diff --git a/reference/PAN-OS/known/11.2.0.html b/reference/PAN-OS/known/11.2.0.html new file mode 100644 index 0000000..d385625 --- /dev/null +++ b/reference/PAN-OS/known/11.2.0.html @@ -0,0 +1,1326 @@ +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-308507
+ |
+
+
+ Strata Logging Service (SLS) log-forwarding streams intermittently
+ show as inactive. When checking the status of log-forwarding
+ connections, one or more streams are reported as inactive. Restarting
+ the log-receiver process temporarily
+ resolves the issue, but the streams become inactive again after
+ approximately 1-2 hours. This intermittent inactivity results in log
+ loss.
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-301801
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ On Log Collectors, the Elasticsearch process might fluctuate between
+ green and red states, causing log collection interruptions. This issue
+ occurs when the number of shards exceeds the supported threshold of
+ 1,000 shards per Elasticsearch instance.
+
+ |
+
|
+ PAN-298505
+
+ This issue is now resolved. See PAN-OS 11.2.7-h4 Addressed Issuesand
+ PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual
+ system IDs (vsys ID) changes causing auto-commit failures with
+ validation errors. This occurs when the multi-vsys firewall has
+ virtual systems managed by Panorama, and the vsys ID sequence breaks
+ when unused virtual systems are deleted and the changes are pushed to
+ the firewall.
+
+ |
+
|
+ PAN-296752
+
+ This issue is now resolved. See PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+
+ The PA-1410 firewalls experience a spike in the management plane CPU
+ utilization when the monitor-dp process attempts to retrieve the power
+ cycle count from the NVMe drive’s SMART data. This condition leads to
+ repeated reboots of the device, requiring a hard reset for recovery.
+
+ |
+
|
+ PAN-295803
+
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues,
+ PAN-OS 11.2.7-h10 Addressed Issues
+ and
+ PAN-OS 11.2.10-h3 Addressed Issues
+
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-292344
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ Upgrading to an affected release causes the firewall to reboot
+ multiple times if the config contains an EDL (External Dynamic List)
+ that doesn't have an associated certificate profile.
+
+ |
+
|
+ PAN-294179
+
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues
+ and
+ PAN-OS 11.2.7-h3 Addressed Issues.
+
+ |
+ + On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. + | +
|
+ PAN-291661
+
+ This issue is now resolved. See PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+
+ Upon upgrade, the ElasticSearch health status intermittently
+ transitions to the Red status for sometime, and then auto-recovers
+ back to Green. During the Red status periods, the cluster logs are
+ unavailable. This occurs due to disk write operations being
+ excessively slow, failing to meet the minimum time threshold required
+ to save the cluster state.
+
+ |
+
|
+
+ PAN-291288This issue is now resolved. See PAN-OS 11.2.8 Addressed Issuesand
+ PAN-OS 11.2.7-h3 Addressed Issues
+
+ |
+ + An active firewall might unexpectedly reboot due to a + pan_task crash caused by a page + allocation failure. This issue is observed after a period of runtime + with traffic and telemetry collection. + | +
|
+ PAN-290449
+ This issue is now resolved. See
+ PAN-OS 11.2.7-h3 Addressed Issuesand
+ PAN-OS 11.2.8 Addressed Issues
+ |
+ + The scheduled vulnerability reports that are configured to be sent via + email with multiple attachments send the first attached report only. The + remaining attachments are dropped. + | +
|
+ PAN-290088
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-286231
+
+ This issue is now resolved. See PAN-OS 11.2.7-h3 Addressed Issues.
+
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-281885
+ |
+
+
+ When exporting and importing the CSV file, the hash values of
+ pre-shared key (PSK) variables set at template and template stack
+ levels inconsistently change, resulting in both variables displaying
+ the same hash value.
+
+ |
+
|
+ PAN-280471
+ |
+
+
+ When applying filters or searching for logs in the
+ section, you might experience slow performance.
+
+ |
+
| + PAN-279415 + | +
+
+ Service routes configured for a data plane interface might incorrectly
+ route traffic through the management plane interface instead. This
+ issue impacts Syslog and CRL status traffic when the service route
+ lacks a specific destination custom service route.
+
+ |
+
|
+ PAN-278296
+ |
+
+
+ The system MAC address of the aggregate interface is the same on both
+ the active and the passive devices, causing some packets to be sent
+ incorrectly to the passive device. This is causing the AE interface on
+ the active firewall to not come up.
+
+ |
+
|
+ PAN-277034
+
+ This issue is now resolved. See PAN-OS 11.2.7-h3 Addressed Issues
+
+ |
+ + WildFire reports might not fully display or be downloadable because some + static resources fail to load. + | +
|
+ PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ When Panorama is not internet-connected and you try to upload images
+ to the managed firewalls by using the
+ Validate option, the upload fails
+ with the following error:
+ Failed to create multi-upload job. No valid software deploy targets
+ found.
+
+ |
+
|
+ PAN-273300
+
+ This issue is now resolved. See PAN-OS 11.2.5 Addressed Issues
+
+ |
+
+
+ When upgrading Panorama from PAN-OS 10.2 or PAN-OS 11.0 to PAN-OS 11.1
+ or a later release, Panorama fails to upgrade if it is operating
+ within a Collector Group. The following error appears:Error: Traceback (most recent call last):File
+ "/opt/panrepo/releases/<PANOS release version>/validate"...
+ (min ([dts['min'] for dts in 10g_type_intv_dir.values() if
+ dts|'min']])-strftime ('%Y-%m-%d'),
+
+ |
+
|
+ PAN-262287
+ |
+
+
+ Dereferencing a NULL pointer that occurs might cause
+ pan_task
+ processes to crash.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
| PAN-259769 | +
+
+ GlobalProtect portal is not accessible via a web browser and the app
+ displays the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-257615
+
+ This issue is now resolved. See PAN-OS 11.2.3 Addressed Issues.
+
+ |
+
+
+ The Panorama web interface intermittently displays logs or fails to
+ display logs completely.
+
+ |
+
|
+ PAN-257045
+ |
+
+
+ The firewall using the Advanced Routing Engine loses PIM Hello
+ messages after a two-day steady state run.
+
+ |
+
|
+ PAN-256780
+ |
+
+
+ The firewall using the Advanced Routing Engine has inconsistent
+ formatting of multicast output from the CLI command:
+ show ip igmp sources json.
+
+ |
+
|
+ PAN-256343
+ |
+
+
+ When the firewall is using the Advanced Routing Engine and OSPFv3 is
+ configured, the interface and area information fails to appear in the
+ CLI or the user interface. Additionally, you shouldn't use the CLI
+ command
+ show advanced-routing ospf interface
+ because it disrupts traffic.
+
+ |
+
|
+ PAN-254305
+ |
+
+
+ DHCP request is not sent when the service route is configured.
+
+ |
+
|
+ PAN-254236
+
+ This issue is now resolved. See PAN-OS 11.2.1 Addressed Issues.
+
+ |
+
+
+ TLSv1.3 hybridized Kyber support in the latest versions of Chrome and
+ Edge browsers results in dropped Client Hello packets when SSL/TLS
+ handshake inspection is enabled.
+
+
+ Workaround: Disable
+ SSL/TLS handshake inspection.
+
+ |
+
|
+ PAN-254143
+ |
+
+
+ A firewall that uses the Advanced Routing Engine fails to add a local
+ route to the Routing Information Base (RIB); it is able to add
+ connected routes to the RIB. However the firewall adds both connected
+ and local routes to the Forwarding Information Base (FIB). This
+ results in a mismatch between the RIB and FIB.
+
+ |
+
|
+ PAN-254108
+ |
+
+
+ when upgrading or downgrading a Panorama management server (), managed device (), or standalone firewall (), Base Releases and
+ Preferred Releases settings are
+ checked (enabled) by default and cause no PAN-OS software images to
+ display.
+
+
+ Workaround: Uncheck (disable)
+ Base Releases or
+ Preferred Releases to display either
+ the available base PAN-OS or preferred PAN-OS releases available to
+ download and install.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
|
+ PAN-253702
+ |
+
+
+ A firewall using the Advanced Routing Engine fails to come up and
+ fails to display OSPFv3 neighbor information.
+
+ |
+
|
+ PAN-252661
+ This issue is now resolved. See PAN-OS 11.2.1 Addressed Issues
+ |
+
+
+ If you change the service route of gp-ip-mgmt in
+ Device > Setup > Services > Service Features >
+ gp-ip-mgmt
+ and Commit, the change won’t take effect.
+ gp-ip-mgmt continues to use the last committed service route.
+
+
+ Workaround: After you change the service route
+ interface for gp-ip-mgmt, navigate to either a GlobalProtect portal or
+ gateway, click OK to save the configuration, and
+ Commit the changes. This commit will include the
+ service route change.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-249700
+ |
+
+
+ On a firewall that uses the Advanced Routing Engine and has BGP
+ enabled, the BGP process crashes with SIGSEGV signal when the local
+ interface and the peer IP address change.
+
+ |
+
|
+ PAN-248836
+ |
+
+
+ The Advanced DNS Security trial license and trial license information
+ cannot be activated and viewed, respectively, on a managed firewall
+ (with expired or active status) from Panorama. These tasks can only be
+ performed on the firewall.
+
+ |
+
|
+ PAN-248147
+ |
+
+
+ The firewall using the Advanced Routing Engine doesn't properly
+ display the interface name in the CLI command: show advanced-routing
+ ospf neighbor brief yes.
+
+ |
+
|
+ PAN-247728
+
+ This issue is now resolved. See PAN-OS 11.2.1 Addressed Issues
+
+ |
+
+
+ When Advanced Routing is enabled, IP multicast is not supported. An
+ upcoming version will provide support for this feature. Customers who
+ have multicast configured or who plan to deploy multicast routing
+ should not upgrade to 11.2.0. Additionally, when Advanced Routing is
+ enabled, the BGP dampening configuration isn't applied to any peers or
+ peer group; the configuration is preserved but has no effect on BGP.
+ Customers can use BGP even if they have applied a Dampening profile to
+ a specific set of peers. The issue doesn't affect any other BGP
+ features.
+
+ |
+
|
+ PAN-247221
+ |
+
+
+ The firewall using the Advanced Routing Engine fails to display output
+ for the CLI command:
+ show advanced-routing bgp peer received-routes.
+
+ |
+
|
+ PAN-241536
+ |
+
+
+ On the Panorama management server, a user with an Admin Role is unable
+ to modify or add filters to profiles under
+ , despite having the necessary read and write privileges.
+
+ |
+
|
+ PAN-239612
+ |
+
+
+ When the firewall is running PAN-OS 11.2.0 and Advanced Routing is
+ enabled, DHCPv4 relay agent functions successfully, but DHCPv6 relay
+ agent doesn't work.
+
+ |
+
|
+ PAN-236649
+ |
+
+
+ If you change the configuration of a firewall acting as a PPPoEv4 or
+ PPPoEv6 client, old routes from the Forwarding Information Base (FIB)
+ and route table for an inherited configuration with dynamic-identifier
+ or client remain visible. Old routes also remain visible for an
+ inherited interface when you execute the CLI command,
+ show interface all.
+
+
+ Workaround: Unconfigure and configure the
+ Inherited Interface.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-164885
+
+ This issue is now resolved. See PAN-OS 11.2.1 Addressed Issues.
+
+ |
+
+
+ On the Panorama management server, pushes to managed firewalls (
+ or Commit and Push) may fail when an
+ EDL () is configured to
+ Check for updates every 5 minutes
+ due to the commit and EDL fetch processes overlapping. This is more
+ likely to occur when multiple EDLs are configured to check for updates
+ every 5 minutes.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-308507
+ |
+
+
+ Strata Logging Service (SLS) log-forwarding streams intermittently
+ show as inactive. When checking the status of log-forwarding
+ connections, one or more streams are reported as inactive. Restarting
+ the log-receiver process temporarily
+ resolves the issue, but the streams become inactive again after
+ approximately 1-2 hours. This intermittent inactivity results in log
+ loss.
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-301801
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ On Log Collectors, the Elasticsearch process might fluctuate between
+ green and red states, causing log collection interruptions. This issue
+ occurs when the number of shards exceeds the supported threshold of
+ 1,000 shards per Elasticsearch instance.
+
+ |
+
|
+ PAN-298505
+
+ This issue is now resolved. See PAN-OS 11.2.7-h4 Addressed Issuesand
+ PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual
+ system IDs (vsys ID) changes causing auto-commit failures with
+ validation errors. This occurs when the multi-vsys firewall has
+ virtual systems managed by Panorama, and the vsys ID sequence breaks
+ when unused virtual systems are deleted and the changes are pushed to
+ the firewall.
+
+ |
+
|
+ PAN-296752
+
+ This issue is now resolved. See PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+
+ The PA-1410 firewalls experience a spike in the management plane CPU
+ utilization when the monitor-dp process attempts to retrieve the power
+ cycle count from the NVMe drive’s SMART data. This condition leads to
+ repeated reboots of the device, requiring a hard reset for recovery.
+
+ |
+
|
+ PAN-295803
+
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues,
+ PAN-OS 11.2.7-h10 Addressed Issues
+ and
+ PAN-OS 11.2.10-h3 Addressed Issues
+
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-294179
+
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues
+ and
+ PAN-OS 11.2.7-h3 Addressed Issues.
+
+ |
+ + On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. + | +
|
+ PAN-292344
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ Upgrading to an affected release causes the firewall to reboot
+ multiple times if the config contains an EDL (External Dynamic List)
+ that doesn't have an associated certificate profile.
+
+ |
+
|
+ PAN-291661
+
+ This issue is now resolved. See PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+
+ Upon upgrade, the ElasticSearch health status intermittently
+ transitions to the Red status for sometime, and then auto-recovers
+ back to Green. During the Red status periods, the cluster logs are
+ unavailable. This occurs due to disk write operations being
+ excessively slow, failing to meet the minimum time threshold required
+ to save the cluster state.
+
+ |
+
|
+
+ PAN-291288This issue is now resolved. See PAN-OS 11.2.8 Addressed Issuesand
+ PAN-OS 11.2.7-h3 Addressed Issues
+
+ |
+ + An active firewall might unexpectedly reboot due to a + pan_task crash caused by a page + allocation failure. This issue is observed after a period of runtime + with traffic and telemetry collection. + | +
|
+
+ PAN-290449This issue is now resolved. See
+ PAN-OS 11.2.7-h3 Addressed Issuesand
+ PAN-OS 11.2.8 Addressed Issues
+
+ |
+ + The scheduled vulnerability reports that are configured to be sent via + email with multiple attachments send the first attached report only. The + remaining attachments are dropped. + | +
|
+ PAN-290088
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-286231
+
+ This issue is now resolved. See PAN-OS 11.2.7-h3 Addressed Issues.
+
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-281885
+ |
+
+
+ When exporting and importing the CSV file, the hash values of
+ pre-shared key (PSK) variables set at template and template stack
+ levels inconsistently change, resulting in both variables displaying
+ the same hash value.
+
+ |
+
|
+ PAN-280471
+ |
+
+
+ When applying filters or searching for logs in the
+ section, you might experience slow performance.
+
+ |
+
|
+ PAN-279746
+ |
+
+
+ An SSL/TLS Client Hello may not be transmitted out of the firewall if
+ the Client Hello arrives in multiple TCP segments and the traffic is
+ not subject to SSL decryption (for example, SMTP over SSL).
+
+ |
+
|
+ PAN-279415
+ |
+
+
+ Service routes configured for a data plane interface might incorrectly
+ route traffic through the management plane interface instead. This
+ issue impacts Syslog and CRL status traffic when the service route
+ lacks a specific destination custom service route.
+
+ |
+
|
+ PAN-277034
+
+ This issue is now resolved. See PAN-OS 11.2.7-h3 Addressed Issues
+
+ |
+ + WildFire reports might not fully display or be downloadable because some + static resources fail to load. + | +
|
+ PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ When Panorama is not internet-connected and you try to upload images
+ to the managed firewalls by using the
+ Validate option, the upload fails
+ with the following error:
+ Failed to create multi-upload job. No valid software deploy targets
+ found.
+
+ |
+
|
+ PAN-273300
+
+ This issue is now resolved. See PAN-OS 11.2.5 Addressed Issues
+
+ |
+
+
+ When upgrading Panorama from PAN-OS 10.2 or PAN-OS 11.0 to PAN-OS 11.1
+ or a later release, Panorama fails to upgrade if it is operating
+ within a Collector Group. The following error appears:Error: Traceback (most recent call last):File
+ "/opt/panrepo/releases/<PANOS release version>/validate"...
+ (min ([dts['min'] for dts in 10g_type_intv_dir.values() if
+ dts|'min']])-strftime ('%Y-%m-%d'),
+
+ |
+
|
+ PAN-262287
+ |
+
+
+ Dereferencing a NULL pointer that occurs might cause
+ pan_task
+ processes to crash.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-259853
+
+ This issue is now resolved. See PAN-OS 11.2.7-h10 Addressed Issues
+
+ |
+
+
+ When the DHCP server is enabled for GlobalProtect, the commit error
+ message is not properly displayed when
+ Any is selected as the source
+ interface in the service router configuration (
+ ).
+
+ |
+
| PAN-259769 | +
+
+ GlobalProtect portal is not accessible via a web browser and the app
+ displays the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-259423
+ |
+
+
+ When the GlobalProtect DHCP feature is enabled with two primary DHCP
+ servers on the GlobalProtect gateway, the gpsvc gets stuck during
+ renewal and after HA failover.
+
+ |
+
|
+ PAN-257615
+
+ This issue is now resolved. See PAN-OS 11.2.3 Addressed Issues.
+
+ |
+
+
+ The Panorama web interface intermittently displays logs or fails to
+ display logs completely.
+
+ |
+
|
+ PAN-254108
+ |
+
+
+ when upgrading or downgrading a Panorama management server (), managed device (), or standalone firewall (), Base Releases and
+ Preferred Releases settings are
+ checked (enabled) by default and cause no PAN-OS software images to
+ display.
+
+
+ Workaround: Uncheck (disable)
+ Base Releases or
+ Preferred Releases to display either
+ the available base PAN-OS or preferred PAN-OS releases available to
+ download and install.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-248836
+ |
+
+
+ The Advanced DNS Security trial license and trial license information
+ cannot be activated and viewed, respectively, on a managed firewall
+ (with expired or active status) from Panorama. These tasks can only be
+ performed on the firewall.
+
+ |
+
|
+ PAN-239612
+ |
+
+
+ When the firewall is running PAN-OS 11.2.0 and Advanced Routing is
+ enabled, DHCPv4 relay agent functions successfully, but DHCPv6 relay
+ agent doesn't work.
+
+ |
+
|
+ PAN-236649
+ |
+
+
+ If you change the configuration of a firewall acting as a PPPoEv4 or
+ PPPoEv6 client, old routes from the Forwarding Information Base (FIB)
+ and route table for an inherited configuration with dynamic-identifier
+ or client remain visible. Old routes also remain visible for an
+ inherited interface when you execute the CLI command,
+ show interface all.
+
+
+ Workaround: Unconfigure and configure the
+ Inherited Interface.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-6271
+ |
+
+
+ A WildFire cluster node that has been configured with an IPv6
+ management port might not display the signature status when using the
+ following CLI:
+ show wildfire global signature-status sha256 equal
+ <SHA_256_Value>
+
+
+ Workaround: Gracefully restart the affected
+ Wildfire cluster nodes.
+
+ |
+
|
+ WF500-6259
+ |
+
+
+ When a WildFire cluster node configured as a server or worker node is
+ rebooted, issuing the CLI command,
+ global sample-status does not update
+ the samples processed list on the active controller and non-server
+ worker nodes.
+
+
+ Workaround: Gracefully restart the affected
+ WildFire active controller and passive controller in the cluster.
+
+ |
+
|
+ WF500-6270
+ |
+
+
+ The WildFire cluster server and worker nodes might disconnect from the
+ Wildfire cluster management network, resulting in a notifier process
+ exit on WildFire cluster controllers.
+
+
+ Workaround: Gracefully restart the WildFire
+ cluster node where the process exit occurred.
+
+ |
+
|
+ WF500-6222
+ |
+
+
+ When WildFire secure cluster communication is enabled using a custom
+ DNS, the cluster formation might fail due to cluster management
+ communication issues.
+
+
+ Workaround: Do not configure a custom DNS when
+ WildFire secure cluster communication is enabled.
+
+ |
+
|
+ WF500-6176
+ |
+
+
+ When Panorama is used to manage a WildFire cluster, switchover
+ functionality for active and passive controller roles is not
+ available.
+
+ |
+
|
+ PAN-308564
+ |
+
+
+ Packets are dropped on SD-WAN interfaces if they require fragmentation
+ for an interface but have the
+ Don't Fragment (DF) bit set. This
+ results in unexpected packet drops. This affects client to server
+ sessions when using SD-WAN for NGFW.
+
+
+ Workaround: Allow fragmenting packets with DF bit
+ set (debug dataplane set ip4-ignore-df yes).
+
+ |
+
|
+ PAN-308507
+ |
+
+
+ Strata Logging Service (SLS) log-forwarding streams intermittently
+ show as inactive. When checking the status of log-forwarding
+ connections, one or more streams are reported as inactive. Restarting
+ the log-receiver process temporarily
+ resolves the issue, but the streams become inactive again after
+ approximately 1-2 hours. This intermittent inactivity results in log
+ loss.
+
+ |
+
|
+ PAN-308418
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ When Advanced DNS Security is enabled and experiences unusually high
+ loads, DNS traffic sessions may be impacted, resulting in DNS
+ resolution failures. Traffic logs for these sessions show an
+ end-reason of resources-unavailable.
+
+
+ Workaround: Disable Advanced DNS Security
+ telemetry (
+ and uncheck Telemetry Enable).
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-304576
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ Traffic interruption may occur when inspection of HTTP/2 traffic is
+ enabled.
+
+
+ Workaround: Disable HTTP/2 server push using the
+ set deviceconfig setting http2 server-push no
+ CLI command.
+
+ |
+
|
+ PAN-303959
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ Traffic that is incorrectly identified as unknown-tcp/unknown-udp
+ eventually drops due to an App-ID resource limitation issue.
+
+ |
+
|
+ PAN-302927
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ After an upgrade, the
+ Push to Devices window fails to
+ populate the list of devices automatically. If you manually select
+ devices by clicking Edit Selections,
+ the OK button becomes unresponsive
+ and fails to save or close the selection window. Additionally,
+ clicking Cancel might incorrectly
+ show the device list as empty while retaining the selections in the
+ background.
+
+ |
+
|
+
+ PAN-301801This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues
+ and
+ PAN-OS 11.2.10-h2 Addressed Issues
+
+ |
+
+
+ On Log Collectors, the Elasticsearch process might fluctuate between
+ green and red states, causing log collection interruptions. This issue
+ occurs when the number of shards exceeds the supported threshold of
+ 1,000 shards per Elasticsearch instance.
+
+ |
+
|
+ PAN-297610
+
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues
+ and
+ PAN-OS 11.2.10-h2 Addressed Issues.
+
+ |
+
+
+ A firewall may become unresponsive after an upgrade due to the
+ fsck
+ command scanning drive partitions in parallel with the root partition,
+ causing the process to take an extended amount of time.
+
+ |
+
|
+ PAN-295803
+
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues,
+ PAN-OS 11.2.7-h10 Addressed Issues, and
+ PAN-OS 11.2.10-h3 Addressed Issues
+
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-295645
+ |
+
+
+ When a WildFire cluster is configured centrally using Panorama, it
+ initiates a series of processes, including a software install and
+ reboot, in an order that will leave the resulting WildFire cluster in
+ an unusable state.
+
+ |
+
|
+ PAN-294179
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+ + On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. + | +
|
+ PAN-288525
+ |
+
+
+ When the Enterprise DLP data filtering profile is configured with a
+ Block action and is used in
+ conjunction with Advanced Threat Prevention, which is configured with
+ an action of reset-both,
+ reset-server,
+ reset-client, or
+ drop for the
+ HTTP Command and Control detector,
+ Dropbox file uploads that exceed the maximum configured file size
+ action will fail.
+
+
+ Workaround: Configure the Advanced Threat
+ Prevention Inline Cloud analysis () action for the HTTP Command and Control detector to
+ alert.
+
+ |
+
|
+ PAN-285061
+ |
+
+
+ When Enterprise DLP is enabled, file uploads might unexpectedly fail
+ when 100 continue response is received from the server during file
+ uploads.
+
+ |
+
|
+ PAN-284700
+ |
+
+
+ File downloads for content encoded with zstd (Zstandard), such as
+ specific content from box.com, fail when using Enterprise DLP because
+ zstd decompression is not supported in PAN-OS.
+
+ |
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-278688
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ (PA-7500, PA-5500, and PA-3500 firewalls only)
+ When DNS Security packet capture is enabled and a domain name has a
+ length of 62 characters, the DNS Security threat log entry is not
+ generated. On the affected platforms, this condition can also trigger
+ a pan_task crash due to shared memory
+ corruption.
+
+
+ Workaround: Disable DNS Security packet capture in
+ anti-spyware profiles () and in the DNS Policies tab, set
+ Packet Capture to
+ disable.
+
+ |
+
|
+ PAN-273158
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ (PA-7000 Series firewalls only) Due to an
+ incorrect configuration on the ASIC, receiving a mix of jumbo and
+ non-jumbo packets may cause silent packet drops or application
+ slowness.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-260212
+ |
+
+
+ When viewing Applications (), child App-IDs may be listed under the incorrect container App-ID.
+
+ |
+
|
+ PAN-259853
+ |
+
+
+ When the DHCP server is enabled for GlobalProtect, the commit error
+ message is not properly displayed when
+ Any is selected as the source
+ interface in the service router configuration (
+ ).
+
+ |
+
|
+ PAN-259423
+ |
+
+
+ When the GlobalProtect DHCP feature is enabled with two primary DHCP
+ servers on the GlobalProtect gateway, the gpsvc gets stuck during
+ renewal and after HA failover.
+
+ |
+
|
+ PAN-254236
+ |
+
+
+ TLSv1.3 hybridized Kyber support in the latest versions of Chrome and
+ Edge browsers results in dropped Client Hello packets when SSL/TLS
+ handshake inspection is enabled.
+
+
+ Workaround: Disable
+ SSL/TLS handshake inspection.
+
+ |
+
|
+ PAN-254108
+ |
+
+
+ when upgrading or downgrading a Panorama management server (), managed device (), or standalone firewall (), Base Releases and
+ Preferred Releases settings are
+ checked (enabled) by default and cause no PAN-OS software images to
+ display.
+
+
+ Workaround: Uncheck (disable)
+ Base Releases or
+ Preferred Releases to display either
+ the available base PAN-OS or preferred PAN-OS releases available to
+ download and install.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
|
+ PAN-252661
+ |
+
+
+ If you change the service route of gp-ip-mgmt in
+ Device > Setup > Services > Service Features >
+ gp-ip-mgmt
+ and Commit, the change won’t take effect.
+ gp-ip-mgmt continues to use the last committed service route.
+
+
+ Workaround: After you change the service route
+ interface for gp-ip-mgmt, navigate to either a GlobalProtect portal or
+ gateway, click OK to save the configuration, and
+ Commit the changes. This commit will include the
+ service route change.
+
+ |
+
|
+ PAN-250246
+ |
+
+
+ Panorama and the firewall display inconsistent IP addresses for
+ dynamic address group members after manually syncing.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-248836
+ |
+
+
+ The Advanced DNS Security trial license and trial license information
+ cannot be activated and viewed, respectively, on a managed firewall
+ (with expired or active status) from Panorama. These tasks can only be
+ performed on the firewall.
+
+ |
+
|
+ PAN-247728
+ |
+
+
+ When Advanced Routing is enabled, IP multicast is not supported. An
+ upcoming version will provide support for this feature. Customers who
+ have multicast configured or who plan to deploy multicast routing
+ should not upgrade to 11.2.0. Additionally, when Advanced Routing is
+ enabled, the BGP dampening configuration isn't applied to any peers or
+ peer group; the configuration is preserved but has no effect on BGP.
+ Customers can use BGP even if they have applied a Dampening profile to
+ a specific set of peers. The issue doesn't affect any other BGP
+ features.
+
+ |
+
|
+ PAN-241994
+ |
+
+
+ The VMX hardware version was upgraded from vmx-10 to vmx-15 on ESXi
+ and NSX-T. Support for vmx-15 is supported on ESXi 6.7 U2 and onwards.
+ Palo Alto Networks recommends that you upgrade your ESXi version if it
+ is less than 6.7 U2. For more information, see the
+ compatibility matrix.
+
+ |
+
|
+ PAN-239612
+ |
+
+
+ When the firewall is running PAN-OS 11.2.0 and Advanced Routing is
+ enabled, DHCPv4 relay agent functions successfully, but DHCPv6 relay
+ agent doesn't work.
+
+ |
+
|
+ PAN-237106
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-236649
+ |
+
+
+ If you change the configuration of a firewall acting as a PPPoEv4 or
+ PPPoEv6 client, old routes from the Forwarding Information Base (FIB)
+ and route table for an inherited configuration with dynamic-identifier
+ or client remain visible. Old routes also remain visible for an
+ inherited interface when you execute the CLI command,
+ show interface all.
+
+
+ Workaround: Unconfigure and configure the
+ Inherited Interface.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-6271
+ |
+
+
+ A WildFire cluster node that has been configured with an IPv6
+ management port might not display the signature status when using the
+ following CLI:
+ show wildfire global signature-status sha256 equal
+ <SHA_256_Value>
+
+
+ Workaround: Gracefully restart the affected
+ Wildfire cluster nodes.
+
+ |
+
|
+ WF500-6259
+ |
+
+
+ When a WildFire cluster node configured as a server or worker node is
+ rebooted, issuing the CLI command,
+ global sample-status does not update
+ the samples processed list on the active controller and non-server
+ worker nodes.
+
+
+ Workaround: Gracefully restart the affected
+ WildFire active controller and passive controller in the cluster.
+
+ |
+
|
+ WF500-6270
+ |
+
+
+ The WildFire cluster server and worker nodes might disconnect from the
+ Wildfire cluster management network, resulting in a notifier process
+ exit on WildFire cluster controllers.
+
+
+ Workaround: Gracefully restart the WildFire
+ cluster node where the process exit occurred.
+
+ |
+
|
+ WF500-6222
+ |
+
+
+ When WildFire secure cluster communication is enabled using a custom
+ DNS, the cluster formation might fail due to cluster management
+ communication issues.
+
+
+ Workaround: Do not configure a custom DNS when
+ WildFire secure cluster communication is enabled.
+
+ |
+
|
+ WF500-6176
+ |
+
+
+ When Panorama is used to manage a WildFire cluster, switchover
+ functionality for active and passive controller roles is not
+ available.
+
+ |
+
|
+ PAN-308564
+ |
+
+
+ Packets are dropped on SD-WAN interfaces if they require fragmentation
+ for an interface but have the
+ Don't Fragment (DF) bit set. This
+ results in unexpected packet drops. This affects client to server
+ sessions when using SD-WAN for NGFW.
+
+
+ Workaround: Allow fragmenting packets with DF bit
+ set (debug dataplane set ip4-ignore-df yes).
+
+ |
+
|
+ PAN-308507
+ |
+
+
+ Strata Logging Service (SLS) log-forwarding streams intermittently
+ show as inactive. When checking the status of log-forwarding
+ connections, one or more streams are reported as inactive. Restarting
+ the log-receiver process temporarily
+ resolves the issue, but the streams become inactive again after
+ approximately 1-2 hours. This intermittent inactivity results in log
+ loss.
+
+ |
+
|
+ PAN-295645
+ |
+
+
+ When a WildFire cluster is configured centrally using Panorama, it
+ initiates a series of processes, including a software install and
+ reboot, in an order that will leave the resulting WildFire cluster in
+ an unusable state.
+
+ |
+
|
+ PAN-288525
+ |
+
+
+ When the Enterprise DLP data filtering profile is configured with a
+ Block action and is used in
+ conjunction with Advanced Threat Prevention, which is configured with
+ an action of reset-both,
+ reset-server,
+ reset-client, or
+ drop for the
+ HTTP Command and Control detector,
+ Dropbox file uploads that exceed the maximum configured file size
+ action will fail.
+
+
+ Workaround: Configure the Advanced Threat
+ Prevention Inline Cloud analysis () action for the HTTP Command and Control detector to
+ alert.
+
+ |
+
|
+ PAN-285061
+ |
+
+
+ When Enterprise DLP is enabled, file uploads might unexpectedly fail
+ when 100 continue response is received from the server during file
+ uploads.
+
+ |
+
|
+ PAN-284700
+ |
+
+
+ File downloads for content encoded with zstd (Zstandard), such as
+ specific content from box.com, fail when using Enterprise DLP because
+ zstd decompression is not supported in PAN-OS.
+
+ |
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-260212
+ |
+
+
+ When viewing Applications (), child App-IDs may be listed under the incorrect container App-ID.
+
+ |
+
|
+ PAN-259853
+ |
+
+
+ When the DHCP server is enabled for GlobalProtect, the commit error
+ message is not properly displayed when
+ Any is selected as the source
+ interface in the service router configuration (
+ ).
+
+ |
+
|
+ PAN-259423
+ |
+
+
+ When the GlobalProtect DHCP feature is enabled with two primary DHCP
+ servers on the GlobalProtect gateway, the gpsvc gets stuck during
+ renewal and after HA failover.
+
+ |
+
|
+ PAN-254236
+ |
+
+
+ TLSv1.3 hybridized Kyber support in the latest versions of Chrome and
+ Edge browsers results in dropped Client Hello packets when SSL/TLS
+ handshake inspection is enabled.
+
+
+ Workaround: Disable
+ SSL/TLS handshake inspection.
+
+ |
+
|
+ PAN-254108
+ |
+
+
+ when upgrading or downgrading a Panorama management server (), managed device (), or standalone firewall (), Base Releases and
+ Preferred Releases settings are
+ checked (enabled) by default and cause no PAN-OS software images to
+ display.
+
+
+ Workaround: Uncheck (disable)
+ Base Releases or
+ Preferred Releases to display either
+ the available base PAN-OS or preferred PAN-OS releases available to
+ download and install.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
|
+ PAN-252661
+ |
+
+
+ If you change the service route of gp-ip-mgmt in
+ Device > Setup > Services > Service Features >
+ gp-ip-mgmt
+ and Commit, the change won’t take effect.
+ gp-ip-mgmt continues to use the last committed service route.
+
+
+ Workaround: After you change the service route
+ interface for gp-ip-mgmt, navigate to either a GlobalProtect portal or
+ gateway, click OK to save the configuration, and
+ Commit the changes. This commit will include the
+ service route change.
+
+ |
+
|
+ PAN-250246
+ |
+
+
+ Panorama and the firewall display inconsistent IP addresses for
+ dynamic address group members after manually syncing.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-248836
+ |
+
+
+ The Advanced DNS Security trial license and trial license information
+ cannot be activated and viewed, respectively, on a managed firewall
+ (with expired or active status) from Panorama. These tasks can only be
+ performed on the firewall.
+
+ |
+
|
+ PAN-247728
+ |
+
+
+ When Advanced Routing is enabled, IP multicast is not supported. An
+ upcoming version will provide support for this feature. Customers who
+ have multicast configured or who plan to deploy multicast routing
+ should not upgrade to 11.2.0. Additionally, when Advanced Routing is
+ enabled, the BGP dampening configuration isn't applied to any peers or
+ peer group; the configuration is preserved but has no effect on BGP.
+ Customers can use BGP even if they have applied a Dampening profile to
+ a specific set of peers. The issue doesn't affect any other BGP
+ features.
+
+ |
+
|
+ PAN-241994
+ |
+
+
+ The VMX hardware version was upgraded from vmx-10 to vmx-15 on ESXi
+ and NSX-T. Support for vmx-15 is supported on ESXi 6.7 U2 and onwards.
+ Palo Alto Networks recommends that you upgrade your ESXi version if it
+ is less than 6.7 U2. For more information, see the
+ compatibility matrix.
+
+ |
+
|
+ PAN-239612
+ |
+
+
+ When the firewall is running PAN-OS 11.2.0 and Advanced Routing is
+ enabled, DHCPv4 relay agent functions successfully, but DHCPv6 relay
+ agent doesn't work.
+
+ |
+
|
+ PAN-237106
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-236649
+ |
+
+
+ If you change the configuration of a firewall acting as a PPPoEv4 or
+ PPPoEv6 client, old routes from the Forwarding Information Base (FIB)
+ and route table for an inherited configuration with dynamic-identifier
+ or client remain visible. Old routes also remain visible for an
+ inherited interface when you execute the CLI command,
+ show interface all.
+
+
+ Workaround: Unconfigure and configure the
+ Inherited Interface.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-308507
+ |
+
+
+ Strata Logging Service (SLS) log-forwarding streams intermittently
+ show as inactive. When checking the status of log-forwarding
+ connections, one or more streams are reported as inactive. Restarting
+ the log-receiver process temporarily
+ resolves the issue, but the streams become inactive again after
+ approximately 1-2 hours. This intermittent inactivity results in log
+ loss.
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-301801
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ On Log Collectors, the Elasticsearch process might fluctuate between
+ green and red states, causing log collection interruptions. This issue
+ occurs when the number of shards exceeds the supported threshold of
+ 1,000 shards per Elasticsearch instance.
+
+ |
+
|
+ PAN-298505
+
+ This issue is now resolved. See PAN-OS 11.2.7-h4 Addressed Issuesand
+ PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual
+ system IDs (vsys ID) changes causing auto-commit failures with
+ validation errors. This occurs when the multi-vsys firewall has
+ virtual systems managed by Panorama, and the vsys ID sequence breaks
+ when unused virtual systems are deleted and the changes are pushed to
+ the firewall.
+
+ |
+
|
+ PAN-296752
+
+ This issue is now resolved. See PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+
+ The PA-1410 firewalls experience a spike in the management plane CPU
+ utilization when the monitor-dp process attempts to retrieve the power
+ cycle count from the NVMe drive’s SMART data. This condition leads to
+ repeated reboots of the device, requiring a hard reset for recovery.
+
+ |
+
|
+ PAN-295803
+
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues,
+ PAN-OS 11.2.7-h10 Addressed Issues
+ and
+ PAN-OS 11.2.10-h3 Addressed Issues
+
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-294179
+
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues
+ and
+ PAN-OS 11.2.7-h3 Addressed Issues.
+
+ |
+ + On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. + | +
|
+ PAN-292344
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ Upgrading to an affected release causes the firewall to reboot
+ multiple times if the config contains an EDL (External Dynamic List)
+ that doesn't have an associated certificate profile.
+
+ |
+
|
+ PAN-291661
+
+ This issue is now resolved. See PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+
+ Upon upgrade, the ElasticSearch health status intermittently
+ transitions to the Red status for sometime, and then auto-recovers
+ back to Green. During the Red status periods, the cluster logs are
+ unavailable. This occurs due to disk write operations being
+ excessively slow, failing to meet the minimum time threshold required
+ to save the cluster state.
+
+ |
+
|
+
+ PAN-291288This issue is now resolved. See
+ PAN-OS 11.2.8 Addressed Issuesand
+ PAN-OS 11.2.7-h3 Addressed Issues
+
+ |
+ + An active firewall might unexpectedly reboot due to a + pan_task crash caused by a page + allocation failure. This issue is observed after a period of runtime + with traffic and telemetry collection. + | +
|
+
+ PAN-290449This issue is now resolved. See
+ PAN-OS 11.2.7-h3 Addressed Issuesand
+ PAN-OS 11.2.8 Addressed Issues
+
+ |
+ + The scheduled vulnerability reports that are configured to be sent via + email with multiple attachments send the first attached report only. The + remaining attachments are dropped. + | +
|
+ PAN-290088
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-287871
+ |
+
+
+ When SSL Inbound Inspection is enabled and the firewall receives
+ fragmented Client Hello packets that include the TCP timestamp option,
+ the Client Hello message is forwarded to the destination server
+ without the timestamp option.
+
+ |
+
|
+ PAN-286231
+
+ This issue is now resolved. See PAN-OS 11.2.7-h3 Addressed Issues.
+
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-281885
+ |
+
+
+ When exporting and importing the CSV file, the hash values of
+ pre-shared key (PSK) variables set at template and template stack
+ levels inconsistently change, resulting in both variables displaying
+ the same hash value.
+
+ |
+
|
+ PAN-280471
+ |
+
+
+ When applying filters or searching for logs in the
+ section, you might experience slow performance.
+
+ |
+
|
+ PAN-279746
+ |
+
+
+ An SSL/TLS Client Hello may not be transmitted out of the firewall if
+ the Client Hello arrives in multiple TCP segments and the traffic is
+ not subject to SSL decryption (for example, SMTP over SSL).
+
+ |
+
|
+ PAN-279415
+ |
+
+
+ Service routes configured for a data plane interface might incorrectly
+ route traffic through the management plane interface instead. This
+ issue impacts Syslog and CRL status traffic when the service route
+ lacks a specific destination custom service route.
+
+ |
+
|
+ PAN-277034
+
+ This issue is now resolved. See PAN-OS 11.2.7-h3 Addressed Issues
+
+ |
+ + WildFire reports might not fully display or be downloadable because some + static resources fail to load. + | +
|
+ PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ When Panorama is not internet-connected and you try to upload images
+ to the managed firewalls by using the
+ Validate option, the upload fails
+ with the following error:
+ Failed to create multi-upload job. No valid software deploy targets
+ found.
+
+ |
+
|
+ PAN-273300
+
+ This issue is now resolved. See PAN-OS 11.2.5 Addressed Issues
+
+ |
+
+
+ When upgrading Panorama from PAN-OS 10.2 or PAN-OS 11.0 to PAN-OS 11.1
+ or a later release, Panorama fails to upgrade if it is operating
+ within a Collector Group. The following error appears:Error: Traceback (most recent call last):File
+ "/opt/panrepo/releases/<PANOS release version>/validate"...
+ (min ([dts['min'] for dts in 10g_type_intv_dir.values() if
+ dts|'min']])-strftime ('%Y-%m-%d'),
+
+ |
+
|
+ PAN-263226
+ |
+
+
+ When SSL decryption is enabled and Client Hello messages span multiple
+ TCP segments, elements from the proxy_l2info memory pool may not be
+ freed properly. Memory leaks in this pool cause some SSL decryption
+ sessions to fail.
+
+
+ Workaround: Disable Client Hello accumulation
+ using the
+ debug dataplane set ssl-decrypt accumulate-client-hello disable
+ yes
+ CLI command.
+
+ |
+
|
+ PAN-262287
+ |
+
+
+ Dereferencing a NULL pointer that occurs might cause
+ pan_task
+ processes to crash.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-260212
+ |
+
+
+ When viewing Applications (), child App-IDs may be listed under the incorrect container App-ID.
+
+ |
+
| PAN-259769 | +
+
+ GlobalProtect portal is not accessible via a web browser and the app
+ displays the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-259853
+
+ This issue is now resolved. See PAN-OS 11.2.7-h10 Addressed Issues
+
+ |
+
+
+ When the DHCP server is enabled for GlobalProtect, the commit error
+ message is not properly displayed when
+ Any is selected as the source
+ interface in the service router configuration (
+ ).
+
+ |
+
|
+ PAN-259423
+ |
+
+
+ When the GlobalProtect DHCP feature is enabled with two primary DHCP
+ servers on the GlobalProtect gateway, the gpsvc gets stuck during
+ renewal and after HA failover.
+
+ |
+
|
+ PAN-257615
+
+ This issue is now resolved. See PAN-OS 11.2.3 Addressed Issues.
+
+ |
+
+
+ The Panorama web interface intermittently displays logs or fails to
+ display logs completely.
+
+ |
+
|
+ PAN-254108
+ |
+
+
+ when upgrading or downgrading a Panorama management server (), managed device (), or standalone firewall (), Base Releases and
+ Preferred Releases settings are
+ checked (enabled) by default and cause no PAN-OS software images to
+ display.
+
+
+ Workaround: Uncheck (disable)
+ Base Releases or
+ Preferred Releases to display either
+ the available base PAN-OS or preferred PAN-OS releases available to
+ download and install.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-248836
+ |
+
+
+ The Advanced DNS Security trial license and trial license information
+ cannot be activated and viewed, respectively, on a managed firewall
+ (with expired or active status) from Panorama. These tasks can only be
+ performed on the firewall.
+
+ |
+
|
+ PAN-239612
+ |
+
+
+ When the firewall is running PAN-OS 11.2.0 and Advanced Routing is
+ enabled, DHCPv4 relay agent functions successfully, but DHCPv6 relay
+ agent doesn't work.
+
+ |
+
|
+ PAN-236649
+ |
+
+
+ If you change the configuration of a firewall acting as a PPPoEv4 or
+ PPPoEv6 client, old routes from the Forwarding Information Base (FIB)
+ and route table for an inherited configuration with dynamic-identifier
+ or client remain visible. Old routes also remain visible for an
+ inherited interface when you execute the CLI command,
+ show interface all.
+
+
+ Workaround: Unconfigure and configure the
+ Inherited Interface.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-308507
+ |
+
+
+ Strata Logging Service (SLS) log-forwarding streams intermittently
+ show as inactive. When checking the status of log-forwarding
+ connections, one or more streams are reported as inactive. Restarting
+ the log-receiver process temporarily
+ resolves the issue, but the streams become inactive again after
+ approximately 1-2 hours. This intermittent inactivity results in log
+ loss.
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-301801
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ On Log Collectors, the Elasticsearch process might fluctuate between
+ green and red states, causing log collection interruptions. This issue
+ occurs when the number of shards exceeds the supported threshold of
+ 1,000 shards per Elasticsearch instance.
+
+ |
+
|
+ PAN-298505
+
+ This issue is now resolved. See PAN-OS 11.2.7-h4 Addressed Issuesand
+ PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual
+ system IDs (vsys ID) changes causing auto-commit failures with
+ validation errors. This occurs when the multi-vsys firewall has
+ virtual systems managed by Panorama, and the vsys ID sequence breaks
+ when unused virtual systems are deleted and the changes are pushed to
+ the firewall.
+
+ |
+
|
+ PAN-296752
+
+ This issue is now resolved. See PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+
+ The PA-1410 firewalls experience a spike in the management plane CPU
+ utilization when the monitor-dp process attempts to retrieve the power
+ cycle count from the NVMe drive’s SMART data. This condition leads to
+ repeated reboots of the device, requiring a hard reset for recovery.
+
+ |
+
|
+ PAN-295803
+
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues,
+ PAN-OS 11.2.7-h10 Addressed Issues
+ and
+ PAN-OS 11.2.10-h3 Addressed Issues
+
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-294179
+
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues
+ and
+ PAN-OS 11.2.7-h3 Addressed Issues.
+
+ |
+ + On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. + | +
|
+ PAN-292344
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ Upgrading to an affected release causes the firewall to reboot
+ multiple times if the config contains an EDL (External Dynamic List)
+ that doesn't have an associated certificate profile.
+
+ |
+
|
+ PAN-291661
+
+ This issue is now resolved. See PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+
+ Upon upgrade, the ElasticSearch health status intermittently
+ transitions to the Red status for sometime, and then auto-recovers
+ back to Green. During the Red status periods, the cluster logs are
+ unavailable. This occurs due to disk write operations being
+ excessively slow, failing to meet the minimum time threshold required
+ to save the cluster state.
+
+ |
+
|
+
+ PAN-291288This issue is now resolved. See
+ PAN-OS 11.2.8 Addressed Issuesand
+ PAN-OS 11.2.7-h3 Addressed Issues
+
+ |
+ + An active firewall might unexpectedly reboot due to a + pan_task crash caused by a page + allocation failure. This issue is observed after a period of runtime + with traffic and telemetry collection. + | +
|
+
+ PAN-290449This issue is now resolved. See PAN-OS 11.2.8 Addressed Issuesand
+ PAN-OS 11.2.7-h3 Addressed Issues
+
+ |
+ + The scheduled vulnerability reports that are configured to be sent via + email with multiple attachments send the first attached report only. The + remaining attachments are dropped. + | +
|
+ PAN-290088
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-287871
+ |
+
+
+ When SSL Inbound Inspection is enabled and the firewall receives
+ fragmented Client Hello packets that include the TCP timestamp option,
+ the Client Hello message is forwarded to the destination server
+ without the timestamp option.
+
+ |
+
|
+ PAN-286231
+
+ This issue is now resolved. See PAN-OS 11.2.7-h3 Addressed Issues.
+
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-281885
+ |
+
+
+ When exporting and importing the CSV file, the hash values of
+ pre-shared key (PSK) variables set at template and template stack
+ levels inconsistently change, resulting in both variables displaying
+ the same hash value.
+
+ |
+
|
+ PAN-280471
+ |
+
+
+ When applying filters or searching for logs in the
+ section, you might experience slow performance.
+
+ |
+
|
+ PAN-279746
+ |
+
+
+ An SSL/TLS Client Hello may not be transmitted out of the firewall if
+ the Client Hello arrives in multiple TCP segments and the traffic is
+ not subject to SSL decryption (for example, SMTP over SSL).
+
+ |
+
|
+ PAN-279415
+ |
+
+
+ Service routes configured for a data plane interface might incorrectly
+ route traffic through the management plane interface instead. This
+ issue impacts Syslog and CRL status traffic when the service route
+ lacks a specific destination custom service route.
+
+ |
+
|
+ PAN-277034
+
+ This issue is now resolved. See PAN-OS 11.2.7-h3 Addressed Issues
+
+ |
+ + WildFire reports might not fully display or be downloadable because some + static resources fail to load. + | +
|
+ PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ When Panorama is not internet-connected and you try to upload images
+ to the managed firewalls by using the
+ Validate option, the upload fails
+ with the following error:
+ Failed to create multi-upload job. No valid software deploy targets
+ found.
+
+ |
+
|
+ PAN-273300
+
+ This issue is now resolved. See PAN-OS 11.2.5 Addressed Issues
+
+ |
+
+
+ When upgrading Panorama from PAN-OS 10.2 or PAN-OS 11.0 to PAN-OS 11.1
+ or a later release, Panorama fails to upgrade if it is operating
+ within a Collector Group. The following error appears:Error: Traceback (most recent call last):File
+ "/opt/panrepo/releases/<PANOS release version>/validate"...
+ (min ([dts['min'] for dts in 10g_type_intv_dir.values() if
+ dts|'min']])-strftime ('%Y-%m-%d'),
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-260212
+ |
+
+
+ When viewing Applications (), child App-IDs may be listed under the incorrect container App-ID.
+
+ |
+
|
+ PAN-259853
+
+ This issue is now resolved. See PAN-OS 11.2.7-h10 Addressed Issues
+
+ |
+
+
+ When the DHCP server is enabled for GlobalProtect, the commit error
+ message is not properly displayed when
+ Any is selected as the source
+ interface in the service router configuration (
+ ).
+
+ |
+
|
+ PAN-259423
+ |
+
+
+ When the GlobalProtect DHCP feature is enabled with two primary DHCP
+ servers on the GlobalProtect gateway, the gpsvc gets stuck during
+ renewal and after HA failover.
+
+ |
+
|
+ PAN-254108
+ |
+
+
+ when upgrading or downgrading a Panorama management server (), managed device (), or standalone firewall (), Base Releases and
+ Preferred Releases settings are
+ checked (enabled) by default and cause no PAN-OS software images to
+ display.
+
+
+ Workaround: Uncheck (disable)
+ Base Releases or
+ Preferred Releases to display either
+ the available base PAN-OS or preferred PAN-OS releases available to
+ download and install.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-248836
+ |
+
+
+ The Advanced DNS Security trial license and trial license information
+ cannot be activated and viewed, respectively, on a managed firewall
+ (with expired or active status) from Panorama. These tasks can only be
+ performed on the firewall.
+
+ |
+
|
+ PAN-239612
+ |
+
+
+ When the firewall is running PAN-OS 11.2.0 and Advanced Routing is
+ enabled, DHCPv4 relay agent functions successfully, but DHCPv6 relay
+ agent doesn't work.
+
+ |
+
|
+ PAN-236649
+ |
+
+
+ If you change the configuration of a firewall acting as a PPPoEv4 or
+ PPPoEv6 client, old routes from the Forwarding Information Base (FIB)
+ and route table for an inherited configuration with dynamic-identifier
+ or client remain visible. Old routes also remain visible for an
+ inherited interface when you execute the CLI command,
+ show interface all.
+
+
+ Workaround: Unconfigure and configure the
+ Inherited Interface.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-308507
+ |
+
+
+ Strata Logging Service (SLS) log-forwarding streams intermittently
+ show as inactive. When checking the status of log-forwarding
+ connections, one or more streams are reported as inactive. Restarting
+ the log-receiver process temporarily
+ resolves the issue, but the streams become inactive again after
+ approximately 1-2 hours. This intermittent inactivity results in log
+ loss.
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-303959
+
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues,
+ PAN-OS 11.2.7-h10 Addressed Issues
+ and
+ PAN-OS 11.2.10-h3 Addressed Issues
+
+ |
+
+
+ Traffic that is incorrectly identified as unknown-tcp/unknown-udp
+ eventually drops due to an App-ID resource limitation issue.
+
+ |
+
|
+ PAN-301801
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ On Log Collectors, the Elasticsearch process might fluctuate between
+ green and red states, causing log collection interruptions. This issue
+ occurs when the number of shards exceeds the supported threshold of
+ 1,000 shards per Elasticsearch instance.
+
+ |
+
|
+ PAN-298505
+
+ This issue is now resolved. See PAN-OS 11.2.7-h4 Addressed Issuesand
+ PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual
+ system IDs (vsys ID) changes causing auto-commit failures with
+ validation errors. This occurs when the multi-vsys firewall has
+ virtual systems managed by Panorama, and the vsys ID sequence breaks
+ when unused virtual systems are deleted and the changes are pushed to
+ the firewall.
+
+ |
+
|
+ PAN-297775
+ |
+
+
+ The wrong vsys is referenced under Visible Virtual System after every
+ local firewall commit (auto-commit, commit, content install) if the
+ display name of the vsys matches another vsys ID (for example, the
+ vsys2 display name is vsys1). The incorrect vsys reference causes
+ inter-vsys routing to fail.
+
+
+ Workaround: Change the vsys display name so that
+ it doesn't reference an existing vsys ID.
+
+ |
+
|
+ PAN-297295
+
+ This issue is now resolved. See PAN-OS 11.2.7-h10 Addressed Issues
+ and
+
+ |
+
+ (VM-Series firewalls on Microsoft Azure environments only)
+
+ After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent process restarts multiple
+ times and exhausts its restart limit, resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-296752
+
+ This issue is now resolved. See PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+
+ The PA-1410 firewalls experience a spike in the management plane CPU
+ utilization when the monitor-dp process attempts to retrieve the power
+ cycle count from the NVMe drive’s SMART data. This condition leads to
+ repeated reboots of the device, requiring a hard reset for recovery.
+
+ |
+
|
+ PAN-295803
+
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues,
+ PAN-OS 11.2.7-h10 Addressed Issues
+ and
+ PAN-OS 11.2.10-h3 Addressed Issues
+
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-294179
+
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues
+ and
+ PAN-OS 11.2.7-h3 Addressed Issues.
+
+ |
+ + On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. + | +
|
+ PAN-292344
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ Upgrading to an affected release causes the firewall to reboot
+ multiple times if the config contains an EDL (External Dynamic List)
+ that doesn't have an associated certificate profile.
+
+ |
+
|
+ PAN-292202
+
+ This issue is now resolved. See PAN-OS 11.2.7-h3 Addressed Issues.
+
+ |
+
+
+ The system logs repeatedly displayed the alert `Clearing snmpd.log due
+ to log overflow` due to the SNMP counters rolling over. This is a
+ benign message and does not impact device functionality.
+
+ |
+
|
+ PAN-291716
+ |
+
+
+ (PA-460 firewalls only) The firewall experiences an out-of-memory
+ (OOM) condition and displays an error message. This issue causes the
+ device to crash and reboot unexpectedly.
+
+ |
+
|
+ PAN-291661
+
+ This issue is now resolved. See PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+
+ Upon upgrade, the ElasticSearch health status intermittently
+ transitions to the Red status for sometime, and then auto-recovers
+ back to Green. During the Red status periods, the cluster logs are
+ unavailable. This occurs due to disk write operations being
+ excessively slow, failing to meet the minimum time threshold required
+ to save the cluster state.
+
+ |
+
|
+
+ PAN-291288This issue is now resolved. See
+ PAN-OS 11.2.8 Addressed Issuesand
+ PAN-OS 11.2.7-h3 Addressed Issues
+
+ |
+ + An active firewall might unexpectedly reboot due to a + pan_task crash caused by a page + allocation failure. This issue is observed after a period of runtime + with traffic and telemetry collection. + | +
|
+
+ PAN-290449This issue is now resolved. See PAN-OS 11.2.8 Addressed Issuesand
+ PAN-OS 11.2.7-h3 Addressed Issues
+
+ |
+ + The scheduled vulnerability reports that are configured to be sent via + email with multiple attachments send the first attached report only. The + remaining attachments are dropped. + | +
|
+ PAN-290088
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-289383
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ (PA-800 series firewalls only) Upgrading
+ firewalls to PAN-OS 11.0 or later causes SFP ports to go
+ non-operational when the firewall uses forced port mode and the
+ connected peer device operates without auto-negotiation.
+
+
+ Workaround: Enable auto-negotiation on the
+ connected peer firewall.
+
+ |
+
|
+ PAN-287803
+ |
+
+
+ After upgrading to PAN-OS 11.1.6-h4, users might be unable to access
+ some URLs due to issues involving the accumulation proxy and the Path
+ Maximum Transmission Unit (MTU).
+
+
+ To address this issue, use one of the following workarounds:
+
+
|
+
|
+ PAN-286848
+
+ This issue is now resolved. See PAN-OS 11.2.7 Addressed Issues
+
+ |
+
+
+ ECMP incorrectly balances sessions across links based on the
+ configured metric, which leads to an imbalance in traffic distribution
+ and results in traffic assignment shifting disproportionately to
+ routes with lower metrics.
+
+ |
+
|
+ PAN-286306
+
+ This issue is now resolved. See PAN-OS 11.2.4-h10 Addressed Issues
+
+ |
+
+
+ When getting transceiver information from ESCC for SFP 25G modules,
+ the transceiver code incorrectly displays
+ Unknown instead of
+ 25GBase-SR.
+
+ |
+
|
+ PAN-286255
+
+ This issue affects PAN-OS 11.2.4-h6
+
+
+ This issue is now resolved. See PAN-OS 11.2.4-h7 Addressed Issues.
+
+ |
+
+
+ When a firewall receives an unexpected termination request for certain
+ SSL sessions, NGFW dataplane might experience a slow buffer resource
+ leak.
+
+
+ Workaround: Disable accumulation proxy on the
+ NGFW.
+
+ |
+
|
+ PAN-286231
+
+ This issue is now resolved. See PAN-OS 11.2.7-h3 Addressed Issues.
+
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-285894
+
+ This issue is now resolved. See PAN-OS 11.2.7 Addressed Issues
+
+ |
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may
+ occur, which could result in firewall reboots.
+
+
+ Workaround: Disable the Preserve Pre-NAT feature
+ using the
+ set deviceconfig setting preserve-prenat-feature no
+ CLI command.
+
+ |
+
|
+ PAN-285590
+ |
+ + VM-Series firewalls deployed behind an AWS GWLB might experience 100% + dataplane CPU utilization when an Anti-Spyware profile is applied to + traffic. + | +
|
+ PAN-284067
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ A cumulative memory leak in the
+ devsrvr
+ process gets progressively worse whenever the CLI command
+ show running application statistics
+ is issued. This memory leak will gradually consume system memory and
+ produce an out-of-memory (OOM) condition, leading to an eventual
+ firewall reboot.
+
+ |
+
|
+ PAN-283467
+
+ This issue is now resolved. See PAN-OS 11.2.6 Addressed Issues
+
+ |
+
+
+ (PA-3400 Series firewalls only) The firewall
+ might unexpectedly reboot and enter maintenance mode due to a
+ ctd-agent
+ out-of-memory (OOM) condition when undergoing advanced services load
+ testing with a high volume of IoT EAL log forwarding.
+
+
+ Workaround: Limit the number of EAL logs generated
+ by the firewall using the following CLI command:
+ debug iot eal key-value EAL_PENDING_BYTES=1000.
+
+ |
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-282277
+ |
+
+
+ (PA-3260 firewalls only) An interface
+ unexpectedly moves out of Link Aggregation Control Protocol (LACP),
+ which causes an out-of-memory (OOM) condition on the *logrcvr*
+ process, resulting in the interface going down and then automatically
+ coming back up without intervention.
+
+ |
+
|
+ PAN-282236
+ (PAN-OS 11.2.4-h5 only)
+ |
+
+
+ The firewall doesn't reassemble IPv6 packets correctly after they are
+ fragmented. IPv6 SSL sessions may not be established if the client
+ hello arrives in multiple segments.
+
+ |
+
|
+ PAN-281885
+ |
+
+
+ When exporting and importing the CSV file, the hash values of
+ pre-shared key (PSK) variables set at template and template stack
+ levels inconsistently change, resulting in both variables displaying
+ the same hash value.
+
+ |
+
|
+ PAN-280471
+ |
+
+
+ When applying filters or searching for logs in the
+ section, you might experience slow performance.
+
+ |
+
|
+ PAN-279901
+
+ (PAN-OS 11.2.4-h6 through PAN-OS 11.2.4-h9)
+
+
+ This issue is now resolved. See PAN-OS 11.2.4-h11 Addressed Issues
+
+ |
+
+
+ When decryption is enabled, segmented Client Hello packets can cause
+ website access issues and memory leaks under the following conditions:
+
+
|
+
|
+ PAN-279746
+
+ (PAN-OS 11.2.4-h1 through PAN-OS 11.2.4-h5)
+
+ |
+
+
+ An SSL/TLS Client Hello may not be transmitted out of the firewall if
+ the Client Hello arrives in multiple TCP segments and the traffic is
+ not subject to SSL decryption (for example, SMTP over SSL).
+
+ |
+
|
+ PAN-279621
+
+ This issue is now resolved. See PAN-OS 11.2.6 Addressed Issues
+
+ |
+
+
+ Early aging and removal of firewall session while they are still
+ active can lead to intermittent instabilities and crashes for proxy
+ traffic, the Content and Threat detection engine, and any data-path
+ processing.
+
+ |
+
|
+ PAN-279604
+ (PAN-OS 11.2.4-h4 only)
+ |
+
+
+ The scheduled SaaS application usage reports are incorrectly generated
+ and only the login page appears instead of the intended report
+ content.
+
+ |
+
|
+ PAN-279415
+ |
+
+
+ Service routes configured for a data plane interface might incorrectly
+ route traffic through the management plane interface instead. This
+ issue impacts Syslog and CRL status traffic when the service route
+ lacks a specific destination custom service route.
+
+ |
+
|
+ PAN-278322
+ |
+ + VM-Series firewalls deployed behind an AWS GWLB might display an + incorrect or empty Source User field in traffic logs and session + details. + | +
|
+ PAN-276920
+ |
+
+
+ URL filtering response pages may load slowly or fail to display when
+ users request websites that are blocked in the URL Filtering profile
+ (site access for the corresponding URL category is
+ block,
+ continue, or
+ override) attached to the matching
+ Security policy rule. This occurs on an intermittent basis.
+
+ |
+
|
+ PAN-277034
+
+ This issue is now resolved. See PAN-OS 11.2.7-h3 Addressed Issues
+
+ |
+ + WildFire reports might not fully display or be downloadable because some + static resources fail to load. + | +
|
+ PAN-275905
+ (PAN-OS 11.2.4-h4 only)
+ |
+
+
+ A high volume of incoming logs to a Collector Group can significantly
+ increase CPU usage on the Elasticsearch and Management Server,
+ potentially causing process instability or crashes.
+
+ |
+
|
+ PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ When Panorama is not internet-connected and you try to upload images
+ to the managed firewalls by using the
+ Validate option, the upload fails
+ with the following error:
+ Failed to create multi-upload job. No valid software deploy targets
+ found.
+
+ |
+
|
+ PAN-273300
+
+ This issue is now resolved. See PAN-OS 11.2.5 Addressed Issues
+
+ |
+
+
+ When upgrading Panorama from PAN-OS 10.2 or PAN-OS 11.0 to PAN-OS 11.1
+ or a later release, Panorama fails to upgrade if it is operating
+ within a Collector Group. The following error appears:Error: Traceback (most recent call last):File
+ "/opt/panrepo/releases/<PANOS release version>/validate"...
+ (min ([dts['min'] for dts in 10g_type_intv_dir.values() if
+ dts|'min']])-strftime ('%Y-%m-%d'),
+
+ |
+
|
+ PAN-275077
+ |
+ + DNS Security intermittently logs malicious domain URLs as alert instead + of taking a sinkhole action, even when + configured to sinkhole malicious DNS domains. + | +
|
+ PAN-275047
+
+ This issue is now resolved. See PAN-OS 11.2.7 Addressed Issues
+
+ |
+
+
+ (VM-Series firewalls only) After an upgrade,
+ the firewall is unable to send logs to the Strata Logging Service
+ (SLS) when using a specific proxy server, and the SSL connection
+ status displays as failed when attempting to forward logs through the
+ web proxy.
+
+ |
+
|
+ PAN-274314
+
+ This issue is now resolved. See PAN-OS 11.2.6 Addressed Issues
+
+ |
+
+
+ (PA-1400 Series firewalls, PA-3400 Series firewalls, and PA-5400
+ Series firewalls only) When the
+ pan_task
+ process restarts, control plane packets are dropped, which can impact
+ LACP and pings to host interfaces.
+
+ |
+
|
+ PAN-274146
+ |
+ + VM-Series firewalls deployed behind an AWS GWLB might crash and reboot + unexpectedly if tunnel sessions are moving through the firewall. + | +
|
+ PAN-272085
+ (PAN-OS 11.2.4-h4 only)
+
+ This issue is now resolved. See PAN-OS 11.2.5 Addressed Issues.
+
+ |
+
+
+ When DoH is enabled for DNS Security, multiple DoH transactions in a
+ single HTTP/1 connection might unexpectedly cause the firewall to
+ crash and reboot.
+
+
+ Workaround: Manually disable DoH support for DNS
+ Security using the
+ set deviceconfig setting dns-over-https enable no
+ CLI command. Alternatively, you can remove the DNS Security
+ configuration used to handle DoH traffic.
+
+ |
+
|
+ PAN-271913
+ (PAN-OS 11.2.4-h9 only)
+
+ This issue is now resolved. See PAN-OS 11.2.5 Addressed Issues.
+
+ |
+
+
+ Firewalls in HA configurations were experiencing consistent memory
+ leaks on the active firewall, leading unexpected failovers while using
+ Cloud Identity Engine (CIE).
+
+ |
+
|
+ PAN-270549
+ |
+
+
+ Some TLS connections are not handled correctly leading to an
+ instability in the dataplane of PAN-OS.
+
+ |
+
|
+ PAN-270224
+ PAN-OS 11.2.4-h4 only
+
+ This issue is now resolved. See PAN-OS 11.2.5 Addressed Issues.
+
+ |
+
+
+ When querying for logs in the
+ Monitor tab in Panorama, some
+ forwarded logs might be missing from the results.
+
+ |
+
|
+ PAN-269106
+ PAN-OS 11.2.4-h4 only
+
+ This issue is now resolved. See PAN-OS 11.2.5 Addressed Issues.
+
+ |
+
+
+ When using a cloud-based ML detection engine (MICA), the
+ wifclient might crash during
+ server cert verification for MICA gRPC connections and cause the
+ dataplane to restart. On certain platforms, this might cause the
+ firewall to reboot.
+
+
+ Workaround: Disable CRL using the following CLI
+ command:debug iot eal key-value PAN_ICD_SERVER_CERT_USE_CRL=False
+
+ |
+
|
+ PAN-269027
+
+ This issue is now resolved. See PAN-OS 11.2.5 Addressed Issues.
+
+ |
+
+
+ External dynamic lists cause the commit time on the firewall to be
+ higher than expected.
+
+ |
+
| PAN-268705 | +
+
+ The firewall intermittently fails to process FTP traffic.
+
+
+ Workaround: Configure an application override
+ policy rule for FTP applications.
+
+ |
+
|
+ PAN-268229
+ |
+
+
+ If you configure an IPSec tunnel, when traffic from the tunnel
+ egresses the firewall on an ECMP route, the firewall stops responding.
+
+
+ Workaround: Disable ECMP for the virtual router or
+ logical router to avoid this issue.
+
+ |
+
|
+ PAN-268127
+
+ This issue is now resolved. See PAN-OS 11.2.5 Addressed Issues.
+
+ |
+
+
+ Tagging a firewall in Panorama produces an error,
+ TypeError: Cannot read properties of undefined (reading
+ 'serial'), and does not tag as expected.
+
+ |
+
|
+ PAN-266900
+
+ This issue is now resolved. See PAN-OS 11.2.5 Addressed Issues.
+
+ |
+
+
+ In Panorama, the OK button does not
+ work when trying to install configurations to a managed firewall from
+ the
+ , even after selecting the update type and file from the dropdown and
+ choosing the firewall.
+
+ |
+
|
+ PAN-263987
+ |
+
+
+ When a NAT traversal (NAT-T or UDP encapsulation) IPSec tunnel is
+ terminated on a Palo Alto Networks firewall and the NAT rule applied
+ to the NAT-T IPSec tunnel is also on the same firewall, then the data
+ traffic flowing through the NAT-T IPSec tunnel can't be NATed
+ correctly.
+
+ |
+
|
+ PAN-263973
+
+ This issue is now resolved. See PAN-OS 11.2.4-h9 Addressed Issues
+ and
+ PAN-OS 11.2.5 Addressed Issues.
+
+ |
+
+
+ After upgrading, the log collectors might experience a low incoming
+ logging rate.
+
+ |
+
|
+ PAN-263208
+
+ This issue is now resolved. See PAN-OS 11.2.5 Addressed Issues.
+
+ |
+
+
+ (PA-5440 and PA-5445 firewalls only) High
+ system load can cause the firewall to generate interrupts and trigger
+ dataplane crashes.
+
+ |
+
|
+ PAN-261429
+
+ This issue is now resolved. See PAN-OS 11.2.6 Addressed Issues
+
+ |
+
+
+ The command
+ show auth radius-require-msg-authentic
+ might return no output.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-260212
+ |
+
+
+ When viewing Applications (), child App-IDs may be listed under the incorrect container App-ID.
+
+ |
+
|
+ PAN-260015
+
+ This issue is now resolved. See PAN-OS 11.2.6 Addressed Issues
+
+ |
+
+
+ When Inline Cloud Analysis features are enabled, an issue related to
+ loopback data handling might cause the firewall to unexpectedly
+ reboot.
+
+
+ Workaround: Disable any Inline Cloud Analysis
+ features on the firewall (e.g. Advanced Threat Prevention Inline Cloud
+ Analysis, WildFire Inline Cloud Analysis, App-ID Cloud Engine, etc) on
+ the firewall.
+
+ |
+
|
+ PAN-259853
+
+ This issue is now resolved. See PAN-OS 11.2.7-h10 Addressed Issues
+
+ |
+
+
+ When the DHCP server is enabled for GlobalProtect, the commit error
+ message is not properly displayed when
+ Any is selected as the source
+ interface in the service router configuration (
+ ).
+
+ |
+
|
+ PAN-259423
+ |
+
+
+ When the GlobalProtect DHCP feature is enabled with two primary DHCP
+ servers on the GlobalProtect gateway, the gpsvc gets stuck during
+ renewal and after HA failover.
+
+ |
+
|
+ PAN-258680
+
+ This issue is now resolved. See
+ PAN-OS 11.2.5 Addressed Issues.
+
+ |
+
+
+ When you remove Security profile groups from a Security policy rule
+ via the CLI and then do a partial commit, the Security policy rule is
+ deleted.
+
+
+ Workaround: Perform one of the following:
+
+
+
+
|
+
|
+ PAN-258570
+
+ This issue affects PAN-OS 11.2.4-h4.
+
+
+ This issue is now resolved. See
+ PAN-OS 11.2.5 Addressed Issues.
+
+ |
+
+
+ The
+ varrcvr
+ process might progressively use more memory resulting in unexpected
+ reboots when WildFire file forwarding is handling PE files.
+
+ |
+
|
+ PAN-257267
+
+ This issue is now resolved. See PAN-OS 11.2.5 Addressed Issues
+
+ |
+
+
+ (VM-Series firewalls only) A warning message
+ stating that the configuration size exceeded the maximum recommended
+ configuration size, was observed during commit completion and critical
+ system log in the VM-Series firewall.
+
+ |
+
|
+ PAN-254901
+
+ This issue is now resolved. See PAN-OS 11.2.5 Addressed Issues
+
+ |
+
+
+ If the GlobalProtect license is not installed or is invalid on the
+ device, GlobalProtect user-to-IP address mapping is unexpectedly
+ removed, despite the fact that the tunnel for a specific user is
+ active and traffic is successfully passing through it. Due to the
+ user-to-IP mapping being removed, the traffic matches the wrong
+ policy.
+
+ |
+
|
+ PAN-254108
+ |
+
+
+ when upgrading or downgrading a Panorama management server (), managed device (), or standalone firewall (), Base Releases and
+ Preferred Releases settings are
+ checked (enabled) by default and cause no PAN-OS software images to
+ display.
+
+
+ Workaround: Uncheck (disable)
+ Base Releases or
+ Preferred Releases to display either
+ the available base PAN-OS or preferred PAN-OS releases available to
+ download and install.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-248836
+ |
+
+
+ The Advanced DNS Security trial license and trial license information
+ cannot be activated and viewed, respectively, on a managed firewall
+ (with expired or active status) from Panorama. These tasks can only be
+ performed on the firewall.
+
+ |
+
|
+ PAN-239612
+ |
+
+
+ When the firewall is running PAN-OS 11.2.0 and Advanced Routing is
+ enabled, DHCPv4 relay agent functions successfully, but DHCPv6 relay
+ agent doesn't work.
+
+ |
+
|
+ PAN-236649
+ |
+
+
+ If you change the configuration of a firewall acting as a PPPoEv4 or
+ PPPoEv6 client, old routes from the Forwarding Information Base (FIB)
+ and route table for an inherited configuration with dynamic-identifier
+ or client remain visible. Old routes also remain visible for an
+ inherited interface when you execute the CLI command,
+ show interface all.
+
+
+ Workaround: Unconfigure and configure the
+ Inherited Interface.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-308507
+ |
+
+
+ Strata Logging Service (SLS) log-forwarding streams intermittently
+ show as inactive. When checking the status of log-forwarding
+ connections, one or more streams are reported as inactive. Restarting
+ the log-receiver process temporarily
+ resolves the issue, but the streams become inactive again after
+ approximately 1-2 hours. This intermittent inactivity results in log
+ loss.
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-303959
+
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues,
+ PAN-OS 11.2.7-h10 Addressed Issues
+ and
+ PAN-OS 11.2.10-h3 Addressed Issues
+
+ |
+
+
+ Traffic that is incorrectly identified as unknown-tcp/unknown-udp
+ eventually drops due to an App-ID resource limitation issue.
+
+ |
+
|
+ PAN-301801
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ On Log Collectors, the Elasticsearch process might fluctuate between
+ green and red states, causing log collection interruptions. This issue
+ occurs when the number of shards exceeds the supported threshold of
+ 1,000 shards per Elasticsearch instance.
+
+ |
+
|
+ PAN-298505
+
+ This issue is now resolved. See PAN-OS 11.2.7-h4 Addressed Issuesand
+ PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual
+ system IDs (vsys ID) changes causing auto-commit failures with
+ validation errors. This occurs when the multi-vsys firewall has
+ virtual systems managed by Panorama, and the vsys ID sequence breaks
+ when unused virtual systems are deleted and the changes are pushed to
+ the firewall.
+
+ |
+
|
+ PAN-297295
+
+ This issue is now resolved. See PAN-OS 11.2.7-h4 Addressed Issuesand
+ PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+ (VM-Series firewalls on Microsoft Azure environments only)
+
+ After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent process restarts multiple
+ times and exhausts its restart limit, resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-296752
+
+ This issue is now resolved. See PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+
+ The PA-1410 firewalls experience a spike in the management plane CPU
+ utilization when the monitor-dp process attempts to retrieve the power
+ cycle count from the NVMe drive’s SMART data. This condition leads to
+ repeated reboots of the device, requiring a hard reset for recovery.
+
+ |
+
|
+ PAN-295803
+
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues,
+ PAN-OS 11.2.7-h10 Addressed Issues
+ and
+ PAN-OS 11.2.10-h3 Addressed Issues
+
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-294179
+
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues
+ and
+ PAN-OS 11.2.7-h3 Addressed Issues.
+
+ |
+ + On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. + | +
|
+ PAN-292202
+
+ This issue is now resolved. See PAN-OS 11.2.7-h3 Addressed Issues.
+
+ |
+
+
+ The system logs repeatedly displayed the alert `Clearing snmpd.log due
+ to log overflow` due to the SNMP counters rolling over. This is a
+ benign message and does not impact device functionality.
+
+ |
+
|
+ PAN-291716
+ |
+
+
+ (PA-460 firewalls only) The firewall experiences an out-of-memory
+ (OOM) condition and displays an error message. This issue causes the
+ device to crash and reboot unexpectedly.
+
+ |
+
|
+ PAN-291661
+
+ This issue is now resolved. See PAN-OS 11.2.10 Addressed Issues
+
+ |
+ + Upon upgrade, the ElasticSearch health status intermittently transitions + to the Red status for sometime, and then auto-recovers back to Green. + During the Red status periods, the cluster logs are unavailable. This + occurs due to disk write operations being excessively slow, failing to + meet the minimum time threshold required to save the cluster state. + | +
|
+
+ PAN-291288This issue is now resolved. See
+ PAN-OS 11.2.8 Addressed Issuesand
+ PAN-OS 11.2.7-h3 Addressed Issues
+
+ |
+ + An active firewall might unexpectedly reboot due to a + pan_task crash caused by a page + allocation failure. This issue is observed after a period of runtime + with traffic and telemetry collection. + | +
|
+
+ PAN-290449This issue is now resolved. See PAN-OS 11.2.8 Addressed Issuesand
+ PAN-OS 11.2.7-h3 Addressed Issues
+
+ |
+ + The scheduled vulnerability reports that are configured to be sent via + email with multiple attachments send the first attached report only. The + remaining attachments are dropped. + | +
|
+ PAN-290088
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-289383
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ (PA-800 series firewalls only) Upgrading
+ firewalls to PAN-OS 11.0 or later causes SFP ports to go
+ non-operational when the firewall uses forced port mode and the
+ connected peer device operates without auto-negotiation.
+
+
+ Workaround: Enable auto-negotiation on the
+ connected peer firewall.
+
+ |
+
|
+ PAN-287803
+ |
+
+
+ After upgrading to PAN-OS 11.1.6-h4, users might be unable to access
+ some URLs due to issues involving the accumulation proxy and the Path
+ Maximum Transmission Unit (MTU).
+
+
+ To address this issue, use one of the following workarounds:
+
+
|
+
|
+ PAN-286848
+
+ This issue is now resolved. See PAN-OS 11.2.7 Addressed Issues
+
+ |
+
+
+ ECMP incorrectly balances sessions across links based on the
+ configured metric, which leads to an imbalance in traffic distribution
+ and results in traffic assignment shifting disproportionately to
+ routes with lower metrics.
+
+ |
+
|
+ PAN-286231
+
+ This issue is now resolved. See PAN-OS 11.2.7-h3 Addressed Issues.
+
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-285894
+
+ This issue is now resolved. See PAN-OS 11.2.7 Addressed Issues
+
+ |
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may
+ occur, which could result in firewall reboots.
+
+
+ Workaround: Disable the Preserve Pre-NAT feature
+ using the
+ set deviceconfig setting preserve-prenat-feature no
+ CLI command.
+
+ |
+
|
+ PAN-285587
+ |
+
+
+ Bootstrapping the VM-Series firewall on OpenStack with user-data does
+ not function correctly. When you run the command show
+ system bootstrap status shows, the
+ output shows the message
+ No Install media detected.
+
+ |
+
|
+ PAN-284067
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ A cumulative memory leak in the
+ devsrvr
+ process gets progressively worse whenever the CLI command
+ show running application statistics
+ is issued. This memory leak will gradually consume system memory and
+ produce an out-of-memory (OOM) condition, leading to an eventual
+ firewall reboot.
+
+ |
+
|
+ PAN-283467
+
+ This issue is now resolved. See PAN-OS 11.2.6 Addressed Issues
+
+ |
+
+
+ (PA-3400 Series firewalls only) The firewall
+ might unexpectedly reboot and enter maintenance mode due to a
+ ctd-agent
+ out-of-memory (OOM) condition when undergoing advanced services load
+ testing with a high volume of IoT EAL log forwarding.
+
+
+ Workaround: Limit the number of EAL logs generated
+ by the firewall using the following CLI command:
+ debug iot eal key-value EAL_PENDING_BYTES=1000.
+
+ |
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-282277
+ |
+
+
+ (PA-3260 firewalls only) An interface
+ unexpectedly moves out of Link Aggregation Control Protocol (LACP),
+ which causes an out-of-memory (OOM) condition on the *logrcvr*
+ process, resulting in the interface going down and then automatically
+ coming back up without intervention.
+
+ |
+
|
+ PAN-281885
+ |
+
+
+ When exporting and importing the CSV file, the hash values of
+ pre-shared key (PSK) variables set at template and template stack
+ levels inconsistently change, resulting in both variables displaying
+ the same hash value.
+
+ |
+
|
+ PAN-280471
+ |
+
+
+ When applying filters or searching for logs in the
+ section, you might experience slow performance.
+
+ |
+
|
+ PAN-279901
+
+ This issue is now resolved. See
+ PAN-OS 11.2.7-h1 Addressed Issues
+
+ |
+
+
+ When decryption is enabled, segmented Client Hello packets can cause
+ website access issues and memory leaks under the following conditions:
+
+
|
+
|
+ PAN-279746
+ |
+
+
+ An SSL/TLS Client Hello may not be transmitted out of the firewall if
+ the Client Hello arrives in multiple TCP segments and the traffic is
+ not subject to SSL decryption (for example, SMTP over SSL).
+
+ |
+
|
+ PAN-279621
+
+ This issue is now resolved. See PAN-OS 11.2.6 Addressed Issues
+
+ |
+
+
+ Early aging and removal of firewall session while they are still
+ active can lead to intermittent instabilities and crashes for proxy
+ traffic, the Content and Threat detection engine, and any data-path
+ processing.
+
+ |
+
|
+ PAN-279415
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ Service routes configured for a data plane interface might incorrectly
+ route traffic through the management plane interface instead. This
+ issue impacts Syslog and CRL status traffic when the service route
+ lacks a specific destination custom service route.
+
+ |
+
|
+ PAN-276920
+ |
+
+
+ URL filtering response pages may load slowly or fail to display when
+ users request websites that are blocked in the URL Filtering profile
+ (site access for the corresponding URL category is
+ block,
+ continue, or
+ override) attached to the matching
+ Security policy rule. This occurs on an intermittent basis.
+
+ |
+
|
+ PAN-277034
+
+ This issue is now resolved. See PAN-OS 11.2.7-h3 Addressed Issues
+
+ |
+ + WildFire reports might not fully display or be downloadable because some + static resources fail to load. + | +
|
+ PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ When Panorama is not internet-connected and you try to upload images
+ to the managed firewalls by using the
+ Validate option, the upload fails
+ with the following error:
+ Failed to create multi-upload job. No valid software deploy targets
+ found.
+
+ |
+
|
+ PAN-275047
+
+ This issue is now resolved. See PAN-OS 11.2.7 Addressed Issues
+
+ |
+
+
+ (VM-Series firewalls only) After an upgrade,
+ the firewall is unable to send logs to the Strata Logging Service
+ (SLS) when using a specific proxy server, and the SSL connection
+ status displays as failed when attempting to forward logs through the
+ web proxy.
+
+ |
+
|
+ PAN-274314
+
+ This issue is now resolved. See PAN-OS 11.2.6 Addressed Issues
+
+ |
+
+
+ (PA-1400 Series firewalls, PA-3400 Series firewalls, and PA-5400
+ Series firewalls only) When the
+ pan_task
+ process restarts, control plane packets are dropped, which can impact
+ LACP and pings to host interfaces.
+
+ |
+
| + PAN-271913 + | +
+
+ Firewalls in HA configurations were experiencing consistent memory
+ leaks on the active firewall, leading unexpected failovers while using
+ Cloud Identity Engine (CIE).
+
+ |
+
|
+ PAN-261429
+
+ This issue is now resolved. See PAN-OS 11.2.6 Addressed Issues
+
+ |
+
+
+ The command
+ show auth radius-require-msg-authentic
+ might return no output.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-260212
+ |
+
+
+ When viewing Applications (), child App-IDs may be listed under the incorrect container App-ID.
+
+ |
+
|
+ PAN-260015
+
+ This issue is now resolved. See PAN-OS 11.2.6 Addressed Issues
+
+ |
+
+
+ When Inline Cloud Analysis features are enabled, an issue related to
+ loopback data handling might cause the firewall to unexpectedly
+ reboot.
+
+
+ Workaround: Disable any Inline Cloud Analysis
+ features on the firewall (e.g. Advanced Threat Prevention Inline Cloud
+ Analysis, WildFire Inline Cloud Analysis, App-ID Cloud Engine, etc) on
+ the firewall.
+
+ |
+
|
+ PAN-259853
+
+ This issue is now resolved. See PAN-OS 11.2.7-h10 Addressed Issues
+
+ |
+
+
+ When the DHCP server is enabled for GlobalProtect, the commit error
+ message is not properly displayed when
+ Any is selected as the source
+ interface in the service router configuration (
+ ).
+
+ |
+
|
+ PAN-259423
+ |
+
+
+ When the GlobalProtect DHCP feature is enabled with two primary DHCP
+ servers on the GlobalProtect gateway, the gpsvc gets stuck during
+ renewal and after HA failover.
+
+ |
+
|
+ PAN-254236
+ |
+
+
+ TLSv1.3 hybridized Kyber support in the latest versions of Chrome and
+ Edge browsers results in dropped Client Hello packets when SSL/TLS
+ handshake inspection is enabled.
+
+
+ Workaround: Disable
+ SSL/TLS handshake inspection.
+
+ |
+
|
+ PAN-254108
+ |
+
+
+ when upgrading or downgrading a Panorama management server (), managed device (), or standalone firewall (), Base Releases and
+ Preferred Releases settings are
+ checked (enabled) by default and cause no PAN-OS software images to
+ display.
+
+
+ Workaround: Uncheck (disable)
+ Base Releases or
+ Preferred Releases to display either
+ the available base PAN-OS or preferred PAN-OS releases available to
+ download and install.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
|
+ PAN-252661
+ |
+
+
+ If you change the service route of gp-ip-mgmt in
+ Device > Setup > Services > Service Features >
+ gp-ip-mgmt
+ and Commit, the change won’t take effect.
+ gp-ip-mgmt continues to use the last committed service route.
+
+
+ Workaround: After you change the service route
+ interface for gp-ip-mgmt, navigate to either a GlobalProtect portal or
+ gateway, click OK to save the configuration, and
+ Commit the changes. This commit will include the
+ service route change.
+
+ |
+
|
+ PAN-250246
+ |
+
+
+ Panorama and the firewall display inconsistent IP addresses for
+ dynamic address group members after manually syncing.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-248836
+ |
+
+
+ The Advanced DNS Security trial license and trial license information
+ cannot be activated and viewed, respectively, on a managed firewall
+ (with expired or active status) from Panorama. These tasks can only be
+ performed on the firewall.
+
+ |
+
|
+ PAN-247728
+ |
+
+
+ When Advanced Routing is enabled, IP multicast is not supported. An
+ upcoming version will provide support for this feature. Customers who
+ have multicast configured or who plan to deploy multicast routing
+ should not upgrade to 11.2.0. Additionally, when Advanced Routing is
+ enabled, the BGP dampening configuration isn't applied to any peers or
+ peer group; the configuration is preserved but has no effect on BGP.
+ Customers can use BGP even if they have applied a Dampening profile to
+ a specific set of peers. The issue doesn't affect any other BGP
+ features.
+
+ |
+
|
+ PAN-241994
+ |
+
+
+ The VMX hardware version was upgraded from vmx-10 to vmx-15 on ESXi
+ and NSX-T. Support for vmx-15 is supported on ESXi 6.7 U2 and onwards.
+ Palo Alto Networks recommends that you upgrade your ESXi version if it
+ is less than 6.7 U2. For more information, see the
+ compatibility matrix.
+
+ |
+
|
+ PAN-239612
+ |
+
+
+ When the firewall is running PAN-OS 11.2.0 and Advanced Routing is
+ enabled, DHCPv4 relay agent functions successfully, but DHCPv6 relay
+ agent doesn't work.
+
+ |
+
|
+ PAN-237106
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-236649
+ |
+
+
+ If you change the configuration of a firewall acting as a PPPoEv4 or
+ PPPoEv6 client, old routes from the Forwarding Information Base (FIB)
+ and route table for an inherited configuration with dynamic-identifier
+ or client remain visible. Old routes also remain visible for an
+ inherited interface when you execute the CLI command,
+ show interface all.
+
+
+ Workaround: Unconfigure and configure the
+ Inherited Interface.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-308507
+ |
+
+
+ Strata Logging Service (SLS) log-forwarding streams intermittently
+ show as inactive. When checking the status of log-forwarding
+ connections, one or more streams are reported as inactive. Restarting
+ the log-receiver process temporarily
+ resolves the issue, but the streams become inactive again after
+ approximately 1-2 hours. This intermittent inactivity results in log
+ loss.
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-303959
+
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues,
+ PAN-OS 11.2.7-h10 Addressed Issues
+ and
+ PAN-OS 11.2.10-h3 Addressed Issues
+
+ |
+
+
+ Traffic that is incorrectly identified as unknown-tcp/unknown-udp
+ eventually drops due to an App-ID resource limitation issue.
+
+ |
+
|
+ PAN-301801
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ On Log Collectors, the Elasticsearch process might fluctuate between
+ green and red states, causing log collection interruptions. This issue
+ occurs when the number of shards exceeds the supported threshold of
+ 1,000 shards per Elasticsearch instance.
+
+ |
+
|
+ PAN-298505
+
+ This issue is now resolved. See PAN-OS 11.2.7-h4 Addressed Issuesand
+ PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual
+ system IDs (vsys ID) changes causing auto-commit failures with
+ validation errors. This occurs when the multi-vsys firewall has
+ virtual systems managed by Panorama, and the vsys ID sequence breaks
+ when unused virtual systems are deleted and the changes are pushed to
+ the firewall.
+
+ |
+
|
+ PAN-297295
+
+ This issue is now resolved. See PAN-OS 11.2.7-h4 Addressed Issuesand
+ PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+ (VM-Series firewalls on Microsoft Azure environments only)
+
+ After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent process restarts multiple
+ times and exhausts its restart limit, resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-296752
+
+ This issue is now resolved. See PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+
+ The PA-1410 firewalls experience a spike in the management plane CPU
+ utilization when the monitor-dp process attempts to retrieve the power
+ cycle count from the NVMe drive’s SMART data. This condition leads to
+ repeated reboots of the device, requiring a hard reset for recovery.
+
+ |
+
|
+ PAN-295803
+
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues,
+ PAN-OS 11.2.7-h10 Addressed Issues
+ and
+ PAN-OS 11.2.10-h3 Addressed Issues
+
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-292344
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ Upgrading to an affected release causes the firewall to reboot
+ multiple times if the config contains an EDL (External Dynamic List)
+ that doesn't have an associated certificate profile.
+
+ |
+
|
+ PAN-294179
+
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues
+ and
+ PAN-OS 11.2.7-h3 Addressed Issues.
+
+ |
+ + On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. + | +
|
+ PAN-293673
+
+ This issue is now resolved. See PAN-OS 11.2.7-h1 Addressed Issues
+
+ |
+ + When the firewall generates a high volume of logs and attempts to export + these logs to an FTP server, it may consume excessive memory leading to + all PAN-OS processes crashing. + | +
|
+ PAN-292202
+
+ This issue is now resolved. See PAN-OS 11.2.7-h3 Addressed Issues.
+
+ |
+
+
+ The system logs repeatedly displayed the alert `Clearing snmpd.log due
+ to log overflow` due to the SNMP counters rolling over. This is a
+ benign message and does not impact device functionality.
+
+ |
+
|
+ PAN-291716
+ |
+
+
+ (PA-460 firewalls only) The firewall experiences an out-of-memory
+ (OOM) condition and displays an error message. This issue causes the
+ device to crash and reboot unexpectedly.
+
+ |
+
|
+ PAN-291661
+
+ This issue is now resolved. See PAN-OS 11.2.10 Addressed Issues
+
+ |
+ + Upon upgrade, the ElasticSearch health status intermittently transitions + to the Red status for sometime, and then auto-recovers back to Green. + During the Red status periods, the cluster logs are unavailable. This + occurs due to disk write operations being excessively slow, failing to + meet the minimum time threshold required to save the cluster state. + | +
|
+
+ PAN-291288This issue is now resolved. See PAN-OS 11.2.8 Addressed Issuesand
+ PAN-OS 11.2.7-h3 Addressed Issues
+
+ |
+ + An active firewall might unexpectedly reboot due to a + pan_task crash caused by a page + allocation failure. This issue is observed after a period of runtime + with traffic and telemetry collection. + | +
|
+
+ PAN-290449This issue is now resolved. See PAN-OS 11.2.8 Addressed Issuesand
+ PAN-OS 11.2.7-h3 Addressed Issues
+
+ |
+ + The scheduled vulnerability reports that are configured to be sent via + email with multiple attachments send the first attached report only. The + remaining attachments are dropped. + | +
|
+ PAN-290088
+
+ This issue is now resolved. See PAN-OS 11.2.7-h1 Addressed Issues
+
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-289383
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ (PA-800 series firewalls only) Upgrading
+ firewalls to PAN-OS 11.0 or later causes SFP ports to go
+ non-operational when the firewall uses forced port mode and the
+ connected peer device operates without auto-negotiation.
+
+
+ Workaround: Enable auto-negotiation on the
+ connected peer firewall.
+
+ |
+
|
+ PAN-288525
+ |
+
+
+ When the Enterprise DLP data filtering profile is configured with a
+ Block action and is used in
+ conjunction with Advanced Threat Prevention, which is configured with
+ an action of reset-both,
+ reset-server,
+ reset-client, or
+ drop for the
+ HTTP Command and Control detector,
+ Dropbox file uploads that exceed the maximum configured file size
+ action will fail.
+
+
+ Workaround: Configure the Advanced Threat
+ Prevention Inline Cloud analysis () action for the HTTP Command and Control detector to
+ alert.
+
+ |
+
|
+ PAN-287803
+ |
+
+
+ After upgrading to PAN-OS 11.1.6-h4, users might be unable to access
+ some URLs due to issues involving the accumulation proxy and the Path
+ Maximum Transmission Unit (MTU).
+
+
+ To address this issue, use one of the following workarounds:
+
+
|
+
|
+ PAN-286848
+
+ This issue is now resolved. See PAN-OS 11.2.7 Addressed Issues
+
+ |
+
+
+ ECMP incorrectly balances sessions across links based on the
+ configured metric, which leads to an imbalance in traffic distribution
+ and results in traffic assignment shifting disproportionately to
+ routes with lower metrics.
+
+ |
+
|
+ PAN-286306
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ When getting transceiver information from ESCC for SFP 25G modules,
+ the transceiver code incorrectly displays
+ Unknown instead of
+ 25GBase-SR.
+
+ |
+
|
+ PAN-286231
+
+ This issue is now resolved. See PAN-OS 11.2.7-h3 Addressed Issues.
+
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-285894
+
+ This issue is now resolved. See PAN-OS 11.2.7 Addressed Issues
+
+ |
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may
+ occur, which could result in firewall reboots.
+
+
+ Workaround: Disable the Preserve Pre-NAT feature
+ using the
+ set deviceconfig setting preserve-prenat-feature no
+ CLI command.
+
+ |
+
|
+ PAN-285061
+ |
+
+
+ When Enterprise DLP is enabled, file uploads might unexpectedly fail
+ when 100 continue response is received from the server during file
+ uploads.
+
+ |
+
|
+ PAN-284700
+ |
+
+
+ File downloads for content encoded with zstd (Zstandard), such as
+ specific content from box.com, fail when using Enterprise DLP because
+ zstd decompression is not supported in PAN-OS.
+
+ |
+
|
+ PAN-284067
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ A cumulative memory leak in the
+ devsrvr
+ process gets progressively worse whenever the CLI command
+ show running application statistics
+ is issued. This memory leak will gradually consume system memory and
+ produce an out-of-memory (OOM) condition, leading to an eventual
+ firewall reboot.
+
+ |
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-282277
+ |
+
+
+ (PA-3260 firewalls only) An interface
+ unexpectedly moves out of Link Aggregation Control Protocol (LACP),
+ which causes an out-of-memory (OOM) condition on the *logrcvr*
+ process, resulting in the interface going down and then automatically
+ coming back up without intervention.
+
+ |
+
|
+ PAN-279901
+
+ This issue is now resolved. See
+ PAN-OS 11.2.7-h1 Addressed Issues
+
+ |
+
+
+ When decryption is enabled, segmented Client Hello packets can cause
+ website access issues and memory leaks under the following conditions:
+
+
|
+
|
+ PAN-279415
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ Service routes configured for a data plane interface might incorrectly
+ route traffic through the management plane interface instead. This
+ issue impacts Syslog and CRL status traffic when the service route
+ lacks a specific destination custom service route.
+
+ |
+
|
+ PAN-276920
+ |
+
+
+ URL filtering response pages may load slowly or fail to display when
+ users request websites that are blocked in the URL Filtering profile
+ (site access for the corresponding URL category is
+ block,
+ continue, or
+ override) attached to the matching
+ Security policy rule. This occurs on an intermittent basis.
+
+ |
+
|
+ PAN-277034
+
+ This issue is now resolved. See PAN-OS 11.2.7-h3 Addressed Issues
+
+ |
+ + WildFire reports might not fully display or be downloadable because some + static resources fail to load. + | +
|
+ PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ When Panorama is not internet-connected and you try to upload images
+ to the managed firewalls by using the
+ Validate option, the upload fails
+ with the following error:
+ Failed to create multi-upload job. No valid software deploy targets
+ found.
+
+ |
+
|
+ PAN-275047
+
+ This issue is now resolved. See PAN-OS 11.2.7 Addressed Issues
+
+ |
+
+
+ (VM-Series firewalls only) After an upgrade,
+ the firewall is unable to send logs to the Strata Logging Service
+ (SLS) when using a specific proxy server, and the SSL connection
+ status displays as failed when attempting to forward logs through the
+ web proxy.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-260212
+ |
+
+
+ When viewing Applications (), child App-IDs may be listed under the incorrect container App-ID.
+
+ |
+
|
+ PAN-259853
+
+ This issue is now resolved. See PAN-OS 11.2.7-h10 Addressed Issues
+
+ |
+
+
+ When the DHCP server is enabled for GlobalProtect, the commit error
+ message is not properly displayed when
+ Any is selected as the source
+ interface in the service router configuration (
+ ).
+
+ |
+
|
+ PAN-259423
+ |
+
+
+ When the GlobalProtect DHCP feature is enabled with two primary DHCP
+ servers on the GlobalProtect gateway, the gpsvc gets stuck during
+ renewal and after HA failover.
+
+ |
+
|
+ PAN-254236
+ |
+
+
+ TLSv1.3 hybridized Kyber support in the latest versions of Chrome and
+ Edge browsers results in dropped Client Hello packets when SSL/TLS
+ handshake inspection is enabled.
+
+
+ Workaround: Disable
+ SSL/TLS handshake inspection.
+
+ |
+
|
+ PAN-254108
+ |
+
+
+ when upgrading or downgrading a Panorama management server (), managed device (), or standalone firewall (), Base Releases and
+ Preferred Releases settings are
+ checked (enabled) by default and cause no PAN-OS software images to
+ display.
+
+
+ Workaround: Uncheck (disable)
+ Base Releases or
+ Preferred Releases to display either
+ the available base PAN-OS or preferred PAN-OS releases available to
+ download and install.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
|
+ PAN-252661
+ |
+
+
+ If you change the service route of gp-ip-mgmt in
+ Device > Setup > Services > Service Features >
+ gp-ip-mgmt
+ and Commit, the change won’t take effect.
+ gp-ip-mgmt continues to use the last committed service route.
+
+
+ Workaround: After you change the service route
+ interface for gp-ip-mgmt, navigate to either a GlobalProtect portal or
+ gateway, click OK to save the configuration, and
+ Commit the changes. This commit will include the
+ service route change.
+
+ |
+
|
+ PAN-250246
+ |
+
+
+ Panorama and the firewall display inconsistent IP addresses for
+ dynamic address group members after manually syncing.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-248836
+ |
+
+
+ The Advanced DNS Security trial license and trial license information
+ cannot be activated and viewed, respectively, on a managed firewall
+ (with expired or active status) from Panorama. These tasks can only be
+ performed on the firewall.
+
+ |
+
|
+ PAN-247728
+ |
+
+
+ When Advanced Routing is enabled, IP multicast is not supported. An
+ upcoming version will provide support for this feature. Customers who
+ have multicast configured or who plan to deploy multicast routing
+ should not upgrade to 11.2.0. Additionally, when Advanced Routing is
+ enabled, the BGP dampening configuration isn't applied to any peers or
+ peer group; the configuration is preserved but has no effect on BGP.
+ Customers can use BGP even if they have applied a Dampening profile to
+ a specific set of peers. The issue doesn't affect any other BGP
+ features.
+
+ |
+
|
+ PAN-241994
+ |
+
+
+ The VMX hardware version was upgraded from vmx-10 to vmx-15 on ESXi
+ and NSX-T. Support for vmx-15 is supported on ESXi 6.7 U2 and onwards.
+ Palo Alto Networks recommends that you upgrade your ESXi version if it
+ is less than 6.7 U2. For more information, see the
+ compatibility matrix.
+
+ |
+
|
+ PAN-239612
+ |
+
+
+ When the firewall is running PAN-OS 11.2.0 and Advanced Routing is
+ enabled, DHCPv4 relay agent functions successfully, but DHCPv6 relay
+ agent doesn't work.
+
+ |
+
|
+ PAN-237106
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-236649
+ |
+
+
+ If you change the configuration of a firewall acting as a PPPoEv4 or
+ PPPoEv6 client, old routes from the Forwarding Information Base (FIB)
+ and route table for an inherited configuration with dynamic-identifier
+ or client remain visible. Old routes also remain visible for an
+ inherited interface when you execute the CLI command,
+ show interface all.
+
+
+ Workaround: Unconfigure and configure the
+ Inherited Interface.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-308564
+ |
+
+
+ Packets are dropped on SD-WAN interfaces if they require fragmentation
+ for an interface but have the
+ Don't Fragment (DF) bit set. This
+ results in unexpected packet drops. This affects client to server
+ sessions when using SD-WAN for NGFW.
+
+
+ Workaround: Allow fragmenting packets with DF bit
+ set (debug dataplane set ip4-ignore-df yes).
+
+ |
+
|
+ PAN-308507
+ |
+
+
+ Strata Logging Service (SLS) log-forwarding streams intermittently
+ show as inactive. When checking the status of log-forwarding
+ connections, one or more streams are reported as inactive. Restarting
+ the log-receiver process temporarily
+ resolves the issue, but the streams become inactive again after
+ approximately 1-2 hours. This intermittent inactivity results in log
+ loss.
+
+ |
+
|
+ PAN-308418
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ When Advanced DNS Security is enabled and experiences unusually high
+ loads, DNS traffic sessions may be impacted, resulting in DNS
+ resolution failures. Traffic logs for these sessions show an
+ end-reason of resources-unavailable.
+
+
+ Workaround: Disable Advanced DNS Security
+ telemetry (
+ and uncheck Telemetry Enable).
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-304576
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ Traffic interruption may occur when inspection of HTTP/2 traffic is
+ enabled.
+
+
+ Workaround: Disable HTTP/2 server push using the
+ set deviceconfig setting http2 server-push no
+ CLI command.
+
+ |
+
|
+ PAN-303959
+
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues,
+ PAN-OS 11.2.7-h10 Addressed Issues
+ and
+ PAN-OS 11.2.10-h3 Addressed Issues
+
+ |
+
+
+ Traffic that is incorrectly identified as unknown-tcp/unknown-udp
+ eventually drops due to an App-ID resource limitation issue.
+
+ |
+
|
+ PAN-301801
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues
+ and
+ PAN-OS 11.2.7-h8 Addressed Issues
+ |
+
+
+ On Log Collectors, the Elasticsearch process might fluctuate between
+ green and red states, causing log collection interruptions. This issue
+ occurs when the number of shards exceeds the supported threshold of
+ 1,000 shards per Elasticsearch instance.
+
+ |
+
|
+ PAN-298505
+
+ This issue is now resolved. See PAN-OS 11.2.7-h4 Addressed Issuesand
+ PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual
+ system IDs (vsys ID) changes causing auto-commit failures with
+ validation errors. This occurs when the multi-vsys firewall has
+ virtual systems managed by Panorama, and the vsys ID sequence breaks
+ when unused virtual systems are deleted and the changes are pushed to
+ the firewall.
+
+ |
+
|
+ PAN-297775
+ |
+
+
+ The wrong vsys is referenced under Visible Virtual System after every
+ local firewall commit (auto-commit, commit, content install) if the
+ display name of the vsys matches another vsys ID (for example, the
+ vsys2 display name is vsys1). The incorrect vsys reference causes
+ inter-vsys routing to fail.
+
+
+ Workaround: Change the vsys display name so that
+ it doesn't reference an existing vsys ID.
+
+ |
+
|
+ PAN-297610
+
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues
+ and
+ PAN-OS 11.2.7-h8 Addressed Issues.
+
+ |
+
+
+ A firewall may become unresponsive after an upgrade due to the
+ fsck
+ command scanning drive partitions in parallel with the root partition,
+ causing the process to take an extended amount of time.
+
+ |
+
|
+ PAN-297295
+
+ This issue is now resolved. See PAN-OS 11.2.7-h4 Addressed Issuesand
+ PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+ (VM-Series firewalls on Microsoft Azure environments only)
+
+ After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent process restarts multiple
+ times and exhausts its restart limit, resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-296752
+
+ This issue is now resolved. See PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+
+ The PA-1410 firewalls experience a spike in the management plane CPU
+ utilization when the monitor-dp process attempts to retrieve the power
+ cycle count from the NVMe drive’s SMART data. This condition leads to
+ repeated reboots of the device, requiring a hard reset for recovery.
+
+ |
+
|
+ PAN-295803
+
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues,
+ PAN-OS 11.2.7-h10 Addressed Issues
+ and
+ PAN-OS 11.2.10-h3 Addressed Issues
+
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-294179
+
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues
+ and
+ PAN-OS 11.2.7-h3 Addressed Issues.
+
+ |
+ + On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. + | +
|
+ PAN-293673
+
+ This issue is now resolved. See PAN-OS 11.2.7-h1 Addressed Issues.
+
+ |
+
+
+ When the firewall generates a high volume of logs and attempts to
+ export these logs to an FTP server, it may consume excessive memory
+ leading to all PAN-OS processes crashing.
+
+ |
+
|
+ PAN-292344
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ Upgrading to an affected release causes the firewall to reboot
+ multiple times if the config contains an EDL (External Dynamic List)
+ that doesn't have an associated certificate profile.
+
+ |
+
|
+ PAN-292202
+
+ This issue is now resolved. See PAN-OS 11.2.7-h3 Addressed Issues.
+
+ |
+
+
+ The system logs repeatedly displayed the alert `Clearing snmpd.log due
+ to log overflow` due to the SNMP counters rolling over. This is a
+ benign message and does not impact device functionality.
+
+ |
+
|
+ PAN-291716
+ |
+
+
+ (PA-460 firewalls only) The firewall experiences an out-of-memory
+ (OOM) condition and displays an error message. This issue causes the
+ device to crash and reboot unexpectedly.
+
+ |
+
|
+ PAN-291661
+
+ This issue is now resolved. See PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+
+ Upon upgrade, the ElasticSearch health status intermittently
+ transitions to the Red status for sometime, and then auto-recovers
+ back to Green. During the Red status periods, the cluster logs are
+ unavailable. This occurs due to disk write operations being
+ excessively slow, failing to meet the minimum time threshold required
+ to save the cluster state.
+
+ |
+
|
+
+ PAN-291288This issue is now resolved. See
+ PAN-OS 11.2.8 Addressed Issuesand
+ PAN-OS 11.2.7-h3 Addressed Issues
+
+ |
+ + An active firewall might unexpectedly reboot due to a + pan_task crash caused by a page + allocation failure. This issue is observed after a period of runtime + with traffic and telemetry collection. + | +
|
+
+ PAN-290449This issue is now resolved. See PAN-OS 11.2.8 Addressed Issuesand
+ PAN-OS 11.2.7-h3 Addressed Issues
+
+ |
+ + The scheduled vulnerability reports that are configured to be sent via + email with multiple attachments send the first attached report only. The + remaining attachments are dropped. + | +
|
+ PAN-290088
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-289383
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ (PA-800 series firewalls only) Upgrading
+ firewalls to PAN-OS 11.0 or later causes SFP ports to go
+ non-operational when the firewall uses forced port mode and the
+ connected peer device operates without auto-negotiation.
+
+
+ Workaround: Enable auto-negotiation on the
+ connected peer firewall.
+
+ |
+
|
+ PAN-288525
+ |
+
+
+ When the Enterprise DLP data filtering profile is configured with a
+ Block action and is used in
+ conjunction with Advanced Threat Prevention, which is configured with
+ an action of reset-both,
+ reset-server,
+ reset-client, or
+ drop for the
+ HTTP Command and Control detector,
+ Dropbox file uploads that exceed the maximum configured file size
+ action will fail.
+
+
+ Workaround: Configure the Advanced Threat
+ Prevention Inline Cloud analysis () action for the HTTP Command and Control detector to
+ alert.
+
+ |
+
|
+ PAN-287803
+ |
+
+
+ After upgrading to PAN-OS 11.1.6-h4, users might be unable to access
+ some URLs due to issues involving the accumulation proxy and the Path
+ Maximum Transmission Unit (MTU).
+
+
+ To address this issue, use one of the following workarounds:
+
+
|
+
|
+ PAN-286306
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ When getting transceiver information from ESCC for SFP 25G modules,
+ the transceiver code incorrectly displays
+ Unknown instead of
+ 25GBase-SR.
+
+ |
+
|
+ PAN-286231
+
+ This issue is now resolved. See PAN-OS 11.2.7-h3 Addressed Issues.
+
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-285061
+ |
+
+
+ When Enterprise DLP is enabled, file uploads might unexpectedly fail
+ when 100 continue response is received from the server during file
+ uploads.
+
+ |
+
|
+ PAN-284700
+ |
+
+
+ File downloads for content encoded with zstd (Zstandard), such as
+ specific content from box.com, fail when using Enterprise DLP because
+ zstd decompression is not supported in PAN-OS.
+
+ |
+
|
+ PAN-284067
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ A cumulative memory leak in the
+ devsrvr
+ process gets progressively worse whenever the CLI command
+ show running application statistics
+ is issued. This memory leak will gradually consume system memory and
+ produce an out-of-memory (OOM) condition, leading to an eventual
+ firewall reboot.
+
+ |
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-282277
+ |
+
+
+ (PA-3260 firewalls only) An interface
+ unexpectedly moves out of Link Aggregation Control Protocol (LACP),
+ which causes an out-of-memory (OOM) condition on the *logrcvr*
+ process, resulting in the interface going down and then automatically
+ coming back up without intervention.
+
+ |
+
|
+ PAN-279901
+
+ This issue is now resolved. See
+ PAN-OS 11.2.7-h1 Addressed Issues
+
+ |
+
+
+ When decryption is enabled, segmented Client Hello packets can cause
+ website access issues and memory leaks under the following conditions:
+
+
|
+
|
+ PAN-279415
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ Service routes configured for a data plane interface might incorrectly
+ route traffic through the management plane interface instead. This
+ issue impacts Syslog and CRL status traffic when the service route
+ lacks a specific destination custom service route.
+
+ |
+
|
+ PAN-278688
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ (PA-7500, PA-5500, and PA-3500 firewalls only)
+ When DNS Security packet capture is enabled and a domain name has a
+ length of 62 characters, the DNS Security threat log entry is not
+ generated. On the affected platforms, this condition can also trigger
+ a pan_task crash due to shared memory
+ corruption.
+
+
+ Workaround: Disable DNS Security packet capture in
+ anti-spyware profiles () and in the DNS Policies tab, set
+ Packet Capture to
+ disable.
+
+ |
+
|
+ PAN-277034
+
+ This issue is now resolved. See PAN-OS 11.2.7-h3 Addressed Issues
+
+ |
+ + WildFire reports might not fully display or be downloadable because some + static resources fail to load. + | +
|
+ PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.2.8 Addressed Issues
+
+ |
+
+
+ When Panorama is not internet-connected and you try to upload images
+ to the managed firewalls by using the
+ Validate option, the upload fails
+ with the following error:
+ Failed to create multi-upload job. No valid software deploy targets
+ found.
+
+ |
+
|
+ PAN-273158
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ (PA-7000 Series firewalls only) Due to an
+ incorrect configuration on the ASIC, receiving a mix of jumbo and
+ non-jumbo packets may cause silent packet drops or application
+ slowness.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-260212
+ |
+
+
+ When viewing Applications (), child App-IDs may be listed under the incorrect container App-ID.
+
+ |
+
|
+ PAN-259853
+
+ This issue is now resolved. See PAN-OS 11.2.7-h10 Addressed Issues
+
+ |
+
+
+ When the DHCP server is enabled for GlobalProtect, the commit error
+ message is not properly displayed when
+ Any is selected as the source
+ interface in the service router configuration (
+ ).
+
+ |
+
|
+ PAN-259423
+ |
+
+
+ When the GlobalProtect DHCP feature is enabled with two primary DHCP
+ servers on the GlobalProtect gateway, the gpsvc gets stuck during
+ renewal and after HA failover.
+
+ |
+
|
+ PAN-254236
+ |
+
+
+ TLSv1.3 hybridized Kyber support in the latest versions of Chrome and
+ Edge browsers results in dropped Client Hello packets when SSL/TLS
+ handshake inspection is enabled.
+
+
+ Workaround: Disable
+ SSL/TLS handshake inspection.
+
+ |
+
|
+ PAN-254108
+ |
+
+
+ when upgrading or downgrading a Panorama management server (), managed device (), or standalone firewall (), Base Releases and
+ Preferred Releases settings are
+ checked (enabled) by default and cause no PAN-OS software images to
+ display.
+
+
+ Workaround: Uncheck (disable)
+ Base Releases or
+ Preferred Releases to display either
+ the available base PAN-OS or preferred PAN-OS releases available to
+ download and install.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
|
+ PAN-252661
+ |
+
+
+ If you change the service route of gp-ip-mgmt in
+ Device > Setup > Services > Service Features >
+ gp-ip-mgmt
+ and Commit, the change won’t take effect.
+ gp-ip-mgmt continues to use the last committed service route.
+
+
+ Workaround: After you change the service route
+ interface for gp-ip-mgmt, navigate to either a GlobalProtect portal or
+ gateway, click OK to save the configuration, and
+ Commit the changes. This commit will include the
+ service route change.
+
+ |
+
|
+ PAN-250246
+ |
+
+
+ Panorama and the firewall display inconsistent IP addresses for
+ dynamic address group members after manually syncing.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-248836
+ |
+
+
+ The Advanced DNS Security trial license and trial license information
+ cannot be activated and viewed, respectively, on a managed firewall
+ (with expired or active status) from Panorama. These tasks can only be
+ performed on the firewall.
+
+ |
+
|
+ PAN-247728
+ |
+
+
+ When Advanced Routing is enabled, IP multicast is not supported. An
+ upcoming version will provide support for this feature. Customers who
+ have multicast configured or who plan to deploy multicast routing
+ should not upgrade to 11.2.0. Additionally, when Advanced Routing is
+ enabled, the BGP dampening configuration isn't applied to any peers or
+ peer group; the configuration is preserved but has no effect on BGP.
+ Customers can use BGP even if they have applied a Dampening profile to
+ a specific set of peers. The issue doesn't affect any other BGP
+ features.
+
+ |
+
|
+ PAN-241994
+ |
+
+
+ The VMX hardware version was upgraded from vmx-10 to vmx-15 on ESXi
+ and NSX-T. Support for vmx-15 is supported on ESXi 6.7 U2 and onwards.
+ Palo Alto Networks recommends that you upgrade your ESXi version if it
+ is less than 6.7 U2. For more information, see the
+ compatibility matrix.
+
+ |
+
|
+ PAN-239612
+ |
+
+
+ When the firewall is running PAN-OS 11.2.0 and Advanced Routing is
+ enabled, DHCPv4 relay agent functions successfully, but DHCPv6 relay
+ agent doesn't work.
+
+ |
+
|
+ PAN-237106
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-236649
+ |
+
+
+ If you change the configuration of a firewall acting as a PPPoEv4 or
+ PPPoEv6 client, old routes from the Forwarding Information Base (FIB)
+ and route table for an inherited configuration with dynamic-identifier
+ or client remain visible. Old routes also remain visible for an
+ inherited interface when you execute the CLI command,
+ show interface all.
+
+
+ Workaround: Unconfigure and configure the
+ Inherited Interface.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-6271
+ |
+
+
+ A WildFire cluster node that has been configured with an IPv6
+ management port might not display the signature status when using the
+ following CLI:
+ show wildfire global signature-status sha256 equal
+ <SHA_256_Value>
+
+
+ Workaround: Gracefully restart the affected
+ Wildfire cluster nodes.
+
+ |
+
|
+ WF500-6259
+ |
+
+
+ When a WildFire cluster node configured as a server or worker node is
+ rebooted, issuing the CLI command,
+ global sample-status does not update
+ the samples processed list on the active controller and non-server
+ worker nodes.
+
+
+ Workaround: Gracefully restart the affected
+ WildFire active controller and passive controller in the cluster.
+
+ |
+
|
+ WF500-6270
+ |
+
+
+ The WildFire cluster server and worker nodes might disconnect from the
+ Wildfire cluster management network, resulting in a notifier process
+ exit on WildFire cluster controllers.
+
+
+ Workaround: Gracefully restart the WildFire
+ cluster node where the process exit occurred.
+
+ |
+
|
+ WF500-6222
+ |
+
+
+ When WildFire secure cluster communication is enabled using a custom
+ DNS, the cluster formation might fail due to cluster management
+ communication issues.
+
+
+ Workaround: Do not configure a custom DNS when
+ WildFire secure cluster communication is enabled.
+
+ |
+
|
+ WF500-6176
+ |
+
+
+ When Panorama is used to manage a WildFire cluster, switchover
+ functionality for active and passive controller roles is not
+ available.
+
+ |
+
|
+ PAN-308564
+ |
+
+
+ Packets are dropped on SD-WAN interfaces if they require fragmentation
+ for an interface but have the
+ Don't Fragment (DF) bit set. This
+ results in unexpected packet drops. This affects client to server
+ sessions when using SD-WAN for NGFW.
+
+
+ Workaround: Allow fragmenting packets with DF bit
+ set (debug dataplane set ip4-ignore-df yes).
+
+ |
+
|
+ PAN-308507
+ |
+
+
+ Strata Logging Service (SLS) log-forwarding streams intermittently
+ show as inactive. When checking the status of log-forwarding
+ connections, one or more streams are reported as inactive. Restarting
+ the log-receiver process temporarily
+ resolves the issue, but the streams become inactive again after
+ approximately 1-2 hours. This intermittent inactivity results in log
+ loss.
+
+ |
+
|
+ PAN-308418
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ When Advanced DNS Security is enabled and experiences unusually high
+ loads, DNS traffic sessions may be impacted, resulting in DNS
+ resolution failures. Traffic logs for these sessions show an
+ end-reason of resources-unavailable.
+
+
+ Workaround: Disable Advanced DNS Security
+ telemetry (
+ and uncheck Telemetry Enable).
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-304576
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ Traffic interruption may occur when inspection of HTTP/2 traffic is
+ enabled.
+
+
+ Workaround: Disable HTTP/2 server push using the
+ set deviceconfig setting http2 server-push no
+ CLI command.
+
+ |
+
|
+ PAN-303959
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ Traffic that is incorrectly identified as unknown-tcp/unknown-udp
+ eventually drops due to an App-ID resource limitation issue.
+
+ |
+
|
+ PAN-302927
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ After an upgrade, the
+ Push to Devices window fails to
+ populate the list of devices automatically. If you manually select
+ devices by clicking Edit Selections,
+ the OK button becomes unresponsive
+ and fails to save or close the selection window. Additionally,
+ clicking Cancel might incorrectly
+ show the device list as empty while retaining the selections in the
+ background.
+
+ |
+
|
+ PAN-301801
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ On Log Collectors, the Elasticsearch process might fluctuate between
+ green and red states, causing log collection interruptions. This issue
+ occurs when the number of shards exceeds the supported threshold of
+ 1,000 shards per Elasticsearch instance.
+
+ |
+
|
+ PAN-298505
+
+ This issue is now resolved. See PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual
+ system IDs (vsys ID) changes causing auto-commit failures with
+ validation errors. This occurs when the multi-vsys firewall has
+ virtual systems managed by Panorama, and the vsys ID sequence breaks
+ when unused virtual systems are deleted and the changes are pushed to
+ the firewall.
+
+ |
+
|
+ PAN-297610
+
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues
+ and
+ PAN-OS 11.2.10-h2 Addressed Issues.
+
+ |
+
+
+ A firewall may become unresponsive after an upgrade due to the
+ fsck
+ command scanning drive partitions in parallel with the root partition,
+ causing the process to take an extended amount of time.
+
+ |
+
|
+ PAN-297295
+ |
+
+ (VM-Series firewalls on Microsoft Azure environments only)
+
+ After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent process restarts multiple
+ times and exhausts its restart limit, resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-296752
+
+ This issue is now resolved. See PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+
+ The PA-1410 firewalls experience a spike in the management plane CPU
+ utilization when the monitor-dp process attempts to retrieve the power
+ cycle count from the NVMe drive’s SMART data. This condition leads to
+ repeated reboots of the device, requiring a hard reset for recovery.
+
+ |
+
|
+ PAN-295803
+
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues
+ and
+ PAN-OS 11.2.10-h3 Addressed Issues
+
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-295645
+ |
+
+
+ When a WildFire cluster is configured centrally using Panorama, it
+ initiates a series of processes, including a software install and
+ reboot, in an order that will leave the resulting WildFire cluster in
+ an unusable state.
+
+ |
+
|
+ PAN-294179
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+ + On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. + | +
|
+ PAN-291716
+ |
+
+
+ (PA-460 firewalls only) The firewall experiences an out-of-memory
+ (OOM) condition and displays an error message. This issue causes the
+ device to crash and reboot unexpectedly.
+
+ |
+
|
+ PAN-291661
+
+ This issue is now resolved. See PAN-OS 11.2.10 Addressed Issues
+
+ |
+ + Upon upgrade, the ElasticSearch health status intermittently transitions + to the Red status for sometime, and then auto-recovers back to Green. + During the Red status periods, the cluster logs are unavailable. This + occurs due to disk write operations being excessively slow, failing to + meet the minimum time threshold required to save the cluster state. + | +
|
+ PAN-288525
+ |
+
+
+ When the Enterprise DLP data filtering profile is configured with a
+ Block action and is used in
+ conjunction with Advanced Threat Prevention, which is configured with
+ an action of reset-both,
+ reset-server,
+ reset-client, or
+ drop for the
+ HTTP Command and Control detector,
+ Dropbox file uploads that exceed the maximum configured file size
+ action will fail.
+
+
+ Workaround: Configure the Advanced Threat
+ Prevention Inline Cloud analysis () action for the HTTP Command and Control detector to
+ alert.
+
+ |
+
|
+ PAN-287803
+ |
+
+
+ After upgrading to PAN-OS 11.1.6-h4, users might be unable to access
+ some URLs due to issues involving the accumulation proxy and the Path
+ Maximum Transmission Unit (MTU).
+
+
+ To address this issue, use one of the following workarounds:
+
+
|
+
|
+ PAN-285061
+ |
+
+
+ When Enterprise DLP is enabled, file uploads might unexpectedly fail
+ when 100 continue response is received from the server during file
+ uploads.
+
+ |
+
|
+ PAN-284700
+ |
+
+
+ File downloads for content encoded with zstd (Zstandard), such as
+ specific content from box.com, fail when using Enterprise DLP because
+ zstd decompression is not supported in PAN-OS.
+
+ |
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-278688
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ (PA-7500, PA-5500, and PA-3500 firewalls only)
+ When DNS Security packet capture is enabled and a domain name has a
+ length of 62 characters, the DNS Security threat log entry is not
+ generated. On the affected platforms, this condition can also trigger
+ a pan_task crash due to shared memory
+ corruption.
+
+
+ Workaround: Disable DNS Security packet capture in
+ anti-spyware profiles () and in the DNS Policies tab, set
+ Packet Capture to
+ disable.
+
+ |
+
|
+ PAN-273158
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ (PA-7000 Series firewalls only) Due to an
+ incorrect configuration on the ASIC, receiving a mix of jumbo and
+ non-jumbo packets may cause silent packet drops or application
+ slowness.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-260212
+ |
+
+
+ When viewing Applications (), child App-IDs may be listed under the incorrect container App-ID.
+
+ |
+
|
+ PAN-259853
+ |
+
+
+ When the DHCP server is enabled for GlobalProtect, the commit error
+ message is not properly displayed when
+ Any is selected as the source
+ interface in the service router configuration (
+ ).
+
+ |
+
|
+ PAN-259423
+ |
+
+
+ When the GlobalProtect DHCP feature is enabled with two primary DHCP
+ servers on the GlobalProtect gateway, the gpsvc gets stuck during
+ renewal and after HA failover.
+
+ |
+
|
+ PAN-254236
+ |
+
+
+ TLSv1.3 hybridized Kyber support in the latest versions of Chrome and
+ Edge browsers results in dropped Client Hello packets when SSL/TLS
+ handshake inspection is enabled.
+
+
+ Workaround: Disable
+ SSL/TLS handshake inspection.
+
+ |
+
|
+ PAN-254108
+ |
+
+
+ when upgrading or downgrading a Panorama management server (), managed device (), or standalone firewall (), Base Releases and
+ Preferred Releases settings are
+ checked (enabled) by default and cause no PAN-OS software images to
+ display.
+
+
+ Workaround: Uncheck (disable)
+ Base Releases or
+ Preferred Releases to display either
+ the available base PAN-OS or preferred PAN-OS releases available to
+ download and install.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
|
+ PAN-252661
+ |
+
+
+ If you change the service route of gp-ip-mgmt in
+ Device > Setup > Services > Service Features >
+ gp-ip-mgmt
+ and Commit, the change won’t take effect.
+ gp-ip-mgmt continues to use the last committed service route.
+
+
+ Workaround: After you change the service route
+ interface for gp-ip-mgmt, navigate to either a GlobalProtect portal or
+ gateway, click OK to save the configuration, and
+ Commit the changes. This commit will include the
+ service route change.
+
+ |
+
|
+ PAN-250246
+ |
+
+
+ Panorama and the firewall display inconsistent IP addresses for
+ dynamic address group members after manually syncing.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-248836
+ |
+
+
+ The Advanced DNS Security trial license and trial license information
+ cannot be activated and viewed, respectively, on a managed firewall
+ (with expired or active status) from Panorama. These tasks can only be
+ performed on the firewall.
+
+ |
+
|
+ PAN-247728
+ |
+
+
+ When Advanced Routing is enabled, IP multicast is not supported. An
+ upcoming version will provide support for this feature. Customers who
+ have multicast configured or who plan to deploy multicast routing
+ should not upgrade to 11.2.0. Additionally, when Advanced Routing is
+ enabled, the BGP dampening configuration isn't applied to any peers or
+ peer group; the configuration is preserved but has no effect on BGP.
+ Customers can use BGP even if they have applied a Dampening profile to
+ a specific set of peers. The issue doesn't affect any other BGP
+ features.
+
+ |
+
|
+ PAN-241994
+ |
+
+
+ The VMX hardware version was upgraded from vmx-10 to vmx-15 on ESXi
+ and NSX-T. Support for vmx-15 is supported on ESXi 6.7 U2 and onwards.
+ Palo Alto Networks recommends that you upgrade your ESXi version if it
+ is less than 6.7 U2. For more information, see the
+ compatibility matrix.
+
+ |
+
|
+ PAN-239612
+ |
+
+
+ When the firewall is running PAN-OS 11.2.0 and Advanced Routing is
+ enabled, DHCPv4 relay agent functions successfully, but DHCPv6 relay
+ agent doesn't work.
+
+ |
+
|
+ PAN-237106
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-236649
+ |
+
+
+ If you change the configuration of a firewall acting as a PPPoEv4 or
+ PPPoEv6 client, old routes from the Forwarding Information Base (FIB)
+ and route table for an inherited configuration with dynamic-identifier
+ or client remain visible. Old routes also remain visible for an
+ inherited interface when you execute the CLI command,
+ show interface all.
+
+
+ Workaround: Unconfigure and configure the
+ Inherited Interface.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ WF500-6271
+ |
+
+
+ A WildFire cluster node that has been configured with an IPv6
+ management port might not display the signature status when using the
+ following CLI:
+ show wildfire global signature-status sha256 equal
+ <SHA_256_Value>
+
+
+ Workaround: Gracefully restart the affected
+ Wildfire cluster nodes.
+
+ |
+
|
+ WF500-6259
+ |
+
+
+ When a WildFire cluster node configured as a server or worker node is
+ rebooted, issuing the CLI command,
+ global sample-status does not update
+ the samples processed list on the active controller and non-server
+ worker nodes.
+
+
+ Workaround: Gracefully restart the affected
+ WildFire active controller and passive controller in the cluster.
+
+ |
+
|
+ WF500-6270
+ |
+
+
+ The WildFire cluster server and worker nodes might disconnect from the
+ Wildfire cluster management network, resulting in a notifier process
+ exit on WildFire cluster controllers.
+
+
+ Workaround: Gracefully restart the WildFire
+ cluster node where the process exit occurred.
+
+ |
+
|
+ WF500-6222
+ |
+
+
+ When WildFire secure cluster communication is enabled using a custom
+ DNS, the cluster formation might fail due to cluster management
+ communication issues.
+
+
+ Workaround: Do not configure a custom DNS when
+ WildFire secure cluster communication is enabled.
+
+ |
+
|
+ WF500-6176
+ |
+
+
+ When Panorama is used to manage a WildFire cluster, switchover
+ functionality for active and passive controller roles is not
+ available.
+
+ |
+
|
+ PAN-308564
+ |
+
+
+ Packets are dropped on SD-WAN interfaces if they require fragmentation
+ for an interface but have the
+ Don't Fragment (DF) bit set. This
+ results in unexpected packet drops. This affects client to server
+ sessions when using SD-WAN for NGFW.
+
+
+ Workaround: Allow fragmenting packets with DF bit
+ set (debug dataplane set ip4-ignore-df yes).
+
+ |
+
|
+ PAN-308507
+ |
+
+
+ Strata Logging Service (SLS) log-forwarding streams intermittently
+ show as inactive. When checking the status of log-forwarding
+ connections, one or more streams are reported as inactive. Restarting
+ the log-receiver process temporarily
+ resolves the issue, but the streams become inactive again after
+ approximately 1-2 hours. This intermittent inactivity results in log
+ loss.
+
+ |
+
|
+ PAN-308418
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ When Advanced DNS Security is enabled and experiences unusually high
+ loads, DNS traffic sessions may be impacted, resulting in DNS
+ resolution failures. Traffic logs for these sessions show an
+ end-reason of resources-unavailable.
+
+
+ Workaround: Disable Advanced DNS Security
+ telemetry (
+ and uncheck Telemetry Enable).
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push may
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-304576
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ Traffic interruption may occur when inspection of HTTP/2 traffic is
+ enabled.
+
+
+ Workaround: Disable HTTP/2 server push using the
+ set deviceconfig setting http2 server-push no
+ CLI command.
+
+ |
+
|
+ PAN-303959
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ Traffic that is incorrectly identified as unknown-tcp/unknown-udp
+ eventually drops due to an App-ID resource limitation issue.
+
+ |
+
|
+ PAN-302927
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ After an upgrade, the
+ Push to Devices window fails to
+ populate the list of devices automatically. If you manually select
+ devices by clicking Edit Selections,
+ the OK button becomes unresponsive
+ and fails to save or close the selection window. Additionally,
+ clicking Cancel might incorrectly
+ show the device list as empty while retaining the selections in the
+ background.
+
+ |
+
|
+ PAN-301801
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ On Log Collectors, the Elasticsearch process might fluctuate between
+ green and red states, causing log collection interruptions. This issue
+ occurs when the number of shards exceeds the supported threshold of
+ 1,000 shards per Elasticsearch instance.
+
+ |
+
|
+ PAN-297610
+
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues
+ and
+ PAN-OS 11.2.10-h2 Addressed Issues.
+
+ |
+
+
+ A firewall may become unresponsive after an upgrade due to the
+ fsck
+ command scanning drive partitions in parallel with the root partition,
+ causing the process to take an extended amount of time.
+
+ |
+
|
+ PAN-297295
+
+ This issue is now resolved. See PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+ (VM-Series firewalls on Microsoft Azure environments only)
+
+ After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent process restarts multiple
+ times and exhausts its restart limit, resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-296752
+
+ This issue is now resolved. See PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+
+ The PA-1410 firewalls experience a spike in the management plane CPU
+ utilization when the monitor-dp process attempts to retrieve the power
+ cycle count from the NVMe drive’s SMART data. This condition leads to
+ repeated reboots of the device, requiring a hard reset for recovery.
+
+ |
+
|
+ PAN-295803
+
+ This issue is now resolved. See PAN-OS 11.2.11 Addressed Issues,
+ PAN-OS 11.2.7-h10 Addressed Issues
+ and
+ PAN-OS 11.2.10-h3 Addressed Issues
+
+ |
+
+
+ A configd memory leak occurs post
+ commit (during Panorama connectivity check), potentially leading to
+ OOM (out of memory condition) and device reboot.
+
+ |
+
|
+ PAN-295645
+ |
+
+
+ When a WildFire cluster is configured centrally using Panorama, it
+ initiates a series of processes, including a software install and
+ reboot, in an order that will leave the resulting WildFire cluster in
+ an unusable state.
+
+ |
+
|
+ PAN-294179
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+ + On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. + | +
|
+ PAN-291661
+
+ This issue is now resolved. See PAN-OS 11.2.10 Addressed Issues
+
+ |
+
+
+ Upon upgrade, the ElasticSearch health status intermittently
+ transitions to the Red status for sometime, and then auto-recovers
+ back to Green. During the Red status periods, the cluster logs are
+ unavailable. This occurs due to disk write operations being
+ excessively slow, failing to meet the minimum time threshold required
+ to save the cluster state.
+
+ |
+
|
+ PAN-288525
+ |
+
+
+ When the Enterprise DLP data filtering profile is configured with a
+ Block action and is used in
+ conjunction with Advanced Threat Prevention, which is configured with
+ an action of reset-both,
+ reset-server,
+ reset-client, or
+ drop for the
+ HTTP Command and Control detector,
+ Dropbox file uploads that exceed the maximum configured file size
+ action will fail.
+
+
+ Workaround: Configure the Advanced Threat
+ Prevention Inline Cloud analysis () action for the HTTP Command and Control detector to
+ alert.
+
+ |
+
|
+ PAN-285061
+ |
+
+
+ When Enterprise DLP is enabled, file uploads might unexpectedly fail
+ when 100 continue response is received from the server during file
+ uploads.
+
+ |
+
|
+ PAN-284700
+ |
+
+
+ File downloads for content encoded with zstd (Zstandard), such as
+ specific content from box.com, fail when using Enterprise DLP because
+ zstd decompression is not supported in PAN-OS.
+
+ |
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-278688
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ (PA-7500, PA-5500, and PA-3500 firewalls only)
+ When DNS Security packet capture is enabled and a domain name has a
+ length of 62 characters, the DNS Security threat log entry is not
+ generated. On the affected platforms, this condition can also trigger
+ a pan_task crash due to shared memory
+ corruption.
+
+
+ Workaround: Disable DNS Security packet capture in
+ anti-spyware profiles () and in the DNS Policies tab, set
+ Packet Capture to
+ disable.
+
+ |
+
|
+ PAN-273158
+
+ This issue is now resolved. See
+ PAN-OS 11.2.11 Addressed Issues
+
+ |
+
+
+ (PA-7000 Series firewalls only) Due to an
+ incorrect configuration on the ASIC, receiving a mix of jumbo and
+ non-jumbo packets may cause silent packet drops or application
+ slowness.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-260212
+ |
+
+
+ When viewing Applications (), child App-IDs may be listed under the incorrect container App-ID.
+
+ |
+
|
+ PAN-259853
+ |
+
+
+ When the DHCP server is enabled for GlobalProtect, the commit error
+ message is not properly displayed when
+ Any is selected as the source
+ interface in the service router configuration (
+ ).
+
+ |
+
|
+ PAN-259423
+ |
+
+
+ When the GlobalProtect DHCP feature is enabled with two primary DHCP
+ servers on the GlobalProtect gateway, the gpsvc gets stuck during
+ renewal and after HA failover.
+
+ |
+
|
+ PAN-254236
+ |
+
+
+ TLSv1.3 hybridized Kyber support in the latest versions of Chrome and
+ Edge browsers results in dropped Client Hello packets when SSL/TLS
+ handshake inspection is enabled.
+
+
+ Workaround: Disable
+ SSL/TLS handshake inspection.
+
+ |
+
|
+ PAN-254108
+ |
+
+
+ when upgrading or downgrading a Panorama management server (), managed device (), or standalone firewall (), Base Releases and
+ Preferred Releases settings are
+ checked (enabled) by default and cause no PAN-OS software images to
+ display.
+
+
+ Workaround: Uncheck (disable)
+ Base Releases or
+ Preferred Releases to display either
+ the available base PAN-OS or preferred PAN-OS releases available to
+ download and install.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
|
+ PAN-252661
+ |
+
+
+ If you change the service route of gp-ip-mgmt in
+ Device > Setup > Services > Service Features >
+ gp-ip-mgmt
+ and Commit, the change won’t take effect.
+ gp-ip-mgmt continues to use the last committed service route.
+
+
+ Workaround: After you change the service route
+ interface for gp-ip-mgmt, navigate to either a GlobalProtect portal or
+ gateway, click OK to save the configuration, and
+ Commit the changes. This commit will include the
+ service route change.
+
+ |
+
|
+ PAN-250246
+ |
+
+
+ Panorama and the firewall display inconsistent IP addresses for
+ dynamic address group members after manually syncing.
+
+ |
+
|
+ PAN-250062
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-248836
+ |
+
+
+ The Advanced DNS Security trial license and trial license information
+ cannot be activated and viewed, respectively, on a managed firewall
+ (with expired or active status) from Panorama. These tasks can only be
+ performed on the firewall.
+
+ |
+
|
+ PAN-247728
+ |
+
+
+ When Advanced Routing is enabled, IP multicast is not supported. An
+ upcoming version will provide support for this feature. Customers who
+ have multicast configured or who plan to deploy multicast routing
+ should not upgrade to 11.2.0. Additionally, when Advanced Routing is
+ enabled, the BGP dampening configuration isn't applied to any peers or
+ peer group; the configuration is preserved but has no effect on BGP.
+ Customers can use BGP even if they have applied a Dampening profile to
+ a specific set of peers. The issue doesn't affect any other BGP
+ features.
+
+ |
+
|
+ PAN-241994
+ |
+
+
+ The VMX hardware version was upgraded from vmx-10 to vmx-15 on ESXi
+ and NSX-T. Support for vmx-15 is supported on ESXi 6.7 U2 and onwards.
+ Palo Alto Networks recommends that you upgrade your ESXi version if it
+ is less than 6.7 U2. For more information, see the
+ compatibility matrix.
+
+ |
+
|
+ PAN-239612
+ |
+
+
+ When the firewall is running PAN-OS 11.2.0 and Advanced Routing is
+ enabled, DHCPv4 relay agent functions successfully, but DHCPv6 relay
+ agent doesn't work.
+
+ |
+
|
+ PAN-237106
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-236649
+ |
+
+
+ If you change the configuration of a firewall acting as a PPPoEv4 or
+ PPPoEv6 client, old routes from the Forwarding Information Base (FIB)
+ and route table for an inherited configuration with dynamic-identifier
+ or client remain visible. Old routes also remain visible for an
+ inherited interface when you execute the CLI command,
+ show interface all.
+
+
+ Workaround: Unconfigure and configure the
+ Inherited Interface.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+