Update PAN-OS 11.1 files

This commit is contained in:
2026-04-15 14:57:19 -05:00
parent 8a243e3d9c
commit 10f549ef2a
84 changed files with 3207 additions and 3509 deletions
+60 -60
View File
@@ -18,7 +18,7 @@ Fixed an issue where Panorama managed firewalls with no defined log collector gr
## PAN-296977
Fixed an issue where the web interface became unresponsive when attempting to view Ethernet interface details after applying a filter in Network > Interfaces.
Fixed an issue where the web interface became unresponsive when attempting to view **Ethernet** interface details after applying a filter in **Network > Interfaces**.
## PAN-296478
@@ -74,7 +74,7 @@ Fixed an issue on Panorama where commit versions did not display correct data in
## PAN-293985
Fixed an issue with the Panorama web interface where admin users were unable to log in and received the error message 504: Gateway Timeout.
Fixed an issue with the Panorama web interface where admin users were unable to log in and received the error message **504: Gateway Timeout**.
## PAN-293877
@@ -106,11 +106,11 @@ Fixed an issue where setting the logdb-quota for the desum log type to 0 caused
Panorama virtual appliances in FIPS mode only
```
Fixed an issue where plugin installs failed with the error invalid image after manually uploading the plugin package from the Customer Support Portal (CSP).
Fixed an issue where plugin installs failed with the error **invalid image** after manually uploading the plugin package from the Customer Support Portal (CSP).
## PAN-292980
Fixed an issue on the web interface where the Connected status for a User-ID agent in a non-User-ID Hub vsys displayed as blank if the same agent was also configured in a User-ID Hub vsys.
Fixed an issue on the web interface where the **Connected** status for a User-ID agent in a non-User-ID Hub vsys displayed as blank if the same agent was also configured in a User-ID Hub vsys.
## PAN-292770
@@ -170,11 +170,11 @@ Fixed an issue where Panorama in FIPS-CC mode failed to push IKEv2 Post-Quantum
## PAN-290702
Fixed an issue where Log Quotas incorrectly displayed a value that was higher than possible.
Fixed an issue where **Log Quotas** incorrectly displayed a value that was higher than possible.
## PAN-290694
Fixed an issue on the Panorama web interface where you were unable to push shared objects to devices if an HA failover occurred during a configuration push.
Fixed an issue on the Panorama web interface where you were unable to **push** shared objects to devices if an HA failover occurred during a configuration push.
## PAN-290691
@@ -186,7 +186,7 @@ Fixed an issue where, when multiple scheduled vulnerability reports were were se
## PAN-290241
Fixed an issue where the useridd process became unresponsive, which caused User ID CLI commands to time out.
Fixed an issue where the **useridd** process became unresponsive, which caused User ID CLI commands to time out.
## PAN-290239
@@ -202,11 +202,11 @@ Fixed an issue where the dscd process crashed continuously on MIPS platforms (fo
## PAN-290191
Fixed an issue where BGP learned routes were not advertised when Legacy Routing was used and an export policy was configured to match the next hop of the learned route.
Fixed an issue where BGP learned routes were not advertised when **Legacy Routing** was used and an export policy was configured to match the next hop of the learned route.
## PAN-290157
Fixed an issue on Panorama where the configd process stopped responding when filtering in the Config Audit window, which caused Panorama to restart unexpectedly.
Fixed an issue on Panorama where the configd process stopped responding when filtering in the **Config Audit** window, which caused Panorama to restart unexpectedly.
## PAN-290088
@@ -242,7 +242,7 @@ Fixed an issue where SD-WAN SaaS monitoring did not work with URL monitoring.
## PAN-289736
Fixed an issue where partial-revert operations were taking a long time, causing config lock timeout issues and resulting in frequent error messages being displayed: Timed out while getting config lock. Please try again.
Fixed an issue where partial-revert operations were taking a long time, causing config lock timeout issues and resulting in frequent error messages being displayed: **Timed out while getting config lock. Please try again.**
## PAN-289652
@@ -250,11 +250,11 @@ Fixed an issue related to external URL lists where pushing configuration changes
## PAN-289573
Fixed an issue on Panorama where the web interface became unresponsive when attempting to edit the Allow traffic to specified FQDN when Enforce GlobalProtect Connection for Network Access setting in a GlobalProtect portal configuration after adding 40 or more FQDN entries.
Fixed an issue on Panorama where the web interface became unresponsive when attempting to edit the **Allow traffic to specified FQDN when Enforce GlobalProtect Connection for Network Access** setting in a GlobalProtect portal configuration after adding 40 or more FQDN entries.
## PAN-289541
Fixed an issue where the bandwidth graphs (Link Monitoring) in Panorama for SD-WAN environments displayed incorrect values.
Fixed an issue where the bandwidth graphs (**Link Monitoring**) in Panorama for SD-WAN environments displayed incorrect values.
## PAN-289532
@@ -322,7 +322,7 @@ Fixed an issue on Panorama where, after logging in to the web interface as the Z
## PAN-288930
Fixed an issue where traffic from cloud applications intermittently matched an incorrect cloud-apps policy rule when ACE (App-ID Cloud Engine) was enabled.
Fixed an issue where traffic from cloud applications intermittently matched an incorrect **cloud-apps** policy rule when ACE (App-ID Cloud Engine) was enabled.
## PAN-288929
@@ -414,7 +414,7 @@ Fixed an issue where the maximum registered IP address for was incorrectly set t
## PAN-287842
Fixed an issue where the comm process stopped responding due to missing heartbeats, which resulted in a system alert and HA communication loss on slot1.
Fixed an issue where the **comm** process stopped responding due to missing heartbeats, which resulted in a system alert and HA communication loss on slot1.
## PAN-287838
@@ -438,7 +438,7 @@ Fixed an issue where SAML authentication failed, which caused the GlobalProtect
## PAN-287688
Fixed an issue where the firewall failed to connect to the Palo Alto Networks update server when using a customized service route with the source interface as MGT.
Fixed an issue where the firewall failed to connect to the Palo Alto Networks update server when using a customized service route with the source interface as **MGT**.
## PAN-287621
@@ -470,7 +470,7 @@ Fixed an issue where the firewall generated critical system log alerts every 3 m
## PAN-287392
Fixed the issue on the web interface where ACC graphs displayed No data to display when a filter was applied to Source IP or Destination IP.
Fixed the issue on the web interface where **ACC** graphs displayed **No data to display** when a filter was applied to **Source IP** or **Destination IP**.
## PAN-287387
@@ -530,7 +530,7 @@ Fixed an issue where ECMP incorrectly balanced sessions across links based on th
VM-Series firewalls only AWS environments only
```
Fixed an issue where the firewall did not send ICMP unreachable - Fragmentation Needed message when it received packets larger than the MTU.
Fixed an issue where the firewall did not send **ICMP unreachable - Fragmentation Needed** message when it received packets larger than the MTU.
## PAN-286818
@@ -542,7 +542,7 @@ Fixed an issue where closing an SSH session to a Panorama using Ctrl+D did not g
Panorama virtual appliances in HA configurations on Microsoft Azure environments only
```
Fixed an issue where plugin versions displayed when hovering over the Green Match icon were inconsistent even though the web interface reported the versions as matching.
Fixed an issue where plugin versions displayed when hovering over the **Green Match** icon were inconsistent even though the web interface reported the versions as matching.
## PAN-286735
@@ -562,7 +562,7 @@ Added uplink counters to enhance debug capability for traffic drops.
Panorama appliances only
```
Fixed an issue where the Require SSL/TLS secured connection in the LDAP profile within the template stack did not take effect after overriding the configuration. This occurred even when the setting was enabled multiple times.
Fixed an issue where the **Require SSL/TLS secured connection** in the LDAP profile within the template stack did not take effect after overriding the configuration. This occurred even when the setting was enabled multiple times.
## PAN-286669
@@ -598,7 +598,7 @@ Fixed an issue where, when getting transceiver information from ESCC for SFP 25G
## PAN-286299
Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the Network and Device tab became read-only.
Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the **Network** and **Device** tab became read-only.
## PAN-286231
@@ -626,7 +626,7 @@ Fixed an issue where the all_task process stopped responding, which caused the f
## PAN-285834
Fixed an issue on Panorama where Policy recommendation displayed Unable to read data for certain profiles due to a large response size.
Fixed an issue on Panorama where **Policy recommendation** displayed **Unable to read data** for certain profiles due to a large response size.
## PAN-285818
@@ -674,7 +674,7 @@ Fixed an issue where commits remained at 98% completion when static route config
## PAN-285117
Fixed an issue on Panorama where Browse for Agent Video Traffic under GlobalProtect Gateway configurations returned an Invalid Sequence error due to an invalid XPath within the Panorama template and template stack.
Fixed an issue on Panorama where **Browse** for Agent Video Traffic under GlobalProtect Gateway configurations returned an **Invalid Sequence** error due to an invalid XPath within the Panorama template and template stack.
## PAN-284968
@@ -682,7 +682,7 @@ Fixed an issue where the dnsproxy process stopped responding when enabling the A
## PAN-284907
Fixed an issue where the Panorama web interface displayed No Data when viewing configuration logs to see changes before and after a configuration change.
Fixed an issue where the Panorama web interface displayed **No Data** when viewing configuration logs to see changes before and after a configuration change.
## PAN-284878
@@ -766,7 +766,7 @@ Fixed an issue where HTTP/2 child streams were blocked by strict-ip-check zone p
## PAN-283613
Fixed an issue on the web interface where the IP Tag Quota(%) value displayed as 2 even when changed.
Fixed an issue on the web interface where the **IP Tag** **Quota(%)** value displayed as 2 even when changed.
## PAN-283575
@@ -790,7 +790,7 @@ Fixed an issue where log forwarding to all syslog servers failed if one syslog s
## PAN-283206
Fixed an issue where configuring an HTTP profile to send Webhook alerts to Microsoft Teams failed with a 400 Bad request error when clicking Send Test Log .
Fixed an issue where configuring an HTTP profile to send Webhook alerts to Microsoft Teams failed with a 400 Bad request error when clicking **Send Test Log** .
## PAN-283138
@@ -834,7 +834,7 @@ Fixed an issue where a firewall was only able to display a maximum of 14 permitt
## PAN-282240
Fixed an issue where, when attempting to modify an Anti-Spyware profile via the web interface under a shared location, clicking the OK button displayed a console exception error.
Fixed an issue where, when attempting to modify an Anti-Spyware profile via the web interface under a shared location, clicking the **OK** button displayed a console exception error.
## PAN-281797
@@ -870,7 +870,7 @@ Fixed an issue on Panorama managed firewalls where, when the service route confi
## PAN-281096
Fixed an issue on HA clusters where, when link and path monitoring was configured and the failover condition was set to all, disconnecting and reconnecting monitored ethernet ports caused the firewall to switch to a nonfunctional role, which resulted in all interfaces except the HA interface going down.
Fixed an issue on HA clusters where, when link and path monitoring was configured and the failover condition was set to **all**, disconnecting and reconnecting monitored ethernet ports caused the firewall to switch to a nonfunctional role, which resulted in all interfaces except the HA interface going down.
## PAN-280910
@@ -886,7 +886,7 @@ Fixed an issue where all data interfaces went down due to a Forward Error Correc
## PAN-280554
Fixed an issue on the web interface where the Enable local inline categorization option in URL Filtering profiles incorrectly appeared as enabled by default.
Fixed an issue on the web interface where the **Enable local inline categorization** option in URL Filtering profiles incorrectly appeared as enabled by default.
## PAN-280409
@@ -906,11 +906,11 @@ Fixed an issue in the URL filtering logs where the columns and the displayed con
## PAN-280013
Fixed an issue where User-ID custom reports were unable to exclude IP address 0.0.0.0 when using the filter ip notin 0.0.0.0.
Fixed an issue where User-ID custom reports were unable to exclude IP address 0.0.0.0 when using the filter **ip notin 0.0.0.0**.
## PAN-279901
Fixed an issue where the firewall dropped client hello packets when decryption was enabled, which prevented access to certain websites. This occurred when the client hello packet was truncated, the accumulation proxy assumed that the first packet contains at least 5 bytes, or out-of-order packets were waiting in L4 TCP.
An issue was fixed where the firewall dropped fragmented TLS ClientHello packets, which blocked access to certain websites. This occurred because the packets arrived truncated, in varying sizes and orders, and the firewall's heuristics failed to handle them correctly.
To enable this fix, run: debug dataplane set ssl-decrypt accumulate-client-hello disjoined yes
@@ -924,7 +924,7 @@ Fixed an issue on M-600 line cards where the /var/log/messages file flooded with
## PAN-279584
Fixed an issue where, during software deployment from Panorama to multiple firewalls, some firewalls did not automatically reboot after the upgrade, even when Reboot device after install was selected. This was due to the Panorama timing out before the software deployment completed on the affected firewalls, which prevented the reboot request from being sent.
Fixed an issue where, during software deployment from Panorama to multiple firewalls, some firewalls did not automatically reboot after the upgrade, even when **Reboot device after install** was selected. This was due to the Panorama timing out before the software deployment completed on the affected firewalls, which prevented the reboot request from being sent.
## PAN-279500
@@ -970,7 +970,7 @@ Fixed an issue where the configd process restarted during a configuration push f
## PAN-278507
Fixed an issue where the OCSP Signing purpose was not included in the Extended Key Usage field when a certificate was generated on the firewall with the OCSP responder called in the certificate. This caused the GlobalProtect connection to fail with the error Missing OCSP signing purpose in the ExtendedKeyUsage.
Fixed an issue where the OCSP Signing purpose was not included in the **Extended Key Usage** field when a certificate was generated on the firewall with the OCSP responder called in the certificate. This caused the GlobalProtect connection to fail with the error **Missing OCSP signing purpose in the ExtendedKeyUsage**.
## PAN-278322
@@ -1002,7 +1002,7 @@ Fixed an issue where the number of registered IP Tags on Panorama did not match
VM-Series firewalls in AWS environments only
```
Fixed an issue where HA failover mode incorrectly changed from interface move to secondary IP move after a reboot.
Fixed an issue where HA failover mode incorrectly changed from **interface move** to **secondary IP move** after a reboot.
## PAN-277808
@@ -1014,11 +1014,11 @@ Fixed an issue where Panorama failed to upgrade due to duplicate path-monitor na
## PAN-277682
Fixed an issue where moving an address object from a device group to shared and renaming it did not reflect in the address group, which caused commits to fail.
Fixed an issue where moving an address object from a device group to **shared** and renaming it did not reflect in the address group, which caused commits to fail.
## PAN-277464
Fixed an issue with intermittent access and slower than expected loading times when accessing websites. This occurred when Anti-Spyware inline cloud analysis was enabled and the SSL Command and Control action was not either allow* or **alert and server hello packets were out of order.
Fixed an issue with intermittent access and slower than expected loading times when accessing websites. This occurred when Anti-Spyware inline cloud analysis was enabled and the **SSL Command and Control** action was not either **allow* or **alert** and server hello packets were out of order.
## PAN-277178
@@ -1064,15 +1064,15 @@ Fixed an issue where Panorama became unresponsive while performing a dynamic add
## PAN-276484
Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (Device Deployment > Licenses) due to the inability to perform batch-license refreshes.
Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (**Device Deployment > Licenses**) due to the inability to perform batch-license refreshes.
## PAN-276321
Fixed an issue where User-ID mappings were not correctly redistributed from Panorama to firewalls, causing some users to be identified as unknown, which prevented access to resources based on AD group membership.
Fixed an issue where User-ID mappings were not correctly redistributed from Panorama to firewalls, causing some users to be identified as **unknown**, which prevented access to resources based on AD group membership.
## PAN-276144
Fixed an issue on the web interface where the Response Page action column was not accessible.
Fixed an issue on the web interface where the **Response Page** **action** column was not accessible.
## PAN-276075
@@ -1080,7 +1080,7 @@ Fixed an issue where a warning message that pending changes were holding a commi
## PAN-276033
Fixed an issue on Panorama managed firewalls where SAML identity provider and Clientless Apps objects did not have override or revert options.
Fixed an issue on Panorama managed firewalls where **SAML identity provider** and **Clientless Apps** objects did not have override or revert options.
## PAN-276000
@@ -1164,7 +1164,7 @@ Fixed an issue where the displayed group name differed depending on whether the
## PAN-273010
Fixed an issue where the configuration version did not increment in the Audit Comment Archive after making changes to the Security policy rule with an audit comment and performing a commit. As a result, all subsequent changes were grouped under the same configuration version, which prevented the comparison of changes in the Rule Changes field of the Security policy rule.
Fixed an issue where the configuration version did not increment in the Audit Comment Archive after making changes to the Security policy rule with an audit comment and performing a commit. As a result, all subsequent changes were grouped under the same configuration version, which prevented the comparison of changes in the **Rule Changes** field of the Security policy rule.
## PAN-273008
@@ -1192,7 +1192,7 @@ Fixed an issue where GlobalProtect cookie authentication failed with the error U
## PAN-272469
Fixed an issue where the DNS exception displayed 0 instead of no result in the anti-spyware profile when no threat ID was available for a DNS security category.
Fixed an issue where the DNS exception displayed **0** instead of **no result** in the anti-spyware profile when no threat ID was available for a DNS security category.
## PAN-272395
@@ -1240,7 +1240,7 @@ Fixed an issue where the firewall displayed an incorrect maximum translated IP c
## PAN-271061
Fixed an issue on the web interface where you were unable to add Threat IDs to Signature Exceptions.
Fixed an issue on the web interface where you were unable to add Threat IDs to **Signature Exceptions**.
## PAN-270323
@@ -1248,7 +1248,7 @@ Fixed an issue where the firewall allowed cleartext web-browsing traffic on port
## PAN-269843
Fixed an issue where the firewall dropped non-SYN TCP packets even when the Reject non-SYN TCP option was set to No when a session rematch was triggered.
Fixed an issue where the firewall dropped non-SYN TCP packets even when the **Reject non-SYN TCP** option was set to **No** when a session rematch was triggered.
## PAN-269812
@@ -1284,7 +1284,7 @@ Fixed an issue where users were unable to log in to Panorama and the following e
## PAN-268522
Fixed an issue where the firewall failed to connect to the update server with a customized service route when the source interface was set to MGT and the source address was set as IPv4.
Fixed an issue where the firewall failed to connect to the update server with a customized service route when the source interface was set to **MGT** and the source address was set as IPv4.
## PAN-268426
@@ -1292,7 +1292,7 @@ Fixed an issue where the firewall was unable to connect to a syslog server that
## PAN-268308
Fixed an issue where the Push Scope was not automatically displayed when you selected Commit and Pushes Changes Made by.
Fixed an issue where the **Push Scope** was not automatically displayed when you selected **Commit and Pushes Changes Made by**.
## PAN-268002
@@ -1308,7 +1308,7 @@ Fixed an issue where the firewall generated AAAA DNS queries when IPv6 firewalli
## PAN-266776
Fixed an issue where virtual machine interfaces displayed unknown for speed and duplex in the CLI and web interface.
Fixed an issue where virtual machine interfaces displayed **unknown** for speed and duplex in the CLI and web interface.
## PAN-266569
@@ -1340,7 +1340,7 @@ Fixed an issue where a selective push was blocked when a configuration load was
## PAN-264040
Fixed an issue where AAAA DNS queries went out even when IPv6 firewalling was disabled.
Fixed an issue where AAAA DNS queries went out even when **IPv6 firewalling** was disabled.
## PAN-263699
@@ -1364,7 +1364,7 @@ Fixed an issue where the bytes transmitted and packet transmitted counters for h
## PAN-260581
Fixed an issue where Panorama template changes to the zone and virtual router were not pushed to managed firewalls when the template stack default virtual system was set to None.
Fixed an issue where Panorama template changes to the zone and virtual router were not pushed to managed firewalls when the template stack default virtual system was set to **None**.
## PAN-260540
@@ -1400,7 +1400,7 @@ Fixed an issue where Panorama became unresponsive and displayed a 504 gateway ti
## PAN-259579
Fixed an issue where the URL Filtering settings on a firewall displayed an override icon even when no settings were overridden. This occurred due to the hold-client-request field did not have a default value and was set to False.
Fixed an issue where the URL Filtering settings on a firewall displayed an override icon even when no settings were overridden. This occurred due to the **hold-client-request** field did not have a default value and was set to **False**.
## PAN-259284
@@ -1416,7 +1416,7 @@ Fixed an issue where the firewall displayed the incorrect rule name when a threa
## PAN-257616
Fixed an issue where selective push operations from Panorama to managed firewalls failed with the error message Failed to generate selective push configuration. Schema validation failed. Please try a full push.
Fixed an issue where selective push operations from Panorama to managed firewalls failed with the error message **Failed to generate selective push configuration. Schema validation failed. Please try a full push**.
## PAN-257195
@@ -1428,7 +1428,7 @@ Fixed an issue where the mp-monitor logs did not print disk SMART data.
## PAN-257074
Fixed an issue on the Panorama web interface where the template sync status showed Out-of-Sync for managed devices after a combined commit-all operation. This occurred due to Panorama sending the default MD5 sum of the template to the firewall instead of the correct MD5 sum.
Fixed an issue on the Panorama web interface where the template sync status showed **Out-of-Sync** for managed devices after a combined commit-all operation. This occurred due to Panorama sending the default MD5 sum of the template to the firewall instead of the correct MD5 sum.
## PAN-255806
@@ -1492,17 +1492,17 @@ Fixed an issue on the Panorama web interface where you were unable to add static
## PAN-242777
Fixed and issue where users previously reported limitations due to session count caps when utilizing Web Proxy features on PA-5400 Series Firewalls. To address these performance complaints and support higher traffic volumes, we have increased the maximum session capacity on specific PA-5400F series platforms, leveraging available system memory. This update ensures greater capacity and stability for high-volume environments.
Fixed and issue where users previously reported limitations due to session count caps when utilizing **Web Proxy** features on PA-5400 Series Firewalls. To address these performance complaints and support higher traffic volumes, we have increased the maximum session capacity on specific **PA-5400F** series platforms, leveraging available system memory. This update ensures greater capacity and stability for high-volume environments.
The supported session limits are:
| Platform | Max Sessions |
| --- | --- |
| PA-5410 | 95K |
| PA-5420 | 95K |
| PA-5430 | 95K |
| PA-5440 | 225K |
| PA-5445 | 250K |
| -------- | ------------ |
| PA-5410 | 95K |
| PA-5420 | 95K |
| PA-5430 | 95K |
| PA-5440 | 225K |
| PA-5445 | 250K |
## PAN-241230
@@ -1518,7 +1518,7 @@ Fixed an issue where EW dynamic address groups were not created in Panorama when
## PAN-224020
Fixed an issue where CIE validation checks on the firewall prevented configuration pushes from Panorama, which resulted in commit failures during new firewall deployment. This occurred when a template with an Authentication Profile with the Authentication Type as Cloud Authentication Service was pushed to a newly deployed firewall without internet access or without a device certificate.
Fixed an issue where CIE validation checks on the firewall prevented configuration pushes from Panorama, which resulted in commit failures during new firewall deployment. This occurred when a template with an Authentication Profile with the **Authentication Type** as **Cloud Authentication Service** was pushed to a newly deployed firewall without internet access or without a device certificate.
## PAN-221137
@@ -1526,7 +1526,7 @@ Fixed an issue where the CLI command to set the target virtual system accepted a
## PAN-215232
Fixed an issue on Panorama where the GlobalProtect app version was displayed incorrectly in the ACC tab.
Fixed an issue on Panorama where the GlobalProtect app version was displayed incorrectly in the **ACC** tab.
## PAN-210501