PAN-OS 10.2.1 Known Issues (2022)

PAN-OS® 10.2.1 known issues.

The following list includes only outstanding known issuesspecific to PAN-OS


10.2.1. This list includes issuesspecific to Panorama™, GlobalProtect™, VM-Series plugins, and WildFire®,as well as known issues that apply more generally or that are notidentified by an issue ID.

Issue ID



The WildFire appliance might erroneouslygenerate and log the following device certification error:

Device certificate is missing or invalid. It cannot be renewed.


In WildFire appliance clusters, issuingthe

show cluster controller

CLI command generatesan error when an IPv6 address is configured for the management interfacebut not for the cluster interface.


Ensureall WildFire appliance interfaces that are enabled use matchingprotocols (all IPv4 or all IPv6).


The number of registered WildFire appliancesreported in Panorama () does not accurately reflect thecurrent status of connected WildFire appliances.


On the Panorama management server, pushinga configuration change to firewalls leveraging SD-WAN erroneouslyshow the auto-provisioned BGP configurations for SD-WAN as beingedited or deleted despite no edits or deletions being made whenyou

Preview Changes

( or ).



WF-500 appliance only

) Systemlog forwarding does not work over a TLS connection.


URL filtering logs ()erroneously truncate a 16KB Header value and do not display theHeader values that follow the truncated 16KB header.

For example,a URL filtering log has 5 Headers. The second Header has a 16KBvalue. In the URL filtering log, the first header and the valueare displayed, second Header value is truncated, and remaining threeheaders are not displayed.



PA-5450 firewall only

) Tryingto configure a custom payload format under yieldsa Javascript error.



PA-5450 firewall only

) The Panoramaweb interface does not display any predefined template stack variablesin the dropdown menu under .


Configurethe log interface IP address on the individual firewall web interfaceinstead of on Panorama.


The PA-220 firewall reaches the maximumdisk usage capacity multiple a day that requires a disk cleanup.A critical system log ()is generated each time the firewall reaches maximum disk usage capacity.


If SAML is configured as the authenticationmethod for GlobalProtect, authentication on the Portal page is not successfulin the browser.


Use the GlobalProtect app installedon the endpoint to authenticate.



(Video) Upgrading the Palo Alto OS

PA-5450 firewall only

) There isno commit warning in the web interface when configuring the management interfaceand logging interface in the same subnetwork. Having both interfacesin the same subnetwork can cause routing and connectivity issues.


Certain webpages that use chunked-encodeddata transfers might not load properly when analyzed by Advanced URLFiltering cloud inline categorization.



PA-5450 firewall only

) Documentationfor configuring the log interface is unavailable on the web interface andin the PAN-OS Administrator’s Guide.


This issue isnow resolved. See

PAN-OS 10.2.2 Addressed Issues


Running any version of PAN-OS 10.2.1 ona PA-400 Series firewall can cause the dataplane process to restart unexpectedlyand trigger a crash.


After you successfully upgrade a PA-3000Series firewall to PAN-OS 10.2.0 or later release and Enterprisedata loss prevention (DLP) plugin 3.0.0 or later release, the first configurationpush from the Panorama management server causes the firewall dataplaneto crash.


Restart the firewall to restore dataplanefunctionality.
  1. Log in to the firewall CLI.

  2. Restart the firewall.


    request restart system


After deleting an MP pod and it comes up,the

show routing

command output appearsempty and traffic stops working.


On a firewall with Advanced Routing enabled,OSPFv3 peers using a broadcast link and a designated router (DR) priorityof 0 (zero) are stuck in a two-way state after HA failover.


Configureat least one OSPFv3 neighbor with a non-zero priority setting inthe same broadcast domain.


This issue isnow resolved. See

PAN-OS 10.2.2 Addressed Issues


On the Panorama management server, Panoramaenters a


state due to


lifetaking up too much space.


Disable the debugflag for Panorama.
  1. Log in to the Panorama web interface.

  2. In the same browser you are logged into the Panorama webinterface, enter the following URL.


  3. Uncheck (disable)



  4. (

    HA configuration

    ) Repeat this step on each Panoramahigh availability (HA) peer if Panorama is in a HA configuration.


Certain web pages and web page contentsmight not properly load when cloud inline categorization is enabledon the firewall.


On the Panorama management server, dynamiccontent updates are not automatically pushed to VM-Series firewalls licensedusing the Panorama Software Firewall License plugin when

Automaticallypush content when software device registers to Panorama

() is enabled.


After triggering a soft reboot on a M-700appliance, the Management port LEDs do not light up when a 10G Ethernet cableis plugged in.

(Video) Upgrading Firewall PAN-OS Software - Palo Alto Networks


The SCP Server Profile configuration ( are not automatically deleted afterdowngrade from PAN-OS 10.2.0 to PAN-OS 10.1 or earlier release.


On the Panorama management server, the Template Statusdisplays no synchronization status ()after a bootstrapped firewall is successfully added to Panorama.


Afterthe bootstrapped firewall is successfully added to Panorama, log in to the Panorama web interface andselect .


If you enable SCTP security using a Panoramatemplate when

SCTP INIT Flood Protection

is enabledin the Zone Protection profile using Panorama and you commit allchanges, the commit is successful but the


optionis not available in the Zone Protection profile.


Logout of the firewall and log in again to make the


option available on the web interface.


On the Panorama management server, not alldata profiles () are displayedafter you:

  • Upgrade Panorama to PAN-OS 10.2 and upgradethe Enterprise DLP plugin to version 3.0.

  • Downgrade Panorama to PAN-OS 10.1 and downgrade the EnterpriseDLP plugin to version 1.0.


Login to the Panorama CLI and reset the DLP plugin.

admin > request plugins dlp reset


This issue isnow resolved. See

PAN-OS 10.2.2 Addressed Issues


On PA-3400 & PA-5400 series firewalls(minus the PA-5450), the CLI and SNMP MIB walk do not display theModel and Serial-number of the Fan tray and PSUs.


The configured Advanced Threat Preventioninline cloud analysis action for a given model might not be honoredunder the following condition: If the firewall is set to

Holdclient request for category lookup

and the action setto


and the URL cache has beencleared, the first request for inline cloud analysis will be bypassed.


On a firewall with Advanced Routing enabled,if there is also a logical router instance that uses the defaultconfiguration and has no interfaces assigned to it, this will resultin terminating the routed and zebrad daemons in the firewall duringcommit.


: Do not use a logical router instancewith no interfaces bound to it.


Certain web pages submitted for analysisby Advanced URL Filtering cloud inline categorization might experiencehigh latency.


This issue isnow resolved. See

PAN-OS 10.2.2 Addressed Issues


On the Panorama management server,

ValidateDevice Group

( erroneouslyissues a CommitAll operation instead of a ValidateAll operationwhen multiple device groups are included in the push and resultsin no configuration validation.


Validatedevice group configurations using one of the following methods.
  • Select only one device group whenyou

    Validate Device Group

    for a

    Commitand Push

    to managed firewalls.

  • To validate multiple device groups, select first. Afterthe device group configuration is committed to Panorama, select and

    ValidateDevice Group

    to validate multiple device groups.


Templates appear out-of-sync on Panoramaafter successfully deploying the CFT stack using the Panorama plugin forAWS.


: Use to synchronizethe templates.


On HA deployments on AWS and Azure, Panoramafails to populate match criteria automatically when adding dynamic addressgroups.


Reboot the Panorama HA pair.


(Video) iOS 10.2.1 Released - All You Need to Know │One Year Anniversary

The Panorama management server in Panoramaor Log Collector mode may become unresponsive as Elasticsearch accumulatesinternal connections related to logging processes. The chances Panoramabecomes unresponsive increases the longer Panorama remains poweredon.


Reboot Panorama if it becomes unresponsive.


On the Panorama management server, performinga

Commit and Push


Commit > Commitand Push

) may intermittently not push the committedconfiguration changes to managed firewalls.



Commit >Push to Devices

to push the committed configurationchanges to your managed firewalls.


Scheduled report emails () are not emailed if:

  • A scheduled report email containsa Report Group ()which includes a SaaS Application Usage report.

  • A scheduled report contains only a SaaS Application Usage Report.


Toreceive a scheduled report email for all other PDF report types:
  1. Select andremove all SaaS Application Usage reports from all Report Groups.

  2. Select andedit the scheduled report email that contains only a SaaS Application Usagereport. For the Recurrence, select





    Repeat this step for all scheduledreport emails that contain only a SaaS Application Usage report.

  3. Commit



    Panorama managed firewalls



On the Panorama management server, an M-700 appliancein Log Collector mode fails to connect to Panorama when added asa managed collector ().


Log in to the M-700 CLI and recover the Log Collector connectivityto Panorama.


When the firewall has Advanced Routing enabled,a static route stays active after the interface goes down.


:For firewalls that support Bidirectional Forwarding Detection (BFD),configure BFD for the static route.


Using the CLI to add a RAID disk pair toan M-700 appliance causes the dmdb process to crash.


Contactcustomer support to stop the dmdb process before adding a RAID diskpair to a M-700 appliance.


Static IP addresses are not recognized when"and" operators are used with IP CIDR range.


On an Advanced Routing Engine, if you changethe IPSec tunnel configuration, BGP flaps.

If you use multiple log forwarding cards(LFCs) on the PA-7000 series, all of the cards may not receive allof the updates and the mappings for the clients may become out of sync,which causes the firewall to not correctly populate the Source Usercolumn in the session logs.


On a PA-5400 Series firewall (minus thePA-5450), setting the peer port to forced 10M or 100M speed causesany multi-gigabit RJ-45 ports on the firewall to go down if theyare set to Auto.


On the Panorama management server, pushingan unsupported Minimum Password Complexity ()to a managed firewall erroneously displays

commit time out

asthe reason the commit failed.


When upgrading a CN-Seriesas a DaemonSet deployment to PAN-OS 10.2, CN-NGFW pods fail to connectto CN-MGMT pod if the Kubernetes cluster previously had a CN-Seriesas a DaemonSet deployment running PAN-OS 10.0 or 10.1.

(Video) Webinar: Security and Compliance with PostgreSQL by Boriss Mejías


:Reboot the worker nodes before upgrading to PAN-OS 10.2.


A user interface issue in PAN-OS rendersthe contents of the

Inline ML

tab in the

URLFiltering Profile

inaccessible on firewalls licensedfor Advanced URL Filtering. Additionally, a message indicating thata

License required for URL filtering to function

isunavailable displays at the bottom of the UI. These errors do notaffect the operation of Advanced URL Filtering or URL FilteringInline ML.


Configuration settings for URL FilteringInline ML must be applied through the CLI. The following configurationcommands are available:
  • Define URL exceptions forspecific web sites—


    set profiles url-filtering <url_filtering_profile_name> mlav-category-exception

    • Configuration settings for each inline ML model—


      set profiles url-filtering <url_filtering_profile_name> mlav-engine-urlbased-enabled


This issue isnow resolved. See

PAN-OS 10.2.2 Addressed Issues


PAN-OS 10.2.0 is not supported on PA-7000Series firewalls with HA (High Availability) clustering enabledand using an HA4 communication link. Attempting to load PAN-OS 10.2.0on the firewall causes the PA-7000 100G NPC to go offline. As aresult, the firewall fails to boot normally and enters maintenancemode. HA Pairs of Active-Passive and Active-Active firewalls arenot affected.



show running resource-monitor



option produces thefollowing server error:

Dataplane is not up or invalid target-dp(*.dp*)



When the firewall is deployed on N3 andN11 interfaces in 5G networks and 5G-HTTP/2 traffic inspection isenabled in the Mobile Network Protection Profile, the traffic logsdo not display network slice SST and SD values.


In HA active/active configurations where,when interfaces that were associated with a virtual router weredeleted, the configuration change did not sync.


When you activate the advanced URL filteringlicense, your license entitlements for PAN-DB and advanced URL filteringmight not display correctly on the firewall — this is a displayanomaly, not a licensing issue, and does not affect access to theservices.


Issue the following command toretrieve and update the licenses:

license request fetch



QoS fails to run on a tunnel interface (forexample, tunnel.1).


No results are displayed when you

Show ApplicationFilter

for a Security policy rule ().

