Update PAN-OS 11.1 files

This commit is contained in:
2026-04-15 14:57:19 -05:00
parent 8a243e3d9c
commit 10f549ef2a
84 changed files with 3207 additions and 3509 deletions
+68 -108
View File
@@ -6,7 +6,7 @@ version: 11.1.5
## PAN-268823
Fixed an issue where Monitor > Log Display did not display all logs when you applied a filter.
Fixed an issue where **Monitor > Log Display** did not display all logs when you applied a filter.
## PAN-265963
@@ -22,7 +22,7 @@ Fixed an issue where you were unable to download PDFs when connected via a Clien
## PAN-265344
Fixed an issue where Import GlobalProtect Client Package did not work after clicking OK after selecting a valid package under Device > GlobalProtect Client > Upload).
Fixed an issue where **Import GlobalProtect Client Package** did not work after clicking **OK** after selecting a valid package under **Device > GlobalProtect Client > Upload**).
## PAN-265287
@@ -38,7 +38,7 @@ Fixed an issue where the firewall was unable to validate or commit a configurati
## PAN-264369
Fixed an issue where the 7 Day Threat Report was empty in the scheduled reports sent via email.
Fixed an issue where the **7 Day Threat Report** was empty in the scheduled reports sent via email.
## PAN-264249
@@ -54,7 +54,7 @@ Fixed an issue on the firewall where, when a NAT transversal IPSec tunnel was te
PA-440 firewalls only
```
Fixed an issue where a firewall running PAN-OS 11.1.2-h3 only displayed the Auto option for the interface duplex setting.
Fixed an issue where a firewall running PAN-OS 11.1.2-h3 only displayed the **Auto** option for the interface duplex setting.
## PAN-263505
@@ -90,11 +90,11 @@ Fixed an issue where traffic to websites failed on the Google Chrome web browser
## PAN-262415
Fixed an issue where a partial configuration load failed for configuration files that contained regenerate-hostkeys.
Fixed an issue where a partial configuration load failed for configuration files that contained **regenerate-hostkeys**.
## PAN-262410
Fixed an issue where the App Scope graph did not display for all days when selecting Last 60 days or Last 90 days.
Fixed an issue where the **App Scope** graph did not display for all days when selecting **Last 60 days** or **Last 90 days**.
## PAN-262340
@@ -170,7 +170,7 @@ Fixed an issue where the firewall did not autocommit after a reboot when the cel
## PAN-261019
Fixed an issue where Evasive Empire C2 Traffic Detection generated benign verdicts and max latency timeout logs simultaneously when the MICA ATP action was configured as reset-both.
Fixed an issue where Evasive Empire C2 Traffic Detection generated benign verdicts and max latency timeout logs simultaneously when the MICA ATP action was configured as **reset-both**.
## PAN-260974
@@ -214,7 +214,7 @@ Fixed an issue where BGP Aggregate Advertise filters did not work as expected wh
## PAN-260193
Fixed an issue where GlobalProtect on macOS clients did not connect when using a client certificate and the X.509 policy was set to Use System Default.
Fixed an issue where GlobalProtect on macOS clients did not connect when using a client certificate and the X.509 policy was set to **Use System Default**.
## PAN-260132
@@ -234,7 +234,7 @@ Fixed an issue where the firewalls behind an Amazon Web Services (AWS) Gateway L
## PAN-259881
Fixed an issue on Panorama where traffic log details were not displayed under detailed log view.
Fixed an issue on Panorama where traffic log details were not displayed under **detailed log view**.
## PAN-259802
@@ -258,21 +258,19 @@ Fixed an issue where the firewall failed to boot up after running power cycle te
## PAN-259370
Fixed an issue on the web interface where Correlation Log Detail > Match Evidence did not populate.
Fixed an issue on the web interface where **Correlation Log Detail > Match Evidence** did not populate.
## PAN-259351
A fix was made to address CVE-2024-3393.
A fix was made to address [CVE-2024-3393](https://security.paloaltonetworks.com/CVE-2024-5921).
## PAN-259344
Fixed an issue where performing a configuration commit on a firewall locally or from Panorama
caused a memory leak related to the configd process and
resulted in an OOM condition.
Fixed an issue where performing a configuration commit on a firewall locally or from Panorama caused a memory leak related to the configd process and resulted in an OOM condition.
## PAN-259200
Fixed an issue where the firewall displayed truncated zone names in the Block IP List log when a zone name contained more than 14 characters.
Fixed an issue where the firewall displayed truncated zone names in the **Block IP List** log when a zone name contained more than 14 characters.
## PAN-259151
@@ -316,7 +314,7 @@ Fixed an issue on the Panorama web interface where Security policy rules loaded
## PAN-258188
Fixed an issue on Panorama Template where the virtual wire subinterface page did not display all fields and the OK button did not work.
Fixed an issue on Panorama Template where the virtual wire subinterface page did not display all fields and the **OK** button did not work.
## PAN-258166
@@ -328,7 +326,7 @@ Fixed an issue where the root partition frequently reached 100%.
## PAN-257961
Fixed an issue on Panorama where Test Security Policy Match failed when the From or To zone fields were populated.
Fixed an issue on Panorama where **Test Security Policy Match** failed when the **From** or **To** zone fields were populated.
## PAN-257957
@@ -372,7 +370,7 @@ Fixed an issue where the firewall web interface was blank after logging in.
## PAN-257619
Fixed an issue on Panorama where the Task Manager took longer than expected to display managed FW report tasks details when its empty
Fixed an issue on Panorama where the **Task Manager** took longer than expected to display managed FW report tasks details when its empty
## PAN-257601
@@ -428,7 +426,7 @@ Fixed an issue where firewalls entered a non-functional state and displayed the
## PAN-257021
"Fixed an issue on the web interface where Match Evidence log details for Monitor > Correlated events did not populate."
"Fixed an issue on the web interface where **Match Evidence** log details for **Monitor > Correlated events** did not populate."
## PAN-256960
@@ -448,7 +446,7 @@ Fixed an issue where BGP routes from the active firewall were lost when the pass
## PAN-256725
Fixed an issue on the Panorama interface where Traffic and Unified event details loaded more slowly than expected.
Fixed an issue on the Panorama interface where **Traffic** and **Unified** event details loaded more slowly than expected.
## PAN-256669
@@ -456,7 +454,7 @@ Fixed an issue where the memory usage reported by SNMP did not match the memory
## PAN-256666
Fixed an issue where the configd process stopped responding when Commit and Push operations were performed on multiple device groups.
Fixed an issue where the configd process stopped responding when **Commit and Push** operations were performed on multiple device groups.
## PAN-256652
@@ -496,7 +494,7 @@ Fixed an issue where the logd process repeatedly restarted due to a buffer overf
## PAN-256249
Fixed an issue on the web interface that occurred when changing the pre-shared key to a variable (Network > Network Profiles > IKE Gateways).
Fixed an issue on the web interface that occurred when changing the pre-shared key to a variable (**Network > Network Profiles > IKE Gateways**).
## PAN-256223
@@ -504,7 +502,7 @@ Fixed an issue where device telemetry log collection filled the root partition.
## PAN-256115
Fixed an issue where, after replacing a Panorama appliance or log collector, the secondary Panorama appliance or log collector displayed a disconnected status for the inter-log collector connection.
Fixed an issue where, after replacing a Panorama appliance or log collector, the secondary Panorama appliance or log collector displayed a **disconnected** status for the inter-log collector connection.
## PAN-256051
@@ -516,7 +514,7 @@ Fixed an issue where persistent DIPP NAT entries were deleted even when being us
## PAN-255895
Fixed an issue where Panorama administrators with the Panorama Administrator dynamic administrator type were not able to create or modify BGP timer profiles or BGP dampening profiles.
Fixed an issue where Panorama administrators with the **Panorama Administrator** dynamic administrator type were not able to create or modify BGP timer profiles or BGP dampening profiles.
## PAN-255820
@@ -524,11 +522,11 @@ Fixed an issue where the WildFire signature generation check box in Panorama did
## PAN-255773
Fixed an issue where errors related to applications in Content-preview caused commit failures.
Fixed an issue where errors related to applications in **Content-preview** caused commit failures.
## PAN-255711
Fixed an issue where the firewall displayed a malformed request error when selecting a custom format and clicking OK on the configuration window due to the log type Correlation incorrectly being displayed (Device > Log Setting - Correlation > Syslog Server Profile > Custom Log Format > Correlation).
Fixed an issue where the firewall displayed a malformed request error when selecting a custom format and clicking **OK** on the configuration window due to the log type **Correlation** incorrectly being displayed (**Device > Log Setting - Correlation > Syslog Server Profile > Custom Log Format > Correlation**).
## PAN-255660
@@ -544,8 +542,7 @@ Fixed an issue where the path monitor displayed as up even when routes to the de
PA-7500 Series firewalls and Panorama appliances only
```
Fixed an issue where dataplane logs were displayed after a
delay.
Fixed an issue where dataplane logs were displayed after a delay.
## PAN-255396
@@ -561,9 +558,7 @@ Fixed an issue where the firewall booted into maintenance mode when there was no
## PAN-255285
Fixed an issue where, when only the HSCI-A link was connected on
firewall cluster nodes, and the management interface went down, a
split brain condition occurred.
Fixed an issue where, when only the HSCI-A link was connected on firewall cluster nodes, and the management interface went down, a split brain condition occurred.
## PAN-255282
@@ -587,9 +582,7 @@ Fixed an issue where the system database key that stored the configuration statu
## PAN-255116
Fixed an issue where, when QoS was enabled, traffic on an NGFW
cluster node that went from an MC-LAG interface to a destination
stopped when a member of the MC-LAG went down.
Fixed an issue where, when QoS was enabled, traffic on an NGFW cluster node that went from an MC-LAG interface to a destination stopped when a member of the MC-LAG went down.
## PAN-254901
@@ -605,9 +598,7 @@ Fixed an issue where the firewall rebooted unexpectedly due to multiple all_task
## PAN-254827
Fixed an issue where, when you changed an IP address on a management
interface on an NGFW cluster node, commit-all operations did not
push the updated IP address.
Fixed an issue where, when you changed an IP address on a management interface on an NGFW cluster node, commit-all operations did not push the updated IP address.
## PAN-254826
@@ -651,9 +642,7 @@ Fixed an issue where the firewall required a restart when an SD-WAN policy rule
## PAN-254351
Fixed an issue where an NGFW cluster node remained in a suspended
state when GRE tunnel termination was used with keepalive enabled on
both ends.
Fixed an issue where an NGFW cluster node remained in a suspended state when GRE tunnel termination was used with keepalive enabled on both ends.
## PAN-254301
@@ -685,7 +674,7 @@ Fixed an issue where the CLI command show running security-policy timed out when
## PAN-253819
Fixed an issue where a User Activity Report was not generated by Run Now or not emailed through the Email Schedule when the locale setting was not English.
Fixed an issue where a **User Activity Report** was not generated by **Run Now** or not emailed through the **Email Schedule** when the locale setting was not English.
## PAN-253626
@@ -697,9 +686,7 @@ Fixed an issue where ikemgr process unexpectedly stopped due to a memory mapping
## PAN-253557
Fixed an issue where, after a cluster manager restart on the leader
node of an NGFW cluster, traffic stopped due to only the state
machine transitioning to unknown and not the leader.
Fixed an issue where, after a cluster manager restart on the leader node of an NGFW cluster, traffic stopped due to only the state machine transitioning to unknown and not the leader.
## PAN-253452
@@ -707,9 +694,7 @@ Fixed an issue where GlobalProtect users were unable to connect to the GlobalPro
## PAN-253466
Fixed an issue where, on NFGW cluster nodes, an expected packet
buffer leak occurred with FTP/SIP traffic over an extended period of
time.
Fixed an issue where, on NFGW cluster nodes, an expected packet buffer leak occurred with FTP/SIP traffic over an extended period of time.
## PAN-253250
@@ -737,7 +722,7 @@ Fixed an issue where multiple SSHD process restarts triggered a firewall reboot
## PAN-252801
Fixed an issue where the LSVPN tunnel monitoring status displayed as No data available after re-key events.
Fixed an issue where the LSVPN tunnel monitoring status displayed as **No data available** after re-key events.
## PAN-252411
@@ -745,7 +730,7 @@ Fixed an issue where, when log files were purged from the rollup summary logs, t
## PAN-252370
Fixed an issue where services with the reserved keyword application-default were allowed.
Fixed an issue where services with the reserved keyword **application-default** were allowed.
## PAN-252270
@@ -801,8 +786,7 @@ Fixed an issue where enabling lockless QoS caused traffic disruptions.
## PAN-251501
Fixed an issue where, after a reboot, NGFW cluster nodes failed to
rejoin a cluster due to a timing issue.
Fixed an issue where, after a reboot, NGFW cluster nodes failed to rejoin a cluster due to a timing issue.
## PAN-251372
@@ -822,12 +806,11 @@ Fixed an issue where, when creating a Security policy rule via the CLI, validati
## PAN-250756
Fixed an issue where querying threat logs using the threat name, such as
generic:<site> did not work.
Fixed an issue where querying threat logs using the threat name, such as generic:<site> did not work.
## PAN-250716
Fixed an issue where Panorama > Push to Devices displayed device group and template entries that had been changed by other administrators.
Fixed an issue where **Panorama > Push to Devices** displayed device group and template entries that had been changed by other administrators.
## PAN-250703
@@ -883,7 +866,7 @@ Fixed an issue on the web interface where templates incorrectly showed that tele
## PAN-250127
Fixed an issue where commits failed with the error message set is not allowed when default originate was enabled with a route map that included a set action.
Fixed an issue where commits failed with the error message set is not allowed when **default originate** was enabled with a route map that included a set action.
## PAN-250062
@@ -891,13 +874,11 @@ Fixed an issue where device telemetry failed after upgrading due to bundle gener
## PAN-250043
Fixed an issue where, on an NGFW cluster node, operations failed when
QoS interfaces were configured with an egress max that exceeded
68,000 Mbps.
Fixed an issue where, on an NGFW cluster node, operations failed when QoS interfaces were configured with an egress max that exceeded 68,000 Mbps.
## PAN-250021
Fixed an issue where Change Summary and Preview Changes displayed inconsistent information when changing an admin user password.
Fixed an issue where **Change Summary** and **Preview Changes** displayed inconsistent information when changing an admin user password.
## PAN-250005
@@ -909,10 +890,7 @@ Fixed an issue where the firewall dropped the active source of the Multicast sou
## PAN-249727
Fixed an issue where, on an NGFW cluster node, the
Custom/Pre-defined URL category was not
in the session flow data, which caused it to be excluded from the
promoted session after a failover.
Fixed an issue where, on an NGFW cluster node, the **Custom/Pre-defined** URL category was not in the session flow data, which caused it to be excluded from the promoted session after a failover.
## PAN-249548
@@ -920,7 +898,7 @@ Fixed an issue where the firewall stopped responding during a high availability
## PAN-249533
Fixed an issue where an internal error message was displayed when you selected Exclude video traffic from the tunnel (Windows and macOS only).
Fixed an issue where an internal error message was displayed when you selected **Exclude video traffic from the tunnel (Windows and macOS only)**.
## PAN-249404
@@ -936,17 +914,15 @@ Fixed an issue where SaaS quality profile probes were dropped on the SD-WAN hub.
## PAN-249132
Fixed an issue on Panorama DG where the address group object created with Disable Override property in Parent DG was overridden by child DG via CLI.
Fixed an issue on Panorama DG where the address group object created with **Disable Override** property in Parent DG was overridden by child DG via CLI.
## PAN-249072
Fixed an issue where content upgrade installation failed with the error Error:
can't find cert <cert> when using cloud
interfaces.
Fixed an issue where content upgrade installation failed with the error Error: can't find cert <cert> when using cloud interfaces.
## PAN-248945
Fixed an issue where commits failed when you committed a configuration to advertise the default route (0.0.0.0/0) as a BGP network statement (Advanced Routing > BGP settings).
Fixed an issue where commits failed when you committed a configuration to advertise the default route (0.0.0.0/0) as a BGP network statement (**Advanced Routing > BGP settings**).
## PAN-248841
@@ -954,9 +930,7 @@ Fixed an issue where the SSL response time was not displayed in the GlobalProtec
## PAN-248762
Fixed an issue where, when the Advanced Routing Engine was configured
with OSPF, the firewall stopped responding when attempting to
connect to the neighbor while exchanging route maps.
Fixed an issue where, when the Advanced Routing Engine was configured with OSPF, the firewall stopped responding when attempting to connect to the neighbor while exchanging route maps.
## PAN-248618
@@ -988,7 +962,7 @@ Fixed an issue on the firewall where a dataplane process restarted when updating
## PAN-247754
Fixed an issue where successful Commit and Push operations performed by SAML authenticated users were not reflected on the firewall.
Fixed an issue where successful **Commit and Push** operations performed by SAML authenticated users were not reflected on the firewall.
## PAN-247230
@@ -1044,7 +1018,7 @@ Fixed an issue where the firewall displayed a message that the license was inval
## PAN-245682
Fixed an issue on Panorama where Commit and Push progress displayed over 100%.
Fixed an issue on Panorama where **Commit and Push** progress displayed over 100%.
## PAN-245545
@@ -1064,8 +1038,7 @@ Fixed an issue where the GlobalProtect VPN connection inactivity TTL value becam
## PAN-244262
Fixed an issue where interface settings were not saved when the template was overridden in the
candidate configuration while enabling DNS settings.
Fixed an issue where interface settings were not saved when the template was overridden in the candidate configuration while enabling DNS settings.
## PAN-244035
@@ -1093,7 +1066,7 @@ Fixed an issue where custom object import for spyware got stuck on uploading pag
## PAN-243816
Fixed an issue where new users were unable to change their password during the first login when the Max session count was set to 1 and Require Password Change on First Login was enabled.
Fixed an issue where new users were unable to change their password during the first login when the **Max session count** was set to 1 and **Require Password Change on First Login** was enabled.
## PAN-243787
@@ -1133,7 +1106,7 @@ Fixed an issue with corrupted images when SSL decryption and Security profiles w
## PAN-242960
Fixed an issue where the firewall did not honor the peer Desired Minimum Tx Interval when in a BFD INIT state.
Fixed an issue where the firewall did not honor the peer **Desired Minimum Tx Interval** when in a BFD INIT state.
## PAN-242958
@@ -1141,7 +1114,7 @@ Fixed an issue where the firewall intermittently logged connect-agent-failure me
## PAN-242957
Fixed an issue where the Rule usage columns of overridden default policy rules on the Security policy page stopped responding.
Fixed an issue where the **Rule usage** columns of overridden default policy rules on the Security policy page stopped responding.
## PAN-242826
@@ -1165,7 +1138,7 @@ Fixed an issue where Prisma Access remote network firewalls intermittently creat
## PAN-242130
Fixed an issue where the firewall displayed the speed and duplex of its dataplane interfaces as Unknown even though the link was up.
Fixed an issue where the firewall displayed the speed and duplex of its dataplane interfaces as **Unknown** even though the link was up.
## PAN-241871
@@ -1173,7 +1146,7 @@ Fixed an issue where the firewall was unable to create new IPSec tunnels when th
## PAN-241821
Fixed an issue where Global Search did not show results past the second level.
Fixed an issue where **Global Search** did not show results past the second level.
## PAN-241781
@@ -1185,11 +1158,11 @@ Fixed an issue where, when TLSv1.3 was used, an incorrect error message invalid
## PAN-241655
Fixed an issue where the firewall incorrectly categorized URLs as phishing due to machine learning analysis MLAV incorrectly marking the URLs as malicious.
Fixed an issue where the firewall incorrectly categorized URLs as **phishing** due to machine learning analysis MLAV incorrectly marking the URLs as malicious.
## PAN-241536
Fixed an issue on Panorama where admin users with the Custom Panorama Admin role were unable to add, edit, or delete route filters under Routing Profiles
Fixed an issue on Panorama where admin users with the Custom Panorama Admin role were unable to add, edit, or delete route filters under **Routing Profiles**
## PAN-241519
@@ -1245,10 +1218,7 @@ Fixed an issue where the CLI command debug user-id dump hip-based-profile-databa
## PAN-239201
Fixed an issue where partial commit or partial validation operations failed for non-super user
administrators with the error <device-group-name>
is invalid. meta data not found for dg
<device-group-name>.
Fixed an issue where partial commit or partial validation operations failed for non-super user administrators with the error <device-group-name> is invalid. meta data not found for dg <device-group-name>.
## PAN-239165
@@ -1256,7 +1226,7 @@ Fixed an issue where adding an interface in a route filter resulted in an OSPF L
## PAN-239143
Fixed an issue with accessing websites when URL filtering profiles were configured with the block-continue action and the server used HTTP/2.
Fixed an issue with accessing websites when URL filtering profiles were configured with the **block-continue** action and the server used HTTP/2.
## PAN-239138
@@ -1308,7 +1278,7 @@ Fixed an issue where, when you committed the first configuration change after bo
## PAN-236830
Fixed an issue where traffic that was correctly detected on the firewall as the threat category DNS was detected on Panorama as the threat category N/A.
Fixed an issue where traffic that was correctly detected on the firewall as the threat category **DNS** was detected on Panorama as the threat category **N/A**.
## PAN-236574
@@ -1336,7 +1306,7 @@ Fixed an issue where an unnamed core file was generated after a reboot.
## PAN-235529
Fixed an issue where the Active Directory IP-address-to-user mappings were not updated on Mappings & Tags on the Cloud Identity Engine.
Fixed an issue where the Active Directory IP-address-to-user mappings were not updated on **Mappings & Tags** on the Cloud Identity Engine.
## PAN-235110
@@ -1348,8 +1318,7 @@ Fixed an issue where the web interface did not load after an upgrade.
## PAN-234461
Fixed an issue where excess distributord process memory use caused processes to
restart due to OOM conditions.
Fixed an issue where excess distributord process memory use caused processes to restart due to OOM conditions.
## PAN-234272
@@ -1377,7 +1346,7 @@ Fixed an issue where the following error message displayed for IoT trial license
## PAN-232792
Fixed an issue on the Panorama where the web interface did not display the Scheduled Config Push page.
Fixed an issue on the Panorama where the web interface did not display the **Scheduled Config Push** page.
## PAN-232594
@@ -1401,15 +1370,11 @@ Fixed an issue where multiple processes stopped responding due to a traffic outa
## PAN-231065
Fixed an issue on Panorama where the CLI command show applications list
<Application-group/application filters> device-group <name
of device-group> returned incomplete result.
Fixed an issue on Panorama where the CLI command show applications list <Application-group/application filters> device-group <name of device-group> returned incomplete result.
## PAN-230934
Fixed an issue where HTTP/S, SSH, and PING were enabled on the AUX port by default even when
these administrative management services were not enabled on the
interface.
Fixed an issue where HTTP/S, SSH, and PING were enabled on the AUX port by default even when these administrative management services were not enabled on the interface.
## PAN-230902
@@ -1429,8 +1394,7 @@ Fixed an issue where GlobalProtect logs returned no data when using the filter (
## PAN-227978
Fixed an issue where the web interface did not accurately list the
status of the port when NGFW clustering was enabled.
Fixed an issue where the web interface did not accurately list the status of the port when NGFW clustering was enabled.
## PAN-226789
@@ -1450,7 +1414,7 @@ Fixed an issue where the ConfigPushScheduler REST API failed when the target dev
## PAN-226125
Fixed an issue where the Management Interface Telnet Service was disabled but the service was still allowed.
Fixed an issue where the **Management Interface Telnet Service** was disabled but the service was still allowed.
## PAN-225806
@@ -1458,7 +1422,7 @@ Fixed an issue where LACP packets did not reach the dataplane, which caused the
## PAN-225228
Fixed an issue where filtering threat logs using any value under THREAT ID/NAME displayed the error Invalid term.
Fixed an issue where filtering threat logs using any value under **THREAT ID/NAME** displayed the error **Invalid term**.
## PAN-224729
@@ -1506,11 +1470,7 @@ Fixed an issue where the management server access log file did not rotate, which
## PAN-164885
Fixed an issue on Panorama where Commit and
Push or Push to Devices
operations failed when an external dynamic list was configured to
check for updates every 5 minutes due to the commit and external
dynamic fetch processes overlapping.
Fixed an issue on Panorama where **Commit and Push** or **Push to Devices** operations failed when an external dynamic list was configured to check for updates every 5 minutes due to the commit and external dynamic fetch processes overlapping.
## PAN-76904