On This Page
Bugs - Resolved and Unresolved
Overview
The reference table below includes bugs resolved in R23-2 and later, as well as unresolved issues across all supported versions. For older resolved bugs, see the relevant release in the Release Notes Knowledge Center. Any bugs existing only in release candidates (RCs) will not appear.
To filter the results, enter text in one or more of the filter fields. To see all items, clear the filter fields.
References
All known internal bug numbers and/or customer case numbers related to the bug.
Known Affected Releases
The major version in which the bug was found plus any additional major versions in which it is known to exist. Other release might be affected as well.
Fixed Versions
The earliest minor version(s) in which the bug was fixed and/or the upcoming GA release. Bugs fixed in one GA release can be assumed fixed in all subsequent releases. For issues that have not been fixed, "Not fixed" will appear.
Reference Table
References |
Known Affected Releases |
Fixed Versions |
Description |
---|---|---|---|
TOS-107388 TOS-107384 |
R24-2 |
R24-2 PHF4.1.0 R25-1 PGA.0.0 |
Upgrade pre-check fails when Extensions and/or PS solutions have been installed. Logs are likely to contain error messages: Executing step "Pod amounts on nodes" in section "Validations section" and ERROR Node <NODENAME> has 110 pods, which is above the allowed limit of 108. |
TOS-103031 Case 00157237 |
R24-2 |
R24-2 PHF4.0.0 R25-1 PGA.0.0 |
TOS functions including backup, upgrade and high availability are not working. When running the tos status command, the node status indicates CHECKER_FAILURE'. |
TOS-104052 Case 00158972 |
R24-1 R24-2 |
R24-2 PHF4.0.0 R25-1 PGA.0.0 |
Disproportionate increase in database size. |
TOS-103567 Case 00159046 Case 00159146 |
R24-2 |
R24-2 PHF4.0.0 R25-1 PGA.0.0 |
Slow processing and/or tickets get stuck in Designer or Verifier. This might be accompanied by high memory consumption and Mongo timeout exception error messages in the logs. |
TOS-103895 Case 00153108 |
R24-1 R24-2 |
R24-2 PHF4.0.0 R25-1 PGA.0.0 |
Missing paths on interactive map for ACI VMM learned endpoints with multiple IP addresses on the same VM |
TOS-103990 Case 00156206 |
R24-2 |
R24-2 PHF4.0.0 R25-1 PGA.0.0 |
Fortinet FMG ADOM revision fails when device has a wildcard object with a metadata variable. Additional information: Error message "Failed parsing configuration" appears in the logs |
TOS-103708 Case 00159372 |
R24-2 |
R24-2 PHF4.0.0 R25-1 PGA.0.0 |
TOS does not start following installation of a Tufin extension. Affect Dashboard Essentials and possibly other extensions as well. Additional information: An error message might appear in the sc-container log mentioning application context and/or context initialization failed |
TOS-103182 Case 00158136 |
R24-1 R24-2 |
R24-2 PHF4.0.0 R25-1 PGA.0.0 |
Last hit information does not appear in Rule Viewer for Azure Firewall. Additional information: The logs might contain a null pointer exception (NPE) |
TOS-104125 Case 00159432 |
R24-1 R24-2 |
R24-2 PHF4.0.0 R25-1 PGA.0.0 |
Verifier incorrectly returns message 'Not implemented' following successful provisioning using option 'Create new rule rule for each AR' |
TOS-104931 TOS-104648 Case 00155762 |
R24-1 R24-2 |
R24-2 PHF4.0.0 R25-1 PGA.0.0 |
Violation calculations fail to detect violated rules when the environment exceeds 200 devices. |
TOS-104826 TOS-104898 Case 00159858 |
R24-2 |
R24-2 PHF4.0.0 R25-1 PGA.0.0 |
For Cisco SD-WAN devices 17.4 and above with multi-tenancy is enabled, dynamic topology fails to update causing missing interfaces in the topology map and incorrect Designer suggestions. |
TOS-104820 Case 00157245 Case 00159994 |
R24-2 |
R24-2 PHF4.0.0 R25-1 PGA.0.0 |
For VMware NSX-T devices that contain global objects, rules are missing from TOS. |
TOS-104929 Case 00159722 Case 00158708 |
R24-1 R24-2 |
R24-2 PHF4.0.0 R25-1 PGA.0.0 |
Upon receiving revisions from a device, SecureTrack fails to process some rules leading to missing violations in the Dashboard widgets as well as missing information in Rule Viewer. |
TOS-104890 Case 00159290 |
R24-2 |
R24-2 PHF4.0.0 R25-1 PGA.0.0 |
Connection failures between TOS and Panorama devices cause revision retrievals to fail. |
TOS-104923 Case 00160015 |
R24-2 |
R24-2 PHF4.0.0 R25-1 PGA.0.0 |
Default GCP VPCs fail to appear in the Topology map. Log message: NullPointerException |
TOS-104665 Case 00155672 |
R23-2 R24-1 R24-2 |
R24-2 PHF4.0.0 |
Revisions cannot be retrieved from Cisco FMC 7.0.6.3 devices when the logs contain duplicate network object names. Error message: "New version verification failed". |
TOS-104615 TOS-104925 TOS-104926 00155026 |
R24-1 R24-2 |
R24-2 PHF4.0.0 R25-1 PGA.0.0 |
Rule Viewer does not display IP addresses and network objects for Panorama Advanced (PanOs) devices. |
TOS-104431 TOS-104414 Case 00154289 |
R24-1 R24-2 |
R24-2 PHF4.0.0 R25-1 PGA.0.0 |
USP exceptions for specific applications and services fully exempt rules that should only be partially exempted. |
TOS-104402 TOS-104404 Case 00154201 |
R24-1 R24-2 |
R24-2 PHF4.0.0 R25-1 PGA.0.0 |
TOS fails to filter out unsupported configurations on revisions from F5 devices resulting, and as a result the revisions cannot be retrieved. |
TOS-104380 TOS-104410 Case 00157087 Case 00156127 |
R24-1 R24-2 |
R24-2 PHF4.0.0 R25-1 PGA.0.0 |
Email notifications to servers that require user authentication are not being sent. |
TOS-104281 TOS-102915 Case 00158636 |
R24-2 |
R25-1 PGA.0.0 R24-2 PHF4.0.0 |
Path REST API function returns an error message when calculating paths for generic devices with MPLS. Error message: "GENERAL_ERROR" |
TOS-104583 TOS-104649 Case 00151566 |
R24-1 R24-2 |
R25-1 PGA.0.0 R24-2 PHF4.0.0 |
Topology information cannot be retrieved from Panorama devices with Prisma |
TOS-102991 Case 00158542 |
R24-2 |
R24-2 PHF4.0.0 |
SecureTrack topology sync is not running properly. |
TOS-103330 |
R24-2 |
R25-1 PGA.0.0 R24-2 PHF4.0.0 |
Topology map does not show routes between Azure VNets in VHubs belonging to different subscriptions. The VNets appear as isolated islands |
TOS-103244 Case 00158640 |
R24-2 |
R25-1 PGA.0.0 R24-2 PHF4.0.0 |
Cannot upload the non-business days CSV file if using Firefox browser. |
TOS-103187 Case 00158220 |
R24-2 |
R25-1 PGA.0.0 R24-2 PHF4.0.0 |
SecureTrack is unable to retrieve revisions from Zscaler devices when there are more than 1,000 rules on the device. |
TOS-103138 Case 00158220 |
R24-2 |
R25-1 PGA.0.0 R24-2 PHF4.0.0 |
Zscaler shows Unknown Error in SecureTrack. |
TOS-103045 Case 00158090 |
R24-2 R24-1 |
R25-1 PGA.0.0 |
The Expiration banner does not appear for expired tickets with an expiration date that was updated via the REST API. |
TOS-100803 Case 00155322 |
R24-2 R24-1 |
R25-1 PGA.0.0 |
For Panorama devices, application field does not appear in Rule Viewer. |
TOS-100065 Case 00154590 |
R24-2 R24-1 R23-2 R23-1 |
R25-1 PGA.0.0 R24-2 PHF2.0.0 |
Searching for a cloned server in SecureApp via API returns data from the original server, even if the cloned server has been modified since cloning. |
TOS-96056 Case 00147311 |
R24-2 R24-1 R23-2 |
R25-1 PGA.0.0 |
Changes received from revisions are missing from Rule Viewer and GraphQL queries. |
TOS-96026 Case 00154366 |
R24-2 |
R25-1 PGA.0.0 |
Upgrade from R24-1 PHF2 to R24-2 fails. Possible error messages include: ERROR Step "Pod amounts on nodes" in section "Validations section" failed ERROR Section "Validations section" failed ERROR Upgrade has encountered a problem in step: "Pod amounts on nodes" due to: Node node1 has 114 pods, which is above the allowed limit of 108 |
TOS-95978 Case 00149318 |
R24-2 R24-1 |
R25-1 PGA.0.0 |
USP exception API omits NSX groups from exceptions created by the API |
TOS-94734 Case 00143135 |
R24-2 R24-1 R23-2 |
R25-1 PGA.0.0 |
The drilldown menu for shadowing rules fails to load when many zones are configured on the device. |
TOS-94394 Case 00147618 |
R24-2 R24-1 |
R25-1 PGA.0.0 |
Following a system service reboot, UI or API results are missing or contain inaccurate data. |
TOS-94147 Case 00146916 |
R24-2 R24-1 R23-2 |
R25-1 PGA.0.0 |
API returns 500 error when device does not support NAT rules. |
TOS-94146 Case 00143825 |
R24-2 R24-1 |
R25-1 PGA.0.0 |
Cassandra status critical. Identified in the output of the TOS precheck tool. |
TOS-93416 Case 00146349 |
R24-1 R24-2 |
R25-1 PGA.0.0 |
Last hit showing up incorrectly in Rule Viewer and TQL queries when the time zone of the user is different from the server . The value is out by one day when compared to the revision details. |
TOS-103173 Case 00157331 |
R24-1 R24-2 |
R24-2 PHF3.0.0 R25-1 PGA.0.0 |
Configured Azure Load Balancers do not appear on the topology map. |
TOS-102919 Case 00156269 |
R24-2 and earlier |
R24-2 PHF3.0.0 R25-1 PGA.0.0 |
Incorrect topology calculation for Cisco MPLS. The path appears as broken. |
TOS-102081 Case 00157392 |
R24-2 R25-1 |
R24-2 PHF3.0.0 R25-1 PGA.0.0 |
During path analysis, FQDN validation fails. |
TOS-101998 Case 00156561 |
R24-2 |
R24-2 PHF3.0.0 |
Login fails when password contains UTF-8 characters Error message: 403 Invalid Credential |
TOS-101615 Case 00155749 |
R24-2 |
Designer suggests creating duplicate rules for Check Point devices. |
|
TOS-98501 Case 00152638 |
R24-2 R24-1 |
R24-2 PHF2.0.0 |
For very large Panorama hierarchies, Designer debug tool get stuck. |
TOS-101258 Case 00156841 |
R24-2 R24-1 |
R24-2 PHF2.0.0 |
Upgrade to R24-1 PHF4.0.0 failed. Error: Upgrade has encountered a problem in step: "Clean old releases" due to: MANIFEST_UNKNOWN. |
TOS-101361 Case 00156782 |
R24-2 R24-1 |
R24-2 PHF2.0.0 |
Deprecated compliance risk calculations failed on OPM devices causing failure to risk calculations. |
TOS-101358 Case 00152134 |
R24-2 R24-1 |
R24-2 PHF2.0.0 R25-1 PGA.0.0 |
Dynamic topology data retrieval is slow because the management table is not cached. |
TOS-101243 Case 00148842 |
R24-2 R24-1 |
R24-2 PHF2.0.0 |
Rules are deleted and recreated, causing the rule documentation to be deleted. |
TOS-101113 Case 00154866 |
R24-2 |
R24-2 PHF2.0.0 |
TOS encounters a Null Pointer Error in Designer when the Target field contains a device without a name saved in the database. |
TOS-101096 Case 00156460 |
R24-1 |
R24-2 PHF2.0.0 R25-1 PGA.0.0 |
Backup fails. Error message: Insufficient disk space on minio Dir |
TOS-100812 Case 00135789 |
R24-2 R24-1 R23-2 R23-1 |
R24-2 PHF2.0.0 |
Designer creates new rules below the cleanup rule, resulting in errors when installing shadowing. |
TOS-100805 Case 00154590 |
R24-2 R24-1 |
R24-2 PHF2 R25-1 PGA |
The "Get Network Objects," "Get Server," "Get Servers," "Get Service," and "Get Services" API functions do not include servers or services cloned via SecureApp in their responses. |
TOS-100776 TOS-101091 Case 00148349 |
R24-2 R24-1 |
R24-2 PHF2 R25-1 PGA |
Fortinet devices appear in Monitored Devices with message Error: SSL failed. See instructions in Using Local DNS Over Fortigate DNS. |
TOS-100741 Case 00142647 |
R24-2 R24-1 |
R24-2 PHF2.0.0 |
For a network object query, the API output is empty. |
TOS-100718 Case 00150264 |
R24-1 R24-2 R25-1 |
R24-2 PHF2.0.0 R25-1 PGA.0.0 |
Path analysis queries returns incorrect results for Check Point devices configured with Star communities because of missing VPN routing information in the revision data. |
TOS-100137 Case 00099368 |
|
R24-2 PHF2.0.0 R24-1 PHF4.1.0 |
Upgrade from earlier release of TOS Aurora fails. Logs contain error message connection to server at "stolon-sc-svc" (IP), port 5432 failed |
TOS-100065 Case 00154590 |
R24-1 R24-2 |
R24-2 PHF2.0.0 R23-2 PGA.0.0 R25-1 PGA.0.0 |
For SecureApp, resolved an issue in which searching for a cloned server via API returns data from the original server, even if the cloned server has been modified since cloning. |
TOS-100063 Case 00149724 00155887 |
R24-1 R24-2 |
R24-2 PHF2.0.0 R25-1 PGA.0.0 |
VIP objects, with IPv6 addresses without mapped IP, cause an error when parsing the revision. |
TOS-99986 Case 00151330 |
R24-1 R24-2 |
R24-2 PHF2.0.0 |
SecureChange users are receiving an error message saying they are unauthorized to access the page they are on. Error message: User is not authorized to see this page |
TOS-99837 Case 00153052 |
R24-2 R24-1 R23-2 R23-1 |
R24-2 PHF2.0.0 R25-1 PGA.0.0 |
The STRE Shadowed Rules report returns a bad request error when there are unprocessed revisions in the SecureTrack database. Error message: 400 bad request |
TOS-99530 Case 00150824 |
R24-1 R24-2 |
R24-2 PHF2.0.0 R25-1 PGA.0.0 |
For Azure virtual WAN, there is a routing issue. Log message: Cannot find connected device with VirtualApplianceIp: <IP> , Urouted! |
TOS-99122 Case 00147222 |
R24-2 R24-1 R23-2 R23-1 R22-2 |
R24-2 PHF2.0.0 R25-1 PGA.0.0 |
Rule Viewer does not show the source for some rules on Fortigate devices with a user group and object group that share the same name. Error message: This data cannot be displayed at the moment. |
TOS-98820 Case 00152855 |
R24-2 R24-1 R23-2 |
R24-2 PGA.0.0 |
When a modify group change is already implemented on a device, if you run redesign on the change request, an error is displayed to the user instead of providing the "fully implemented" result. Error message: An error occurred. Please contact your system administrator for help. |
TOS-101638 TOS-99324 Case 00157014 00153952 |
R23-2 R24-1 R24-2 |
R24-2 PHF1.2.0 R24-2 PHF2.0.0 R25-1 PGA.0.0 |
SecureChange is inaccessible. |
TOS-99521 Case 00138877 |
R23-2 R24-1 R24-2 |
R24-2 PHF1.0.0 R25-1 PGA.0.0 |
Auto-verifier needlessly waits for a new revision, after no provisioning took place, and times out. |
TOS-97897 Case 00149835 |
R24-1 R24-2 |
R24-2 PHF1.0.0 |
For Cisco FMC devices, groups with literal wildcards cause the revision to fail. |
TOS-98443 Case 00152155 |
R24-1 R24-2 |
R24-2 PHF1.0.0 |
Cisco ACI cannot retrieve a revision. Error: <error code="403" text="Token was invalid (Error: Invalid input token data)"/> |
TOS-97683 Case 00149835 |
R24-1 R24-2 |
R24-2 PHF1.0.0 |
FMC devices that use legacy UI configured with literal subnets, which contain white spaces at beginning or end, cause the revision to fail. |
TOS-98556 Case 00151883 |
R24-1 R24-2 |
R24-2 PHF1.0.0 |
After an upgrade to R24-2 with more than 500 devices, running Verifier returns the following error: Error message: "No revisions were received for this target device (0)" |
TOS-98214 Case 00150752 |
R24-1 R24-2 |
R24-2 PHF1.0.0 |
On Cisco ASA devices, revisions are associated with the wrong accounts in Change Viewer. |
TOS-97827 Case 00146653 00149146 |
R23-2 R24-1 R24-2 |
R24-2 PHF1.0.0 R25-1 PGA.0.0 |
Rule Viewer's Last Hit field displays inaccurate length of time. |
TOS-99091 Case 00147952 |
R24-2 |
R24-2 PHF1.0.0 |
Upgrade procedure gets stuck on the bridge-scheduler validation. |
TOS-96071 Case 00148677 |
R24-2 |
R24-2 PHF1.0.0 |
When the network contains two secured hubs, path analysis shows incorrect data. |
TOS-97557 Case 00138877 |
R23-2 R24-1 R24-2 |
R24-2 PHF1.0.0 |
For FMG devices, tickets get stuck and cannot progress unless adjusted manually. |
TOS-97969 Case 00151207 |
R24-1 R24-2 |
R24-2 PHF1.0.0 |
Sorting by the “Last Update” column in the Tickets table causes rows to appear out of order when some tickets have update dates in the UTC time zone without milliseconds. |
TOS-99238 TOS-99623 Case 00152155 |
R24-1 R24-2 |
R25-1 PGA.0.0 R24-2 PHF1.0.0
|
Revisions cannot be retrieved from an ACI 5.3 device configured with a transparent proxy in SecureTrack. |
TOS-97784 Case 00148296 |
R24-1 R24-2 |
R25-1 PGA.0.0 R24-2 PHF1.0.0 |
Exporting the Audit trail report fails due to a Null Pointer Exception. |
TOS-97036 Case 00141223 |
R23-2 R24-1 R24-2 |
R24-2 PHF1.0.0 |
Ticket dependency calculations for group modification tickets on Check Point Devices causes the SecureTrack server to crash due to lack of memory. |
TOS-96301 Case 00148819 |
R24-1 R24-2 |
R24-2 PHF1.0.0 |
Rules for Cisco XR Routers are missing in Rule Viewer, and in the Compare Revisions page > Rules tab. This occurs when the interface is configured with “!” before the associated Access Control List (ACL). |
TOS-96177 Case 00148687 |
R23-2 R24-1 R24-2 |
R24-2 PHF1.0.0 |
Parsing fails to identify SD-WAN routes for Cisco Routers when the output returned from the router starts with information unrelated to the actual routing data. Log message: Finish parsing content. evpn route count: 0. |
TOS-99577 TOS-99615 TOS-99685 TOS-99682 Case 00153213 |
R24-1 R24-2 |
R24-1 PHF4.1.0 R24-2 PHF1.0.0
|
After running tos dr switch as part of Disaster Recovery, the cluster does not return to a healthy state. Error messages include:
|
TOS-99181 TOS-99182 Case 00154081 |
R24-1 R24-2 |
R24-1 PHF4.1.0 R24-2 PHF1.0.0 |
TOS install and upgrade procedures fail with DNS error message when DNS is configured correctly. Error message: ERROR DNS misconfiguration: lookup test-tufin.local on xx.xx.xx.x:xx: server misbehaving In R24-1, only relevant for PHF4.0.0. |
TOS-96848 TOS-96849 Case 00146741 |
R24-1 R24-2 |
R24-1 PHF4.0.0 R24-2 PHF1.0.0 |
After upgrading to R24-1, syslog change manager crashes. |
TOS-96490 Case 00146667 |
R24-1 R24-2 |
R24-1 PHF4.0.0 R24-2 PHF1.0.0 R25-1 PGA.0.0 |
Prisma/GPCS RN-SPN object does not appear in the Topology Map. |
TOS-96206 TOS-96207 Case 00139132 00144092 |
R24-1 R24-2 |
R24-1 PHF4.0.0 R24-2 PHF1.0.0 R25-1 PGA.0.0 |
Error page appears shortly after logging in to TOS. Additional information: neo4j timeout error appears in log. |
TOS-96191 TOS-96322 TOS-96323 Case 00148349 |
R23-1 R23-2 R24-1 R24-2 |
R24-1 PHF4.0.0 R24-2 PHF1.0.0 R25-1 PGA.0.0 |
Fortinet firewalls appear connected, but the ADOMs and VDOMs under it show a connection error. |
TOS-96028 TOS-96064 Case 00148528 |
R24-1 R24-2 |
R24-1 PHF4.0.0 R24-2 PHF1.0.0 |
Last hit not working for Azure Firewall rules. |
TOS-93139 Case 00145499 |
R24-1 |
R24-1 PHF4.0.0 |
The number of pods exceeds the Kubernetes limit of 110. |
TOS-92774 Case 00144198 |
R24-1 |
R24-1 PHF4.0.0 |
Clean install of R24-1 shows no TLS 1.2 ciphers; however, if you upgrade from a previous version to R24-1, the TLS 1.2 ciphers still exist. |
TOS-93485 TOS-93476 Case 00146342 |
R24-1 |
R24-1 PHF4.0.0 |
Scheduled reports are not shown in the report repository. |
TOS-96065 TOS-96064 TOS-96028 Case 00148528 |
R24-1 R24-2 |
R24-1 PHF4.0.0 R24-2 PHF1.0.0 |
No last hits are received on the Azure Firewall due to a case sensitivity issue between the Workspaces API and the Diagnostic Settings API for the workspaceID field. |
TOS-96193 TOS-96306 Case 00147700 |
R24-1 R24-2 |
R24-1 PHF4.0.0 R24-2 PHF1.0.0 |
Import of Panorama devices to TOS fails. Error message: CSM error:General Failure |
TOS-95518 Case 00146252 |
R24-1 R24-2 |
R24-1 PHF4.0.0 R24-2 PHF1.0.0 R25-1 PGA.0.0 |
For Cisco ACI devices, path analysis shows incorrect contracts when clicking on a matched rule. |
TOS-96233 TOS-96234 Case 00128075 |
R24-1 R24-2 |
R24-1 PHF4.0.0 R24-2 PHF1.0.0 |
For Azure VNETS, subnets are missing from the topology map. |
TOS-96339 TOS-96546 Case 00149627 |
R24-1 R24-2 |
R24-1 PHF4.0.0 R24-2 PHF1.0.0 |
Provisioning to a VMware NSX device fails when the rule contains an internet object. |
TOS-96576 TOS-96659 Case 00142305 |
R23-2 R24-1 R24-2 |
R24-1 PHF4.0.0 R24-2 PHF1.0.0 R25-1 PGA.0.0 |
In large environments, dashboard widgets USP Compliance and Cleanup are missing data due to Neo4j timeout. Error message: Something went wrong. |
TOS-97050 Case 00149833 |
R24-1 |
R24-1 PHF4.0.0 |
Some non-tiered perpetual licenses installed on certain time-zones cause workflows in TOS to be disabled. |
TOS-94481 Case 00141815 |
R23-2 R24-1 R24-2 |
R25-1 PGA.0.0
|
TOS restore fails because of a corrupt postgres database index. |
TOS-95267 Case 00148423 |
R24-1 |
R24-1 PHF4.0.0 |
Designer fails to run on Cisco ASA devices causing a timeout error due to a service_group with type 0. Error message: Designer fails with error (attached). |
TOS-95438 TOS-95439 TOS-95440 Case 00148600 |
R24-1 R24-2 |
R24-1 PHF4.0.0 R23-2 PHF1.0.0 |
The Topology Map does not display AWS cloud data if there is no main route table for one of the VPCs, and the VPC has a Transit Gateway (TGW) attachment connected to a subnet without a routing table. |
TOS-95980 TOS-96177 TOS-96178 Case 00148687 |
R23-2 R24-1 R24-2 |
R24-1 PHF4.0.0 R24-2 PHF1.0.0 |
Parsing fails to identify SD-WAN routes for Cisco Routers when the output returned from the router starts with information unrelated to the actual routing data. Log message: Finish parsing content. evpn route count: 0. |
TOS-96198 TOS-96301 TOS-96302 Case 00148819 |
R24-1 R24-2 |
R24-1-PHF4.0.0 R24-2 PHF1.0.0 |
Rules for Cisco XR Routers are missing in Rule Viewer, and in the Compare Revisions page > Rules tab. This occurs when the interface is configured with “!” before the associated Access Control List (ACL). |
TOS-96402 Case 00149553 |
R24-1 |
R24-1 PHF4.0.0 |
Scheduled topology sync runs a day late. |
TOS-96543 TOS-96621 TOS-96628 Case 00147151 |
R23-2 R24-1 R24-2
|
R24-1 PHF4.0.0 R24-2 PHF1.0.0 R25-1 PGA.0.0 |
last hit is not being updated in Rule Viewer for some large devices when multiple devices with many rules are added. |
TOS-93802 TOS-93738 Case 00145647 |
R24-1 |
R24-1 PHF4.0.0 R24-2 PGA.0.0
|
For Cisco devices, incorrect paths are shown in the Topology Map when there are multiple MPLS-VPN next hops. |
TOS-94073 TOS-93079 Case 00137167 |
R24-1 |
R24-1 PHF4.0.0 R24-2 PGA.0.0 |
SecureApp application accepts logs that should be excluded according to the configured conditions. |
TOS-94265 TOS-94734 Case 00143135 |
R24-1 |
R24-2 PGA.0.0 |
For Juniper SRX devices, shadowing rules load a blank page in Rule Viewer. In Compare Revision, the Source and Destination are empty. |
TOS-94254 TOS-94507 Case 00143746 |
R23-2 R24-1 |
R24-1 PHF4.0.0 R24-2 PGA.0.0 |
FQDN objects in Check Point devices fail to resolve, preventing their use in SecureChange tickets. |
TOS-93621 TOS-93622 TOS-93623 Case 00145833 |
R24-1 |
R24-1 PHF4.0.0 R24-2 PGA.0.0 |
Revisions cannot be retrieved from Cisco FMC devices due to intermittent 401 errors from the device API. Error messages: Access token invalid, unknown error, unable to get configuration |
TOS-95140 TOS-95141 TOS-95142 Case 00148825 |
R23-2 R24-1 |
R24-1 PHF4.0.0 R24-2 PGA.0.0 |
topology-service crashes when there are large amounts of generic routes. |
TOS-94215 TOS-94932 Case 00140393 |
R23-1 R24-1 |
R24-2 PGA.0.0 |
When attempting to remove access for a NAT rule with multiple source zones on a FortiManager device , Designer displays an incorrect error message. Incorrect error message: Remove Access suggestions for NAT rules are not supported. Correct error message: No suggestions for this request. |
TOS-95315 TOS-95560 Case 149061 |
R24-1 |
R24-2 PGA.0.0 |
LDAP users are unable to access SecureChange from SecureTrack despite having the appropriate permissions and SSO enabled. Error message: You do not have permission to access the requested page |
TOS-93590 TOS-93872 Case 00140802 |
R22-2 R23-1 R24-1 R24-2 |
R24-2 PGA.0.0 |
Destination zones are removed from USP exception calculations after they are edited. |
TOS-95285 TOS-95281 TOS-95341 Case 00147230 |
R23-1 R23-2 R24-1 |
R24-1 PHF4.0.0 R24-2 PGA.0.0 |
Designer gave incorrect suggestions for Fortimanager devices with central NAT enabled. |
TOS-95423 TOS-95314 TOS-95424 Case 00149133 |
R22-2 R23-1 R23-2 R24-1 |
R24-2 PGA.0.0 R24-1 PHF4.0.0 |
Device revisions fail to appear in TOS when multiple versions are received at once. |
TOS-93843 TOS-93511 TOS-93844 TOS-96295 TOS-96755 TOS-96756 Case 00146745 |
R24-1 R24-2 R25-1 |
R24-2 PGA.0.0 R24-2 PHF1.0.0 R24-1 PHF4.0.0 |
Provisioning task fails in Designer after 10 minutes. |
TOS-94127 TOS-94126 TOS-94128 Case 00147293 |
R24-1 R25-1 |
R24-2 PGA.0.0 R24-1 PHF4.0.0 |
NSX-T 4.1 objects do not appear in the Compare Revisions tab. |
TOS-94357 TOS-93516 TOS-94358
Case 00143648 |
R24-1 R25-1 |
R24-2 PGA.0.0 R24-1 PHF4.0.0 |
Verifier returns only one result for each Cisco FMC device, even when there are multiple relevant policies. As a consequence, incorrect ticket closures may occur. |
TOS-94803 TOS-94103 Case 00136029 |
R23-2 R24-1 |
R24-2 PGA.0.0 R24-1 PHF4.0.0 |
SecureApp performance slows after performing an action with a Server Group that contains several thousand servers. |
TOS-94743 Case 00147146 |
R24-1 |
R24-2 PGA.0.0 R24-1 PHF4.0.0 |
Policy Change Notifications syslogs are not generated properly when defining a remote server with FQDN. |
TOS-95753 TOS-95482 TOS-95755 Case 00146974 |
R24-1 R25-1 |
R24-2 PGA.0.0 R24-1 PHF4.0.0 |
SecureTrack cannot retrieve information about rules using this API call: https://<TUFIN_BASE_URL>/securetrack/api/devices/<device_id>/rules/<id>/documentation |
TOS-94002 TOS-93525 TOS-93526 TOS-93531 Case 00146427 |
R22-2 R23-1 R23-2 R24-1 |
R24-1 PHF3.0.0 R24-2 PGA.0.0 |
Upgrade to TOS R24-1 fails when database has saved SecureChange search queries that contain parameters with null values. ![]() upgrade failed on Error in /opt/tufin/logs/services/upgrade-manager/scw_upgrade_log 2024-05-29T20:12:48,298 DEBUG [c.t.s.u.BaseUpgrade.readFromResultSet] (main:[]) readFromResultSet query= select id, name, user_id from query order by user_id, lower(name) DESC, last_used DESC NULLS LAST; 2024-05-29T20:12:48,298 DEBUG [c.t.s.u.BaseUpgrade.logParams] (main:[]) params= 2024-05-29T20:12:48,310 ERROR [c.t.s.u.UpgradeProcedure.upgradeFailed] (main:[]) Failed to perform upgrade from version 23.2_GA java.lang.NullPointerException: null cannot be cast to non-null type kotlin.Long at com.tufin.securechange.upgrade.UpgradeTo_24_1_RC1.toUserId(UpgradeTo_24_1_RC1.kt:154) ~[tos2-upgrade.jar:?] at com.tufin.securechange.upgrade.UpgradeTo_24_1_RC1.updateQueriesName(UpgradeTo_24_1_RC1.kt:53) ~[tos2-upgrade.jar:?] at com.tufin.securechange.upgrade.UpgradeTo_24_1_RC1.handleQueryTable(UpgradeTo_24_1_RC1.kt:36) ~[tos2-upgrade.jar:?] at com.tufin.securechange.upgrade.UpgradeTo_24_1_RC1.execute(UpgradeTo_24_1_RC1.kt:24) ~[tos2-upgrade.jar:?] at com.tufin.securechange.upgrade.UpgradeProcedure.upgradeToSpecificVersion(UpgradeProcedure.java:287) [tos2-upgrade.jar:?]at com.tufin.securechange.upgrade.UpgradeProcedure.executeUpgradeFrom(UpgradeProcedure.java:263) [tos2-upgrade.jar:?] at com.tufin.securechange.upgrade.UpgradeProcedure.execute(UpgradeProcedure.java:187) [tos2-upgrade.jar:?] at com.tufin.securechange.upgrade.UpgradeProcedure.main(UpgradeProcedure.java:296) [tos2-upgrade.jar:?] 2024-05-29T20:12:48,314 ERROR [c.t.s.u.UpgradeProcedure.upgradeFailed] (main:[]) Performing Rollback |
TOS-82487 TOS-83623 TOS-76514 |
R23-1 |
R23-1 PHF3.0.0 R24-1 PGA.0.0 R24-2 PGA.0.0 |
There is an issue with Designer when submitting an access request. Message: Cannot modify the initial default policy. You need to associate a policy with <FW_Name>. |
TOS-89207 Case 00131167 |
R23-1 R23-2 R24-1 |
R24-2 PGA.0.0 |
In an LDAP group with multiple users, some users cannot log in to TOS Aurora. |
TOS-92105 TOS-92096 Case 00146422 |
R24-1 |
R24-1 PHF3.0.0 R24-2 PGA.0.0 |
Revisions cannot be fetched from Cisco Layer 2 switches. Error message: Error occurred when pulling configuration from the device: Wrong arguments |
TOS-92930 TOS-92931 TOS-93098 Case 00141080 |
R24-1 |
R24-1 PHF3.0.0 R24-2 PGA.0.0 |
Azure rule usage data cannot be retrieved when one of the workspaces in the Azure subscription does not have a firewall. |
TOS-85264 Case 00132604 |
R23-2 R24-1 |
R24-2 PGA.0.0 |
The SecureTrack user interface is not responsive and backups fail. |
TOS-88663 TOS-86210 TOS-88662 Case 00135105 Case 00134604 |
R23-1 R23-2 R24-1 |
R23-2 PHF3.0.0 R24-1 PHF1.0.0 R24-2 PGA.0.0 |
A memory leak in the queue-server process causes the device-collector container to receive a signal segmentation violation (SIGSEGV) and terminate. |
TOS-87755 Case 00130078 |
R23-1 R23-2 R24-1 |
R24-2 PGA.0.0 |
Tufin MIB file does not contain records of all traps that could be sent to the SNMP server. |
TOS-92217 Case 00142229 00144867 |
R24-1 |
R24-2 PGA.0.0 |
TOS logs users out after one minute when LDAP names contain special characters. |
REL-940 TOS-93395 Case 00146342 |
R24-1 PHF2.0.0 only |
R24-1 PHF2.1.0 R24-2 PGA.0.0 |
Affects R24-1 PHF2.0.0 only. Preconfigured and new scheduled SecureTrack reports in SecureTrack will not run. STRE reports are not affected. |
TOS-85527 Case 00132604 |
R23-2 R24-1 |
R24-2 PGA.0.0 |
Policy configuration files cannot be uploaded via the CLI for offline analysis |
TOS-88908 Case 00128822 |
R23-1 R23-2 R24-1 |
R24-2 PGA.0.0 |
Designer is not ignoring rules with the legacy automation attribute. |
TOS-91546 TOS-91010 Case 00140569 |
R23-2 R24-1 |
R24-1 PHF3.0.0 R24-2 PGA.0.0 |
The connection between Azure hubs is not displayed in the Topology Map. |
TOS-92216 Case 00139204 |
R23-2 R24-1 |
R24-1 PHF3.0.0 R24-2 PGA.0.0 |
Topology information cannot be retrieved for AWS gateway load balancers when there is a NAT object on one of the firewall devices in the target group |
TOS-92626 TOS-92664 Case 00144173 |
R23-2 R23-1 |
R24-1 PHF3.0.0 R24-2 PGA.0.0 |
Cisco ASA service groups are parsed incorrectly when revisions from offline versions are uploaded. Critical messages appear in the device log files. |
TOS-92748 Case 00137338 |
R23-1 R23-2 R24-1 |
R24-1 PHF3.0.0 R24-2 PGA.0.0 |
For Fortinet devices, after running Designer for the first time and selecting Update Devices, there is an error. Error message: Remove network object <object name> from existing group < group name>. |
TOS-91732 Case 00145833 |
R24-1 |
R24-1 PHF3.0.0 R24-2 PGA.0.0 |
For Cisco FMC device logs, received an authentication token for the API, but could not get a revision. Error message: 401 invalid session |
TOS-92473 TOS-93494 TOS-93495 Case 00143723 |
R24-1 |
R24-1 PHF3.0.0 R24-2 PGA.0.0 |
Source and destination fields are empty in Compare Revision and appear as N/A in Rule Viewer. |
TOS-91198 TOS-92353 Case 00135272 |
R23-2 R24-1 |
R24-1 PHF3.0.0 |
Tickets cannot be split into smaller tickets when initiated from SecureApp. |
TOS-92113 TOS-92291 Case 00142645 |
R23-2 R24-1 |
R24-1 PHF3.0.0 R24-2 PGA.0.0 |
SecureTrack cannot retrieve revisions from Cisco Meraki devices when the device contains a WAN interface with a missing gateway. The user interface shows that the device is being monitored correctly. |
TOS-90268 Case 00137969 |
R24-1 R23-2 |
R24-1 PHF3.0.0 |
Designer suggests creating new network objects on Juniper SRX devices that replace existing network objects. The new network objects have larger/smaller subnets. |
TOS-90846 TOS-64433 Case 00136704 |
R24-1 R23-2 |
R24-1 PHF3.0.0 |
Revisions from Juniper SRX devices are missing NAT objects with 'any' in the rule source or destination. |
TOS-91598 |
R24-1 |
R24-1 PHF3.0.0 |
Azure vnets cannot be imported when there is a proxy server with the local DNS disabled configured in the Azure management device. |
TOS-90662 TOS-90551 Case 00141900 |
R24-1 |
R24-1 PHF3.0.0 R24-2 PGA.0.0 |
SecureTrack cannot monitor Cisco layer 3 devices with a custom login prompt. |
TOS-90763 TOS-91141 Case 00140256 |
R23-1 R23-2 R24-1 |
R24-1 PHF3.0.0 R24-2 PGA.0.0 |
SecureChange tickets are displayed incorrectly in the user interface (for example, closed tickets appear open) because of an indexing issue. |
TOS-91048 TOS-91828 Case 00139686 |
R23-2 R24-1 |
R24-1 PHF3.0.0 R24-2 PGA.0.0 |
Permitted traffic to Panorama devices is shown as blocked due to a mismatch between the predefined services in TOS and the predefined service on the device. |
TOS-89953 TOS-89954 Case 00139616 |
R22-2 R23-1 R23-2 R24-1 |
R24-1 PHF3.0.0 |
For Cisco ASA devices on a remote collector, rule last hit information is inaccurate. |
TOS-90842 Case 00142404 |
R24-1 |
R24-1 PHF3.0.0 |
The content of ACI objects in Panorama dynamic access groups does not appear in TOS when the device Is configured with more than one IP address (on the Panorama side). |
TOS-90842 Case 00142404 |
R24-1 |
R24-1 PHF3.0.0 |
The content of ACI objects that appear within Panorama dynamic access groups does not appear in TOS. |
TOS-90740 Case 00141155 |
R24-1 |
R24-1 PHF3.0.0 |
Installation crashes. |
TOS-90938 TOS-90963 Case 00141793 |
R23-2 R24-1 |
R24-1 PHF3.0.0
|
Device revisions generate errors for Authorization and Ticket Mapping when a deleted object exists a in closed ticket. |
TOS-91570 TOS-91830 Case 00136813 |
R23-2 R24-1 |
R24-2 PGA.0.0 |
SecureApp's application history is incorrect for server groups whose connections were updated via API. |
TOS-92074 TOS-92117 Case 00143723 |
R24-1 |
R24-1 PHF3.0.0 |
For NSX devices, source and destination appear as N/A in Rule Viewer. |
TOS-90949 Case 00141220 |
R23-2 R24-2 R24-2 |
R24-2 PGA.0.0 |
Provisioning fails when special character ü appears in the rule name from SecureApp. |
TOS-88465 TOS-88282 Case 00137095 |
R23-1 |
R24-1 PHF3.0.0 R24-2 PGA.0.0 |
For very large installations, the |
TOS-90327 Case 00139216 |
R23-2 |
R23-2 PHF2.0.0 R24-1 PHF3.0.0 |
Designer fails to update Panorama configuration in SecureChange. After clicking UPDATE DEVICE, the following error appears: Unexpected error, please, try again |
TOS-90335 Case 00141220 |
R23-2 |
R23-2 PHF4.1.0 R24-1 PHF3.0.0 |
For Fortinet devices, Designer calculations are timing out when the rule name is long and contains special characters. |
TOS-90739 Case 00136704 |
R23-2 R24-1 |
R23-2 PHF1.0.0 R24-1 PHF3.0.0
|
NAT objects (Any, Any-IPv4, and Any-IPv6) do not appear in NST tables. |
TOS-90786 TOS-90816 Case 00142649 Case 00145231 Case 00145677 |
R24-1 |
R24-1 PHF3.0.0 |
Topology Map synchronization does not work after the |
TOS-90877 TOS-90964 Case 00142644 |
R23-2 |
R24-1 PHF3.0.0 |
After processing a request to delete unused tickets, Verifier results are empty. |
TOS-91360 Case 00142762 |
R23-2 |
R24-1 PHF3.0.0 |
FQDNs are getting removed from the rule when disabling a rule with Rule decommission workflow. |
TOS-91784 Case 00143903 |
R23-2 |
R24-1 PHF3.0.0 |
Upgrading to R24-1 PHF2.0.0 failed. Error message: Failed to execute topology-facade API call. |
TOS-91784 TOS-91847 Case 00143903 |
R23-2 R24-1 |
R24-1 PHF3.0.0 R24-2 PGA.0.0 |
Upgrading to R24-1 PHF2.0.0 failed. Error message: Failed to execute topology-facade API call. |
TOS-90686 TOS-90685 TOS-90699 |
R23-2 |
R23-2 PHF3.2.0 R24-1 PHF2.0 R24-2 PGA.0.0 |
The tos snapshot restore command fails on TOS R23-2 PHF3.1.0. |
TOS-90249 TOS-90413 Case 00140888 |
R23-1 R23-2 R24-1 |
R24-1 PHF2.0.0 R24-2-PGA.0.0 |
Netscreen devices managed by Telnet fail to receive revisions. |
TOS-90122 TOS-90644 Case 00140908 |
R23-2 R24-1 |
R24-1 PHF2.0.0 R24-2 PGA.0.0 |
Gateway load balancers cannot be imported when traffic is blocked from one or more AWS regions. |
TOS-88758 TOS-88792 Cases 00138801 00136903 00141673 |
R23-2 R24-1 |
R24-1 PHF2.0.0 R24-2 PGA.0.0 |
Fortinet ADOM fails to retrieve a revision when there is a space character in the FQDN name. |
TOS-88009 TOS-90200 Case 00133017 |
R23-1 R24-1 |
R24-1 PHF2.0.0 |
Tickets page loads slowly if there are more than 10,000 tickets present. In addition to improving performance, users can change the default amount of tickets loaded to a lower number. |
TOS-88858 TOS-89238 Case 00136095 |
R23-2 R24-1 |
R24-1 PHF2.0.0 R24-2 PGA.0.0 |
Path analysis queries get stuck and do not return results. |
TOS-89278 TOS-89279 Case 00138255 |
R23-2 R24-1 |
R24-1 PHF2.0.0 R24-2 PGA.0.0 |
Cleanup rest API call returns General error when getting fully shadowed or disabled rules without including the start and count parameters. |
|
R20-1 and later |
Not fixed |
When logging into TOS, a Vimeo cookie is placed in the browser. |
TOS-90147 TOS-90241 TOS-90297 TOS-90562 Case 00140747 Case 141734 |
R24-1 |
R24-1 PHF2.0.0 R24-2 PGA.0.0 |
Revisions cannot be retrieved from Palo Alto devices. In the Compare Revisions page data for these devices is incomplete, and in the Administration > Status page imported Prisma objects show: Error: unknown error. |
TOS-90248 00141900 TOS-90154 TOS-90192 Case 00139664 |
R24-1 |
R24-1 PHF2.0.0 |
Path analysis is incorrect for Cisco VXLAN when the interfaces all share the same IP address and are in different VRF tables. |
TOS-80967 Case 00123548, 00128040, 00128578, 00133201, 00136137, 00141218 |
R23-2 R24-1 |
R23-2 PHF1.0.0 |
For FortiGate 7.2.6v devices, cannot get a new revision. |
TOS-89913 TOS-89773 Case 00140235 |
R23-2 |
R24-1 PHF2.0.0 |
Unable to open a ticket for a workflow, that includes a script, from the "My request" page. Error message: Could not initialize proxy - no Session |
TOS-89372 TOS-89373 Case 00139132 |
R23-2 R24-1 |
R24-1 PHF2.0.0 |
Unable to add Fortinet ADOM when the comment includes an array of strings. Error message: Fail to unmarshal data. |
TOS-89233 TOS-89253 Case 00136569 |
R24-1 |
R24-1 PHF2.0.0 |
Unable to import virtual systems (VSYS) from the PanOS device when the version is 11 or higher. |
TOS-88624 TOS-87559 Case 00135252 |
R23-2 R24-1 |
R24-1 PHF2.0.0 |
Cisco ASA device fails to provision when editing a rule which contains DM_INLINE group even though Designer suggests using it. |
TOS-88475 TOS-88193 Case 00136571 |
R23-2 R24-1 |
R24-1 PHF2.0.0 |
Knowledge Center is unavailable when not connected to the internet. Error message: 503 Service Temporarily Unavailable |
TOS-88875 Case 00137263 |
R23-1 R24-1 |
R24-1 PHF2.0.0 |
Designer cannot create an object with NAT information if it was added from the Object Browser, from a VIP/MIB NAT policy filter, or from the results of path analysis if there is NAT in the path. Error message: <OBJECT NAME> is defined in Zone A and cannot be used in Zone B. |
TOS-90248 Case 00141900 |
R24-1 |
R24-1 PHF2.0.0 |
Unable to connect to Layer 3 devices when using a custom login prompt. |
TOS-89950 TOS-90055
|
R24-1 |
R24-1 PHF2.0.0 |
After upgrading to R24-1 on a machine with IPv6 configured, the Topology map fails to load and displays the error message "The server is temporarily unable to service your request due to maintenance downtime or capacity problems. Please try again later.” |
TOS-89455 TOS-89679 Case 00139534 |
R23-2 R24-1 |
R24-1 PHF2.0.0 |
For very large devices, TOS failed to migrate device from the Central Cluster to the Remote Collector. |
TOS-89275 TOS-89442 Case 00134503 |
R23-1 R23-2 R24-1 |
R24-1 PHF2.0.0 |
FMC devices cease to function, with tickets failing to process and an error message “Unknown error.” Evidence of memory leaks appear in the logs. |
TOS-89166 TOS-88655 Case 00137340 |
R23-2 R24-1 |
R24-1 PHF2.0.0 |
When running a SecureApp ticket with the internet as a source or destination, Designer fails. |
TOS-88686 TOS-88839 Case 00137782 |
R23-1 R23-2 R24-1 |
R24-1 PHF2.0.0 |
The Cleanup Browser, Object Lookup, and Change Browser pages fail to perform device calculations when a large number of devices are present. |
TOS-87987 TOS-88199 Case 00136023 |
R23-2 R24-1 |
R24-1 PHF2.0.0 |
Running path analysis when the cloud is the only end point causes broken path. |
TOS-87466 No case |
R22-2 R23-1 R23-2 R24-1 |
R24-1 PHF2.0.0 |
Tickets page always reverts to last saved query when navigating away from the page instead of keeping the query performed by the user. |
TOS-89211 TOS-89172 |
R23-1 R23-2 R24-1 |
R24-2 PGA.0.0 |
tos cluster snapshot create and tos cluster snapshot restore commands cannot be run on remote connector clusters. If you are upgrading TufinOS 3 to 4 on a remote collector cluster, you must use the procedure Upgrade TufinOS 3 to 4 Reinstall on Same VM, which requires reinstalling TOS. In R23-2 PHF3.1.0, R24-1 PHF2.0.0 and later versions of the same releases, these commands are blocked from running on remote clusters |
TOS-88660 TOS-88686 TOS-88839 Case 00137782 |
R23-1 R23-2 R24-1 |
R24-1 PHF1.0.0 |
When there are more than 15,000 devices, the SecureTrack Object Lookup page loads initial data, but no buttons work. |
TOS-87558 TOS-87566 Case 00135264 |
R24-1 |
R24-1 PHF1.0.0 |
For north-south, ACI-integrated Panorama paths, topology simulation yields an inaccurate security calculation. Error message: Request input is not supported |
TOS-87927 Case 00134578 |
R23-2 R24-1 |
R24-1 PHF1.0.0 |
When running Designer on a device which doesn’t support Provisioning “Not run” appears next to the device name in the SecureChange. |
TOS-85792 TOS-85806 Case 00128917 |
R23-1 R23-2 R24-1 |
R23-2 PHF3.0.0 R24-1 PHF1.0.0 |
SecureTrack can't retrieve topology data for Azure Virtual hubs when the next hop type is VPN_S2S_Gateway and there is a path with a range. |
TOS-87552 Case 00128408 |
R22-2 R23-1 R23-2 |
R23-2 PHF3.0.0 |
When running Designer on a Check Point device with an access request that is shadowing a different access request, Designer returns an error. Error message: Designer is unable to suggest changes for this device. |
TOS-86966 TOS-87046 Case 00131298 |
R23-1 R23-2 R24-1 |
R23-2 PHF3.0.0 R24-1 PHF1.0.0 R24-2 PGA.0.0 |
Cisco MPLS interfaces with a short name are parsed incorrectly and displayed as normal interfaces. |
TOS-87173 TOS-87371 Case 00136366 |
R23-2 R24-1 |
R23-2 PHF3.0.0 R24-1 PHF1.0.0 R24-2 PGA.0.0 |
Access-role and security zone objects are displayed as network objects in the CSV file that is created when exporting Unattached Network Objects from the Cleanup Browser. |
TOS-87256 TOS-87365 Case 00131298 |
R22-2 R23-1 R23-2 R24-1 |
R23-2 PHF3.0.0 R24-1 PHF1.0.0 R24-2 PGA.0.0 |
The New Revision report isn't being created when new revisions arrive in SecureTrack, and recipients aren't receiving an email. This occurs when the report is the only report, and it is generated for any changes to any devices. |
TOS-87380 TOS-87096 TOS-87381 Case 00133018 |
R22-2 R23-1 R23-2 R24-1 |
R23-2 PHF3.0.0 R24-1 PHF1.0.0 R24-2 PGA.0.0 |
The result returned by the security_zones api function is missing zone hierarchies |
TOS-87727 TOS-88373 TOS-87813 TOS-87814 Case 00135080 |
R23-2 R24-1 |
R23-2 PHF2.0.0 R24-1 PGA.0.0 R24-2 PGA.0.0 |
SecureTrack can't retrieve dynamic topology for logical routers belonging to NSX-T devices. cloud-topology-service app.log exception: Internal Server Error: null java.lang.NullPointerException: null at com.tufin.cloudtopology.service.builder.nsx.NsxInterfaceBuilder.containIpAddresses(NsxInterfaceBuilder.java:46) ~[classes/:?] |
TOS-87903 TOS-87904 Case 00135249 |
R22-2 R23-2 R24-1 |
R23-2 PHF2.0.0 R24-1 PHF1.0.0 |
Upgrade to R23-2 PHF1.0.0 fails due to license restriction errors. Error message: Upgrade service failed with the following errors:\nService tss failed with error: Failed due to license restrictions |
REL-903 Case 00138348 |
R23-2 R24-1 |
R23-2 PHF3.0.0 R24-1 PHF1.0.0
|
Users with external SSO Authentication lose access to SecureChange after upgrading to affected releases. |
TOS-87733 TOS-87652 Case 00136639 Case 00137992 |
R23-2 R24-1 |
R23-2 PHF3.0.0 R24-1 PHF1.0.0 |
When processing UI requests, TOS virtual network issues yield errors or delays in response. |
TOS-87583 TOS-87791 Case 00135634 |
R22-2 R23-1 R23-2 R24-1 |
R23-2 PHF3.0.0 R24-1 PHF1.0.0 |
SecureApp fails to add an application while trying to delete an application. |
TOS-87433 TOS-87562 TOS-87563 Case 00131110 |
R23-1 R23-2 R24-1 |
R23-2 PHF3.0.0 R24-1 PHF1.0.0 |
Some devices are missing in the path when inbound and outbound VRFs are different. |
TOS-87311 Case 00130377 |
R23-1 R23-2 |
R23-2 PHF3.0.0 |
Connection status is red when it should be green. |
TOS-87224 TOS-87369 Case 00135784 |
R23-1 R23-2 R24-1 |
R23-2 PHF3.0.0 R24-1 PHF1.0.0 |
Rule Change report does not send notification emails and is not saved in the repository. |
TOS-86215 Case 00134994 |
R23-1 R23-2 |
R24-1 PGA.0.0 |
When decommissioning a Juniper SRX device with global zone rules, Designer incorrectly includes these rules in its suggestions that can be provisioned. Provisioning global zone rules is not supported for SRX devices. Designer provides manual suggestions only. |
TOS-86210 TOS-88662 TOS-88663 Case 00135105 |
R23-1 R23-2 R24-1 |
R23-2 PHF3.0.0 R24-2 PGA.0.0 R24-1 PHF1.0.0 |
Device Collector container crashes with exit code 139 (SIGSEV). Related to memory leak on Queue_Server process. |
TOS-86064 TOS-86020 TOS-86065 Case 00135174 |
R23-1 R23-2 |
R23-2 PHF3.0.0 R24-1 PGA.0.0 |
Path analysis provides an incorrect path for Cisco devices when there is an MPLS route. |
TOS-85256 Case 00132604 |
R23-2 |
R24-1 PGA.0.0 |
SecureTrack user interface stops responding and displays the following message: Looks like something went wrong. Performance queries were enhanced to resolve this issue. |
TOS-85308 Case 00133746 |
R23-2 |
R24-1 PGA.0.0 |
TOS backup export from external storage is not working. |
TOS-86097 Case 00135594 |
R23-1 R23-2 |
R24-1 PGA.0.0 |
For Check Point devices, cannot create a rule name with more than 30 characters. |
TOS-81891 TOS-83443 TOS-82557 TOS-82556 |
R23-2 |
R23-2 PHF2.0.0 |
After restoring from a backup, you may experience one or more of the following: high CPU usage, slow response time, incorrect violation calculations, and other unexpected behavior. After upgrading, make a new backup. |
TOS-81736 TOS-81737 Case 00125837 |
R23-2 |
R23-2 PHF2.0.0 R24-1 PGA.0.0 |
On the Dashboard, Cleanup Trend data for devices with disabled or shadowed rules includes only the first 100 devices. |
TOS-80744 TOS-81930 Case 00127381 |
R23-2 |
R23-2 PHF2.0.0 |
After committing an update suggested by Designer, the commit status report for the ticket displays an end time that’s different from the ticket history. This causes inconsistencies between the Commit Status Report (available after clicking Commit) and the Ticket History and PDF Exports (available from the Ticket screen). |
TOS-79030 Case 00123865 |
R22-2 and later |
Not fixed |
Revisions cannot be processed for Check Point CMA devices that have ‘@’ in an object name. This can be resolved by removing the @ character from all object names in the policy and fetching the revision again. |
TOS-80793 TOS-83531 TOS-83611 Case 00121065 |
R23-2 |
R23-2 PHF2.0.0 |
For Fortinet FMG devices with a single policy that has over 140,000 rules, SecureTrack returns an out-of-memory error and cannot retrieve revisions. |
TOS-80822 TOS-81413 TOS-81585 Case 00115997 |
R23-2 |
R23-2 PHF2.0.0 |
Slow FMC syslog messages retrieval by SecureTrack due to logs full of prints by the syslog translator. |
TOS-81563 TOS-82008 TOS-82025 Case 00115997 |
R22-2 R23-1 R23-2 |
R23-2 PHF2.0.0 |
For Cisco FMC devices with more than 30,000 rules, translating FMC syslog traffic devices takes 50 EPS (events per second) instead of 5000 EPS. |
TOS-82067 TOS-82784 Case 00128589 |
R22-2 R23-1 R23-2 |
R23-2 PHF2.0.0 |
Following forced removal, devices still appear in the Device Viewer and Rule Viewer. |
TOS-82452 TOS-82577 Case 00130384 |
R23-2 |
R23-2 PHF2.0.0 |
For Cisco FMC devices, after a rule modification in SecureChange, the TRUST action for the rule changes to a BLOCK action on the device. |
TOS-83533 TOS-83235 Case 00131700 |
R23-2 |
R23- 2 PHF2.0.0 R24-1 PGA.0.0 |
Failure to import Meraki managed devices. |
TOS-82108 TOS-83235 Case 00125832 |
R22-2 R23-1 R23-2 |
R23-2 PHF2.0.0 |
Access list entry removal provisioning fails when there are extra spaces at the end of the remark in the configuration file for Cisco ASA devices. |
TOS-83918 TOS-84101 Case 00131106 |
R23-1 R23-2 |
R23-2 PHF2.0.0 |
Verifier returns a "User Network zone is not configured" message when the User Network zone has no subnet, but a child zone (of the User Network zone) contains a subnet. |
TOS-81698 TOS-81702 Case 00127600 |
R23-1 R23-2 |
R23-2 PHF2.0.0 |
Topology Map shows incorrect routing information when there is an Azure VNET with multiple route circuits. |
TOS-81388 TOS-81137 TOS-82330 Case 00127011 |
R23-1 R23-2 |
R23-2 PHF2.0.0 |
Topology and zone mapping incomplete for Cisco Meraki devices. |
TOS-56648 |
R22-1 and later |
Not fixed |
For Check Point management devices, there is a known issue with loading the Automatic Policy Generation (APG) page when there is a special character in the inline-layer group name. There is no workaround for this issue. Avoid using special characters (such as #, %, &) when creating inline-layer groups. |
TOS-71264 Case 00116185 |
R23-1 R23-2 |
Not fixed |
For Palo Alto devices, there is a known issue causing Designer to give a global object a name that already exists. |
TOS-66508 Case 00110830 |
R23-1 R23-2 |
Not fixed |
For FortiManager devices, there is a known issue preventing revisions from being retrieved when there is a policy name containing an en dash character. |
R23-2 and later |
Not fixed | On rare occasions, older requests do not appear in the Requests list upon TOS startup. If this occurs, wait a few minutes and refresh the page. | |
R23-2 and later |
Not fixed |
Rule history is not available for Zscaler devices. |
|
TOS-74048 TOS-76166 |
R23-2 and later |
Not fixed |
In the Rule History tab, there is no indication of the object type for changes to services or security profiles. |
TOS-48645 |
R21-1 and later |
Not fixed |
When an admin uses Rule Viewer to select rules and open a ticket for them, a new SecureChange tab opens in the browser with a draft of the ticket to be submitted. If the new tab does not display the relevant ticket, you will need to refresh the browser window to see the ticket. This issue occurs with the Rule Modification, Rule Decommission, and Rule Recertification workflows. |
TOS-80597 |
R23-1 R23-2 |
R24-1 PGA.0.0 | Verifier fails for NSX-V objects with the message: Verifier could not calculate the traffic of the input objects in the access request. Contact Tufin support. |
TOS-82841 TOS-82842 Case 00130640 |
R23-1 R23-2 |
R23-2 PHF2.0.0 |
Topology Map is not updated due to failure when receiving data from an external OPM agent. This occurs when the amount of topology data is over 15,000 entries. |
TOS-82803 TOS-83424 Case 00127150 |
R22-2 R23-1 R23-2 |
R23-2 PHF2.0.0 |
Designer suggestions for Panorama devices cannot be modified. The following error is returned: Waiting for revision from a conflicting ticket, cannot modify the Designer results. This occurs when Designer is configured to create shared objects. |
TOS-81465 TOS-81507 Case 00124227 |
R22-2 R23-1 R23-2 |
R23-2 PHF2.0.0 |
Designer suggests creating new rules to provide access when that access is already provided by existing rules. This behavior occurs when the ticket includes applications, and is a result of traffic miscalculation for apps with the same service in a different port when there is a Cisco ACI device in the path. |
TOS-80622 Case 00123016 |
R23-1 R23-2 |
|
When running path analysis on a shared Azure ExpressRoute, additional VNETs are displayed in the path. |
TOS-81745 TOS-82188 Case 00124898 |
R23-1 R23-2 |
R23-2 PHF2.0.0 |
Cleanup instances do not open in the Cleanup page when the revisions have multiple versions. The following message appears to users: Recalculating Revision results. This can take a while. |
TOS-87079 TOS-87148 TOS-87149 Case 00135795 |
R23-2 R24-1 |
R23-2 PHF3.0.0 R24-1 PHF1.0.0 |
Cleanup instances do not open in the Cleanup page when the revisions have multiple versions and there is revision parsing order is inconsistent. The following message appears to uses: Recalculating revision results. This may take a while. |
TOS-83733 Case 00126772 |
R22-2 R23-1 R23-2 |
R23-2 PHF2.0.0
|
When running tos dr switch or tos dr status, the command fails due to no compatible backup files being found even though completed scheduled backup files exist. |
TOS-82608 TOS-82493 Case 00128588 |
R23-1 R23-2 |
R23-2 PHF2.0.0 |
After running a scan in RLM, tickets with an expiration date later than the rule recertification date will cause a related ticket to be created in Rule Viewer with an ID of 0. |
TOS-82829 TOS-82550 Case 00128588 |
R23-1 R23-2 |
R23-2 PHF2.0.0, |
Backup files stored on NFS will cannot be deleted in HA environments with disaster recovery configured. |
TOS-80781 Case 00127809 |
R23-1 R23-2 |
|
After new tiered license is activated, SecureChange tickets get stuck on the auto-verifier step and cannot proceed. |
TOS-79379 Case 00123476 |
R21-3 R22-1 R22-2 R23-1 R23-2 |
|
Performance issues when connecting to an LDAP server. |
TOS-83494 TOS-77831 TOS-83495 Case 00131041 |
R23-1 R23-2 |
R23-2 PHF2.0.0, |
When fetching a revision from a Cisco ACI device, a null pointer exception (NullPointerException) occurs. |
TOS-84153 TOS-84154 Case 00131095 |
R23-2 |
R23-2 PHF2.0.0 |
Domain information for cloud and network objects is missing from the Path Analysis view in the Topology Map. |
TOS-79559 TOS-79435 Case 00120593 |
R22-2 R23-1 R23-2 |
R23-2 PHF2.0.0 |
A Certified rule status is being overridden by the rule documentation backward-compatibility API. |
TOS-82162 Case 00129097 |
R23-1 R23-2 |
R23-2 PHF2.0.0 |
Using an API call to add multiple ARs to a ticket, and marking the status as Done, removes the last AR. |
TOS-83501 TOS-83503 Case 00130078 |
R23-1 R23-2 |
R23-2 PHF2.0.0 |
Fields are missing from the MIB file. |
TOS-84094 TOS-85275 TOS-85276 Case 00131641 |
R23-1 R23-2 |
R23-2 PHF2.0.0 |
For Juniper SRX devices, static NAT rules do not contain all source members. |
TOS-84633 TOS-84657 TOS-84658 Case 00131309 |
R23-1 R23-2 R24-1 |
R23-2 PHF2.0.0 R24-2 PGA.0.0 |
Automatic target analysis fails for Check Point FQDN objects, even though the objects exists. Topology returns the error message: Internal error occurred |
TOS-85138 TOS-85312 TOS-85313 Case 00132715 Case 00133578 |
R23-1 R23-2 |
R23-2 PHF2.0.0 R24-2 PGA.0.0 |
Running the GET Ticket API returns the error: "Parameter specified as non-null is null." |
TOS-85162 TOS-85491 TOS-85244 Case 00130856 |
R22-1 R22-2 R23-1 R23-2 |
R23-2 PHF2.0.0 R24-1 PGA.0.0
|
An "invalid server certificate" error is returned when logging into devices from TOS using Cyberark for external authentication. |
TOS-85070 TOS-85110 TOS-85111 Case 00132624 Case 00133290 |
R23-1 R23-2 |
R23-2 PHF2.0.0 R24-1 PGA.0.0 |
Verifier does not support the icmp-proto service in access requests. |
TOS-84627 Case 00131389 |
R23-1 R23-2 |
R23-2 PHF2.0.0 |
Local backup fails. |
TOS-83662 Case 00132169 |
R23-1 R23-2 |
R23-2 PHF2.0.0 |
Provisioning fails on FortiManager devices with the message: Update FortiManager_for_FFM did not run: Rule contains only IPv4 src or dest addresses, both IPv6 srcAddr and IPv6 dstAddr should be available in a change. This occurs when trying to replace a group. |
TOS-82694 Case 00129609 Case 00114483 |
R22-2 R23-1 R23-2 |
R23-2 PHF2.0.0 |
No requests shown when filtering for closed tickets in a group that contains more then 35310 tickets. |
TOS-81384 Case 00126283 |
R23-1 R23-2 |
R23-2 PHF2.0.0 |
Communication between SecureTrack and SecureChange is frequently interrupted. The following message appears: SecureTrack settings:Cannot connect to SecureTrack.Five minutes later, this message appears: SecureTrack settings:Connection successful. |
TOS-84941 TOS-85084 Case 00133674 |
R23-1 R23-2 |
R23-2 PHF2.0.0 |
Importing data using the SecureApp Import Applications template fails with error message “Cannot import application data” when empty rows are present. |
TOS-83357 TOS-83394 TOS-83357 Case 00126123 |
R23-2 |
R23-2 PHF2.0.0 |
Designer failed with the error message "There are matching unresolved FQDN objects. You may be able to resolve the problem by enabling a local DNS." due to FQDN objects containing uppercase letters. |
TOS-82097 TOS-82588 Case 00128812 |
R23-2 |
R23-2 PHF2.0.0 |
Verifier and Path Analysis fail to display rules implemented on a monitored firewall, due to incorrect parsing of network object groups |
TOS-82566 TOS-83032 Case 00127221 |
R23-2 |
R23-2 PHF2.0.0 |
The error message “Verifier could not calculate the traffic of the input objects in the access request” appears when Verifier is run on NSX-T devices that contain rules with security groups in the Source/Destination. This occurs after upgrading to a new version and running Verifier on an Access Request submitted in the previous version. |
TOS-82474 TOS-82832 Case 00130229
|
R23-2 |
R23-2 PHF2.0.0 |
Editing Designer results is not allowed after Designer fails within an auto-step. |
TOS-85144 Case 133815 |
R23-2 |
R23-2 PHF2.0.0 |
“New version verification failed” message displayed when parsing AWS VPC fails due to duplicate objects. |
TOS-84597 TOS-83682 Case 00133552 |
R23-2 |
R23-2 PHF2.0.0 |
When restarting TOS after running “tos cluster snapshot,” “tos cluster snapshot restore” fails with error “no global configuration found”. |
TOS-80139 TOS-80551 Case 00124301 |
R23-2 |
R23-2 PHF2.0.0 |
Application interfaces can’t be retrieved via API when the same server is used for both the application pack and the connection to application pack. |
TOS-85704 TOS-85561 Case 00131777 |
R23-2 |
R23-2 PHF2.0.0 R24-1 PGA.0.0 |
Topology information cannot be retrieved from AWS devices when there is a gateway load balancer linked to multiple AWS accounts. |
TOS-82077 Case 00130053 |
R23-2 |
R23-2 PHF2.0.0 |
Users are not able to use the Server Lookup page to find objects in the apps they created. The View all applications permit is incorrectly required. |
TOS-85814 TOS-85438 Case 00126032 Case 00130632 Case 00133278 |
R23-2 |
R23-2 PHF2.0.0 R24-1 PGA.0.0 |
Revisions cannot be retrieved. Caused by a failure in the device collector service |
TOS-85567 TOS-85841 Case 00130394 |
|
R24-1 PGA.0.0
|
Comments are duplicated to Cisco FMC rules when Rule Decommission workflow changes are provisioned. |
TOS-86118 TOS-86145 Case 00133299 |
|
R24-1 PGA.0.0 |
Tos backup create suffers performance issues when configured to local storage. |
TOS-86008
|
|
R24-1 PGA.0.0 |
During upgrades, TOS status displays “Checker failure” and upgrade fails. |
TOS-87324 Case 00136556 |
R23-2 |
R23-2 PHF3.0.0 R24-1 PGA.0.0 |
Revision retrieval fails due to a single client running on two different pods. |
TOS-87853 TOS-87517 Case 00135870 Case 00133044 |
R22-2 R23-1 R23-2 R24-1 |
R23-2 PHF3.0.0 R24-1 PHF1.0.0 |
TOS pages (including Cleanup Browser, Object Lookup, and others) have loading times of 2-5 minutes when more than 10,000 devices are present in the environment. |
TOS-87594 Case 00136555 |
R23-2 |
R23-2 PHF3.0.0 |
After upgrading to R23-2 PHF3.0.0 when the jvm.extraOpts parameter is present, calling the logs of SecureTrack jobs returns the message ERROR unable to locate appender "${env:logging.appender}" for logger config "root." |
TOS-87096 TOS-87380 TOS-87381 Case 00133018 |
R22-2 R23-1 R23-2 R24-1 |
R23-2 PHF3.0.0 R24-1 PHF1.0.0 |
The API /securetrack/api/security_zones takes over 10 seconds to respond. |
TOS-86887 TOS-87103 Case 00130227 |
R23-1 R23-2 R24-1 |
R23-2 PHF3.0.0 R24-1 PHF1.0.0 |
For Cisco routers, rule numbers are parsed incorrectly when the device is not configured to collect rule usage analysis. As a result, attempts to provision ACL removal fail. |
TOS-88316 TOS-88327 TOS-88328 TOS-88334 Case 00138348 |
R23-2 |
R23-2 PHF3.0.0 R24-1 PHF1.0.0 |
After upgrading, users belonging to nested groups can not access SecureChange. |
TOS-85794 Case 00129891 |
R23-1 R23-2 |
R23-2 PHF3.0.0 |
Revision fetching for NSX-T devices was not triggered when the NSX Manager NSX-T revisions fail to be retrieved when the NSX Manager hostname is an FQDN. |
TOS-85470 TOS-87815 TOS-87816 Case 00133673 |
R23-2 R24-1 |
R23-2 PHF3.0.0 R24-1 PHF1.0.0 |
For Panorama 10.2 devices, Provisioning fails. |
TOS-88154 TOS-85046 TOS-88157 Case 00133483 |
R23-1 R23-2 R24-1 |
R24-1 PHF2.0.0 |
After upgrading, TOS fails to receive device revisions if monitored Check Point devices use LEA authentication on RC. |
TOS-87237 TOS-87893 TOS-87892 TOS-87891 Case 00133117 |
R22-2 R23-1 R23-2 |
R23-2 PHF3.0.0 R24-1 PHF1.0.0 |
Designer fails when in topology mode, when a specific domain is selected, returning message "<Firewall> not in path". This occurs because Designer looks for the path outside of the currently selected domain. |
Was this helpful?
Thank you!
We’d love your feedback
We really appreciate your feedback
Send this page to a colleague