Bugs - Resolved and Unresolved

Overview

The reference table below includes bugs resolved in R23-2 and later, as well as unresolved issues across all supported versions. For older resolved bugs, see the relevant release in the Release Notes Knowledge Center. Any bugs existing only in release candidates (RCs) will not appear.

To filter the results, enter text in one or more of the filter fields. To see all items, clear the filter fields.

References

All known internal bug numbers and/or customer case numbers related to the bug.

Known Affected Releases

The major version in which the bug was found plus any additional major versions in which it is known to exist. Other release might be affected as well.

Fixed Versions

The earliest minor version(s) in which the bug was fixed and/or the upcoming GA release. Bugs fixed in one GA release can be assumed fixed in all subsequent releases. For issues that have not been fixed, "Not fixed" will appear.

Reference Table

References

Known Affected Releases

Fixed Versions

Description

TOS-106199

Case 00160950

R24-2

R24-2 PGA.0.0

R25-1 PGA.0.0

Rule viewer does not display Last Hit information for NSX-T devices

TOS-105908

Case 00160662

R24-2 not fixed

SecureChange runs slowly following use of Designer

TOS-105829

Case 00161875

R24-2 R25-1 PGA.0.0

Following upgrade, slow response and high CPU

TOS-105739

Case 00160155

R24-2 R25-1 PGA.0.0

USP exceptions partially exempt rule violations that in previous versions of TOS were fully exempted.

TOS-105478

Case 00160487

R24-2 R25-1 PGA.0.0

The interactive map displays only the first 1,000 routes retrieved from NSX-T devices, instead of all routes.

TOS-105424

Case 00153561

R24-2 not fixed

Revision not retrieved for FMG Global, when It contains Internet-Service-Group

TOS-105363

Case 00158700

R24-2 R25-1 PGA.0.0

After updating the name of a network object, the original name still appears in Designer's Rule View.

TOS-104986

Case 00156325

R24-2 R25-1 PGA.0.0

Auto Verifier incorrectly showing red when there is a revision with an AR change.

TOS-104346

Case 00153846

Case 00149386

R24-2

R24-2 PHF5.0.0

R25-1 PGA.0.0

Rule Viewer is showing incorrect information on Fully Shadowed rules.

TOS-103643

R24-2 R25-1 PGA.0.0

Deleting SA application takes about 8 hours and reaches a memory peak of 31GB

TOS-102187

not fixed R25-1 PGA.0.0

"Ready" calculation is not executing until the "Map Connections" calculation is finished.

TOS-107388

TOS-107384

R24-2

R24-2 PHF4.1.0

R25-1 PGA.0.0

Upgrade pre-check fails when Extensions and/or PS solutions have been installed. Logs are likely to contain error messages: Executing step "Pod amounts on nodes" in section "Validations section" and ERROR Node <NODENAME> has 110 pods, which is above the allowed limit of 108.

TOS-103031

Case 00157237

R24-2

R24-2 PHF4.0.0

R25-1 PGA.0.0

TOS functions including backup, upgrade and high availability are not working. When running the tos status command, the node status indicates CHECKER_FAILURE'.

TOS-104052

TOS-104765

Case 00158972

R24-1

R24-2

R24-2 PHF4.0.0

R25-1 PGA.0.0

Disproportionate increase in database size.

TOS-103567

Case 00159046

Case 00159146

R24-2

R24-2 PHF4.0.0

R25-1 PGA.0.0

Slow processing and/or tickets get stuck in Designer or Verifier. This might be accompanied by high memory consumption and Mongo timeout exception error messages in the logs.

TOS-103895

TOS-104642

Case 00153108

R24-1

R24-2

R24-2 PHF4.0.0

R25-1 PGA.0.0

Missing paths on interactive map for ACI VMM learned endpoints with multiple IP addresses on the same VM

TOS-103990

TOS-104019

Case 00156206

R24-2

R24-2 PHF4.0.0

R25-1 PGA.0.0

Fortinet FMG ADOM revision fails when device has a wildcard object with a metadata variable. Additional information: Error message "Failed parsing configuration" appears in the logs

TOS-103708

TOS-104081

Case 00159372

R24-2

R24-2 PHF4.0.0

R25-1 PGA.0.0

TOS does not start following installation of a Tufin extension. Affect Dashboard Essentials and possibly other extensions as well. Additional information: An error message might appear in the sc-container log mentioning application context and/or context initialization failed

TOS-103182

Case 00158136

R24-1

R24-2

R24-2 PHF4.0.0

R25-1 PGA.0.0

Last hit information does not appear in Rule Viewer for Azure Firewall. Additional information: The logs might contain a null pointer exception (NPE)

TOS-104125

Case 00159432

R24-1

R24-2

R24-2 PHF4.0.0

R25-1 PGA.0.0

Verifier incorrectly returns message 'Not implemented' following successful provisioning using option 'Create new rule rule for each AR'

TOS-104931

TOS-104648

Case 00155762

R24-1

R24-2

R24-2 PHF4.0.0

R25-1 PGA.0.0

Violation calculations fail to detect violated rules when the environment exceeds 200 devices.

TOS-104826

TOS-104898

Case 00159858

R24-2

R24-2 PHF4.0.0

R25-1 PGA.0.0

For Cisco SD-WAN devices 17.4 and above with multi-tenancy is enabled, dynamic topology fails to update causing missing interfaces in the topology map and incorrect Designer suggestions.

TOS-104820

TOS-104900

Case 00157245

Case 00159994

R24-2

R24-2 PHF4.0.0

R25-1 PGA.0.0

For VMware NSX-T devices that contain global objects, rules are missing from TOS.

TOS-104929

TOS-104644

Case 00159722

Case 00158708

R24-1

R24-2

R24-2 PHF4.0.0

R25-1 PGA.0.0

When large revisions are received from a Panorama device, entities (such as rules, hosts, or groups) are missing from Rule Viewer.

TOS-104890

Case 00159290

R24-2

R24-2 PHF4.0.0

R25-1 PGA.0.0

Connection failures between TOS and Panorama devices cause revision retrievals to fail.

TOS-104923

TOS-104947

Case 00160015

R24-2

R24-2 PHF4.0.0

R25-1 PGA.0.0

Default GCP VPCs fail to appear in the Topology map.

Log message: NullPointerException

TOS-104665

Case 00155672

R23-2

R24-1

R24-2

R24-2 PHF4.0.0

Revisions cannot be retrieved from Cisco FMC 7.0.6.3 devices when the logs contain duplicate network object names.

Error message: "New version verification failed".

TOS-104615

TOS-104925

TOS-104926

00155026

R24-1

R24-2

R24-2 PHF4.0.0

R25-1 PGA.0.0

Rule Viewer does not display IP addresses and network objects for Panorama Advanced (PanOs) devices.

TOS-104431

TOS-104414

Case 00154289

R24-1

R24-2

R24-2 PHF4.0.0

R25-1 PGA.0.0

USP exceptions for specific applications and services fully exempt rules that should only be partially exempted.

TOS-104402

TOS-104404

Case 00154201

R24-1

R24-2

R24-2 PHF4.0.0

R25-1 PGA.0.0

TOS fails to filter out unsupported configurations on revisions from F5 devices resulting, and as a result the revisions cannot be retrieved.

TOS-104380

TOS-104410

Case 00157087

Case 00156127

R24-1

R24-2

R24-2 PHF4.0.0

R25-1 PGA.0.0

Email notifications to servers that require user authentication are not being sent.

TOS-104281

TOS-102915

Case 00158636

R24-2

R25-1 PGA.0.0

R24-2 PHF4.0.0

Path REST API function returns an error message when calculating paths for generic devices with MPLS.

Error message: "GENERAL_ERROR"

TOS-104583

TOS-104649

Case 00151566

R24-1

R24-2

R25-1 PGA.0.0

R24-2 PHF4.0.0

Topology information cannot be retrieved from Panorama devices with Prisma

TOS-102991

Case 00158542

R24-2

R24-2 PHF4.0.0

SecureTrack topology sync is not running properly.

TOS-103330

R24-2

R25-1 PGA.0.0

R24-2 PHF4.0.0

Topology map does not show routes between Azure VNets in VHubs belonging to different subscriptions. The VNets appear as isolated islands

TOS-103244

Case 00158640

R24-2

R25-1 PGA.0.0

R24-2 PHF4.0.0

Cannot upload the non-business days CSV file if using Firefox browser.

TOS-103187

Case 00158220

R24-2

R25-1 PGA.0.0

R24-2 PHF4.0.0

SecureTrack is unable to retrieve revisions from Zscaler devices when there are more than 1,000 rules on the device.

TOS-103138

Case 00158220

R24-2

R25-1 PGA.0.0

R24-2 PHF4.0.0

Zscaler shows Unknown Error in SecureTrack.

TOS-103045

Case 00158090

R24-2

R24-1

R25-1 PGA.0.0

The Expiration banner does not appear for expired tickets with an expiration date that was updated via the REST API.

TOS-100803

Case 00155322

R24-2

R24-1

R25-1 PGA.0.0

For Panorama devices, application field does not appear in Rule Viewer.

TOS-100065

Case 00154590

R24-2

R24-1

R23-2

R23-1

R25-1 PGA.0.0

R24-2 PHF2.0.0

Searching for a cloned server in SecureApp via API returns data from the original server, even if the cloned server has been modified since cloning.

TOS-96056

Case 00147311

R24-2

R24-1

R23-2

R25-1 PGA.0.0

Changes received from revisions are missing from Rule Viewer and GraphQL queries.

TOS-96026

Case 00154366

R24-2

R25-1 PGA.0.0

Upgrade from R24-1 PHF2 to R24-2 fails. Possible error messages include:

ERROR Step "Pod amounts on nodes" in section "Validations section" failed

ERROR Section "Validations section" failed

ERROR Upgrade has encountered a problem in step: "Pod amounts on nodes" due to: Node node1 has 114 pods, which is above the allowed limit of 108

TOS-95978

Case 00149318

R24-2

R24-1

R24-2 PHF5.0.0

R25-1 PGA.0.0

USP exception API omits NSX groups from exceptions created by the API

TOS-94734

Case 00143135

R24-2

R24-1

R23-2

R25-1 PGA.0.0

The drilldown menu for shadowing rules fails to load when many zones are configured on the device.

TOS-94394

Case 00147618

R24-2

R24-1

R25-1 PGA.0.0

Following a system service reboot, UI or API results are missing or contain inaccurate data.

TOS-94147

Case 00146916

R24-2

R24-1

R23-2

R25-1 PGA.0.0

API returns 500 error when device does not support NAT rules.

TOS-94146

Case 00143825

R24-2

R24-1

R25-1 PGA.0.0

Cassandra status critical. Identified in the output of the TOS precheck tool.

TOS-93416

Case 00146349

R24-1

R24-2

R25-1 PGA.0.0

Last hit showing up incorrectly in Rule Viewer and TQL queries when the time zone of the user is different from the server . The value is out by one day when compared to the revision details.

TOS-103173

Case 00157331

R24-1

R24-2

R24-2 PHF3.0.0

R25-1 PGA.0.0

Configured Azure Load Balancers do not appear on the topology map.

TOS-102919

Case 00156269

R24-2 and earlier

R24-2 PHF3.0.0

R25-1 PGA.0.0

Incorrect topology calculation for Cisco MPLS. The path appears as broken.

TOS-102081

Case 00157392

R24-2

R25-1

R24-2 PHF3.0.0

R25-1 PGA.0.0

During path analysis, FQDN validation fails.

TOS-101998

Case 00156561

R24-2

R24-2 PHF3.0.0

Login fails when password contains UTF-8 characters

Error message: 403 Invalid Credential

TOS-101615

Case 00155749

R24-2

 

Designer suggests creating duplicate rules for Check Point devices.

TOS-98501

Case 00152638

R24-2

R24-1

R24-2 PHF2.0.0

For very large Panorama hierarchies, Designer debug tool get stuck.

TOS-101258

Case 00156841

R24-2

R24-1

R24-2 PHF2.0.0

Upgrade to R24-1 PHF4.0.0 failed.

Error: Upgrade has encountered a problem in step: "Clean old releases" due to: MANIFEST_UNKNOWN.

TOS-101361

Case 00156782

R24-2

R24-1

R24-2 PHF2.0.0

Deprecated compliance risk calculations failed on OPM devices causing failure to risk calculations.

TOS-101358

Case 00152134

R24-2

R24-1

R24-2 PHF2.0.0

R25-1 PGA.0.0

Dynamic topology data retrieval is slow because the management table is not cached.

TOS-101243

Case 00148842

R24-2

R24-1

R24-2 PHF2.0.0

Rules are deleted and recreated, causing the rule documentation to be deleted.

TOS-101113

Case 00154866

R24-2

R24-2 PHF2.0.0

TOS encounters a Null Pointer Error in Designer when the Target field contains a device without a name saved in the database.

TOS-101096

Case 00156460

R24-1

R24-2 PHF2.0.0

R25-1 PGA.0.0

Backup fails.

Error message: Insufficient disk space on minio Dir

TOS-100812

Case 00135789

R24-2

R24-1

R23-2

R23-1

R24-2 PHF2.0.0

Designer creates new rules below the cleanup rule, resulting in errors when installing shadowing.

TOS-100805

Case 00154590

R24-2

R24-1

R24-2 PHF2

R25-1 PGA

The "Get Network Objects," "Get Server," "Get Servers," "Get Service," and "Get Services" API functions do not include servers or services cloned via SecureApp in their responses.

TOS-100776

TOS-101091

Case 00148349

R24-2

R24-1

R24-2 PHF2

R25-1 PGA

Fortinet devices appear in Monitored Devices with message Error: SSL failed.

See instructions in Using Local DNS Over Fortigate DNS.

TOS-100741

Case 00142647

R24-2

R24-1

R24-2 PHF2.0.0

For a network object query, the API output is empty.

TOS-100718

Case 00150264

R24-1

R24-2

R25-1

R24-2 PHF2.0.0

R25-1 PGA.0.0

Path analysis queries returns incorrect results for Check Point devices configured with Star communities because of missing VPN routing information in the revision data.

TOS-100137

Case 00099368

 

R24-2 PHF2.0.0

R24-1 PHF4.1.0

Upgrade from earlier release of TOS Aurora fails.

Logs contain error message connection to server at "stolon-sc-svc" (IP), port 5432 failed

TOS-100065

Case 00154590

R24-1

R24-2

R24-2 PHF2.0.0

R23-2 PGA.0.0

R25-1 PGA.0.0

For SecureApp, resolved an issue in which searching for a cloned server via API returns data from the original server, even if the cloned server has been modified since cloning.

TOS-100063

Case 00149724

00155887

R24-1

R24-2

R24-2 PHF2.0.0

R25-1 PGA.0.0

VIP objects, with IPv6 addresses without mapped IP, cause an error when parsing the revision.

TOS-99986

Case 00151330

R24-1

R24-2

R24-2 PHF2.0.0

SecureChange users are receiving an error message saying they are unauthorized to access the page they are on.

Error message: User is not authorized to see this page

TOS-99837

Case 00153052

R24-2

R24-1

R23-2

R23-1

R24-2 PHF2.0.0

R25-1 PGA.0.0

The STRE Shadowed Rules report returns a bad request error when there are unprocessed revisions in the SecureTrack database.

Error message: 400 bad request

TOS-99530

Case 00150824

R24-1

R24-2

R24-2 PHF2.0.0

R25-1 PGA.0.0

For Azure virtual WAN, there is a routing issue.

Log message: Cannot find connected device with VirtualApplianceIp: <IP> , Urouted!

TOS-99122

Case 00147222

R24-2

R24-1

R23-2

R23-1

R22-2

R24-2 PHF2.0.0

R25-1 PGA.0.0

Rule Viewer does not show the source for some rules on Fortigate devices with a user group and object group that share the same name.

Error message: This data cannot be displayed at the moment.

TOS-98820

Case 00152855

R24-2

R24-1

R23-2

R24-2 PGA.0.0

When a modify group change is already implemented on a device, if you run redesign on the change request, an error is displayed to the user instead of providing the "fully implemented" result.

Error message: An error occurred. Please contact your system administrator for help.

TOS-101638

TOS-99324

Case 00157014

00153952

R23-2

R24-1

R24-2

R24-2 PHF1.2.0

R24-2 PHF2.0.0

R25-1 PGA.0.0

SecureChange is inaccessible.
Error 503 appears when going to SecureChange using UI or API.

TOS-99521

Case 00138877

R23-2

R24-1

R24-2

R24-2 PHF1.0.0

R25-1 PGA.0.0

Auto-verifier needlessly waits for a new revision, after no provisioning took place, and times out.

TOS-97897

Case 00149835

R24-1

R24-2

R24-2 PHF1.0.0

For Cisco FMC devices, groups with literal wildcards cause the revision to fail.

TOS-98443

Case 00152155

R24-1

R24-2

R24-2 PHF1.0.0

Cisco ACI cannot retrieve a revision.

Error: <error code="403" text="Token was invalid (Error: Invalid input token data)"/>

TOS-97683

Case 00149835

R24-1

R24-2

R24-2 PHF1.0.0

FMC devices that use legacy UI configured with literal subnets, which contain white spaces at beginning or end, cause the revision to fail.

TOS-98556

Case 00151883

R24-1

R24-2

R24-2 PHF1.0.0

After an upgrade to R24-2 with more than 500 devices, running Verifier returns the following error:

Error message: "No revisions were received for this target device (0)"

TOS-98214

Case 00150752

R24-1

R24-2

R24-2 PHF1.0.0

On Cisco ASA devices, revisions are associated with the wrong accounts in Change Viewer.

TOS-97827

Case 00146653

00149146

R23-2

R24-1

R24-2

R24-2 PHF1.0.0

R25-1 PGA.0.0

Rule Viewer's Last Hit field displays inaccurate length of time.

TOS-99091

Case 00147952

R24-2

R24-2 PHF1.0.0

Upgrade procedure gets stuck on the bridge-scheduler validation.

TOS-96071

Case 00148677

R24-2

R24-2 PHF1.0.0

When the network contains two secured hubs, path analysis shows incorrect data.

TOS-97557

Case 00138877

R23-2

R24-1

R24-2

R24-2 PHF1.0.0

For FMG devices, tickets get stuck and cannot progress unless adjusted manually.

TOS-97969

Case 00151207

R24-1

R24-2

R24-2 PHF1.0.0

Sorting by the “Last Update” column in the Tickets table causes rows to appear out of order when some tickets have update dates in the UTC time zone without milliseconds.

TOS-99238

TOS-99623

Case 00152155

R24-1

R24-2

R25-1 PGA.0.0

R24-2 PHF1.0.0

 

Revisions cannot be retrieved from an ACI 5.3 device configured with a transparent proxy in SecureTrack.

TOS-97784

Case 00148296

R24-1

R24-2

R25-1 PGA.0.0

R24-2 PHF1.0.0

Exporting the Audit trail report fails due to a Null Pointer Exception.

TOS-97036

Case 00141223

R23-2

R24-1

R24-2

R24-2 PHF1.0.0

Ticket dependency calculations for group modification tickets on Check Point Devices causes the SecureTrack server to crash due to lack of memory.

TOS-96301

Case 00148819

R24-1

R24-2

R24-2 PHF1.0.0

Rules for Cisco XR Routers are missing in Rule Viewer, and in the Compare Revisions page > Rules tab. This occurs when the interface is configured with “!” before the associated Access Control List (ACL).

TOS-96177

Case 00148687

R23-2

R24-1

R24-2

R24-2 PHF1.0.0

Parsing fails to identify SD-WAN routes for Cisco Routers when the output returned from the router starts with information unrelated to the actual routing data.

Log message: Finish parsing content. evpn route count: 0.

TOS-99577

TOS-99615

TOS-99685

TOS-99682

Case 00153213

R24-1

R24-2

R24-1 PHF4.1.0

R24-2 PHF1.0.0

 

After running tos dr switch as part of Disaster Recovery, the cluster does not return to a healthy state.

Error messages include:
Kafka out of sync.
Running tos status returns checker failure for the Cassandra database.

 

TOS-99181

TOS-99182

Case 00154081

R24-1

R24-2

R24-1 PHF4.1.0

R24-2 PHF1.0.0

TOS install and upgrade procedures fail with DNS error message when DNS is configured correctly.

Error message: ERROR DNS misconfiguration:

lookup test-tufin.local on xx.xx.xx.x:xx: server misbehaving

In R24-1, only relevant for PHF4.0.0.

TOS-96848

TOS-96849

Case 00146741

R24-1

R24-2

R24-1 PHF4.0.0

R24-2 PHF1.0.0

After upgrading to R24-1, syslog change manager crashes.

TOS-96490

Case 00146667

R24-1

R24-2

R24-1 PHF4.0.0

R24-2 PHF1.0.0

R25-1 PGA.0.0

Prisma/GPCS RN-SPN object does not appear in the Map.

TOS-96206

TOS-96207

Case 00139132

00144092

R24-1

R24-2

R24-1 PHF4.0.0

R24-2 PHF1.0.0

R25-1 PGA.0.0

Error page appears shortly after logging in to TOS. Additional information: neo4j timeout error appears in log.

TOS-96191

TOS-96322

TOS-96323

Case 00148349

R23-1

R23-2

R24-1

R24-2

R24-1 PHF4.0.0

R24-2 PHF1.0.0

R25-1 PGA.0.0

Fortinet firewalls appear connected, but the ADOMs and VDOMs under it show a connection error.

TOS-96028

TOS-96064

Case 00148528

R24-1

R24-2

R24-1 PHF4.0.0

R24-2 PHF1.0.0

Last hit not working for Azure Firewall rules.

TOS-93139

Case 00145499

R24-1

R24-1 PHF4.0.0

The number of pods exceeds the Kubernetes limit of 110.

TOS-92774

Case 00144198

R24-1

R24-1 PHF4.0.0

Clean install of R24-1 shows no TLS 1.2 ciphers; however, if you upgrade from a previous version to R24-1, the TLS 1.2 ciphers still exist.

TOS-93485

TOS-93476

Case 00146342

R24-1

R24-1 PHF4.0.0

Scheduled reports are not shown in the report repository.

TOS-96065

TOS-96064

TOS-96028

Case

00148528

R24-1

R24-2

R24-1 PHF4.0.0

R24-2 PHF1.0.0

No last hits are received on the Azure Firewall due to a case sensitivity issue between the Workspaces API and the Diagnostic Settings API for the workspaceID field.

TOS-96193

TOS-96306

Case

00147700

R24-1

R24-2

R24-1 PHF4.0.0

R24-2 PHF1.0.0

Import of Panorama devices to TOS fails.

Error message: CSM error:General Failure

TOS-95518

Case

00146252

R24-1

R24-2

R24-1 PHF4.0.0

R24-2 PHF1.0.0

R25-1 PGA.0.0

For Cisco ACI devices, path analysis shows incorrect contracts when clicking on a matched rule.

TOS-96233

TOS-96234

Case

00128075

R24-1

R24-2

R24-1 PHF4.0.0

R24-2 PHF1.0.0

For Azure VNETS, subnets are missing from the topology map.

TOS-96339

TOS-96546

Case

00149627

R24-1

R24-2

R24-1 PHF4.0.0

R24-2 PHF1.0.0

Provisioning to a VMware NSX device fails when the rule contains an internet object.

TOS-96576

TOS-96659

Case 00142305

R23-2

R24-1

R24-2

R24-1 PHF4.0.0

R24-2 PHF1.0.0

R25-1 PGA.0.0

In large environments, dashboard widgets USP Compliance and Cleanup are missing data due to Neo4j timeout.

Error message: Something went wrong.

TOS-97050

Case 00149833

R24-1

R24-1 PHF4.0.0

Some non-tiered perpetual licenses installed on certain time-zones cause workflows in TOS to be disabled.

TOS-94481

Case 00141815

R23-2

R24-1

R24-2

R25-1 PGA.0.0

 

TOS restore fails because of a corrupt postgres database index.

TOS-95267

Case 00148423

R24-1

R24-1 PHF4.0.0

Designer fails to run on Cisco ASA devices causing a timeout error due to a service_group with type 0. Error message: Designer fails with error (attached).

TOS-95438

TOS-95439

TOS-95440

Case 00148600

R24-1

R24-2

R24-1 PHF4.0.0

R23-2 PHF1.0.0

The Map does not display AWS cloud data if there is no main route table for one of the VPCs, and the VPC has a Transit Gateway (TGW) attachment connected to a subnet without a routing table.

TOS-95980

TOS-96177

TOS-96178

Case 00148687

R23-2

R24-1

R24-2

R24-1 PHF4.0.0

R24-2 PHF1.0.0

Parsing fails to identify SD-WAN routes for Cisco Routers when the output returned from the router starts with information unrelated to the actual routing data.

Log message: Finish parsing content. evpn route count: 0.

TOS-96198

TOS-96301

TOS-96302

Case 00148819

R24-1

R24-2

R24-1-PHF4.0.0

R24-2 PHF1.0.0

Rules for Cisco XR Routers are missing in Rule Viewer, and in the Compare Revisions page > Rules tab. This occurs when the interface is configured with “!” before the associated Access Control List (ACL).

TOS-96402

Case 00149553

R24-1

R24-1 PHF4.0.0

Scheduled topology sync runs a day late.

TOS-96543

TOS-96621

TOS-96628

Case 00147151

R23-2

R24-1

R24-2

 

R24-1 PHF4.0.0

R24-2 PHF1.0.0

R25-1 PGA.0.0

last hit is not being updated in Rule Viewer for some large devices when multiple devices with many rules are added.

TOS-93802

TOS-93738

Case

00145647

R24-1

R24-1 PHF4.0.0

R24-2 PGA.0.0

 

For Cisco devices, incorrect paths are shown in the Topology Map when there are multiple MPLS-VPN next hops.

TOS-94073

TOS-93079

Case

00137167

R24-1

R24-1 PHF4.0.0

R24-2 PGA.0.0

SecureApp application accepts logs that should be excluded according to the configured conditions.

TOS-94265

TOS-94734

Case

00143135

R24-1

R24-2 PGA.0.0

For Juniper SRX devices, shadowing rules load a blank page in Rule Viewer. In Compare Revision, the Source and Destination are empty.

TOS-94254

TOS-94507

Case

00143746

R23-2

R24-1

R24-1 PHF4.0.0

R24-2 PGA.0.0

FQDN objects in Check Point devices fail to resolve, preventing their use in SecureChange tickets.

TOS-93621

TOS-93622

TOS-93623

Case 00145833

R24-1

R24-1 PHF4.0.0

R24-2 PGA.0.0

Revisions cannot be retrieved from Cisco FMC devices due to intermittent 401 errors from the device API.

Error messages: Access token invalid, unknown error, unable to get configuration

TOS-95140

TOS-95141

TOS-95142

Case

00148825

R23-2

R24-1

R24-1 PHF4.0.0

R24-2 PGA.0.0

topology-service crashes when there are large amounts of generic routes.

TOS-94215

TOS-94932

Case 00140393

R23-1

R24-1

R24-2 PGA.0.0

When attempting to remove access for a NAT rule with multiple source zones on a FortiManager device , Designer displays an incorrect error message.

Incorrect error message: Remove Access suggestions for NAT rules are not supported.

Correct error message: No suggestions for this request.

TOS-95315

TOS-95560

Case 149061

R24-1

R24-2 PGA.0.0

LDAP users are unable to access SecureChange from SecureTrack despite having the appropriate permissions and SSO enabled.

Error message: You do not have permission to access the requested page

TOS-93590

TOS-93872

Case 00140802

R22-2

R23-1

R24-1

R24-2

R24-2 PGA.0.0

Destination zones are removed from USP exception calculations after they are edited.

TOS-95285

TOS-95281

TOS-95341

Case

00147230

R23-1

R23-2

R24-1

R24-1 PHF4.0.0

R24-2 PGA.0.0

Designer gave incorrect suggestions for Fortimanager devices with central NAT enabled.

TOS-95423

TOS-95314

TOS-95424

Case

00149133

R22-2

R23-1

R23-2

R24-1

R24-2 PGA.0.0

R24-1 PHF4.0.0

Device revisions fail to appear in TOS when multiple versions are received at once.

TOS-93843

TOS-93511

TOS-93844

TOS-96295

TOS-96755

TOS-96756

Case 00146745

R24-1

R24-2

R25-1

R24-2 PGA.0.0

R24-2 PHF1.0.0

R24-1 PHF4.0.0

Provisioning task fails in Designer after 10 minutes.

TOS-94127

TOS-94126

TOS-94128

Case 00147293

R24-1

R25-1

R24-2 PGA.0.0

R24-1 PHF4.0.0

NSX-T 4.1 objects do not appear in the Compare Revisions tab.

TOS-94357

TOS-93516

TOS-94358

 

Case 00143648

R24-1

R25-1

R24-2 PGA.0.0

R24-1 PHF4.0.0

Verifier returns only one result for each Cisco FMC device, even when there are multiple relevant policies. As a consequence, incorrect ticket closures may occur.

TOS-94803

TOS-94103

Case 00136029

R23-2

R24-1

R24-2 PGA.0.0

R24-1 PHF4.0.0

SecureApp performance slows after performing an action with a Server Group that contains several thousand servers.

TOS-94743

Case 00147146

R24-1

R24-2 PGA.0.0

R24-1 PHF4.0.0

Policy Change Notifications syslogs are not generated properly when defining a remote server with FQDN.

TOS-95753

TOS-95482

TOS-95755

Case 00146974

R24-1

R25-1

R24-2 PGA.0.0

R24-1 PHF4.0.0

SecureTrack cannot retrieve information about rules using this API call: https://<TUFIN_BASE_URL>/securetrack/api/devices/<device_id>/rules/<id>/documentation

TOS-94002

TOS-93525

TOS-93526

TOS-93531

Case 00146427

R22-2

R23-1

R23-2

R24-1

R24-1 PHF3.0.0

R24-2 PGA.0.0

Upgrade to TOS R24-1 fails when database has saved SecureChange search queries that contain parameters with null values.

TOS-82487

TOS-83623

TOS-76514

R23-1

R23-1 PHF3.0.0

R24-1 PGA.0.0

R24-2 PGA.0.0

There is an issue with Designer when submitting an access request.

Message: Cannot modify the initial default policy. You need to associate a policy with <FW_Name>.

TOS-89207

Case 00131167

R23-1

R23-2

R24-1

R24-2 PGA.0.0

In an LDAP group with multiple users, some users cannot log in to TOS.

TOS-92105

TOS-92096

Case 00146422

R24-1

R24-1 PHF3.0.0

R24-2 PGA.0.0

Revisions cannot be fetched from Cisco Layer 2 switches.

Error message: Error occurred when pulling configuration from the device: Wrong arguments

TOS-92930

TOS-92931

TOS-93098

Case 00141080

R24-1

R24-1 PHF3.0.0

R24-2 PGA.0.0

Azure rule usage data cannot be retrieved when one of the workspaces in the Azure subscription does not have a firewall.

TOS-85264

Case 00132604

R23-2

R24-1

R24-2 PGA.0.0

The SecureTrack user interface is not responsive and backups fail.

TOS-88663

TOS-86210

TOS-88662

Case 00135105

Case 00134604

R23-1

R23-2

R24-1

R23-2 PHF3.0.0

R24-1 PHF1.0.0

R24-2 PGA.0.0

A memory leak in the queue-server process causes the device-collector container to receive a signal segmentation violation (SIGSEGV) and terminate.

TOS-87755

Case

00130078

R23-1

R23-2

R24-1

R24-2 PGA.0.0

Tufin MIB file does not contain records of all traps that could be sent to the SNMP server.

TOS-92217

Case

00142229

00144867

R24-1

R24-2 PGA.0.0

TOS logs users out after one minute when LDAP names contain special characters.

REL-940

TOS-93395

Case 00146342

R24-1

PHF2.0.0 only

R24-1 PHF2.1.0

R24-2 PGA.0.0

Affects R24-1 PHF2.0.0 only. Preconfigured and new scheduled SecureTrack reports in SecureTrack will not run. STRE reports are not affected.

TOS-85527

Case 00132604

R23-2

R24-1

R24-2 PGA.0.0

Policy configuration files cannot be uploaded via the CLI for offline analysis

TOS-88908

Case 00128822

R23-1

R23-2

R24-1

R24-2 PGA.0.0

Designer is not ignoring rules with the legacy automation attribute.

TOS-91546

TOS-91010

Case 00140569

R23-2

R24-1

R24-1 PHF3.0.0

R24-2 PGA.0.0

The connection between Azure hubs is not displayed in the Map.

TOS-92216

Case 00139204

R23-2

R24-1

R24-1 PHF3.0.0

R24-2 PGA.0.0

Topology information cannot be retrieved for AWS gateway load balancers when there is a NAT object on one of the firewall devices in the target group

TOS-92626

TOS-92664

Case 00144173

R23-2

R23-1

R24-1 PHF3.0.0

R24-2 PGA.0.0

Cisco ASA service groups are parsed incorrectly when revisions from offline versions are uploaded. Critical messages appear in the device log files.

TOS-92748

Case 00137338

R23-1

R23-2

R24-1

R24-1 PHF3.0.0

R24-2 PGA.0.0

For Fortinet devices, after running Designer for the first time and selecting Update Devices, there is an error.

Error message: Remove network object <object name> from existing group < group name>.

TOS-91732

Case 00145833

R24-1

R24-1 PHF3.0.0

R24-2 PGA.0.0

For Cisco FMC device logs, received an authentication token for the API, but could not get a revision.

Error message: 401 invalid session

TOS-92473

TOS-93494

TOS-93495

Case 00143723

R24-1

R24-1 PHF3.0.0

R24-2 PGA.0.0

Source and destination fields are empty in Compare Revision and appear as N/A in Rule Viewer.

TOS-91198

TOS-92353

Case 00135272

R23-2

R24-1

R24-1 PHF3.0.0

Tickets cannot be split into smaller tickets when initiated from SecureApp.

TOS-92113

TOS-92291

Case 00142645

R23-2

R24-1

R24-1 PHF3.0.0

R24-2 PGA.0.0

SecureTrack cannot retrieve revisions from Cisco Meraki devices when the device contains a WAN interface with a missing gateway. The user interface shows that the device is being monitored correctly.

TOS-90268

Case 00137969

R24-1

R23-2

R24-1 PHF3.0.0

Designer suggests creating new network objects on Juniper SRX devices that replace existing network objects. The new network objects have larger/smaller subnets.

TOS-90846

TOS-64433

Case 00136704

R24-1

R23-2

R24-1 PHF3.0.0

Revisions from Juniper SRX devices are missing NAT objects with 'any' in the rule source or destination.

TOS-91598

R24-1

R24-1 PHF3.0.0

Azure vnets cannot be imported when there is a proxy server with the local DNS disabled configured in the Azure management device.

TOS-90662

TOS-90551

Case 00141900

R24-1

R24-1 PHF3.0.0

R24-2 PGA.0.0

SecureTrack cannot monitor Cisco layer 3 devices with a custom login prompt.

TOS-90763

TOS-91141

Case 00140256

R23-1

R23-2

R24-1

R24-1 PHF3.0.0

R24-2 PGA.0.0

SecureChange tickets are displayed incorrectly in the user interface (for example, closed tickets appear open) because of an indexing issue.

TOS-91048

TOS-91828

Case 00139686

R23-2

R24-1

R24-1 PHF3.0.0

R24-2 PGA.0.0

Permitted traffic to Panorama devices is shown as blocked due to a mismatch between the predefined services in TOS and the predefined service on the device.

TOS-89953

TOS-89954

Case 00139616

R22-2

R23-1

R23-2

R24-1

R24-1 PHF3.0.0

For Cisco ASA devices on a remote collector, rule last hit information is inaccurate.

TOS-90842

Case 00142404

R24-1

R24-1 PHF3.0.0

The content of ACI objects in Panorama dynamic access groups does not appear in TOS when the device Is configured with more than one IP address (on the Panorama side).

TOS-90842

Case 00142404

R24-1

R24-1 PHF3.0.0

The content of ACI objects that appear within Panorama dynamic access groups does not appear in TOS.

TOS-90740

Case 00141155

R24-1

R24-1 PHF3.0.0

Installation crashes.

TOS-90938

TOS-90963

Case 00141793

R23-2

R24-1

R24-1 PHF3.0.0

 

Device revisions generate errors for Authorization and Ticket Mapping when a deleted object exists a in closed ticket.

TOS-91570

TOS-91830

Case 00136813

R23-2

R24-1

R24-2 PGA.0.0

SecureApp's application history is incorrect for server groups whose connections were updated via API.

TOS-92074

TOS-92117

Case 00143723

R24-1

R24-1 PHF3.0.0

For NSX devices, source and destination appear as N/A in Rule Viewer.

TOS-90949

Case 00141220

R23-2

R25-1

R24-2

R24-2 PGA.0.0

Provisioning fails when special character ü appears in the rule name from SecureApp.

TOS-88465

TOS-88282

Case 00137095

R23-1

R24-1 PHF3.0.0

R24-2 PGA.0.0

For very large installations, the tos start command almost times out.

TOS-90327

Case 00139216

R23-2

R23-2 PHF2.0.0

R24-1 PHF3.0.0

Designer fails to update Panorama configuration in SecureChange. After clicking UPDATE DEVICE, the following error appears: Unexpected error, please, try again

TOS-90335

Case 00141220

R23-2

R23-2 PGA.0.0

R24-1 PHF3.0.0

For Fortinet devices, Designer calculations are timing out when the rule name is long and contains special characters.

TOS-90739

Case 00136704

R23-2

R24-1

R23-2 PHF1.0.0

R24-1 PHF3.0.0

 

NAT objects (Any, Any-IPv4, and Any-IPv6) do not appear in NST tables.

TOS-90786

TOS-90816

Case 00142649

Case 00145231

Case 00145677

R24-1

R24-1 PHF3.0.0

Map synchronization does not work after the tos vacuum command runs.

TOS-90877

TOS-90964

Case 00142644

R23-2

R24-1 PHF3.0.0

After processing a request to delete unused tickets, Verifier results are empty.

TOS-91360

Case 00142762

R23-2

R24-1 PHF3.0.0

FQDNs are getting removed from the rule when disabling a rule with Rule decommission workflow.

TOS-91784

Case 00143903

R23-2

R24-1 PHF3.0.0

Upgrading to R24-1 PHF2.0.0 failed. Error message: Failed to execute topology-facade API call.

TOS-91784

TOS-91847

Case 00143903

R23-2

R24-1

R24-1 PHF3.0.0

R24-2 PGA.0.0

Upgrading to R24-1 PHF2.0.0 failed. Error message: Failed to execute topology-facade API call.

TOS-90686

TOS-90685

TOS-90699

R23-2

R23-2 PHF3.2.0

R24-1 PHF2.0

R24-2 PGA.0.0

The tos snapshot restore command fails on TOS R23-2 PHF3.1.0.

TOS-90249

TOS-90413

Case 00140888

R23-1

R23-2

R24-1

R24-1 PHF2.0.0

R24-2-PGA.0.0

Netscreen devices managed by Telnet fail to receive revisions.

TOS-90122

TOS-90644

Case 00140908

R23-2

R24-1

R24-1 PHF2.0.0

R24-2 PGA.0.0

Gateway load balancers cannot be imported when traffic is blocked from one or more AWS regions.

TOS-88758

TOS-88792

Cases 00138801 00136903 00141673

R23-2

R24-1

R24-1 PHF2.0.0

R24-2 PGA.0.0

Fortinet ADOM fails to retrieve a revision when there is a space character in the FQDN name.

TOS-88009

TOS-90200

Case 00133017

R23-1

R24-1

R24-1 PHF2.0.0

Tickets page loads slowly if there are more than 10,000 tickets present. In addition to improving performance, users can change the default amount of tickets loaded to a lower number.

TOS-88858

TOS-89238

Case 00136095

R23-2

R24-1

R24-1 PHF2.0.0

R24-2 PGA.0.0

Path analysis queries get stuck and do not return results.

TOS-89278

TOS-89279

Case 00138255

R23-2

R24-1

R24-1 PHF2.0.0

R24-2 PGA.0.0

Cleanup rest API call returns General error when getting fully shadowed or disabled rules without including the start and count parameters.

 

R20-1 and later

Not fixed

When logging into TOS, a Vimeo cookie is placed in the browser.

TOS-90147

TOS-90241

TOS-90297

TOS-90562

Case 00140747

Case 141734

R24-1

R24-1 PHF2.0.0

R24-2 PGA.0.0

Revisions cannot be retrieved from Palo Alto devices. In the Compare Revisions page data for these devices is incomplete, and in the Administration > Status page imported Prisma objects show: Error: unknown error.

TOS-90248

00141900

TOS-90154

TOS-90192

Case 00139664

R24-1

R24-1 PHF2.0.0

Path analysis is incorrect for Cisco VXLAN when the interfaces all share the same IP address and are in different VRF tables.

TOS-80967

Case 00123548, 00128040, 00128578, 00133201, 00136137, 00141218

R23-2

R24-1

R23-2 PHF1.0.0

For FortiGate 7.2.6v devices, cannot get a new revision.

TOS-89913

TOS-89773

Case 00140235

R23-2

R24-1 PHF2.0.0

Unable to open a ticket for a workflow, that includes a script, from the "My request" page.

Error message: Could not initialize proxy - no Session

TOS-89372

TOS-89373

Case 00139132

R23-2

R24-1

R24-1 PHF2.0.0

Unable to add Fortinet ADOM when the comment includes an array of strings.

Error message: Fail to unmarshal data.

TOS-89233

TOS-89253

Case 00136569

R24-1

R24-1 PHF2.0.0

Unable to import virtual systems (VSYS) from the PanOS device when the version is 11 or higher.

TOS-88624

TOS-87559

Case 00135252

R23-2

R24-1

R24-1 PHF2.0.0

Cisco ASA device fails to provision when editing a rule which contains DM_INLINE group even though Designer suggests using it.

TOS-88475

TOS-88193

Case 00136571

R23-2

R24-1

R24-1 PHF2.0.0

Knowledge Center is unavailable when not connected to the internet.

Error message: 503 Service Temporarily Unavailable

TOS-88875

Case 00137263

R23-1

R24-1

R24-1 PHF2.0.0

Designer cannot create an object with NAT information if it was added from the Object Browser, from a VIP/MIB NAT policy filter, or from the results of path analysis if there is NAT in the path.

Error message: <OBJECT NAME> is defined in Zone A and cannot be used in Zone B.

TOS-90248

Case 00141900

R24-1

R24-1 PHF2.0.0

Unable to connect to Layer 3 devices when using a custom login prompt.

TOS-89950

TOS-90055

 

R24-1

R24-1 PHF2.0.0

After upgrading to R24-1 on a machine with IPv6 configured, the Topology map fails to load and displays the error message "The server is temporarily unable to service your request due to maintenance downtime or capacity problems. Please try again later.”

TOS-89455

TOS-89679

Case 00139534

R23-2

R24-1

R24-1 PHF2.0.0

For very large devices, TOS failed to migrate device from the Central Cluster to the Remote Collector.

TOS-89275

TOS-89442

Case 00134503

R23-1

R23-2

R24-1

R24-1 PHF2.0.0

FMC devices cease to function, with tickets failing to process and an error message “Unknown error.” Evidence of memory leaks appear in the logs.

TOS-89166

TOS-88655

Case 00137340

R23-2

R24-1

R24-1 PHF2.0.0

When running a SecureApp ticket with the internet as a source or destination, Designer fails.

TOS-88686

TOS-88839

Case 00137782

R23-1

R23-2

R24-1

R24-1 PHF2.0.0

The Cleanup Browser, Object Lookup, and Change Browser pages fail to perform device calculations when a large number of devices are present.

TOS-87987

TOS-88199

Case 00136023

R23-2

R24-1

R24-1 PHF2.0.0

Running path analysis when the cloud is the only end point causes broken path.

TOS-87466

No case

R22-2

R23-1

R23-2

R24-1

R24-1 PHF2.0.0

Tickets page always reverts to last saved query when navigating away from the page instead of keeping the query performed by the user.

TOS-89211

TOS-89172

R23-1

R23-2

R24-1

R24-2 PGA.0.0

tos cluster snapshot create and tos cluster snapshot restore commands cannot be run on remote connector clusters. If you are upgrading TufinOS 3 to 4 on a remote collector cluster, you must use the procedure Upgrade TufinOS 3 to 4 Reinstall on Same VM, which requires reinstalling TOS.

In R23-2 PHF3.1.0, R24-1 PHF2.0.0 and later versions of the same releases, these commands are blocked from running on remote clusters

TOS-88660

TOS-88686

TOS-88839

Case 00137782

R23-1

R23-2

R24-1

R24-1 PHF1.0.0

When there are more than 15,000 devices, the SecureTrack Object Lookup page loads initial data, but no buttons work.

TOS-87558

TOS-87566

Case 00135264

R24-1

R24-1 PHF1.0.0

For north-south, ACI-integrated Panorama paths, topology simulation yields an inaccurate security calculation.

Error message: Request input is not supported

TOS-87927

Case 00134578

R23-2

R24-1

R24-1 PHF1.0.0

When running Designer on a device which doesn’t support Provisioning “Not run” appears next to the device name in the SecureChange.

TOS-85792

TOS-85806

Case 00128917

R23-1

R23-2

R24-1

R23-2 PHF3.0.0

R24-1 PHF1.0.0

SecureTrack can't retrieve topology data for Azure Virtual hubs when the next hop type is VPN_S2S_Gateway and there is a path with a range.

TOS-87552

Case 00128408

R22-2

R23-1

R23-2

R23-2 PHF3.0.0

When running Designer on a Check Point device with an access request that is shadowing a different access request, Designer returns an error.

Error message: Designer is unable to suggest changes for this device.

TOS-86966

TOS-87046

Case 00131298

R23-1

R23-2

R24-1

R23-2 PHF3.0.0

R24-1 PHF1.0.0

R24-2 PGA.0.0

Cisco MPLS interfaces with a short name are parsed incorrectly and displayed as normal interfaces.

TOS-87173

TOS-87371

Case 00136366

R23-2

R24-1

R23-2 PHF3.0.0

R24-1 PHF1.0.0

R24-2 PGA.0.0

Access-role and security zone objects are displayed as network objects in the CSV file that is created when exporting Unattached Network Objects from the Cleanup Browser.

TOS-87256

TOS-87365

Case 00131298

R22-2

R23-1

R23-2

R24-1

R23-2 PHF3.0.0

R24-1 PHF1.0.0

R24-2 PGA.0.0

The New Revision report isn't being created when new revisions arrive in SecureTrack, and recipients aren't receiving an email. This occurs when the report is the only report, and it is generated for any changes to any devices.

TOS-87380

TOS-87096

TOS-87381

Case 00133018

R22-2

R23-1

R23-2

R24-1

R23-2 PHF3.0.0

R24-1 PHF1.0.0

R24-2 PGA.0.0

The result returned by the security_zones api function is missing zone hierarchies

TOS-87727

TOS-88373

TOS-87813

TOS-87814

Case 00135080

R23-2

R24-1

R23-2 PHF2.0.0

R24-1 PGA.0.0

R24-2 PGA.0.0

SecureTrack can't retrieve dynamic topology for logical routers belonging to NSX-T devices.

cloud-topology-service app.log exception:

Internal Server Error: null

java.lang.NullPointerException: null

at com.tufin.cloudtopology.service.builder.nsx.NsxInterfaceBuilder.containIpAddresses(NsxInterfaceBuilder.java:46) ~[classes/:?]

TOS-87903

TOS-87904

Case 00135249

R22-2

R23-2

R24-1

R23-2 PHF2.0.0

R24-1 PHF1.0.0

Upgrade to R23-2 PHF1.0.0 fails due to license restriction errors.

Error message: Upgrade service failed with the following errors:\nService tss failed with error: Failed due to license restrictions

REL-903

Case 00138348

R23-2

R24-1

R23-2 PHF3.0.0

R24-1 PHF1.0.0

 

Users with external SSO Authentication lose access to SecureChange after upgrading to affected releases.

TOS-87733

TOS-87652

Case 00136639

Case 00137992

R23-2

R24-1

R23-2 PHF3.0.0

R24-1 PHF1.0.0

When processing UI requests, TOS virtual network issues yield errors or delays in response.

TOS-87583

TOS-87791

Case 00135634

R22-2

R23-1

R23-2

R24-1

R23-2 PHF3.0.0

R24-1 PHF1.0.0

SecureApp fails to add an application while trying to delete an application.

TOS-87433

TOS-87562

TOS-87563

Case 00131110

R23-1

R23-2

R24-1

R23-2 PHF3.0.0

R24-1 PHF1.0.0

Some devices are missing in the path when inbound and outbound VRFs are different.

TOS-87311

Case 00130377

R23-1

R23-2

R23-2 PHF3.0.0

Connection status is red when it should be green.

TOS-87224

TOS-87369

Case 00135784

R23-1

R23-2

R24-1

R23-2 PHF3.0.0

R24-1 PHF1.0.0

Rule Change report does not send notification emails and is not saved in the repository.

TOS-86215

Case 00134994

R23-1

R23-2

R24-1 PGA.0.0

When decommissioning a Juniper SRX device with global zone rules, Designer incorrectly includes these rules in its suggestions that can be provisioned. Provisioning global zone rules is not supported for SRX devices. Designer provides manual suggestions only.

TOS-86210

TOS-88662

TOS-88663

Case 00135105

R23-1

R23-2

R24-1

R23-2 PHF3.0.0

R24-2 PGA.0.0

R24-1 PHF1.0.0

Device Collector container crashes with exit code 139 (SIGSEV). Related to memory leak on Queue_Server process.

TOS-86064

TOS-86020

TOS-86065

Case 00135174

R23-1

R23-2

R23-2 PHF3.0.0

R24-1 PGA.0.0

Path analysis provides an incorrect path for Cisco devices when there is an MPLS route.

TOS-85256

Case 00132604

R23-2

R24-1 PGA.0.0

SecureTrack user interface stops responding and displays the following message: Looks like something went wrong. Performance queries were enhanced to resolve this issue.

TOS-85308

Case 00133746

R23-2

R24-1 PGA.0.0

TOS backup export from external storage is not working.

TOS-86097

Case 00135594

R23-1

R23-2

R24-1 PGA.0.0

For Check Point devices, cannot create a rule name with more than 30 characters.

TOS-81891

TOS-83443

TOS-82557

TOS-82556

R23-2

R23-2 PHF2.0.0

After restoring from a backup, you may experience one or more of the following: high CPU usage, slow response time, incorrect violation calculations, and other unexpected behavior. After upgrading, make a new backup.

TOS-81736

TOS-81737

Case 00125837

R23-2

R23-2 PHF2.0.0

R24-1 PGA.0.0

On the Dashboard, Cleanup Trend data for devices with disabled or shadowed rules includes only the first 100 devices.

TOS-80744

TOS-81930

Case 00127381

R23-2

R23-2 PHF2.0.0

After committing an update suggested by Designer, the commit status report for the ticket displays an end time that’s different from the ticket history. This causes inconsistencies between the Commit Status Report (available after clicking Commit) and the Ticket History and PDF Exports (available from the Ticket screen).

TOS-79030

Case 00123865

R22-2 and later

Not fixed

Revisions cannot be processed for Check Point CMA devices that have ‘@’ in an object name. This can be resolved by removing the @ character from all object names in the policy and fetching the revision again.

TOS-80793

TOS-83531

TOS-83611

Case 00121065

R23-2

R23-2 PHF2.0.0

For Fortinet FMG devices with a single policy that has over 140,000 rules, SecureTrack returns an out-of-memory error and cannot retrieve revisions.

TOS-80822

TOS-81413

TOS-81585

Case 00115997

R23-2

R23-2 PHF2.0.0

Slow FMC syslog messages retrieval by SecureTrack due to logs full of prints by the syslog translator.

TOS-81563

TOS-82008

TOS-82025

Case 00115997

R22-2

R23-1

R23-2

R23-2 PHF2.0.0

For Cisco FMC devices with more than 30,000 rules, translating FMC syslog traffic devices takes 50 EPS (events per second) instead of 5000 EPS.

TOS-82067

TOS-82784

Case 00128589

R22-2

R23-1

R23-2

R23-2 PHF2.0.0

Following forced removal, devices still appear in the Device Viewer and Rule Viewer.

TOS-82452

TOS-82577

Case 00130384

R23-2

R23-2 PHF2.0.0

For Cisco FMC devices, after a rule modification in SecureChange, the TRUST action for the rule changes to a BLOCK action on the device.

TOS-83533

TOS-83235

Case 00131700

R23-2

R23- 2 PHF2.0.0

R24-1 PGA.0.0

Failure to import Meraki managed devices.

TOS-82108

TOS-83235

Case 00125832

R22-2

R23-1

R23-2

R23-2 PHF2.0.0

Access list entry removal provisioning fails when there are extra spaces at the end of the remark in the configuration file for Cisco ASA devices.

TOS-83918

TOS-84101

Case 00131106

R23-1

R23-2

R23-2 PHF2.0.0

Verifier returns a "User Network zone is not configured" message when the User Network zone has no subnet, but a child zone (of the User Network zone) contains a subnet.

TOS-81698

TOS-81702

Case 00127600

R23-1

R23-2

R23-2 PHF2.0.0

Map shows incorrect routing information when there is an Azure VNET with multiple route circuits.

TOS-81388

TOS-81137

TOS-82330

Case 00127011

R23-1

R23-2

R23-2 PHF2.0.0

Topology and zone mapping incomplete for Cisco Meraki devices.

TOS-56648

R22-1 and later

Not fixed

For Check Point management devices, there is a known issue with loading the Automatic Policy Generation (APG) page when there is a special character in the inline-layer group name. There is no workaround for this issue. Avoid using special characters (such as #, %, &) when creating inline-layer groups.

TOS-71264

Case 00116185

R23-1

R23-2

Not fixed

For Palo Alto devices, there is a known issue causing Designer to give a global object a name that already exists.

TOS-66508

Case 00110830

R23-1

R23-2

Not fixed

For FortiManager devices, there is a known issue preventing revisions from being retrieved when there is a policy name containing an en dash character.
 

R23-2 and later

Not fixed On rare occasions, older requests do not appear in the Requests list upon TOS startup. If this occurs, wait a few minutes and refresh the page.
 

R23-2 and later

Not fixed

Rule history is not available for Zscaler devices.

TOS-74048

TOS-76166

R23-2 and later

Not fixed

In the Rule History tab, there is no indication of the object type for changes to services or security profiles.

TOS-48645

R21-1 and later

Not fixed

When an admin uses Rule Viewer to select rules and open a ticket for them, a new SecureChange tab opens in the browser with a draft of the ticket to be submitted. If the new tab does not display the relevant ticket, you will need to refresh the browser window to see the ticket. This issue occurs with the Rule Modification, Rule Decommission, and Rule Recertification workflows.

TOS-80597

R23-1

R23-2

R24-1 PGA.0.0 Verifier fails for NSX-V objects with the message: Verifier could not calculate the traffic of the input objects in the access request. Contact Tufin support.

TOS-82841

TOS-82842

Case 00130640

R23-1

R23-2

R23-2 PHF2.0.0

Map is not updated due to failure when receiving data from an external OPM agent. This occurs when the amount of topology data is over 15,000 entries.

TOS-82803

TOS-83424

Case 00127150

R22-2

R23-1

R23-2

R23-2 PHF2.0.0

Designer suggestions for Panorama devices cannot be modified. The following error is returned: Waiting for revision from a conflicting ticket, cannot modify the Designer results. This occurs when Designer is configured to create shared objects.

TOS-81465

TOS-81507

Case 00124227

R22-2

R23-1

R23-2

R23-2 PHF2.0.0

Designer suggests creating new rules to provide access when that access is already provided by existing rules. This behavior occurs when the ticket includes applications, and is a result of traffic miscalculation for apps with the same service in a different port when there is a Cisco ACI device in the path.

TOS-80622

Case 00123016

R23-1

R23-2

 

When running path analysis on a shared Azure ExpressRoute, additional VNETs are displayed in the path.

TOS-81745

TOS-82188

Case 00124898

R23-1

R23-2

R23-2 PHF2.0.0

Cleanup instances do not open in the Cleanup page when the revisions have multiple versions. The following message appears to users: Recalculating Revision results. This can take a while.

TOS-87079

TOS-87148

TOS-87149

Case 00135795

R23-2

R24-1

R23-2 PHF3.0.0

R24-1 PHF1.0.0

Cleanup instances do not open in the Cleanup page when the revisions have multiple versions and there is revision parsing order is inconsistent. The following message appears to uses: Recalculating revision results. This may take a while.

TOS-83733

Case 00126772

R22-2

R23-1

R23-2

R23-2 PHF2.0.0

When running tos dr switch or tos dr status, the command fails due to no compatible backup files being found even though completed scheduled backup files exist.

TOS-82608

TOS-82493

Case 00128588

R23-1

R23-2

R23-2 PHF2.0.0

After running a scan in RLM, tickets with an expiration date later than the rule recertification date will cause a related ticket to be created in Rule Viewer with an ID of 0.

TOS-82829

TOS-82550

Case 00128588

R23-1

R23-2

R23-2 PHF2.0.0,

Backup files stored on NFS will cannot be deleted in HA environments with disaster recovery configured.

TOS-80781

Case 00127809

R23-1

R23-2

 

After new tiered license is activated, SecureChange tickets get stuck on the auto-verifier step and cannot proceed.

TOS-79379

Case 00123476

R21-3

R22-1

R22-2

R23-1

R23-2

 

Performance issues when connecting to an LDAP server.

TOS-83494

TOS-77831

TOS-83495

Case 00131041

R23-1

R23-2

R23-2 PHF2.0.0,

When fetching a revision from a Cisco ACI device, a null pointer exception (NullPointerException) occurs.

TOS-84153

TOS-84154

Case 00131095

R23-2

R23-2 PHF2.0.0

Domain information for cloud and network objects is missing from the Path Analysis view in the Map.

TOS-79559

TOS-79435

Case 00120593

R22-2

R23-1

R23-2

R23-2 PHF2.0.0

A Certified rule status is being overridden by the rule documentation backward-compatibility API.

TOS-82162

Case 00129097

R23-1

R23-2

R23-2 PHF2.0.0

Using an API call to add multiple ARs to a ticket, and marking the status as Done, removes the last AR.

TOS-83501

TOS-83503

Case 00130078

R23-1

R23-2

R23-2 PHF2.0.0

Fields are missing from the MIB file.

TOS-84094

TOS-85275

TOS-85276

Case 00131641

R23-1

R23-2

R23-2 PHF2.0.0

For Juniper SRX devices, static NAT rules do not contain all source members.

TOS-84633

TOS-84657

TOS-84658

Case 00131309

R23-1

R23-2

R24-1

R23-2 PHF2.0.0

R24-2 PGA.0.0

Automatic target analysis fails for Check Point FQDN objects, even though the objects exists. Topology returns the error message: Internal error occurred

TOS-85138

TOS-85312

TOS-85313

Case 00132715

Case 00133578

R23-1

R23-2

R23-2 PHF2.0.0

R24-2 PGA.0.0

Running the GET Ticket API returns the error: "Parameter specified as non-null is null."

TOS-85162

TOS-85491

TOS-85244

Case 00130856

R22-1

R22-2

R23-1

R23-2

R23-2 PHF2.0.0

R24-1 PGA.0.0

 

An "invalid server certificate" error is returned when logging into devices from TOS using Cyberark for external authentication.

TOS-85070

TOS-85110

TOS-85111

Case 00132624

Case 00133290

R23-1

R23-2

R23-2 PHF2.0.0

R24-1 PGA.0.0

Verifier does not support the icmp-proto service in access requests.

TOS-84627

Case 00131389

R23-1

R23-2

R23-2 PHF2.0.0

Local backup fails.

TOS-83662

Case 00132169

R23-1

R23-2

R23-2 PHF2.0.0

Provisioning fails on FortiManager devices with the message: Update FortiManager_for_FFM did not run: Rule contains only IPv4 src or dest addresses, both IPv6 srcAddr and IPv6 dstAddr should be available in a change. This occurs when trying to replace a group.

TOS-82694

Case 00129609

Case 00114483

R22-2

R23-1

R23-2

R23-2 PHF2.0.0

No requests shown when filtering for closed tickets in a group that contains more then 35310 tickets.

TOS-81384

Case 00126283

R23-1

R23-2

R23-2 PHF2.0.0

Communication between SecureTrack and SecureChange is frequently interrupted.

The following message appears:

SecureTrack settings:Cannot connect to SecureTrack.

Five minutes later, this message appears:

SecureTrack settings:Connection successful.

TOS-84941

TOS-85084

Case 00133674

R23-1

R23-2

R23-2 PHF2.0.0

Importing data using the SecureApp Import Applications template fails with error message “Cannot import application data” when empty rows are present.

TOS-83357

TOS-83394

TOS-83357

Case 00126123

R23-2

R23-2 PHF2.0.0

Designer failed with the error message "There are matching unresolved FQDN objects. You may be able to resolve the problem by enabling a local DNS." due to FQDN objects containing uppercase letters.

TOS-82097

TOS-82588

Case 00128812

R23-2

R23-2 PHF2.0.0

Verifier and Path Analysis fail to display rules implemented on a monitored firewall, due to incorrect parsing of network object groups

TOS-82566

TOS-83032

Case 00127221

R23-2

R23-2 PHF2.0.0

The error message “Verifier could not calculate the traffic of the input objects in the access request” appears when Verifier is run on NSX-T devices that contain rules with security groups in the Source/Destination. This occurs after upgrading to a new version and running Verifier on an Access Request submitted in the previous version.

TOS-82474

TOS-82832

Case 00130229

 

R23-2

R23-2 PHF2.0.0

Editing Designer results is not allowed after Designer fails within an auto-step.

TOS-85144

Case 133815

R23-2

R23-2 PHF2.0.0

“New version verification failed” message displayed when parsing AWS VPC fails due to duplicate objects.

TOS-84597

TOS-83682

Case 00133552

R23-2

R23-2 PHF2.0.0

When restarting TOS after running “tos cluster snapshot,” “tos cluster snapshot restore” fails with error “no global configuration found”.

TOS-80139

TOS-80551

Case 00124301

R23-2

R23-2 PHF2.0.0

Application interfaces can’t be retrieved via API when the same server is used for both the application pack and the connection to application pack.

TOS-85704

TOS-85561

Case 00131777

R23-2

R23-2 PHF2.0.0

R24-1 PGA.0.0

Topology information cannot be retrieved from AWS devices when there is a gateway load balancer linked to multiple AWS accounts.

TOS-82077

Case 00130053

R23-2

R23-2 PHF2.0.0

Users are not able to use the Server Lookup page to find objects in the apps they created. The View all applications permit is incorrectly required.

TOS-85814

TOS-85438

Case 00126032

Case 00130632

Case 00133278

R23-2

R23-2 PHF2.0.0

R24-1 PGA.0.0

Revisions cannot be retrieved. Caused by a failure in the device collector service

TOS-85567

TOS-85841

Case 00130394

 

R24-1 PGA.0.0

 

Comments are duplicated to Cisco FMC rules when Rule Decommission workflow changes are provisioned.

TOS-86118

TOS-86145

Case 00133299

 

R24-1 PGA.0.0

Tos backup create suffers performance issues when configured to local storage.

TOS-86008
Case 00135250


 

R24-1 PGA.0.0

During upgrades, TOS status displays “Checker failure” and upgrade fails.

TOS-87324

Case 00136556

R23-2

R23-2 PHF3.0.0

R24-1 PGA.0.0

Revision retrieval fails due to a single client running on two different pods.

TOS-87853

TOS-87517

Case 00135870

Case 00133044

R22-2

R23-1

R23-2

R24-1

R23-2 PHF3.0.0

R24-1 PHF1.0.0

TOS pages (including Cleanup Browser, Object Lookup, and others) have loading times of 2-5 minutes when more than 10,000 devices are present in the environment.

TOS-87594

Case 00136555

R23-2

R23-2 PHF3.0.0

After upgrading to R23-2 PHF3.0.0 when the jvm.extraOpts parameter is present, calling the logs of SecureTrack jobs returns the message ERROR unable to locate appender "${env:logging.appender}" for logger config "root."

TOS-87096

TOS-87380

TOS-87381

Case 00133018

R22-2

R23-1

R23-2

R24-1

R23-2 PHF3.0.0

R24-1 PHF1.0.0

The API /securetrack/api/security_zones takes over 10 seconds to respond.

TOS-86887

TOS-87103

Case 00130227

R23-1

R23-2

R24-1

R23-2 PHF3.0.0

R24-1 PHF1.0.0

For Cisco routers, rule numbers are parsed incorrectly when the device is not configured to collect rule usage analysis. As a result, attempts to provision ACL removal fail.

TOS-88316

TOS-88327

TOS-88328

TOS-88334

Case 00138348

R23-2

R23-2 PHF3.0.0

R24-1 PHF1.0.0

After upgrading, users belonging to nested groups can not access SecureChange.

TOS-85794

Case 00129891

R23-1

R23-2

R23-2 PHF3.0.0

Revision fetching for NSX-T devices was not triggered when the NSX Manager NSX-T revisions fail to be retrieved when the NSX Manager hostname is an FQDN.

TOS-85470

TOS-87815

TOS-87816

Case 00133673

R23-2

R24-1

R23-2 PHF3.0.0

R24-1 PHF1.0.0

For Panorama 10.2 devices, Provisioning fails.

TOS-88154

TOS-85046

TOS-88157

Case 00133483

R23-1

R23-2

R24-1

R24-1 PHF2.0.0

After upgrading, TOS fails to receive device revisions if monitored Check Point devices use LEA authentication on RC.

TOS-87237

TOS-87893

TOS-87892

TOS-87891

Case 00133117

R22-2

R23-1

R23-2

R23-2 PHF3.0.0

R24-1 PHF1.0.0

Designer fails when in topology mode, when a specific domain is selected, returning message "<Firewall> not in path". This occurs because Designer looks for the path outside of the currently selected domain.