Add some PAN-OS 11.1 references and URLs

This commit is contained in:
2026-04-14 17:01:57 -05:00
parent 99b0420a4d
commit 245c34705f
15 changed files with 13767 additions and 18 deletions
+988
View File
@@ -0,0 +1,988 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-241230</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the SNMP get request status value for Panorama
connections was incorrect.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253187</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
the class of service (CoS) priority bit was not modified, causing
access points to lose connectivity to the wireless controller when
traffic was routed through the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253778</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-7500 Series firewalls in a cluster configuration only</tt
>) Fixed an issue where users were able to enable or disable certain
configurations.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-290239</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-455 firewalls in active/passive HA configurations only</tt
>) Fixed an issue where, after an upgrade, the TCP session for syslog
forwarding did not resume after the syslog server service was disabled
and then re-enabled, which caused logs to be dropped. This occurred
when the syslog server was down for more than 16 minutes.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-290088</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a memory leak occurred related to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process when pushing configurations from Panorama to a firewall. This
occurred when the configurations contained shared policy rules.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-289304</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7500 firewalls only</tt>) Fixed an issue where
SNMP polling failed due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>snmpd</a
>
process becoming unresponsive to incoming requests, which resulted in
high CPU usage.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-289102</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed a race condition issue related to predict processing on
multi-core platforms, which resulted in a dataplane restart and
traffic loss.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-288930</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic from cloud applications intermittently
matched an incorrect
<span class="ph uicontrol">cloud-apps</span> policy rule when ACE
(App-ID Cloud Engine) was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-288893</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in multi-vsys configurations only</tt>)
Fixed an issue where HTTP/2 traffic failed due when one virtual system
(vsys) had a decryption policy rule enabled and another vsys had a
no-decrypt policy rule for the same session.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-288363</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the MIB ID returned an incorrect value via SNMP.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-287838</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue on
the web interface where resetting the rule hit counter for multiple
policy rules failed with the error message
<span class="ph systemoutput">Failed to reset rule-hit job</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-287818</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where sessions timed out sooner than expected due to
the <span class="ph systemoutput">pan_proxy_accumulation_</span>
<span class="ph systemoutput">restore_timeout</span> not initiating
when the accumulation
<span class="ph systemoutput"> session_init</span> failed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-287734</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">Scan ERR: Internal Err 1002</span> messages
were unexpectedly generated when WIF shared memory use was high.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-287621</b></div>
</td>
<td class="entry relcol">
<div class="p">
Added debug logs for an issue where a slow IP address pool NAT leak
occurred when persistent NAT was enabled, which led to NAT IP pool
exhaustion.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-287584</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where the address object pop up
window only displayed a maximum of four address objects in the policy
rule even after expanding the window.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-287056</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where BGP export policy rules with next-hop matching
failed to block the advertisement of static routes, and the firewall
incorrectly matched the egress interface IP address instead of the
original next-hop IP address of the static route, which caused the
deny rule to fail.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-287023</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a large number of logs caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process to stop responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-286857</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where only failed Kerberos authentication events were
logged in <span class="ph systemoutput">auth.log</span>, and
successful authentication events were not logged.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-286848</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where ECMP incorrectly balanced sessions across links
based on the configured metric, which led to an imbalance in traffic
distribution and resulted in traffic assignment shifting
disproportionately to routes with lower metrics.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-286443</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after an upgrade, the firewall was unable to be
managed via HTTPS or SSH.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-286306</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when getting transceiver information from ESCC
for SFP 25G modules, the transceiver code was incorrectly updated with
<span class="ph systemoutput">Unknown</span> instead of
<span class="ph systemoutput">25GBase-SR</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-285894</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding, which caused the firewall to reboot
unexpectedly, and traffic failures occurred.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-285818</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a tool was needed to display leaked NAT port
numbers without requiring a forced synchronization.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-284908</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where retrieving filenames from OneDrive resulted in a
cache miss.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-284067</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>devsrvr</a
>
process experienced OOM conditions due to the
<span class="ph systemoutput"
>show running application statistics </span
>CLI command, which caused the firewall to reboot.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-284003</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where clients did not receive a valid response when
when searching a website due to a compression error.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-283979</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall became non-functional due to high
root partition use.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-283813</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the web interface performance was
slower than usual when retrieving read-only configurations from
Panorama.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-282394</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a firewall was only able to display a maximum of
14 permitted IP addresses from a Panorama Template Variable.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-282277</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an OOM condition on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process caused interface flapping, and the interface unexpectedly went
down and then recovered without intervention.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-281509</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue where
log exports were slower than expected or failed when filtering logs
after an upgrade, which resulted in timeouts or delays in displaying
logs on the web interface.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-280101</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where set and edit commands took longer than expected
when adding address objects with a large number of dynamic groups due
to the completion cache being enabled. With this fix, the completion
cache is disabled by default.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-279706</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">M-600 appliances only</tt>) Fixed an issue where
Panorama did not update all
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>panreplay</a
>
database entries after performing a commit and full push to all
devices.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-279500</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TLS connections failed to establish in asymmetric
routing environments if the firewall did not see server-to-client
(s2c) packets of the TLS handshake.
</div>
<div class="p">
To use this fix, run the following CLI command:
<span class="ph systemoutput"
>debug dataplane set ssl-decrypt accumulate-client-hello
asym-disable yes</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-278836</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after an upgrade, GlobalProtect attempted to use
the embedded browser instead of the default browser for gateway
authentication even when it was configured to use the default browser.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-278812</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where authentication to GlobalProtect failed with the
error message
<span class="ph systemoutput">User not in allowed list</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-278150</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall removed the Authentication Key
Identifier (AKID) from the certificate during SSL decryption, which
caused Python 3.13 to fail with a certificate verification error.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-277808</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>eproxy</a
>
process stopped responding when running a long duration test using
IXload with hybrid SWG SAML authentication bypass for HTTPS payloads,
which caused the proxy to become unreachable.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-277617</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where deleting the NTP server address caused a commit
validation error. This occurred when the configuration included both
primary and secondary NTP servers and the secondary server was
removed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-277234</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a device group import resulted in a Security
policy rule being created with
<span class="ph uicontrol">Application</span> set to
<span class="ph uicontrol">none</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-276920</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where web-advertisement traffic was not immediately
blocked which resulted in pages loading indefinitely.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-276678</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama became unresponsive while performing a
dynamic address update without a lock.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-275451</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances only</tt>) Fixed an issue where
sequence numbers were lost when forwarded from Panorama, which
resulted in missing or lost logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-275133</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where HTTP 503 server errors occurred while browsing
websites due to slow Secure Web Gateway (SWG) bypass rule lookup.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-275047</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue
where, after an upgrade, the firewall was unable to send logs to the
Strata Logging Service (SLS) when using a specific proxy server, and
the SSL connection status displayed as failed when attempting to
forward logs through the web proxy.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-274797</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a DPC on slot 3 failed intermittently due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pktlog_forwarding</a
>
process restarting, which resulted in an unexpected HA failover.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-273964</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where SNMP scans to a firewall timed out after
upgrading to a PAN-OS 10.2 release.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-272395</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where informational logs caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>distributord</a
>
process log file to be frequently overwritten.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-272175</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where session rematch caused ACE cloud application
traffic to match the wrong policy.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-271810</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where auto-negotiation advertised and negotiated 10/100
half and full duplex.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-271432</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to decrypt SSL traffic
when using forward proxy and HSM with an ECDSA signing certificate.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-271425</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/active HA configurations only</tt
>) Fixed an issue with SSL inbound decryption on firewalls on a vwire
setup with asymmetric routing.
</div>
<div class="p">
To use this fix, enter the CLI command
<span class="ph systemoutput"
>set system setting ssl-decrypt ha-vwire-mac-learn global yes</span
>
on both firewalls in an HA pair.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-269700</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where commits to service connection firewalls from
Panorama failed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-269057</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>routed</a
>
process stopped responding due to accessing freed memory from a hash
table when the route vectors were resized. This occurred when a large
number of static routes were configured.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-268787</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where users were unable to log in to Panorama and the
following error message was displayed:
<span class="ph systemoutput"
>Timed out while getting config lock. Please try again</span
>. This occurred when pushing configurations to a large number of
devices.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-268313</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Priority Code Point (PCP) bits in the VLAN
header were not reset to 0 when a packet was received from one Layer 3
tagged interface and forwarded to another, which resulted in dropped
packets.
</div>
<div class="p">
To use this fix, run the CLI command
<span class="ph systemoutput">set force-vlan-pcp-reset yes</span> and
reboot the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-267759 </b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Prisma Access gateway downloads were slower than
expected.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-267328</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding, which caused the firewall to stop
processing traffic.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-264708</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a selective push was blocked when a configuration
load was done.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259727</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances in HA configurations only</tt>)
Fixed an issue where Panorama became unresponsive and displayed a 504
gateway timeout error when accessing the web interface or the CLI.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253778</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-7500 Series firewalls in a cluster configuration only</tt
>) Fixed an issue where users were able to enable or disable certain
configurations.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-253187</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
the class of service (CoS) priority bit was not modified, causing
access points to lose connectivity to the wireless controller when
traffic was routed through the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-241230</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the SNMP get request status value for Panorama
connections was incorrect.
</div>
</td>
</tr>
</tbody>
</table>