog or&lt;BR /&gt;SNMP.&lt;BR /&gt;• [21610] If errors occur when generating a certificate in the UI, the window must be closed&lt;BR /&gt;and reopened to correct the issues and regenerate.&lt;BR /&gt;• [21546] Changing the continue timeout in a URL profile does not immediately take effect.&lt;BR /&gt;• [21544] An imported inbound inspection certificate with a long name cannot be&lt;BR /&gt;subsequently deleted.&lt;BR /&gt;• [21504] After a factory-reset, the default web certificate uses SHA256 which is not&lt;BR /&gt;compatible with Internet Explorer.&lt;BR /&gt;• [21485] System instability may occur in some environments where a high volume of&lt;BR /&gt;Skype or P2P traffic is present.&lt;BR /&gt;• [21481] In some cases, when doing inbound SSL decryption the eicar virus may not be&lt;BR /&gt;detected.&lt;BR /&gt;• [21476] Deleting the reports that have been run for custom reports with spaces in the&lt;BR /&gt;name will fail.&lt;BR /&gt;• [21440] If configuration synchronization between HA peers takes longer than 30 seconds&lt;BR /&gt;then synchronization will fail and passive device will incorrectly indicate that&lt;BR /&gt;configuration is in sync.&lt;BR /&gt;• [21396] The IKE dead-peer detection mechanism may inappropriately detect failure,&lt;BR /&gt;causing tunnel connections to fail.&lt;BR /&gt;PAN-OS Release Notes, Version 3.1.4 rev A&lt;BR /&gt;6&lt;BR /&gt;• [21352] Default route metrics are advertised incorrectly in OSPF stub networks.&lt;BR /&gt;• [21345] The auto-commit process after bootup may fail when large certificates are present&lt;BR /&gt;in the configuration.&lt;BR /&gt;• [21341] The source address portion of an application override rule does not take effect.&lt;BR /&gt;• [21331] Users that get locked out of an SSL-VPN do not get displayed as locked.&lt;BR /&gt;• [21319] When a commit is performed where the only change is to the management proxy&lt;BR /&gt;settings, the dataplane will restart.&lt;BR /&gt;• [21271] When the dynamic URL categorization server is not reachable, all requests&lt;BR /&gt;needing cloud-based categorization will be delayed.&lt;BR /&gt;• [21255] Read-only super users cannot access data filtering captures.&lt;BR /&gt;• [21233] Only 10 QoS rules can be configured on a PA-500 device.&lt;BR /&gt;• [21231] When using a single address object in an address group in the source translation&lt;BR /&gt;field of a NAT rule, the resulting source address is 0.0.0.0.&lt;BR /&gt;• [21216] BrightCloud database updates fail when traversing a proxy.&lt;BR /&gt;• [21213] Next-hop monitoring with policy-based forwarding does not function properly&lt;BR /&gt;when using VLAN interfaces.&lt;BR /&gt;• [21165] Custom applications cannot be created with Panorama.&lt;BR /&gt;• [21053] The system may improperly classify FTP traffic within a proxy session. Session&lt;BR /&gt;statistics for these sessions may also be incorrect. These two issues are addressed.&lt;BR /&gt;However, FTP data sessions within proxy tunnels will show up as unknown.&lt;BR /&gt;• [21052] Occasionally user to IP mapping is corrupted and users are unnecessarily&lt;BR /&gt;presented with a captive portal login page.&lt;BR /&gt;• [20991] Content updates may be partially synced to an HA peer even when syncing is&lt;BR /&gt;disabled, causing unpredictable content versions on the peer.&lt;BR /&gt;• [20894] The text/html filetype inappropriately appears as a valid filetype within Panorama&lt;BR /&gt;when configuring file blocking profiles.&lt;BR /&gt;• [20893] When creating a log forwarding profile with Panorama, the setting for&lt;BR /&gt;forwarding critical severity threat logs is not saved even though it was selected.&lt;BR /&gt;• [20890] DHCP clients that request lease times longer than the configured maximum are&lt;BR /&gt;granted those times.&lt;BR /&gt;• [20829] The system is not able to properly identify SNMP sessions when an SNMP&lt;BR /&gt;response is fragmented into more than 3 fragments.&lt;BR /&gt;PAN-OS Release Notes, Version 3.1.4 rev A&lt;BR /&gt;7&lt;BR /&gt;• [20733] The request private-data-reset command clears out antivirus signatures even&lt;BR /&gt;though content updates are intended to remain.&lt;BR /&gt;• [20698] URL admin override functionality does not work properly when a certificate is&lt;BR /&gt;configured.&lt;BR /&gt;• [20593] Custom URL categories starting with a numeral do not show up properly in the&lt;BR /&gt;log viewer.&lt;BR /&gt;• [20517] HTTP long chunk responses trigger anomalous threat detections.&lt;BR /&gt;• [20375] Probability of a passive device incorrectly becoming active is increased during a&lt;BR /&gt;URL database update.&lt;BR /&gt;• [20257] SSL-VPN users are not able to successfully authenticate via RADIUS in some&lt;BR /&gt;environments.&lt;BR /&gt;• [20239] The port field of a service object is limited to 63 characters.&lt;BR /&gt;• [20164] The system incorrectly discards lone IPv6 fragments.&lt;BR /&gt;• [19854] System may be unable to correctly present block pages when blocked requests&lt;BR /&gt;exceed 100 pages per second.&lt;BR /&gt;• [18767] SSL inbound inspection may fail when active SSL flows to the server exceeds&lt;BR /&gt;1000.&lt;BR /&gt;• [18271] In some environments session rematch on a PA-4000 does not properly remove&lt;BR /&gt;sessions when a policy is changed and committed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 03 Sep 2010 14:09:04 GMT</pubDate>
    <dc:creator>keith_whitley</dc:creator>
    <dc:date>2010-09-03T14:09:04Z</dc:date>
    <item>
      <title>Is Pan OS 3.1.4 stable?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-pan-os-3-1-4-stable/m-p/17203#M12560</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I currently have PanOS 3.1.2. All my devices are currently in tap mode. It was recommended to upgrade to Pan OS 3.1.4 due to a bug in the 3.1.2. Does any one know what the bug is and also would like to know if 3.1.4 stable?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Sep 2010 04:40:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-pan-os-3-1-4-stable/m-p/17203#M12560</guid>
      <dc:creator>jputham</dc:creator>
      <dc:date>2010-09-03T04:40:08Z</dc:date>
    </item>
    <item>
      <title>Re: Is Pan OS 3.1.4 stable?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-pan-os-3-1-4-stable/m-p/17204#M12561</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://support.paloaltonetworks.com/index.php?option=com_pan&amp;amp;task=view_releasenotes&amp;amp;vn=3.1.4&amp;amp;ut=sw&amp;amp;ct=&amp;amp;prod=panos&amp;amp;plat=2000"&gt;https://support.paloaltonetworks.com/index.php?option=com_pan&amp;amp;task=view_releasenotes&amp;amp;vn=3.1.4&amp;amp;ut=sw&amp;amp;ct=&amp;amp;prod=panos&amp;amp;plat=2000&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of course there are known issues in 3.1.4 too, check that document.&amp;nbsp; Some of these probably impact you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Addressed Issues in 3.1.4.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The following issues have been addressed in this release:&lt;BR /&gt;• [21676] PA-2000 series devices may become unresponsive.&lt;BR /&gt;• [21641] An admin with the device administrator role cannot create local users.&lt;BR /&gt;• [21620] URL category does not show up properly when logs are forwarded via syslog or&lt;BR /&gt;SNMP.&lt;BR /&gt;• [21610] If errors occur when generating a certificate in the UI, the window must be closed&lt;BR /&gt;and reopened to correct the issues and regenerate.&lt;BR /&gt;• [21546] Changing the continue timeout in a URL profile does not immediately take effect.&lt;BR /&gt;• [21544] An imported inbound inspection certificate with a long name cannot be&lt;BR /&gt;subsequently deleted.&lt;BR /&gt;• [21504] After a factory-reset, the default web certificate uses SHA256 which is not&lt;BR /&gt;compatible with Internet Explorer.&lt;BR /&gt;• [21485] System instability may occur in some environments where a high volume of&lt;BR /&gt;Skype or P2P traffic is present.&lt;BR /&gt;• [21481] In some cases, when doing inbound SSL decryption the eicar virus may not be&lt;BR /&gt;detected.&lt;BR /&gt;• [21476] Deleting the reports that have been run for custom reports with spaces in the&lt;BR /&gt;name will fail.&lt;BR /&gt;• [21440] If configuration synchronization between HA peers takes longer than 30 seconds&lt;BR /&gt;then synchronization will fail and passive device will incorrectly indicate that&lt;BR /&gt;configuration is in sync.&lt;BR /&gt;• [21396] The IKE dead-peer detection mechanism may inappropriately detect failure,&lt;BR /&gt;causing tunnel connections to fail.&lt;BR /&gt;PAN-OS Release Notes, Version 3.1.4 rev A&lt;BR /&gt;6&lt;BR /&gt;• [21352] Default route metrics are advertised incorrectly in OSPF stub networks.&lt;BR /&gt;• [21345] The auto-commit process after bootup may fail when large certificates are present&lt;BR /&gt;in the configuration.&lt;BR /&gt;• [21341] The source address portion of an application override rule does not take effect.&lt;BR /&gt;• [21331] Users that get locked out of an SSL-VPN do not get displayed as locked.&lt;BR /&gt;• [21319] When a commit is performed where the only change is to the management proxy&lt;BR /&gt;settings, the dataplane will restart.&lt;BR /&gt;• [21271] When the dynamic URL categorization server is not reachable, all requests&lt;BR /&gt;needing cloud-based categorization will be delayed.&lt;BR /&gt;• [21255] Read-only super users cannot access data filtering captures.&lt;BR /&gt;• [21233] Only 10 QoS rules can be configured on a PA-500 device.&lt;BR /&gt;• [21231] When using a single address object in an address group in the source translation&lt;BR /&gt;field of a NAT rule, the resulting source address is 0.0.0.0.&lt;BR /&gt;• [21216] BrightCloud database updates fail when traversing a proxy.&lt;BR /&gt;• [21213] Next-hop monitoring with policy-based forwarding does not function properly&lt;BR /&gt;when using VLAN interfaces.&lt;BR /&gt;• [21165] Custom applications cannot be created with Panorama.&lt;BR /&gt;• [21053] The system may improperly classify FTP traffic within a proxy session. Session&lt;BR /&gt;statistics for these sessions may also be incorrect. These two issues are addressed.&lt;BR /&gt;However, FTP data sessions within proxy tunnels will show up as unknown.&lt;BR /&gt;• [21052] Occasionally user to IP mapping is corrupted and users are unnecessarily&lt;BR /&gt;presented with a captive portal login page.&lt;BR /&gt;• [20991] Content updates may be partially synced to an HA peer even when syncing is&lt;BR /&gt;disabled, causing unpredictable content versions on the peer.&lt;BR /&gt;• [20894] The text/html filetype inappropriately appears as a valid filetype within Panorama&lt;BR /&gt;when configuring file blocking profiles.&lt;BR /&gt;• [20893] When creating a log forwarding profile with Panorama, the setting for&lt;BR /&gt;forwarding critical severity threat logs is not saved even though it was selected.&lt;BR /&gt;• [20890] DHCP clients that request lease times longer than the configured maximum are&lt;BR /&gt;granted those times.&lt;BR /&gt;• [20829] The system is not able to properly identify SNMP sessions when an SNMP&lt;BR /&gt;response is fragmented into more than 3 fragments.&lt;BR /&gt;PAN-OS Release Notes, Version 3.1.4 rev A&lt;BR /&gt;7&lt;BR /&gt;• [20733] The request private-data-reset command clears out antivirus signatures even&lt;BR /&gt;though content updates are intended to remain.&lt;BR /&gt;• [20698] URL admin override functionality does not work properly when a certificate is&lt;BR /&gt;configured.&lt;BR /&gt;• [20593] Custom URL categories starting with a numeral do not show up properly in the&lt;BR /&gt;log viewer.&lt;BR /&gt;• [20517] HTTP long chunk responses trigger anomalous threat detections.&lt;BR /&gt;• [20375] Probability of a passive device incorrectly becoming active is increased during a&lt;BR /&gt;URL database update.&lt;BR /&gt;• [20257] SSL-VPN users are not able to successfully authenticate via RADIUS in some&lt;BR /&gt;environments.&lt;BR /&gt;• [20239] The port field of a service object is limited to 63 characters.&lt;BR /&gt;• [20164] The system incorrectly discards lone IPv6 fragments.&lt;BR /&gt;• [19854] System may be unable to correctly present block pages when blocked requests&lt;BR /&gt;exceed 100 pages per second.&lt;BR /&gt;• [18767] SSL inbound inspection may fail when active SSL flows to the server exceeds&lt;BR /&gt;1000.&lt;BR /&gt;• [18271] In some environments session rematch on a PA-4000 does not properly remove&lt;BR /&gt;sessions when a policy is changed and committed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Sep 2010 14:09:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-pan-os-3-1-4-stable/m-p/17204#M12561</guid>
      <dc:creator>keith_whitley</dc:creator>
      <dc:date>2010-09-03T14:09:04Z</dc:date>
    </item>
  </channel>
</rss>

