diff --git a/web/data/issues/PAN-OS/known/11.0.0_2026-03-16.md b/web/data/issues/PAN-OS/known/11.0.0_2026-03-16.md new file mode 100644 index 0000000..65ce2b2 --- /dev/null +++ b/web/data/issues/PAN-OS/known/11.0.0_2026-03-16.md @@ -0,0 +1,726 @@ +--- +type: Known +product: PAN-OS +version: 11.0.0 +--- + +## WF500-5632 + +The number of registered WildFire appliances +reported in Panorama (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the +current status of connected WildFire appliances. + +## PAN-260851 + +From the NGFW or Panorama CLI, you can override the existing +application tag even if Disable Override is enabled for the +application (ObjectsApplications) tag. + +## PAN-250062 + +Device telemetry might fail at configured intervals due to bundle generation issues. + +## PAN-234408 + +Enterprise DLP cannot detect and block non-file based traffic for +ChatGPT from traffic forwarded to the DLP cloud service from an +NGFW. + +## PAN-234015 + +The X-Forwarded-For (XFF) value is not displayed in traffic logs. + +## PAN-243951 + +On the Panorama management sever in an active/passive High +Availability (HA) configuration, managed devices (PanoramaManaged DevicesSummary) display as out-of-sync +on the passive HA peer when configuration changes are made to the +SD-WAN (PanoramaSD-WAN) configuration on the active HA peer. + +Workaround: Manually synchronize the Panorama HA peers. + +1. Log in to the Panorama web + interface on the active HA peer. +2. Select Commit and Commit to + Panorama the SD-WAN configuration changes on + the active HA peer. + On the passive HA peer, select PanoramaManaged DevicesSummary and observe that the managed devices are now + out-of-sync. +3. Log in to the primary HA peer Panorama CLI and + trigger a manual synchronization between the active and + secondary HA peers. + request high-availability sync-to-remote + running-config +4. Log back in to the active HA peer Panorama web interface and + select CommitPush to Devices and Push. + +## PAN-242910 + +On the Panorama management server, Panorama administrators (PanoramaAdministrators) that are assigned a custom Panorama admin role (PanoramaAdmin Roles) with Push All Changes enabled +are unable to push configuration changes to managed firewalls when +Managed Devices and Push For +Other Admins are disabled. + +## PAN-241041 + +On the Panorama management server exporting template or template +stack variables (PanoramaTemplates) in CSV format results in an empty CSV file. + +## PAN-229702 + +After upgrading a Panorama HA pair to PAN-OS 11.1, the ElasticSearch +connectivity might fail to establish. The issue occurs because the +client certificate on one of the Panorama devices does not have the +necessary Extended Key Usage (EKU) set for server authentication, +which is required for secure TLS communication. + +Workaround:Contact Customer Support to renew the root client +certificate. + +## PAN-228515 + +The EleasticSearch SSH flaps on the M-600 appliance in Panorama or +Log Collector mode. This causes logs to not display on the Panorama +management server (MonitorLogs) and the Log Collector health status (PanoramaManaged CollectorsStatus) to display as degraded. + +## PAN-228273 + +On the Panorama management server in FIPS-CC mode, the ElasticSearch +cluster fails to come up and the show +log-collector-es-cluster health command displays +the status is +red. This results in log ingestion +issues for Panorama in Panorama only or Log Collector mode. + +## PAN-227344 + +On the Panorama management server, PDF Summary Reports (MonitorPDF ReportsManage PDF Summary) display no data and are blank when predefined +reports are included in the summary report. + +## PAN-225886 + +If you enable explicit proxy mode for the web proxy, intermittent +errors and unexpected TCP reconnections may occur. + +## PAN-225337 + +On the Panorama management server, the configuration push to a +multi-vsys firewall fails if you: + +1. Create a Shared and vsys-specific + device group configuration object with an indentical name. + For example, a Shared address object + called SharedAO1 and a + vsys-specific address object also called + SharedAO1. +2. Reference the Shared object in another + Shared configuration. For + example, reference the Shared address + object (SharedAO1) in a + Shared address group called + SharedAG1. +3. Use the Shared configuration object + with the reference in a vsys-specific configuration. For + example, reference the Shared address + group (SharedAG1) in a + vsys-specific policy rule. + +Workaround: Select PanoramaSetupManagement and edit the Panorama Settings to enable one of the +following: + +- Shared Unused Address and Service Objects with + Devices—This options pushes all + Shared objects, along with device + group specific objects, to managed firewalls. + This is a global setting and applies to all managed + firewalls, and may result in pushing too many configuration + objects to your managed firewalls. +- Objects defined in ancestors will take higher + precedence—This option specifies that in the event + of objects with the same name, ancestor object take + precedence over descendent objects. In this case, the + Shared objects take precedence + over the vsys-specific object. + This is a global setting and applies to all managed + firewalls. In the example above, if the IP address for the + Shared + SharedAO1 object was + 10.1.1.1 and the device + group specific SharedAO1 was + 10.2.2.2, the + 10.1.1.1 IP address takes + precedence. + +Alternatively, you can remove the duplicate address objects from the +device group configuration to allow only the +Shared objects in your configuration. + +## PAN-223488 + +Closed ElasticSearch shards are not deleted from the Panorama +M-Series and virtual appliance. This causes the ElasticSearch shard +purging to not work as expected, resulting in high disk usage. + +## PAN-223365 + +The Panorama management server is unable to query any logs if the +ElasticSearch health status for any Log Collector (PanoramaManaged Collector is degraded. + +Workaround: +Log in to the Log Collector +CLI and restart ElasticSearch. + +admindebug elasticsearch es-restart all + +## PAN-222586 + +On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter +dropdown menus, Forward Methods, and Built-In Actions for +Correlation Log settings (DeviceLog Settings) are not displayed and cannot be configured. + +## PAN-222253 + +On the Panorama management server, policy rulebase reordering when +you View Rulebase by Groups (Policy) does not persist if you reorder the policy rulebase +by dragging and dropping individual policy rules and then moving the +entire tag group. + +## PAN-221015 + +On M-600 appliances in Panorama or Log Collector mode, the +es-1 and +es-2 ElasticSearch processes fail +to restart when the M-600 appliance is rebooted. The results in the +Managed Collector ES health status (PanoramaManaged CollectorsHealth Status) to be degraded. + +Workaround: +Log in to the Panorama or Log +Collector CLI experiencing degraded ElasticSearch health +and restart all ElasticSearch processes. + +admin>debug elasticsearch es-restart optional all + +Code copied to clipboard + +Unable to copy due to lack of browser support. + +Copy + +## PAN-220180 + +Configured botnet reports (MonitorBotnet) are not generated. + +## PAN-219644 + +Firewalls forwarding logs to a syslog server over TLS (ObjectsLog Forwarding) use the default Palo Alto Networks certificate +instead of the custom certificate configured on the firewall. + +## PAN-218521 + +The ElasticSearch process on the M-600 appliance in Log Collector +mode may enter a continuous reboot cycle. This results in the M-600 +appliance becoming unresponsive, consuming logging disk space, and +preventing new log ingestion. + +## PAN-217307 + +The following Security policy rule (PoliciesSecurity) filters return no results: + +log-start eq no + +log-end eq no + +log-end eq yes + +## PAN-216214 + +For Panorama-managed firewalls in an Active/Active High Availability +(HA) configuration where you configure the firewall HA settings (DeviceHigh Availability) in a template or template stack (PanoramaTemplates), performing a local commit on one of the HA +firewalls triggers an HA config sync on the peer firewall. This +causes the HA peer configuration to go Out of +Sync. + +## PAN-215778 + +On the M-600 appliance in Management Only mode, XML API Get requests +for /config fail with the following +error due to exceeding the total configuration size +supported on the M-600 appliance. + +504 Gateway timeout + +## PAN-215082 + +M-300 and M-700 appliances may generate erroneous system logs (MonitorLogsSystem) to alert that the M-Series appliance memory usage +limits are reached. + +## PAN-213746 + +On the Panorama management server, the Hostkey +displayed as undefined undefined if you +override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template +Stack. + +## PAN-213119 + +PA-5410 and PA-5420 firewalls display the following error when you +view the Block IP list (MonitorBlock IP): + +show -> dis-block-table is +unexpected + +## PAN-212889 + +On the Panorama management server, different threat names are used +when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the +ACC displaying no data to display when +you are redirected to the ACC after clicking a threat name in the +Threat Monitor and filtering the same threat name in the Global +Filters. + +## PAN-212533 + +Modifying the Administrator Type for an +existing administrator (DeviceAdministrators or PanoramaAdministrators) from Superuser to a +Role-Based custom admin, or vice versa, +does not modify the access privileges of the administrator. + +## PAN-211531 + +On the Panorama management server, admins can still +perform a selective push to managed firewalls when Push All +Changes and Push for Other Admins +are disabled in the admin role profile (PanoramaAdmin Roles). + +## PAN-209937 + +Certificate-based authentication for administrator accounts may be +unable to log into the Panorama or firewall web interface with the +following error: + +Bad Request - Your browser sent a request that this +server could not understand + +## PAN-208325 + +The following NextGen firewalls and Panorama management server models +are unable to automatically renew the device certificate (DeviceSetupManagement or PanoramaSetupManagement). + +- M-300 and M-700 +- PA-410 Firewall +- PA-415 and PA-445 Firewalls +- PA-440, PA-450, and PA-460 Firewalls +- PA-1400 Series +- PA-3400 Series +- PA-5410, PA-5420, and PA-5430 Firewalls +- PA-5440 Firewall +- PA-5450 Firewall + +Workaround: Log in to the firewall CLI or Panorama CLI and fetch the +device certificate. + +admin>request certificate fetch + +## PAN-208189 + +Traffic fails to match and reach all destinations if a Security +policy rule includes FQDN objects that resolve to two or more IP +addresses. + +## PAN-207770 + +Data filtering logs (MonitorLogsData Filtering) +incorrectly display the traffic Direction as server-to-client instead +of client-to-server for upload traffic +that matches Enterprise data loss prevention (DLP) data patterns (ObjectsDLPData +Filtering Patterns) in an Enterprise DLP data +filtering profile (ObjectsDLPData Filtering Profiles). + +## PAN-207733 + +When a DHCPv6 client is configured on HA +Active/Passive firewalls, if the DHCPv6 server goes down, after +the lease time expires, the DHCPv6 client should enter SOLICIT state +on both the Active and Passive firewalls. Instead, the client is +stuck in BOUND state with an IPv6 address having lease time 0 on +the Passive firewall. + +## PAN-207629 + +On the Panorama management server, selective push fails to managed +firewalls if the managed firewalls are enabled with multiple vsys +and the Push Scope contains shared objects in device groups. + +## PAN-207616 + +On the Panorama management server, after +selecting managed firewalls and creating a new Tag (PanoramaManaged DevicesSummary) the managed firewalls are +automatically unselected and any new tag created is applied to the +managed firewalls for which you initially created the new tag. + +Workaround: Select +and then unselect the managed firewalls for which you created a +new tag. + +## PAN-207611 + +When a DHCPv6 client is configured on HA +Active/Passive firewalls, the Passive firewall sometimes crashes. + +## PAN-207040 + +If you disable Advanced Routing, remove +logical routers, and downgrade from PAN-OS 11.0.0 to a PAN-OS 10.2.x +or 10.1.x release, subsequent commits fail and SD-WAN devices on +Panorama have no Virtual Router name. + +## PAN-206913 + +When a DHCPv6 client is configured on HA +Active/Passive firewalls, releasing the IPv6 address from the client +(using Release in the UI or using the request dhcp client ipv6 release all CLI +command) releases the IPv6 address from the Active firewall, but +not the Passive firewall. + +## PAN-206909 + +The Dedicated Log Collector is unable to +reconnect to the Panorama management server if the configd process +crashes. This results in the Dedicated Log Collector losing connectivity +to Panorama despite the managed collector connection Status (PanoramaManaged Collector) +displaying connected and the managed colletor Health status displaying +as healthy. + +This results in the local Panorama config and +system logs not being forwarded to the Dedicated Log Collector. +Firewall log forwarding to the disconnected Dedicated Log Collector +is not impacted. + +Workaround: Restart the mgmtsrvr process +on the Dedicated Log Collector. + +1. Log in to the Dedicated Log Collector + CLI. +2. Confirm the Dedicated Log Collector is disconnected from + Panorama. + admin> show panorama-status + Verify + the Connected status is no. +3. Restart the mgmtsrvr process. + admin> debug software restart process management-server + +## PAN-206416 + +On the Panorama management server, no data +filtering log (MonitorLogsData Filtering) is generated +when the managed firewall loses connectivity to the following cloud services, +and as a result fails to forward matched traffic for inspection. + +- DLP cloud service +- Advanced Threat Protection inline cloud analysis service +- Advanced URL Filtering cloud service + +## PAN-206315 + +```caveat +PA-1420 firewall only +``` + +In an active/passive high +availability (HA) configuration, the show session info CLI +command shows that the passive firewall has packet rate and throughput +values. The packet rate and throughput of the passive firewall should +be zero since it is not processing traffic. + +## PAN-206253 + +For PA-1400 and PA-3400 Series firewalls, the default log rate is set +too low and the max configurable log rate is incorrectly capped +resulting in the firewall not generating more than 6,826 logs per +second. + +## PAN-206005 + +```caveat +PA-1400 Series, PA-3400 Series, and PA-5440 firewalls only +``` + +The I7_misc memory pool on these platforms +is undersized and can cause a loss of connectivity when reaching +the limit of the memory pool. Certain features, like using a decryption +profile with Strip ALPN disabled, can lead to depleting the memory +pool and causing a connection loss. + +Workaround: Disable +HTTP2 by enabling Strip ALPN in the decryption profile or avoid +usage of the I7_misc memory pool. + +## PAN-205255 + +There is a rare PAN-OS issue that causes the dataplane to restart unexpectedly. + +## PAN-205187 + +ElasticSearch may not start properly when a newly installed Panorama +virtual appliance powers on for the first time, resulting in the +Panorama virtual appliance being unable to query logs forwarded from +the managed firewall to a Log Collector. + +Workaround: +Log in to the Panorama CLI +and start the PAN-OS software. + +admin>request restart software + +## PAN-205009 + +```caveat +PA-1420 firewall only +``` + +In an active/passive high +availability (HA) configuration, the show interface all, show-high availability interface ha2, +and show high-availability all CLI +commands display the HSCI port state as unknown on both the active +and passive firewalls. + +## PAN-204615 + +BGP sessions can flap even when an unrelated configuration is +committed. This results in the BGP session going down and getting +established again. As a result, BGP routes get exchanged again, +which can lead to momentary traffic disruption if BGP routes were in +use for establishing traffic. + +## PAN-201910 + +PAN-OS security profiles might consume a +large amount of memory depending on the profile configuration and +quantity. In some cases, this might reduce the number of supported security +profiles below the stated maximum for a given platform. + +## PAN-201855 + +On the Panorama management server, cloning any template (PanoramaTemplates) corrupts certificates (DeviceCertificate ManagementCertificates) with the Block Private Key +Export setting enabled across all templates. This +results in managed firewalls experiencing issues wherever the +corrupted certificate is referenced. + +For example, you have template A, B, and C where templates A and B +have certificates with the Block Private Key +Export setting enabled. Cloning template C corrupts +the certificates with Block Private Key +Export setting enabled in templates A and B. + +Workaround: After cloning a template, delete and re-import the +corrupted certificates. + +## PAN-199557 + +On M-600 appliances in an Active/Passive high availability (HA) +configuration, the configd process +restarts due to a memory leak on the +Active Panorama HA peer. This +causes the Panorama web interface and CLI to become unresponsive. + +Workaround: Manually reboot the +Active Panorama HA peer. + +## PAN-197588 + +The PAN-OS ACC (Application Command Center) +does not display a widget detailing statistics and data associated +with vulnerability exploits that have been detected using inline +cloud analysis. + +## PAN-197419 + +```caveat +PA-1400 Series firewalls only +``` + +In NetworkInterfaceEthernet, the power over Ethernet +(PoE) ports do not display a Tag value. + +## PAN-197097 + +Large Scale VPN (LSVPN) does not support +IPv6 addresses on the satellite firewall. + +## PAN-196758 + +On the Panorama management server, pushing +a configuration change to firewalls leveraging SD-WAN erroneously +show the auto-provisioned BGP configurations for SD-WAN as being +edited or deleted despite no edits or deletions being made when +you Preview Changes (CommitPush to DevicesEdit Selections or CommitCommit and PushEdit Selections). + +## PAN-196146 + +The VM-Series firewall on Azure does not +boot up with a hostname (specified in an init-cgf.txt or user data) +when bootstrapped. + +## PAN-195968 + +```caveat +PA-1400 Series firewalls only +``` + +When using the CLI to configure power over Ethernet (PoE) on a non-PoE +port, the CLI prints an error depending on whether an interface +type was selected on the non-PoE port or not. If an interface type, such +as tap, Layer 2, or virtual wire, was selected before PoE was configured, +the error message will not include the interface name (eg. ethernet1/4). +If an interface type was not selected before PoE was configured, +the error message will include the interface name. + +## PAN-195568 + +When PAN-OS 11.0 is installed on multiple data plane platforms, users +are unable to connect to the GlobalProtect portal or gateway. + +## PAN-195342 + +On the Panorama management server, Context +Switch fails when you try to Context Switch from a managed firewall running +PAN-OS 10.1.7 or earlier release back to Panorama and the following +error is displayed: + +Could not find start token '@start@' + +## PAN-194978 + +```caveat +PA-1400 Series firewalls only +``` + +In NetworkInterfaceEthernet, hovering the mouse over +a power over Ethernet (PoE) Link State icon +does not display link speed and link duplex details. + +## PAN-194424 + +```caveat +PA-5450 firewall only +``` + +Upgrading +to PAN-OS 10.2.2 while having a log interface configured can cause +both the log interface and the management interface to remain connected +to the log collector. + +Workaround: Restart the log receiver service +by running the following CLI command: + +debug software restart process log-receiver + +## PAN-192282 + +```caveat +PA-415 and PA-445 firewalls only +``` + +In 1G mode, the MGT and Ethernet 1/1 port LEDs glow amber instead of +green. + +## PAN-187685 + +On the Panorama management server, the Template Status +displays no synchronization status (PanoramaManaged DevicesSummary) +after a bootstrapped firewall is successfully added to Panorama. + +Workaround: After +the bootstrapped firewall is successfully added to Panorama, log in to the Panorama web interface and +select CommitPush +to Devices. + +## PAN-187407 + +The configured Advanced Threat Prevention +inline cloud analysis action for a given model might not be honored +under the following condition: If the firewall is set to Hold +client request for category lookup and the action set +to Reset-Both and the URL cache has been +cleared, the first request for inline cloud analysis will be bypassed. + +## PAN-186283 + +Templates appear out-of-sync on Panorama +after successfully deploying the CFT stack using the Panorama plugin for +AWS. + +Workaround: Use CommitPush to Devices to synchronize +the templates. + +## PAN-184708 + +```caveat +Panorama managed firewalls +``` + +Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: + +- A scheduled report email contains + a Report Group (MonitorPDF + ReportsReport Group) + which includes a SaaS Application Usage report. +- A scheduled report contains only a SaaS Application Usage Report. + +Workaround: To +receive a scheduled report email for all other PDF report types: + +1. Select MonitorPDF ReportsReport Groups and + remove all SaaS Application Usage reports from all Report Groups. +2. Select MonitorPDF + ReportsEmail Scheduler and + edit the scheduled report email that contains only a SaaS Application Usage + report. For the Recurrence, select Disable and + click OK. + Repeat this step for all scheduled + report emails that contain only a SaaS Application Usage report. +3. Commit. + () + Select CommitCommit + and Push + +## PAN-184406 + +Using the CLI to add a RAID disk pair to +an M-700 appliance causes the dmdb process to crash. + +Workaround: Contact +customer support to stop the dmdb process before adding a RAID disk +pair to a M-700 appliance. + +## PAN-183404 + +Static IP addresses are not recognized when +"and" operators are used with IP CIDR range. + +## PAN-182734 + +On an Advanced Routing Engine, if you change +the IPSec tunnel configuration, BGP flaps. + +## PAN-181933 + +If you use multiple log forwarding cards +(LFCs) on the PA-7000 series, all of the cards may not receive all +of the updates and the mappings for the clients may become out of sync, +which causes the firewall to not correctly populate the Source User +column in the session logs. + +## PAN-171938 + +No results are displayed when you Show Application +Filter for a Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). + +## PAN-164885 + +On the Panorama management server, pushes to managed firewalls (CommitPush to Devices or Commit and Push) may fail +when an EDL (ObjectsExternal Dynamic Lists) is configured to Check for +updates every 5 minutes due to the commit and EDL +fetch processes overlapping. This is more likely to occur when +multiple EDLs are configured to check for updates every 5 +minutes. diff --git a/web/data/issues/PAN-OS/known/11.0.1_2026-03-16.md b/web/data/issues/PAN-OS/known/11.0.1_2026-03-16.md new file mode 100644 index 0000000..4f4ea9d --- /dev/null +++ b/web/data/issues/PAN-OS/known/11.0.1_2026-03-16.md @@ -0,0 +1,699 @@ +--- +type: Known +product: PAN-OS +version: 11.0.1 +--- + +## WF500-5632 + +The number of registered WildFire appliances +reported in Panorama (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the +current status of connected WildFire appliances. + +## PAN-260851 + +From the NGFW or Panorama CLI, you can override the existing +application tag even if Disable Override is enabled for the +application (ObjectsApplications) tag. + +## PAN-250062 + +Device telemetry might fail at configured intervals due to bundle generation issues. + +## PAN-243951 + +On the Panorama management sever in an active/passive High +Availability (HA) configuration, managed devices (PanoramaManaged DevicesSummary) display as out-of-sync +on the passive HA peer when configuration changes are made to the +SD-WAN (PanoramaSD-WAN) configuration on the active HA peer. + +Workaround: Manually synchronize the Panorama HA peers. + +1. Log in to the Panorama web + interface on the active HA peer. +2. Select Commit and Commit to + Panorama the SD-WAN configuration changes on + the active HA peer. + On the passive HA peer, select PanoramaManaged DevicesSummary and observe that the managed devices are now + out-of-sync. +3. Log in to the primary HA peer Panorama CLI and + trigger a manual synchronization between the active and + secondary HA peers. + request high-availability sync-to-remote + running-config +4. Log back in to the active HA peer Panorama web interface and + select CommitPush to Devices and Push. + +## PAN-234408 + +Enterprise DLP cannot detect and block non-file based traffic for +ChatGPT from traffic forwarded to the DLP cloud service from an +NGFW. + +## PAN-234015 + +The X-Forwarded-For (XFF) value is not displayed in traffic logs. + +## PAN-242910 + +On the Panorama management server, Panorama administrators (PanoramaAdministrators) that are assigned a custom Panorama admin role (PanoramaAdmin Roles) with Push All Changes enabled +are unable to push configuration changes to managed firewalls when +Managed Devices and Push For +Other Admins are disabled. + +## PAN-241041 + +On the Panorama management server exporting template or template +stack variables (PanoramaTemplates) in CSV format results in an empty CSV file. + +## PAN-228515 + +The EleasticSearch SSH flaps on the M-600 appliance in Panorama or +Log Collector mode. This causes logs to not display on the Panorama +management server (MonitorLogs) and the Log Collector health status (PanoramaManaged CollectorsStatus) to display as degraded. + +## PAN-228273 + +On the Panorama management server in FIPS-CC mode, the ElasticSearch +cluster fails to come up and the show +log-collector-es-cluster health command displays +the status is +red. This results in log ingestion +issues for Panorama in Panorama only or Log Collector mode. + +## PAN-227344 + +On the Panorama management server, PDF Summary Reports (MonitorPDF ReportsManage PDF Summary) display no data and are blank when predefined +reports are included in the summary report. + +## PAN-225886 + +If you enable explicit proxy mode for the web proxy, intermittent +errors and unexpected TCP reconnections may occur. + +## PAN-225337 + +On the Panorama management server, the configuration push to a +multi-vsys firewall fails if you: + +1. Create a Shared and vsys-specific + device group configuration object with an indentical name. + For example, a Shared address object + called SharedAO1 and a + vsys-specific address object also called + SharedAO1. +2. Reference the Shared object in another + Shared configuration. For + example, reference the Shared address + object (SharedAO1) in a + Shared address group called + SharedAG1. +3. Use the Shared configuration object + with the reference in a vsys-specific configuration. For + example, reference the Shared address + group (SharedAG1) in a + vsys-specific policy rule. + +Workaround: Select PanoramaSetupManagement and edit the Panorama Settings to enable one of the +following: + +- Shared Unused Address and Service Objects with + Devices—This options pushes all + Shared objects, along with device + group specific objects, to managed firewalls. + This is a global setting and applies to all managed + firewalls, and may result in pushing too many configuration + objects to your managed firewalls. +- Objects defined in ancestors will take higher + precedence—This option specifies that in the event + of objects with the same name, ancestor object take + precedence over descendent objects. In this case, the + Shared objects take precedence + over the vsys-specific object. + This is a global setting and applies to all managed + firewalls. In the example above, if the IP address for the + Shared + SharedAO1 object was + 10.1.1.1 and the device + group specific SharedAO1 was + 10.2.2.2, the + 10.1.1.1 IP address takes + precedence. + +Alternatively, you can remove the duplicate address objects from the +device group configuration to allow only the +Shared objects in your configuration. + +## PAN-223488 + +Closed ElasticSearch shards are not deleted from the Panorama +M-Series and virtual appliance. This causes the ElasticSearch shard +purging to not work as expected, resulting in high disk usage. + +## PAN-223365 + +The Panorama management server is unable to query any logs if the +ElasticSearch health status for any Log Collector (PanoramaManaged Collector is degraded. + +Workaround: +Log in to the Log Collector +CLI and restart ElasticSearch. + +admindebug elasticsearch es-restart all + +## PAN-222586 + +On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter +dropdown menus, Forward Methods, and Built-In Actions for +Correlation Log settings (DeviceLog Settings) are not displayed and cannot be configured. + +## PAN-222253 + +On the Panorama management server, policy rulebase reordering when +you View Rulebase by Groups (Policy) does not persist if you reorder the policy rulebase +by dragging and dropping individual policy rules and then moving the +entire tag group. + +## PAN-221126 + +Email server profiles (DeviceServer ProfilesEmail and PanoramaServer ProfilesEmail) to forward logs as email notifications are not +forwarded in a readable format. + +Workaround: Use a Custom Log Format to +forward logs as email notifications in a readable format. + +## PAN-221015 + +On M-600 appliances in Panorama or Log Collector mode, the +es-1 and +es-2 ElasticSearch processes fail +to restart when the M-600 appliance is rebooted. The results in the +Managed Collector ES health status (PanoramaManaged CollectorsHealth Status) to be degraded. + +Workaround: +Log in to the Panorama or Log +Collector CLI experiencing degraded ElasticSearch health +and restart all ElasticSearch processes. + +admin>debug elasticsearch es-restart optional all + +Code copied to clipboard + +Unable to copy due to lack of browser support. + +Copy + +## PAN-220180 + +Configured botnet reports (MonitorBotnet) are not generated. + +## PAN-220176 + +```caveat +PAN-OS 11.0.1-h2 hotfix +``` + +System process crashes might occur +with VoIP traffic when NAT is enabled with Persistent Dynamic IP and +Port settings. + +## PAN-219644 + +Firewalls forwarding logs to a syslog server over TLS (ObjectsLog Forwarding) use the default Palo Alto Networks certificate +instead of the custom certificate configured on the firewall. + +## PAN-218521 + +The ElasticSearch process on the M-600 appliance in Log Collector +mode may enter a continuous reboot cycle. This results in the M-600 +appliance becoming unresponsive, consuming logging disk space, and +preventing new log ingestion. + +## PAN-217307 + +The following Security policy rule (PoliciesSecurity) filters return no results: + +log-start eq no + +log-end eq no + +log-end eq yes + +## PAN-216821 + +The reportd process crashes after you +successfully upgrade an M-200 appliance to PAN-OS 10.2.4. + +## PAN-216314 + +Upon upgrade or downgrade to or from PAN-OS 10.1.9 or 10.1.9-h1, +offloaded application traffic sessions may disconnect after a period +of time even if a session is active. The disconnect occurs after the +application's default session timeout value is exceeded. This +behavior affects only PAN-OS 10.1.9 and 10.1.9-h1. If you are on +PAN-OS 10.1.9 and 10.1.9-h1, please use the following workaround. If +you have already upgraded or downgraded to another PAN-OS version, +use the following workaround in that version. + +Workaround: Run the CLI command debug dataplane +internal pdt fe100 csr wr_sem_ctrl_ctr_scan_dis value +0 to set the value to zero (0). + +## PAN-216214 + +For Panorama-managed firewalls in an Active/Active High Availability +(HA) configuration where you configure the firewall HA settings (DeviceHigh Availability) in a template or template stack (PanoramaTemplates), performing a local commit on one of the HA +firewalls triggers an HA config sync on the peer firewall. This +causes the HA peer configuration to go Out of +Sync. + +## PAN-215778 + +On the M-600 appliance in Management Only mode, XML API Get requests +for /config fail with the following +error due to exceeding the total configuration size +supported on the M-600 appliance. + +504 Gateway timeout + +## PAN-215082 + +M-300 and M-700 appliances may generate erroneous system logs (MonitorLogsSystem) to alert that the M-Series appliance memory usage +limits are reached. + +## PAN-213746 + +On the Panorama management server, the Hostkey +displayed as undefined undefined if you +override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template +Stack. + +## PAN-213119 + +PA-5410 and PA-5420 firewalls display the following error when you +view the Block IP list (MonitorBlock IP): + +show -> dis-block-table is +unexpected + +## PAN-212889 + +On the Panorama management server, different threat names are used +when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the +ACC displaying no data to display when +you are redirected to the ACC after clicking a threat name in the +Threat Monitor and filtering the same threat name in the Global +Filters. + +## PAN-211531 + +On the Panorama management server, admins can still +perform a selective push to managed firewalls when Push All +Changes and Push for Other Admins +are disabled in the admin role profile (PanoramaAdmin Roles). + +## PAN-209937 + +Certificate-based authentication for administrator accounts may be +unable to log into the Panorama or firewall web interface with the +following error: + +Bad Request - Your browser sent a request that this +server could not understand + +## PAN-208325 + +The following NextGen firewalls and Panorama management server models +are unable to automatically renew the device certificate (DeviceSetupManagement or PanoramaSetupManagement). + +- M-300 and M-700 +- PA-410 Firewall +- PA-415 and PA-445 Firewalls +- PA-440, PA-450, and PA-460 Firewalls +- PA-1400 Series +- PA-3400 Series +- PA-5410, PA-5420, and PA-5430 Firewalls +- PA-5440 Firewall +- PA-5450 Firewall + +Workaround: Log in to the firewall CLI or Panorama CLI and fetch the +device certificate. + +admin>request certificate fetch + +## PAN-208189 + +Traffic fails to match and reach all destinations if a Security +policy rule includes FQDN objects that resolve to two or more IP +addresses. + +## PAN-207770 + +Data filtering logs (MonitorLogsData Filtering) +incorrectly display the traffic Direction as server-to-client instead +of client-to-server for upload traffic +that matches Enterprise data loss prevention (DLP) data patterns (ObjectsDLPData +Filtering Patterns) in an Enterprise DLP data +filtering profile (ObjectsDLPData Filtering Profiles). + +## PAN-207733 + +When a DHCPv6 client is configured on HA +Active/Passive firewalls, if the DHCPv6 server goes down, after +the lease time expires, the DHCPv6 client should enter SOLICIT state +on both the Active and Passive firewalls. Instead, the client is +stuck in BOUND state with an IPv6 address having lease time 0 on +the Passive firewall. + +## PAN-207616 + +On the Panorama management server, after +selecting managed firewalls and creating a new Tag (PanoramaManaged DevicesSummary) the managed firewalls are +automatically unselected and any new tag created is applied to the +managed firewalls for which you initially created the new tag. + +Workaround: Select +and then unselect the managed firewalls for which you created a +new tag. + +## PAN-207611 + +When a DHCPv6 client is configured on HA +Active/Passive firewalls, the Passive firewall sometimes crashes. + +## PAN-207442 + +For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the +active-primary HA peer +configuration sync to the +secondary-passive HA peer may fail. +When the config sync fails, the job Results is +Successful +(Tasks), however the sync status on the +Dashboard displays as Out +of Sync for both HA peers. + +Workaround: Perform a local commit on the +active-primary HA peer and then +synchronize the HA configuration. + +1. Log in to the Panorama + web interface of the + active-primary HA peer. +2. Select Commit and Commit to + Panorama. +3. In the active-primary HA peer + Dashboard, click Sync + to Peer in the High Availability widget. + +## PAN-207040 + +If you disable Advanced Routing, remove +logical routers, and downgrade from PAN-OS 11.0.0 to a PAN-OS 10.2.x +or 10.1.x release, subsequent commits fail and SD-WAN devices on +Panorama have no Virtual Router name. + +## PAN-206913 + +When a DHCPv6 client is configured on HA +Active/Passive firewalls, releasing the IPv6 address from the client +(using Release in the UI or using the request dhcp client ipv6 release all CLI +command) releases the IPv6 address from the Active firewall, but +not the Passive firewall. + +## PAN-206909 + +The Dedicated Log Collector is unable to +reconnect to the Panorama management server if the configd process +crashes. This results in the Dedicated Log Collector losing connectivity +to Panorama despite the managed collector connection Status (PanoramaManaged Collector) +displaying connected and the managed colletor Health status displaying +as healthy. + +This results in the local Panorama config and +system logs not being forwarded to the Dedicated Log Collector. +Firewall log forwarding to the disconnected Dedicated Log Collector +is not impacted. + +Workaround: Restart the mgmtsrvr process +on the Dedicated Log Collector. + +1. Log in to the Dedicated Log Collector + CLI. +2. Confirm the Dedicated Log Collector is disconnected from + Panorama. + admin> show panorama-status + Verify + the Connected status is no. +3. Restart the mgmtsrvr process. + admin> debug software restart process management-server + +## PAN-206416 + +On the Panorama management server, no data +filtering log (MonitorLogsData Filtering) is generated +when the managed firewall loses connectivity to the following cloud services, +and as a result fails to forward matched traffic for inspection. + +- DLP cloud service +- Advanced Threat Protection inline cloud analysis service +- Advanced URL Filtering cloud service + +## PAN-206315 + +```caveat +PA-1420 firewall only +``` + +In an active/passive high +availability (HA) configuration, the show session info CLI +command shows that the passive firewall has packet rate and throughput +values. The packet rate and throughput of the passive firewall should +be zero since it is not processing traffic. + +## PAN-205009 + +```caveat +PA-1420 firewall only +``` + +In an active/passive high +availability (HA) configuration, the show interface all, show-high availability interface ha2, +and show high-availability all CLI +commands display the HSCI port state as unknown on both the active +and passive firewalls. + +## PAN-204689 + +Upon upgrade to PAN-OS 11.0.1, the following GlobalProtect settings +do not work: + +- Allow user to disconnect GlobalProtect + AppAllow with Passcode +- Allow user to Disable GlobalProtect + AppAllow with Passcode +- Allow User to Uninstall GlobalProtect + AppAllow with Password + +## PAN-201910 + +PAN-OS security profiles might consume a +large amount of memory depending on the profile configuration and +quantity. In some cases, this might reduce the number of supported security +profiles below the stated maximum for a given platform. + +## PAN-199557 + +On M-600 appliances in an Active/Passive high availability (HA) +configuration, the configd process +restarts due to a memory leak on the +Active Panorama HA peer. This +causes the Panorama web interface and CLI to become unresponsive. + +Workaround: Manually reboot the +Active Panorama HA peer. + +## PAN-197588 + +The PAN-OS ACC (Application Command Center) +does not display a widget detailing statistics and data associated +with vulnerability exploits that have been detected using inline +cloud analysis. + +## PAN-197419 + +```caveat +PA-1400 Series firewalls only +``` + +In NetworkInterfaceEthernet, the power over Ethernet +(PoE) ports do not display a Tag value. + +## PAN-197097 + +Large Scale VPN (LSVPN) does not support +IPv6 addresses on the satellite firewall. + +## PAN-196758 + +On the Panorama management server, pushing +a configuration change to firewalls leveraging SD-WAN erroneously +show the auto-provisioned BGP configurations for SD-WAN as being +edited or deleted despite no edits or deletions being made when +you Preview Changes (CommitPush to DevicesEdit Selections or CommitCommit and PushEdit Selections). + +## PAN-196146 + +The VM-Series firewall on Azure does not +boot up with a hostname (specified in an init-cgf.txt or user data) +when bootstrapped. + +## PAN-195968 + +```caveat +PA-1400 Series firewalls only +``` + +When using the CLI to configure power over Ethernet (PoE) on a non-PoE +port, the CLI prints an error depending on whether an interface +type was selected on the non-PoE port or not. If an interface type, such +as tap, Layer 2, or virtual wire, was selected before PoE was configured, +the error message will not include the interface name (eg. ethernet1/4). +If an interface type was not selected before PoE was configured, +the error message will include the interface name. + +## PAN-195342 + +On the Panorama management server, Context +Switch fails when you try to Context Switch from a managed firewall running +PAN-OS 10.1.7 or earlier release back to Panorama and the following +error is displayed: + +Could not find start token '@start@' + +## PAN-194978 + +```caveat +PA-1400 Series firewalls only +``` + +In NetworkInterfaceEthernet, hovering the mouse over +a power over Ethernet (PoE) Link State icon +does not display link speed and link duplex details. + +## PAN-194424 + +```caveat +PA-5450 firewall only +``` + +Upgrading +to PAN-OS 10.2.2 while having a log interface configured can cause +both the log interface and the management interface to remain connected +to the log collector. + +Workaround: Restart the log receiver service +by running the following CLI command: + +debug software restart process log-receiver + +## PAN-187685 + +On the Panorama management server, the Template Status +displays no synchronization status (PanoramaManaged DevicesSummary) +after a bootstrapped firewall is successfully added to Panorama. + +Workaround: After +the bootstrapped firewall is successfully added to Panorama, log in to the Panorama web interface and +select CommitPush +to Devices. + +## PAN-187407 + +The configured Advanced Threat Prevention +inline cloud analysis action for a given model might not be honored +under the following condition: If the firewall is set to Hold +client request for category lookup and the action set +to Reset-Both and the URL cache has been +cleared, the first request for inline cloud analysis will be bypassed. + +## PAN-186283 + +Templates appear out-of-sync on Panorama +after successfully deploying the CFT stack using the Panorama plugin for +AWS. + +Workaround: Use CommitPush to Devices to synchronize +the templates. + +## PAN-184708 + +```caveat +Panorama managed firewalls +``` + +Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: + +- A scheduled report email contains + a Report Group (MonitorPDF + ReportsReport Group) + which includes a SaaS Application Usage report. +- A scheduled report contains only a SaaS Application Usage Report. + +Workaround: To +receive a scheduled report email for all other PDF report types: + +1. Select MonitorPDF ReportsReport Groups and + remove all SaaS Application Usage reports from all Report Groups. +2. Select MonitorPDF + ReportsEmail Scheduler and + edit the scheduled report email that contains only a SaaS Application Usage + report. For the Recurrence, select Disable and + click OK. + Repeat this step for all scheduled + report emails that contain only a SaaS Application Usage report. +3. Commit. + () + Select CommitCommit + and Push + +## PAN-184406 + +Using the CLI to add a RAID disk pair to +an M-700 appliance causes the dmdb process to crash. + +Workaround: Contact +customer support to stop the dmdb process before adding a RAID disk +pair to a M-700 appliance. + +## PAN-183404 + +Static IP addresses are not recognized when +"and" operators are used with IP CIDR range. + +## PAN-182734 + +On an Advanced Routing Engine, if you change +the IPSec tunnel configuration, BGP flaps. + +## PAN-181933 + +If you use multiple log forwarding cards +(LFCs) on the PA-7000 series, all of the cards may not receive all +of the updates and the mappings for the clients may become out of sync, +which causes the firewall to not correctly populate the Source User +column in the session logs. + +## PAN-171938 + +No results are displayed when you Show Application +Filter for a Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). + +## PAN-164885 + +On the Panorama management server, pushes to managed firewalls (CommitPush to Devices or Commit and Push) may fail +when an EDL (ObjectsExternal Dynamic Lists) is configured to Check for +updates every 5 minutes due to the commit and EDL +fetch processes overlapping. This is more likely to occur when +multiple EDLs are configured to check for updates every 5 +minutes. diff --git a/web/data/issues/PAN-OS/known/11.0.2_2026-03-16.md b/web/data/issues/PAN-OS/known/11.0.2_2026-03-16.md new file mode 100644 index 0000000..7ddf290 --- /dev/null +++ b/web/data/issues/PAN-OS/known/11.0.2_2026-03-16.md @@ -0,0 +1,657 @@ +--- +type: Known +product: PAN-OS +version: 11.0.2 +--- + +## WF500-5632 + +The number of registered WildFire appliances +reported in Panorama (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the +current status of connected WildFire appliances. + +## PAN-260851 + +From the NGFW or Panorama CLI, you can override the existing +application tag even if Disable Override is enabled for the +application (ObjectsApplications) tag. + +## PAN-250062 + +Device telemetry might fail at configured intervals due to bundle generation issues. + +## PAN-243951 + +On the Panorama management sever in an active/passive High +Availability (HA) configuration, managed devices (PanoramaManaged DevicesSummary) display as out-of-sync +on the passive HA peer when configuration changes are made to the +SD-WAN (PanoramaSD-WAN) configuration on the active HA peer. + +Workaround: Manually synchronize the Panorama HA peers. + +1. Log in to the Panorama web + interface on the active HA peer. +2. Select Commit and Commit to + Panorama the SD-WAN configuration changes on + the active HA peer. + On the passive HA peer, select PanoramaManaged DevicesSummary and observe that the managed devices are now + out-of-sync. +3. Log in to the primary HA peer Panorama CLI and + trigger a manual synchronization between the active and + secondary HA peers. + request high-availability sync-to-remote + running-config +4. Log back in to the active HA peer Panorama web interface and + select CommitPush to Devices and Push. + +## PAN-234408 + +Enterprise DLP cannot detect and block non-file based traffic for +ChatGPT from traffic forwarded to the DLP cloud service from an +NGFW. + +## PAN-234015 + +The X-Forwarded-For (XFF) value is not displayed in traffic logs. + +## PAN-242910 + +On the Panorama management server, Panorama administrators (PanoramaAdministrators) that are assigned a custom Panorama admin role (PanoramaAdmin Roles) with Push All Changes enabled +are unable to push configuration changes to managed firewalls when +Managed Devices and Push For +Other Admins are disabled. + +## PAN-241041 + +On the Panorama management server exporting template or template +stack variables (PanoramaTemplates) in CSV format results in an empty CSV file. + +## PAN-231507 + +On PA-1400 Series firewalls only, when an HSCI interface is used as +an HA2 interface, HA2 packets are intermittently dropped on the +passive device, which can cause the HA2 connection to flap due to +missing HA2 keepalive messages. Workaround: use data ports +configured as HA2 interface. + +## PAN-228515 + +The EleasticSearch SSH flaps on the M-600 appliance in Panorama or +Log Collector mode. This causes logs to not display on the Panorama +management server (MonitorLogs) and the Log Collector health status (PanoramaManaged CollectorsStatus) to display as degraded. + +## PAN-228273 + +On the Panorama management server in FIPS-CC mode, the ElasticSearch +cluster fails to come up and the show +log-collector-es-cluster health command displays +the status is +red. This results in log ingestion +issues for Panorama in Panorama only or Log Collector mode. + +## PAN-227344 + +On the Panorama management server, PDF Summary Reports (MonitorPDF ReportsManage PDF Summary) display no data and are blank when predefined +reports are included in the summary report. + +## PAN-225886 + +If you enable explicit proxy mode for the web proxy, intermittent +errors and unexpected TCP reconnections may occur. + +## PAN-225337 + +On the Panorama management server, the configuration push to a +multi-vsys firewall fails if you: + +1. Create a Shared and vsys-specific + device group configuration object with an indentical name. + For example, a Shared address object + called SharedAO1 and a + vsys-specific address object also called + SharedAO1. +2. Reference the Shared object in another + Shared configuration. For + example, reference the Shared address + object (SharedAO1) in a + Shared address group called + SharedAG1. +3. Use the Shared configuration object + with the reference in a vsys-specific configuration. For + example, reference the Shared address + group (SharedAG1) in a + vsys-specific policy rule. + +Workaround: Select PanoramaSetupManagement and edit the Panorama Settings to enable one of the +following: + +- Shared Unused Address and Service Objects with + Devices—This options pushes all + Shared objects, along with device + group specific objects, to managed firewalls. + This is a global setting and applies to all managed + firewalls, and may result in pushing too many configuration + objects to your managed firewalls. +- Objects defined in ancestors will take higher + precedence—This option specifies that in the event + of objects with the same name, ancestor object take + precedence over descendent objects. In this case, the + Shared objects take precedence + over the vsys-specific object. + This is a global setting and applies to all managed + firewalls. In the example above, if the IP address for the + Shared + SharedAO1 object was + 10.1.1.1 and the device + group specific SharedAO1 was + 10.2.2.2, the + 10.1.1.1 IP address takes + precedence. + +Alternatively, you can remove the duplicate address objects from the +device group configuration to allow only the +Shared objects in your configuration. + +## PAN-223488 + +Closed ElasticSearch shards are not deleted from the Panorama +M-Series and virtual appliance. This causes the ElasticSearch shard +purging to not work as expected, resulting in high disk usage. + +## PAN-223365 + +The Panorama management server is unable to query any logs if the +ElasticSearch health status for any Log Collector (PanoramaManaged Collector is degraded. + +Workaround: +Log in to the Log Collector +CLI and restart ElasticSearch. + +admindebug elasticsearch es-restart all + +## PAN-227368 + +The GlobalProtect app cannot connect to a portal or gateway and +GlobalProtect Clientless VPN users cannot access applications if +authentication takes longer than 20 seconds. + +Workaround: Increase the TCP handshake timeout to the maximum +value of 60 seconds. + +## PAN-222586 + +On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter +dropdown menus, Forward Methods, and Built-In Actions for +Correlation Log settings (DeviceLog Settings) are not displayed and cannot be configured. + +## PAN-222253 + +On the Panorama management server, policy rulebase reordering when +you View Rulebase by Groups (Policy) does not persist if you reorder the policy rulebase +by dragging and dropping individual policy rules and then moving the +entire tag group. + +## PAN-221126 + +Email server profiles (DeviceServer ProfilesEmail and PanoramaServer ProfilesEmail) to forward logs as email notifications are not +forwarded in a readable format. + +Workaround: Use a Custom Log Format to +forward logs as email notifications in a readable format. + +## PAN-221015 + +On M-600 appliances in Panorama or Log Collector mode, the +es-1 and +es-2 ElasticSearch processes fail +to restart when the M-600 appliance is rebooted. The results in the +Managed Collector ES health status (PanoramaManaged CollectorsHealth Status) to be degraded. + +Workaround: +Log in to the Panorama or Log +Collector CLI experiencing degraded ElasticSearch health +and restart all ElasticSearch processes. + +admin>debug elasticsearch es-restart optional all + +Code copied to clipboard + +Unable to copy due to lack of browser support. + +Copy + +## PAN-220180 + +Configured botnet reports (MonitorBotnet) are not generated. + +## PAN-220176 + +```caveat +PAN-OS 11.0.1-h2 hotfix +``` + +System process crashes might occur +with VoIP traffic when NAT is enabled with Persistent Dynamic IP and +Port settings. + +## PAN-219644 + +Firewalls forwarding logs to a syslog server over TLS (ObjectsLog Forwarding) use the default Palo Alto Networks certificate +instead of the custom certificate configured on the firewall. + +## PAN-218521 + +The ElasticSearch process on the M-600 appliance in Log Collector +mode may enter a continuous reboot cycle. This results in the M-600 +appliance becoming unresponsive, consuming logging disk space, and +preventing new log ingestion. + +## PAN-217307 + +The following Security policy rule (PoliciesSecurity) filters return no results: + +log-start eq no + +log-end eq no + +log-end eq yes + +## PAN-216314 + +Upon upgrade or downgrade to or from PAN-OS 10.1.9 or 10.1.9-h1, +offloaded application traffic sessions may disconnect after a period +of time even if a session is active. The disconnect occurs after the +application's default session timeout value is exceeded. This +behavior affects only PAN-OS 10.1.9 and 10.1.9-h1. If you are on +PAN-OS 10.1.9 and 10.1.9-h1, please use the following workaround. If +you have already upgraded or downgraded to another PAN-OS version, +use the following workaround in that version. + +Workaround: Run the CLI command debug dataplane +internal pdt fe100 csr wr_sem_ctrl_ctr_scan_dis value +0 to set the value to zero (0). + +## PAN-216214 + +For Panorama-managed firewalls in an Active/Active High Availability +(HA) configuration where you configure the firewall HA settings (DeviceHigh Availability) in a template or template stack (PanoramaTemplates), performing a local commit on one of the HA +firewalls triggers an HA config sync on the peer firewall. This +causes the HA peer configuration to go Out of +Sync. + +## PAN-213746 + +On the Panorama management server, the Hostkey +displayed as undefined undefined if you +override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template +Stack. + +## PAN-213119 + +PA-5410 and PA-5420 firewalls display the following error when you +view the Block IP list (MonitorBlock IP): + +show -> dis-block-table is +unexpected + +## PAN-212978 + +The Palo Alto Networks firewall stops responding when executing an +SD-WAN debug operational CLI command. + +## PAN-212889 + +On the Panorama management server, different threat names are used +when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the +ACC displaying no data to display when +you are redirected to the ACC after clicking a threat name in the +Threat Monitor and filtering the same threat name in the Global +Filters. + +## PAN-211531 + +On the Panorama management server, admins can still +perform a selective push to managed firewalls when Push All +Changes and Push for Other Admins +are disabled in the admin role profile (PanoramaAdmin Roles). + +## PAN-207770 + +Data filtering logs (MonitorLogsData Filtering) +incorrectly display the traffic Direction as server-to-client instead +of client-to-server for upload traffic +that matches Enterprise data loss prevention (DLP) data patterns (ObjectsDLPData +Filtering Patterns) in an Enterprise DLP data +filtering profile (ObjectsDLPData Filtering Profiles). + +## PAN-207733 + +When a DHCPv6 client is configured on HA +Active/Passive firewalls, if the DHCPv6 server goes down, after +the lease time expires, the DHCPv6 client should enter SOLICIT state +on both the Active and Passive firewalls. Instead, the client is +stuck in BOUND state with an IPv6 address having lease time 0 on +the Passive firewall. + +## PAN-207616 + +On the Panorama management server, after +selecting managed firewalls and creating a new Tag (PanoramaManaged DevicesSummary) the managed firewalls are +automatically unselected and any new tag created is applied to the +managed firewalls for which you initially created the new tag. + +Workaround: Select +and then unselect the managed firewalls for which you created a +new tag. + +## PAN-207611 + +When a DHCPv6 client is configured on HA +Active/Passive firewalls, the Passive firewall sometimes crashes. + +## PAN-207442 + +For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the +active-primary HA peer +configuration sync to the +secondary-passive HA peer may fail. +When the config sync fails, the job Results is +Successful +(Tasks), however the sync status on the +Dashboard displays as Out +of Sync for both HA peers. + +Workaround: Perform a local commit on the +active-primary HA peer and then +synchronize the HA configuration. + +1. Log in to the Panorama + web interface of the + active-primary HA peer. +2. Select Commit and Commit to + Panorama. +3. In the active-primary HA peer + Dashboard, click Sync + to Peer in the High Availability widget. + +## PAN-207040 + +If you disable Advanced Routing, remove +logical routers, and downgrade from PAN-OS 11.0.0 to a PAN-OS 10.2.x +or 10.1.x release, subsequent commits fail and SD-WAN devices on +Panorama have no Virtual Router name. + +## PAN-206913 + +When a DHCPv6 client is configured on HA +Active/Passive firewalls, releasing the IPv6 address from the client +(using Release in the UI or using the request dhcp client ipv6 release all CLI +command) releases the IPv6 address from the Active firewall, but +not the Passive firewall. + +## PAN-206909 + +The Dedicated Log Collector is unable to +reconnect to the Panorama management server if the configd process +crashes. This results in the Dedicated Log Collector losing connectivity +to Panorama despite the managed collector connection Status (PanoramaManaged Collector) +displaying connected and the managed colletor Health status displaying +as healthy. + +This results in the local Panorama config and +system logs not being forwarded to the Dedicated Log Collector. +Firewall log forwarding to the disconnected Dedicated Log Collector +is not impacted. + +Workaround: Restart the mgmtsrvr process +on the Dedicated Log Collector. + +1. Log in to the Dedicated Log Collector + CLI. +2. Confirm the Dedicated Log Collector is disconnected from + Panorama. + admin> show panorama-status + Verify + the Connected status is no. +3. Restart the mgmtsrvr process. + admin> debug software restart process management-server + +## PAN-206416 + +On the Panorama management server, no data +filtering log (MonitorLogsData Filtering) is generated +when the managed firewall loses connectivity to the following cloud services, +and as a result fails to forward matched traffic for inspection. + +- DLP cloud service +- Advanced Threat Protection inline cloud analysis service +- Advanced URL Filtering cloud service + +## PAN-206315 + +```caveat +PA-1420 firewall only +``` + +In an active/passive high +availability (HA) configuration, the show session info CLI +command shows that the passive firewall has packet rate and throughput +values. The packet rate and throughput of the passive firewall should +be zero since it is not processing traffic. + +## PAN-205009 + +```caveat +PA-1420 firewall only +``` + +In an active/passive high +availability (HA) configuration, the show interface all, show-high availability interface ha2, +and show high-availability all CLI +commands display the HSCI port state as unknown on both the active +and passive firewalls. + +## PAN-204689 + +Upon upgrade to PAN-OS 11.0.1, the following GlobalProtect settings +do not work: + +- Allow user to disconnect GlobalProtect + AppAllow with Passcode +- Allow user to Disable GlobalProtect + AppAllow with Passcode +- Allow User to Uninstall GlobalProtect + AppAllow with Password + +## PAN-201910 + +PAN-OS security profiles might consume a +large amount of memory depending on the profile configuration and +quantity. In some cases, this might reduce the number of supported security +profiles below the stated maximum for a given platform. + +## PAN-197588 + +The PAN-OS ACC (Application Command Center) +does not display a widget detailing statistics and data associated +with vulnerability exploits that have been detected using inline +cloud analysis. + +## PAN-197419 + +```caveat +PA-1400 Series firewalls only +``` + +In NetworkInterfaceEthernet, the power over Ethernet +(PoE) ports do not display a Tag value. + +## PAN-197097 + +Large Scale VPN (LSVPN) does not support +IPv6 addresses on the satellite firewall. + +## PAN-196758 + +On the Panorama management server, pushing +a configuration change to firewalls leveraging SD-WAN erroneously +show the auto-provisioned BGP configurations for SD-WAN as being +edited or deleted despite no edits or deletions being made when +you Preview Changes (CommitPush to DevicesEdit Selections or CommitCommit and PushEdit Selections). + +## PAN-196146 + +The VM-Series firewall on Azure does not +boot up with a hostname (specified in an init-cgf.txt or user data) +when bootstrapped. + +## PAN-195968 + +```caveat +PA-1400 Series firewalls only +``` + +When using the CLI to configure power over Ethernet (PoE) on a non-PoE +port, the CLI prints an error depending on whether an interface +type was selected on the non-PoE port or not. If an interface type, such +as tap, Layer 2, or virtual wire, was selected before PoE was configured, +the error message will not include the interface name (eg. ethernet1/4). +If an interface type was not selected before PoE was configured, +the error message will include the interface name. + +## PAN-195342 + +On the Panorama management server, Context +Switch fails when you try to Context Switch from a managed firewall running +PAN-OS 10.1.7 or earlier release back to Panorama and the following +error is displayed: + +Could not find start token '@start@' + +## PAN-194978 + +```caveat +PA-1400 Series firewalls only +``` + +In NetworkInterfaceEthernet, hovering the mouse over +a power over Ethernet (PoE) Link State icon +does not display link speed and link duplex details. + +## PAN-194424 + +```caveat +PA-5450 firewall only +``` + +Upgrading +to PAN-OS 10.2.2 while having a log interface configured can cause +both the log interface and the management interface to remain connected +to the log collector. + +Workaround: Restart the log receiver service +by running the following CLI command: + +debug software restart process log-receiver + +## PAN-193004 + +The Panorama management server fails to delete old IP Tag data. This +causes the /opt/pancfg partition to +reach maximum capacity which impacts Panorama performance. + +## PAN-187685 + +On the Panorama management server, the Template Status +displays no synchronization status (PanoramaManaged DevicesSummary) +after a bootstrapped firewall is successfully added to Panorama. + +Workaround: After +the bootstrapped firewall is successfully added to Panorama, log in to the Panorama web interface and +select CommitPush +to Devices. + +## PAN-187407 + +The configured Advanced Threat Prevention +inline cloud analysis action for a given model might not be honored +under the following condition: If the firewall is set to Hold +client request for category lookup and the action set +to Reset-Both and the URL cache has been +cleared, the first request for inline cloud analysis will be bypassed. + +## PAN-186283 + +Templates appear out-of-sync on Panorama +after successfully deploying the CFT stack using the Panorama plugin for +AWS. + +Workaround: Use CommitPush to Devices to synchronize +the templates. + +## PAN-184708 + +```caveat +Panorama managed firewalls +``` + +Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: + +- A scheduled report email contains + a Report Group (MonitorPDF + ReportsReport Group) + which includes a SaaS Application Usage report. +- A scheduled report contains only a SaaS Application Usage Report. + +Workaround: To +receive a scheduled report email for all other PDF report types: + +1. Select MonitorPDF ReportsReport Groups and + remove all SaaS Application Usage reports from all Report Groups. +2. Select MonitorPDF + ReportsEmail Scheduler and + edit the scheduled report email that contains only a SaaS Application Usage + report. For the Recurrence, select Disable and + click OK. + Repeat this step for all scheduled + report emails that contain only a SaaS Application Usage report. +3. Commit. + () + Select CommitCommit + and Push + +## PAN-184406 + +Using the CLI to add a RAID disk pair to +an M-700 appliance causes the dmdb process to crash. + +Workaround: Contact +customer support to stop the dmdb process before adding a RAID disk +pair to a M-700 appliance. + +## PAN-183404 + +Static IP addresses are not recognized when +"and" operators are used with IP CIDR range. + +## PAN-181933 + +If you use multiple log forwarding cards +(LFCs) on the PA-7000 series, all of the cards may not receive all +of the updates and the mappings for the clients may become out of sync, +which causes the firewall to not correctly populate the Source User +column in the session logs. + +## PAN-171938 + +No results are displayed when you Show Application +Filter for a Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). + +## PAN-164885 + +On the Panorama management server, pushes to managed firewalls (CommitPush to Devices or Commit and Push) may fail +when an EDL (ObjectsExternal Dynamic Lists) is configured to Check for +updates every 5 minutes due to the commit and EDL +fetch processes overlapping. This is more likely to occur when +multiple EDLs are configured to check for updates every 5 +minutes. diff --git a/web/data/issues/PAN-OS/known/11.0.3_2026-03-16.md b/web/data/issues/PAN-OS/known/11.0.3_2026-03-16.md new file mode 100644 index 0000000..36fa7c6 --- /dev/null +++ b/web/data/issues/PAN-OS/known/11.0.3_2026-03-16.md @@ -0,0 +1,667 @@ +--- +type: Known +product: PAN-OS +version: 11.0.3 +--- + +## WF500-5632 + +The number of registered WildFire appliances +reported in Panorama (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the +current status of connected WildFire appliances. + +## PAN-260851 + +From the NGFW or Panorama CLI, you can override the existing +application tag even if Disable Override is enabled for the +application (ObjectsApplications) tag. + +## PAN-250062 + +Device telemetry might fail at configured intervals due to bundle generation issues. + +## PAN-243951 + +On the Panorama management sever in an active/passive High +Availability (HA) configuration, managed devices (PanoramaManaged DevicesSummary) display as out-of-sync +on the passive HA peer when configuration changes are made to the +SD-WAN (PanoramaSD-WAN) configuration on the active HA peer. + +Workaround: Manually synchronize the Panorama HA peers. + +1. Log in to the Panorama web + interface on the active HA peer. +2. Select Commit and Commit to + Panorama the SD-WAN configuration changes on + the active HA peer. + On the passive HA peer, select PanoramaManaged DevicesSummary and observe that the managed devices are now + out-of-sync. +3. Log in to the primary HA peer Panorama CLI and + trigger a manual synchronization between the active and + secondary HA peers. + request high-availability sync-to-remote + running-config +4. Log back in to the active HA peer Panorama web interface and + select CommitPush to Devices and Push. + +## PAN-241536 + +On the Panorama management server, a user with an Admin Role is +unable to modify or add filters to profiles under PanoramaNetworkRoutingRouting ProfilesFilters, despite having the necessary read and write +privileges. + +## PAN-234408 + +Enterprise DLP cannot detect and block non-file based traffic for +ChatGPT from traffic forwarded to the DLP cloud service from an +NGFW. + +## PAN-234015 + +The X-Forwarded-For (XFF) value is not displayed in traffic logs. + +## PAN-242910 + +On the Panorama management server, Panorama administrators (PanoramaAdministrators) that are assigned a custom Panorama admin role (PanoramaAdmin Roles) with Push All Changes enabled +are unable to push configuration changes to managed firewalls when +Managed Devices and Push For +Other Admins are disabled. + +## PAN-242837 + +Default login credentials and SSH fail after enabling FIPS-CC Mode on +a firewall or Panorama after converting through the Maintenance +Recovery Tool (MRT). The firewall or Panorama becomes stuck and +requires a factory reset to recover. + +## PAN-241041 + +On the Panorama management server exporting template or template +stack variables (PanoramaTemplates) in CSV format results in an empty CSV file. + +## PAN-238769 + +FIPS-CC VM only. Upgrading to 10.1.10-h2 or 10.1.11 will change all +locally created security Policy actions to Deny. Re-load the back-up +config taken before upgrading or the last version to get the +previous config back. Also, Unable to login to FIPSCC Mode devices +with default credentials after converting the mode for 10.1.12 +release , 10.2.7 release , 11.1.0 , 11.1.1, 11.0.3 versions. + +## PAN-234929 + +The tabs in the ACC, such as +Network Activity, Threat +Activity, and Blocked +Activity, may not display any data when you apply a +Time filter for the Last 15 minutes, Last Hour, Last 6 Hours, or +Last 12 Hours. With the Last 24 Hours filter, the data displayed may +not be accurate. Additionally, reports run against summary logs may +not display accurate results. + +## PAN-231507 + +On PA-1400 Series firewalls only, when an HSCI interface is used as +an HA2 interface, HA2 packets are intermittently dropped on the +passive device, which can cause the HA2 connection to flap due to +missing HA2 keepalive messages. Workaround: use data ports +configured as HA2 interface. + +## PAN-228515 + +The EleasticSearch SSH flaps on the M-600 appliance in Panorama or +Log Collector mode. This causes logs to not display on the Panorama +management server (MonitorLogs) and the Log Collector health status (PanoramaManaged CollectorsStatus) to display as degraded. + +## PAN-227344 + +On the Panorama management server, PDF Summary Reports (MonitorPDF ReportsManage PDF Summary) display no data and are blank when predefined +reports are included in the summary report. + +## PAN-225886 + +If you enable explicit proxy mode for the web proxy, intermittent +errors and unexpected TCP reconnections may occur. + +## PAN-225337 + +On the Panorama management server, the configuration push to a +multi-vsys firewall fails if you: + +1. Create a Shared and vsys-specific + device group configuration object with an indentical name. + For example, a Shared address object + called SharedAO1 and a + vsys-specific address object also called + SharedAO1. +2. Reference the Shared object in another + Shared configuration. For + example, reference the Shared address + object (SharedAO1) in a + Shared address group called + SharedAG1. +3. Use the Shared configuration object + with the reference in a vsys-specific configuration. For + example, reference the Shared address + group (SharedAG1) in a + vsys-specific policy rule. + +Workaround: Select PanoramaSetupManagement and edit the Panorama Settings to enable one of the +following: + +- Shared Unused Address and Service Objects with + Devices—This options pushes all + Shared objects, along with device + group specific objects, to managed firewalls. + This is a global setting and applies to all managed + firewalls, and may result in pushing too many configuration + objects to your managed firewalls. +- Objects defined in ancestors will take higher + precedence—This option specifies that in the event + of objects with the same name, ancestor object take + precedence over descendent objects. In this case, the + Shared objects take precedence + over the vsys-specific object. + This is a global setting and applies to all managed + firewalls. In the example above, if the IP address for the + Shared + SharedAO1 object was + 10.1.1.1 and the device + group specific SharedAO1 was + 10.2.2.2, the + 10.1.1.1 IP address takes + precedence. + +Alternatively, you can remove the duplicate address objects from the +device group configuration to allow only the +Shared objects in your configuration. + +## PAN-233677 + +```caveat +PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, PA-5430, and PA-5440 firewalls +``` + +By enabling Lockless QoS feature, a +slight degradation in App-ID and Threat performance is expected. + +## PAN-223365 + +The Panorama management server is unable to query any logs if the +ElasticSearch health status for any Log Collector (PanoramaManaged Collector is degraded. + +Workaround: +Log in to the Log Collector +CLI and restart ElasticSearch. + +admindebug elasticsearch es-restart all + +## PAN-227368 + +The GlobalProtect app cannot connect to a portal or gateway and +GlobalProtect Clientless VPN users cannot access applications if +authentication takes longer than 20 seconds. + +Workaround: Increase the TCP handshake timeout to the maximum +value of 60 seconds. + +## PAN-222586 + +On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter +dropdown menus, Forward Methods, and Built-In Actions for +Correlation Log settings (DeviceLog Settings) are not displayed and cannot be configured. + +## PAN-222253 + +On the Panorama management server, policy rulebase reordering when +you View Rulebase by Groups (Policy) does not persist if you reorder the policy rulebase +by dragging and dropping individual policy rules and then moving the +entire tag group. + +## PAN-221015 + +On M-600 appliances in Panorama or Log Collector mode, the +es-1 and +es-2 ElasticSearch processes fail +to restart when the M-600 appliance is rebooted. The results in the +Managed Collector ES health status (PanoramaManaged CollectorsHealth Status) to be degraded. + +Workaround: +Log in to the Panorama or Log +Collector CLI experiencing degraded ElasticSearch health +and restart all ElasticSearch processes. + +admin>debug elasticsearch es-restart optional all + +Code copied to clipboard + +Unable to copy due to lack of browser support. + +Copy + +## PAN-220176 + +```caveat +PAN-OS 11.0.1-h2 hotfix +``` + +System process crashes might occur +with VoIP traffic when NAT is enabled with Persistent Dynamic IP and +Port settings. + +## PAN-218521 + +The ElasticSearch process on the M-600 appliance in Log Collector +mode may enter a continuous reboot cycle. This results in the M-600 +appliance becoming unresponsive, consuming logging disk space, and +preventing new log ingestion. + +## PAN-217307 + +The following Security policy rule (PoliciesSecurity) filters return no results: + +log-start eq no + +log-end eq no + +log-end eq yes + +## PAN-216314 + +Upon upgrade or downgrade to or from PAN-OS 10.1.9 or 10.1.9-h1, +offloaded application traffic sessions may disconnect after a period +of time even if a session is active. The disconnect occurs after the +application's default session timeout value is exceeded. This +behavior affects only PAN-OS 10.1.9 and 10.1.9-h1. If you are on +PAN-OS 10.1.9 and 10.1.9-h1, please use the following workaround. If +you have already upgraded or downgraded to another PAN-OS version, +use the following workaround in that version. + +Workaround: Run the CLI command debug dataplane +internal pdt fe100 csr wr_sem_ctrl_ctr_scan_dis value +0 to set the value to zero (0). + +## PAN-216214 + +For Panorama-managed firewalls in an Active/Active High Availability +(HA) configuration where you configure the firewall HA settings (DeviceHigh Availability) in a template or template stack (PanoramaTemplates), performing a local commit on one of the HA +firewalls triggers an HA config sync on the peer firewall. This +causes the HA peer configuration to go Out of +Sync. + +## PAN-213746 + +On the Panorama management server, the Hostkey +displayed as undefined undefined if you +override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template +Stack. + +## PAN-213119 + +PA-5410 and PA-5420 firewalls display the following error when you +view the Block IP list (MonitorBlock IP): + +show -> dis-block-table is +unexpected + +## PAN-212978 + +The Palo Alto Networks firewall stops responding when executing an +SD-WAN debug operational CLI command. + +## PAN-212889 + +On the Panorama management server, different threat names are used +when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the +ACC displaying no data to display when +you are redirected to the ACC after clicking a threat name in the +Threat Monitor and filtering the same threat name in the Global +Filters. + +## PAN-211531 + +On the Panorama management server, admins can still +perform a selective push to managed firewalls when Push All +Changes and Push for Other Admins +are disabled in the admin role profile (PanoramaAdmin Roles). + +## PAN-207770 + +Data filtering logs (MonitorLogsData Filtering) +incorrectly display the traffic Direction as server-to-client instead +of client-to-server for upload traffic +that matches Enterprise data loss prevention (DLP) data patterns (ObjectsDLPData +Filtering Patterns) in an Enterprise DLP data +filtering profile (ObjectsDLPData Filtering Profiles). + +## PAN-207733 + +When a DHCPv6 client is configured on HA +Active/Passive firewalls, if the DHCPv6 server goes down, after +the lease time expires, the DHCPv6 client should enter SOLICIT state +on both the Active and Passive firewalls. Instead, the client is +stuck in BOUND state with an IPv6 address having lease time 0 on +the Passive firewall. + +## PAN-207616 + +On the Panorama management server, after +selecting managed firewalls and creating a new Tag (PanoramaManaged DevicesSummary) the managed firewalls are +automatically unselected and any new tag created is applied to the +managed firewalls for which you initially created the new tag. + +Workaround: Select +and then unselect the managed firewalls for which you created a +new tag. + +## PAN-207611 + +When a DHCPv6 client is configured on HA +Active/Passive firewalls, the Passive firewall sometimes crashes. + +## PAN-207442 + +For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the +active-primary HA peer +configuration sync to the +secondary-passive HA peer may fail. +When the config sync fails, the job Results is +Successful +(Tasks), however the sync status on the +Dashboard displays as Out +of Sync for both HA peers. + +Workaround: Perform a local commit on the +active-primary HA peer and then +synchronize the HA configuration. + +1. Log in to the Panorama + web interface of the + active-primary HA peer. +2. Select Commit and Commit to + Panorama. +3. In the active-primary HA peer + Dashboard, click Sync + to Peer in the High Availability widget. + +## PAN-207040 + +If you disable Advanced Routing, remove +logical routers, and downgrade from PAN-OS 11.0.0 to a PAN-OS 10.2.x +or 10.1.x release, subsequent commits fail and SD-WAN devices on +Panorama have no Virtual Router name. + +## PAN-206913 + +When a DHCPv6 client is configured on HA +Active/Passive firewalls, releasing the IPv6 address from the client +(using Release in the UI or using the request dhcp client ipv6 release all CLI +command) releases the IPv6 address from the Active firewall, but +not the Passive firewall. + +## PAN-206909 + +The Dedicated Log Collector is unable to +reconnect to the Panorama management server if the configd process +crashes. This results in the Dedicated Log Collector losing connectivity +to Panorama despite the managed collector connection Status (PanoramaManaged Collector) +displaying connected and the managed colletor Health status displaying +as healthy. + +This results in the local Panorama config and +system logs not being forwarded to the Dedicated Log Collector. +Firewall log forwarding to the disconnected Dedicated Log Collector +is not impacted. + +Workaround: Restart the mgmtsrvr process +on the Dedicated Log Collector. + +1. Log in to the Dedicated Log Collector + CLI. +2. Confirm the Dedicated Log Collector is disconnected from + Panorama. + admin> show panorama-status + Verify + the Connected status is no. +3. Restart the mgmtsrvr process. + admin> debug software restart process management-server + +## PAN-206416 + +On the Panorama management server, no data +filtering log (MonitorLogsData Filtering) is generated +when the managed firewall loses connectivity to the following cloud services, +and as a result fails to forward matched traffic for inspection. + +- DLP cloud service +- Advanced Threat Protection inline cloud analysis service +- Advanced URL Filtering cloud service + +## PAN-206315 + +```caveat +PA-1420 firewall only +``` + +In an active/passive high +availability (HA) configuration, the show session info CLI +command shows that the passive firewall has packet rate and throughput +values. The packet rate and throughput of the passive firewall should +be zero since it is not processing traffic. + +## PAN-205009 + +```caveat +PA-1420 firewall only +``` + +In an active/passive high +availability (HA) configuration, the show interface all, show-high availability interface ha2, +and show high-availability all CLI +commands display the HSCI port state as unknown on both the active +and passive firewalls. + +## PAN-204689 + +Upon upgrade to PAN-OS 11.0.1, the following GlobalProtect settings +do not work: + +- Allow user to disconnect GlobalProtect + AppAllow with Passcode +- Allow user to Disable GlobalProtect + AppAllow with Passcode +- Allow User to Uninstall GlobalProtect + AppAllow with Password + +## PAN-201910 + +PAN-OS security profiles might consume a +large amount of memory depending on the profile configuration and +quantity. In some cases, this might reduce the number of supported security +profiles below the stated maximum for a given platform. + +## PAN-197588 + +The PAN-OS ACC (Application Command Center) +does not display a widget detailing statistics and data associated +with vulnerability exploits that have been detected using inline +cloud analysis. + +## PAN-197419 + +```caveat +PA-1400 Series firewalls only +``` + +In NetworkInterfaceEthernet, the power over Ethernet +(PoE) ports do not display a Tag value. + +## PAN-197097 + +Large Scale VPN (LSVPN) does not support +IPv6 addresses on the satellite firewall. + +## PAN-196758 + +On the Panorama management server, pushing +a configuration change to firewalls leveraging SD-WAN erroneously +show the auto-provisioned BGP configurations for SD-WAN as being +edited or deleted despite no edits or deletions being made when +you Preview Changes (CommitPush to DevicesEdit Selections or CommitCommit and PushEdit Selections). + +## PAN-196146 + +The VM-Series firewall on Azure does not +boot up with a hostname (specified in an init-cgf.txt or user data) +when bootstrapped. + +## PAN-195968 + +```caveat +PA-1400 Series firewalls only +``` + +When using the CLI to configure power over Ethernet (PoE) on a non-PoE +port, the CLI prints an error depending on whether an interface +type was selected on the non-PoE port or not. If an interface type, such +as tap, Layer 2, or virtual wire, was selected before PoE was configured, +the error message will not include the interface name (eg. ethernet1/4). +If an interface type was not selected before PoE was configured, +the error message will include the interface name. + +## PAN-195342 + +On the Panorama management server, Context +Switch fails when you try to Context Switch from a managed firewall running +PAN-OS 10.1.7 or earlier release back to Panorama and the following +error is displayed: + +Could not find start token '@start@' + +## PAN-194978 + +```caveat +PA-1400 Series firewalls only +``` + +In NetworkInterfaceEthernet, hovering the mouse over +a power over Ethernet (PoE) Link State icon +does not display link speed and link duplex details. + +## PAN-194424 + +```caveat +PA-5450 firewall only +``` + +Upgrading +to PAN-OS 10.2.2 while having a log interface configured can cause +both the log interface and the management interface to remain connected +to the log collector. + +Workaround: Restart the log receiver service +by running the following CLI command: + +debug software restart process log-receiver + +## PAN-193004 + +The Panorama management server fails to delete old IP Tag data. This +causes the /opt/pancfg partition to +reach maximum capacity which impacts Panorama performance. + +## PAN-187685 + +On the Panorama management server, the Template Status +displays no synchronization status (PanoramaManaged DevicesSummary) +after a bootstrapped firewall is successfully added to Panorama. + +Workaround: After +the bootstrapped firewall is successfully added to Panorama, log in to the Panorama web interface and +select CommitPush +to Devices. + +## PAN-187407 + +The configured Advanced Threat Prevention +inline cloud analysis action for a given model might not be honored +under the following condition: If the firewall is set to Hold +client request for category lookup and the action set +to Reset-Both and the URL cache has been +cleared, the first request for inline cloud analysis will be bypassed. + +## PAN-186283 + +Templates appear out-of-sync on Panorama +after successfully deploying the CFT stack using the Panorama plugin for +AWS. + +Workaround: Use CommitPush to Devices to synchronize +the templates. + +## PAN-184708 + +```caveat +Panorama managed firewalls +``` + +Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: + +- A scheduled report email contains + a Report Group (MonitorPDF + ReportsReport Group) + which includes a SaaS Application Usage report. +- A scheduled report contains only a SaaS Application Usage Report. + +Workaround: To +receive a scheduled report email for all other PDF report types: + +1. Select MonitorPDF ReportsReport Groups and + remove all SaaS Application Usage reports from all Report Groups. +2. Select MonitorPDF + ReportsEmail Scheduler and + edit the scheduled report email that contains only a SaaS Application Usage + report. For the Recurrence, select Disable and + click OK. + Repeat this step for all scheduled + report emails that contain only a SaaS Application Usage report. +3. Commit. + () + Select CommitCommit + and Push + +## PAN-184406 + +Using the CLI to add a RAID disk pair to +an M-700 appliance causes the dmdb process to crash. + +Workaround: Contact +customer support to stop the dmdb process before adding a RAID disk +pair to a M-700 appliance. + +## PAN-183404 + +Static IP addresses are not recognized when +"and" operators are used with IP CIDR range. + +## PAN-181933 + +If you use multiple log forwarding cards +(LFCs) on the PA-7000 series, all of the cards may not receive all +of the updates and the mappings for the clients may become out of sync, +which causes the firewall to not correctly populate the Source User +column in the session logs. + +## PAN-171938 + +No results are displayed when you Show Application +Filter for a Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). + +## PAN-164885 + +On the Panorama management server, pushes to managed firewalls (CommitPush to Devices or Commit and Push) may fail +when an EDL (ObjectsExternal Dynamic Lists) is configured to Check for +updates every 5 minutes due to the commit and EDL +fetch processes overlapping. This is more likely to occur when +multiple EDLs are configured to check for updates every 5 +minutes. diff --git a/web/data/issues/PAN-OS/known/11.0.4_2026-03-16.md b/web/data/issues/PAN-OS/known/11.0.4_2026-03-16.md new file mode 100644 index 0000000..a5958c7 --- /dev/null +++ b/web/data/issues/PAN-OS/known/11.0.4_2026-03-16.md @@ -0,0 +1,493 @@ +--- +type: Known +product: PAN-OS +version: 11.0.4 +--- + +## WF500-5632 + +The number of registered WildFire appliances +reported in Panorama (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the +current status of connected WildFire appliances. + +## PAN-260851 + +From the NGFW or Panorama CLI, you can override the existing +application tag even if Disable Override is enabled for the +application (ObjectsApplications) tag. + +## PAN-234015 + +The X-Forwarded-For (XFF) value is not displayed in traffic logs. + +## PAN-252744 + +After upgrading PA-3200 Series, PA-5200 Series, or PA-7000 Series +firewalls that are equipped with OCTEON 7x00 dataplane chips to +PAN-OS 11.0.4 or 11.0.4-h1, the firewall might see continuous +crashes, reboot repeatedly, and/or go into a non-functional +state. + +Workaround: If you have already upgraded to one of those +releases, downgrade to an earlier release or upgrade to PAN-OS +11.0.4-h2. + +## PAN-241041 + +On the Panorama management server exporting template or template +stack variables (PanoramaTemplates) in CSV format results in an empty CSV file. + +## PAN-234929 + +The tabs in the ACC, such as +Network Activity, Threat +Activity, and Blocked +Activity, may not display any data when you apply a +Time filter for the Last 15 minutes, Last Hour, Last 6 Hours, or +Last 12 Hours. With the Last 24 Hours filter, the data displayed may +not be accurate. Additionally, reports run against summary logs may +not display accurate results. + +## PAN-225886 + +If you enable explicit proxy mode for the web proxy, intermittent +errors and unexpected TCP reconnections may occur. + +## PAN-233677 + +```caveat +PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, PA-5430, and PA-5440 firewalls +``` + +By enabling Lockless QoS feature, a +slight degradation in App-ID and Threat performance is expected. + +## PAN-222586 + +On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter +dropdown menus, Forward Methods, and Built-In Actions for +Correlation Log settings (DeviceLog Settings) are not displayed and cannot be configured. + +## PAN-222253 + +On the Panorama management server, policy rulebase reordering when +you View Rulebase by Groups (Policy) does not persist if you reorder the policy rulebase +by dragging and dropping individual policy rules and then moving the +entire tag group. + +## PAN-221033 + +The firewall is responding to an ARP request for an IP address in the +firewall's NAT address pool when that IP address isn't in the same +subnet as the IP address of the ingress interface. + +## PAN-220176 + +```caveat +PAN-OS 11.0.1-h2 hotfix +``` + +System process crashes might occur +with VoIP traffic when NAT is enabled with Persistent Dynamic IP and +Port settings. + +## PAN-218521 + +The ElasticSearch process on the M-600 appliance in Log Collector +mode may enter a continuous reboot cycle. This results in the M-600 +appliance becoming unresponsive, consuming logging disk space, and +preventing new log ingestion. + +## PAN-216314 + +Upon upgrade or downgrade to or from PAN-OS 10.1.9 or 10.1.9-h1, +offloaded application traffic sessions may disconnect after a period +of time even if a session is active. The disconnect occurs after the +application's default session timeout value is exceeded. This +behavior affects only PAN-OS 10.1.9 and 10.1.9-h1. If you are on +PAN-OS 10.1.9 and 10.1.9-h1, please use the following workaround. If +you have already upgraded or downgraded to another PAN-OS version, +use the following workaround in that version. + +Workaround: Run the CLI command debug dataplane +internal pdt fe100 csr wr_sem_ctrl_ctr_scan_dis value +0 to set the value to zero (0). + +## PAN-216214 + +For Panorama-managed firewalls in an Active/Active High Availability +(HA) configuration where you configure the firewall HA settings (DeviceHigh Availability) in a template or template stack (PanoramaTemplates), performing a local commit on one of the HA +firewalls triggers an HA config sync on the peer firewall. This +causes the HA peer configuration to go Out of +Sync. + +## PAN-213746 + +On the Panorama management server, the Hostkey +displayed as undefined undefined if you +override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template +Stack. + +## PAN-213119 + +PA-5410 and PA-5420 firewalls display the following error when you +view the Block IP list (MonitorBlock IP): + +show -> dis-block-table is +unexpected + +## PAN-212978 + +The Palo Alto Networks firewall stops responding when executing an +SD-WAN debug operational CLI command. + +## PAN-212889 + +On the Panorama management server, different threat names are used +when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the +ACC displaying no data to display when +you are redirected to the ACC after clicking a threat name in the +Threat Monitor and filtering the same threat name in the Global +Filters. + +## PAN-211531 + +On the Panorama management server, admins can still +perform a selective push to managed firewalls when Push All +Changes and Push for Other Admins +are disabled in the admin role profile (PanoramaAdmin Roles). + +## PAN-207770 + +Data filtering logs (MonitorLogsData Filtering) +incorrectly display the traffic Direction as server-to-client instead +of client-to-server for upload traffic +that matches Enterprise data loss prevention (DLP) data patterns (ObjectsDLPData +Filtering Patterns) in an Enterprise DLP data +filtering profile (ObjectsDLPData Filtering Profiles). + +## PAN-207733 + +When a DHCPv6 client is configured on HA +Active/Passive firewalls, if the DHCPv6 server goes down, after +the lease time expires, the DHCPv6 client should enter SOLICIT state +on both the Active and Passive firewalls. Instead, the client is +stuck in BOUND state with an IPv6 address having lease time 0 on +the Passive firewall. + +## PAN-207616 + +On the Panorama management server, after +selecting managed firewalls and creating a new Tag (PanoramaManaged DevicesSummary) the managed firewalls are +automatically unselected and any new tag created is applied to the +managed firewalls for which you initially created the new tag. + +Workaround: Select +and then unselect the managed firewalls for which you created a +new tag. + +## PAN-207611 + +When a DHCPv6 client is configured on HA +Active/Passive firewalls, the Passive firewall sometimes crashes. + +## PAN-207442 + +For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the +active-primary HA peer +configuration sync to the +secondary-passive HA peer may fail. +When the config sync fails, the job Results is +Successful +(Tasks), however the sync status on the +Dashboard displays as Out +of Sync for both HA peers. + +Workaround: Perform a local commit on the +active-primary HA peer and then +synchronize the HA configuration. + +1. Log in to the Panorama + web interface of the + active-primary HA peer. +2. Select Commit and Commit to + Panorama. +3. In the active-primary HA peer + Dashboard, click Sync + to Peer in the High Availability widget. + +## PAN-207040 + +If you disable Advanced Routing, remove +logical routers, and downgrade from PAN-OS 11.0.0 to a PAN-OS 10.2.x +or 10.1.x release, subsequent commits fail and SD-WAN devices on +Panorama have no Virtual Router name. + +## PAN-206913 + +When a DHCPv6 client is configured on HA +Active/Passive firewalls, releasing the IPv6 address from the client +(using Release in the UI or using the request dhcp client ipv6 release all CLI +command) releases the IPv6 address from the Active firewall, but +not the Passive firewall. + +## PAN-206909 + +The Dedicated Log Collector is unable to +reconnect to the Panorama management server if the configd process +crashes. This results in the Dedicated Log Collector losing connectivity +to Panorama despite the managed collector connection Status (PanoramaManaged Collector) +displaying connected and the managed colletor Health status displaying +as healthy. + +This results in the local Panorama config and +system logs not being forwarded to the Dedicated Log Collector. +Firewall log forwarding to the disconnected Dedicated Log Collector +is not impacted. + +Workaround: Restart the mgmtsrvr process +on the Dedicated Log Collector. + +1. Log in to the Dedicated Log Collector + CLI. +2. Confirm the Dedicated Log Collector is disconnected from + Panorama. + admin> show panorama-status + Verify + the Connected status is no. +3. Restart the mgmtsrvr process. + admin> debug software restart process management-server + +## PAN-206416 + +On the Panorama management server, no data +filtering log (MonitorLogsData Filtering) is generated +when the managed firewall loses connectivity to the following cloud services, +and as a result fails to forward matched traffic for inspection. + +- DLP cloud service +- Advanced Threat Protection inline cloud analysis service +- Advanced URL Filtering cloud service + +## PAN-206315 + +```caveat +PA-1420 firewall only +``` + +In an active/passive high +availability (HA) configuration, the show session info CLI +command shows that the passive firewall has packet rate and throughput +values. The packet rate and throughput of the passive firewall should +be zero since it is not processing traffic. + +## PAN-205009 + +```caveat +PA-1420 firewall only +``` + +In an active/passive high +availability (HA) configuration, the show interface all, show-high availability interface ha2, +and show high-availability all CLI +commands display the HSCI port state as unknown on both the active +and passive firewalls. + +## PAN-204689 + +Upon upgrade to PAN-OS 11.0.1, the following GlobalProtect settings +do not work: + +- Allow user to disconnect GlobalProtect + AppAllow with Passcode +- Allow user to Disable GlobalProtect + AppAllow with Passcode +- Allow User to Uninstall GlobalProtect + AppAllow with Password + +## PAN-201910 + +PAN-OS security profiles might consume a +large amount of memory depending on the profile configuration and +quantity. In some cases, this might reduce the number of supported security +profiles below the stated maximum for a given platform. + +## PAN-197588 + +The PAN-OS ACC (Application Command Center) +does not display a widget detailing statistics and data associated +with vulnerability exploits that have been detected using inline +cloud analysis. + +## PAN-197419 + +```caveat +PA-1400 Series firewalls only +``` + +In NetworkInterfaceEthernet, the power over Ethernet +(PoE) ports do not display a Tag value. + +## PAN-197097 + +Large Scale VPN (LSVPN) does not support +IPv6 addresses on the satellite firewall. + +## PAN-196758 + +On the Panorama management server, pushing +a configuration change to firewalls leveraging SD-WAN erroneously +show the auto-provisioned BGP configurations for SD-WAN as being +edited or deleted despite no edits or deletions being made when +you Preview Changes (CommitPush to DevicesEdit Selections or CommitCommit and PushEdit Selections). + +## PAN-196146 + +The VM-Series firewall on Azure does not +boot up with a hostname (specified in an init-cgf.txt or user data) +when bootstrapped. + +## PAN-195968 + +```caveat +PA-1400 Series firewalls only +``` + +When using the CLI to configure power over Ethernet (PoE) on a non-PoE +port, the CLI prints an error depending on whether an interface +type was selected on the non-PoE port or not. If an interface type, such +as tap, Layer 2, or virtual wire, was selected before PoE was configured, +the error message will not include the interface name (eg. ethernet1/4). +If an interface type was not selected before PoE was configured, +the error message will include the interface name. + +## PAN-195342 + +On the Panorama management server, Context +Switch fails when you try to Context Switch from a managed firewall running +PAN-OS 10.1.7 or earlier release back to Panorama and the following +error is displayed: + +Could not find start token '@start@' + +## PAN-194978 + +```caveat +PA-1400 Series firewalls only +``` + +In NetworkInterfaceEthernet, hovering the mouse over +a power over Ethernet (PoE) Link State icon +does not display link speed and link duplex details. + +## PAN-194424 + +```caveat +PA-5450 firewall only +``` + +Upgrading +to PAN-OS 10.2.2 while having a log interface configured can cause +both the log interface and the management interface to remain connected +to the log collector. + +Workaround: Restart the log receiver service +by running the following CLI command: + +debug software restart process log-receiver + +## PAN-187685 + +On the Panorama management server, the Template Status +displays no synchronization status (PanoramaManaged DevicesSummary) +after a bootstrapped firewall is successfully added to Panorama. + +Workaround: After +the bootstrapped firewall is successfully added to Panorama, log in to the Panorama web interface and +select CommitPush +to Devices. + +## PAN-187407 + +The configured Advanced Threat Prevention +inline cloud analysis action for a given model might not be honored +under the following condition: If the firewall is set to Hold +client request for category lookup and the action set +to Reset-Both and the URL cache has been +cleared, the first request for inline cloud analysis will be bypassed. + +## PAN-186283 + +Templates appear out-of-sync on Panorama +after successfully deploying the CFT stack using the Panorama plugin for +AWS. + +Workaround: Use CommitPush to Devices to synchronize +the templates. + +## PAN-184708 + +```caveat +Panorama managed firewalls +``` + +Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: + +- A scheduled report email contains + a Report Group (MonitorPDF + ReportsReport Group) + which includes a SaaS Application Usage report. +- A scheduled report contains only a SaaS Application Usage Report. + +Workaround: To +receive a scheduled report email for all other PDF report types: + +1. Select MonitorPDF ReportsReport Groups and + remove all SaaS Application Usage reports from all Report Groups. +2. Select MonitorPDF + ReportsEmail Scheduler and + edit the scheduled report email that contains only a SaaS Application Usage + report. For the Recurrence, select Disable and + click OK. + Repeat this step for all scheduled + report emails that contain only a SaaS Application Usage report. +3. Commit. + () + Select CommitCommit + and Push + +## PAN-184406 + +Using the CLI to add a RAID disk pair to +an M-700 appliance causes the dmdb process to crash. + +Workaround: Contact +customer support to stop the dmdb process before adding a RAID disk +pair to a M-700 appliance. + +## PAN-183404 + +Static IP addresses are not recognized when +"and" operators are used with IP CIDR range. + +## PAN-181933 + +If you use multiple log forwarding cards +(LFCs) on the PA-7000 series, all of the cards may not receive all +of the updates and the mappings for the clients may become out of sync, +which causes the firewall to not correctly populate the Source User +column in the session logs. + +## PAN-171938 + +No results are displayed when you Show Application +Filter for a Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). + +## PAN-164885 + +On the Panorama management server, pushes to managed firewalls (CommitPush to Devices or Commit and Push) may fail +when an EDL (ObjectsExternal Dynamic Lists) is configured to Check for +updates every 5 minutes due to the commit and EDL +fetch processes overlapping. This is more likely to occur when +multiple EDLs are configured to check for updates every 5 +minutes. diff --git a/web/data/issues/PAN-OS/known/11.0.5_2026-03-16.md b/web/data/issues/PAN-OS/known/11.0.5_2026-03-16.md new file mode 100644 index 0000000..16ff67f --- /dev/null +++ b/web/data/issues/PAN-OS/known/11.0.5_2026-03-16.md @@ -0,0 +1,471 @@ +--- +type: Known +product: PAN-OS +version: 11.0.5 +--- + +## WF500-5632 + +The number of registered WildFire appliances +reported in Panorama (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the +current status of connected WildFire appliances. + +## PAN-260851 + +From the NGFW or Panorama CLI, you can override the existing +application tag even if Disable Override is enabled for the +application (ObjectsApplications) tag. + +## PAN-250062 + +Device telemetry might fail at configured intervals due to bundle generation issues. + +## PAN-234015 + +The X-Forwarded-For (XFF) value is not displayed in traffic logs. + +## PAN-252744 + +After upgrading PA-3200 Series, PA-5200 Series, or PA-7000 Series +firewalls that are equipped with OCTEON 7x00 dataplane chips to +PAN-OS 11.0.4 or 11.0.4-h1, the firewall might see continuous +crashes, reboot repeatedly, and/or go into a non-functional +state. + +Workaround: If you have already upgraded to one of those +releases, downgrade to an earlier release or upgrade to PAN-OS +11.0.4-h2. + +## PAN-241041 + +On the Panorama management server exporting template or template +stack variables (PanoramaTemplates) in CSV format results in an empty CSV file. + +## PAN-234929 + +The tabs in the ACC, such as +Network Activity, Threat +Activity, and Blocked +Activity, may not display any data when you apply a +Time filter for the Last 15 minutes, Last Hour, Last 6 Hours, or +Last 12 Hours. With the Last 24 Hours filter, the data displayed may +not be accurate. Additionally, reports run against summary logs may +not display accurate results. + +## PAN-225886 + +If you enable explicit proxy mode for the web proxy, intermittent +errors and unexpected TCP reconnections may occur. + +## PAN-233677 + +```caveat +PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, PA-5430, and PA-5440 firewalls +``` + +By enabling Lockless QoS feature, a +slight degradation in App-ID and Threat performance is expected. + +## PAN-222586 + +On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter +dropdown menus, Forward Methods, and Built-In Actions for +Correlation Log settings (DeviceLog Settings) are not displayed and cannot be configured. + +## PAN-220176 + +```caveat +PAN-OS 11.0.1-h2 hotfix +``` + +System process crashes might occur +with VoIP traffic when NAT is enabled with Persistent Dynamic IP and +Port settings. + +## PAN-216314 + +Upon upgrade or downgrade to or from PAN-OS 10.1.9 or 10.1.9-h1, +offloaded application traffic sessions may disconnect after a period +of time even if a session is active. The disconnect occurs after the +application's default session timeout value is exceeded. This +behavior affects only PAN-OS 10.1.9 and 10.1.9-h1. If you are on +PAN-OS 10.1.9 and 10.1.9-h1, please use the following workaround. If +you have already upgraded or downgraded to another PAN-OS version, +use the following workaround in that version. + +Workaround: Run the CLI command debug dataplane +internal pdt fe100 csr wr_sem_ctrl_ctr_scan_dis value +0 to set the value to zero (0). + +## PAN-216214 + +For Panorama-managed firewalls in an Active/Active High Availability +(HA) configuration where you configure the firewall HA settings (DeviceHigh Availability) in a template or template stack (PanoramaTemplates), performing a local commit on one of the HA +firewalls triggers an HA config sync on the peer firewall. This +causes the HA peer configuration to go Out of +Sync. + +## PAN-213746 + +On the Panorama management server, the Hostkey +displayed as undefined undefined if you +override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template +Stack. + +## PAN-213119 + +PA-5410 and PA-5420 firewalls display the following error when you +view the Block IP list (MonitorBlock IP): + +show -> dis-block-table is +unexpected + +## PAN-212978 + +The Palo Alto Networks firewall stops responding when executing an +SD-WAN debug operational CLI command. + +## PAN-212889 + +On the Panorama management server, different threat names are used +when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the +ACC displaying no data to display when +you are redirected to the ACC after clicking a threat name in the +Threat Monitor and filtering the same threat name in the Global +Filters. + +## PAN-211531 + +On the Panorama management server, admins can still +perform a selective push to managed firewalls when Push All +Changes and Push for Other Admins +are disabled in the admin role profile (PanoramaAdmin Roles). + +## PAN-207770 + +Data filtering logs (MonitorLogsData Filtering) +incorrectly display the traffic Direction as server-to-client instead +of client-to-server for upload traffic +that matches Enterprise data loss prevention (DLP) data patterns (ObjectsDLPData +Filtering Patterns) in an Enterprise DLP data +filtering profile (ObjectsDLPData Filtering Profiles). + +## PAN-207733 + +When a DHCPv6 client is configured on HA +Active/Passive firewalls, if the DHCPv6 server goes down, after +the lease time expires, the DHCPv6 client should enter SOLICIT state +on both the Active and Passive firewalls. Instead, the client is +stuck in BOUND state with an IPv6 address having lease time 0 on +the Passive firewall. + +## PAN-207616 + +On the Panorama management server, after +selecting managed firewalls and creating a new Tag (PanoramaManaged DevicesSummary) the managed firewalls are +automatically unselected and any new tag created is applied to the +managed firewalls for which you initially created the new tag. + +Workaround: Select +and then unselect the managed firewalls for which you created a +new tag. + +## PAN-207611 + +When a DHCPv6 client is configured on HA +Active/Passive firewalls, the Passive firewall sometimes crashes. + +## PAN-207442 + +For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the +active-primary HA peer +configuration sync to the +secondary-passive HA peer may fail. +When the config sync fails, the job Results is +Successful +(Tasks), however the sync status on the +Dashboard displays as Out +of Sync for both HA peers. + +Workaround: Perform a local commit on the +active-primary HA peer and then +synchronize the HA configuration. + +1. Log in to the Panorama + web interface of the + active-primary HA peer. +2. Select Commit and Commit to + Panorama. +3. In the active-primary HA peer + Dashboard, click Sync + to Peer in the High Availability widget. + +## PAN-207040 + +If you disable Advanced Routing, remove +logical routers, and downgrade from PAN-OS 11.0.0 to a PAN-OS 10.2.x +or 10.1.x release, subsequent commits fail and SD-WAN devices on +Panorama have no Virtual Router name. + +## PAN-206913 + +When a DHCPv6 client is configured on HA +Active/Passive firewalls, releasing the IPv6 address from the client +(using Release in the UI or using the request dhcp client ipv6 release all CLI +command) releases the IPv6 address from the Active firewall, but +not the Passive firewall. + +## PAN-206909 + +The Dedicated Log Collector is unable to +reconnect to the Panorama management server if the configd process +crashes. This results in the Dedicated Log Collector losing connectivity +to Panorama despite the managed collector connection Status (PanoramaManaged Collector) +displaying connected and the managed colletor Health status displaying +as healthy. + +This results in the local Panorama config and +system logs not being forwarded to the Dedicated Log Collector. +Firewall log forwarding to the disconnected Dedicated Log Collector +is not impacted. + +Workaround: Restart the mgmtsrvr process +on the Dedicated Log Collector. + +1. Log in to the Dedicated Log Collector + CLI. +2. Confirm the Dedicated Log Collector is disconnected from + Panorama. + admin> show panorama-status + Verify + the Connected status is no. +3. Restart the mgmtsrvr process. + admin> debug software restart process management-server + +## PAN-206416 + +On the Panorama management server, no data +filtering log (MonitorLogsData Filtering) is generated +when the managed firewall loses connectivity to the following cloud services, +and as a result fails to forward matched traffic for inspection. + +- DLP cloud service +- Advanced Threat Protection inline cloud analysis service +- Advanced URL Filtering cloud service + +## PAN-206315 + +```caveat +PA-1420 firewall only +``` + +In an active/passive high +availability (HA) configuration, the show session info CLI +command shows that the passive firewall has packet rate and throughput +values. The packet rate and throughput of the passive firewall should +be zero since it is not processing traffic. + +## PAN-205009 + +```caveat +PA-1420 firewall only +``` + +In an active/passive high +availability (HA) configuration, the show interface all, show-high availability interface ha2, +and show high-availability all CLI +commands display the HSCI port state as unknown on both the active +and passive firewalls. + +## PAN-204689 + +Upon upgrade to PAN-OS 11.0.1, the following GlobalProtect settings +do not work: + +- Allow user to disconnect GlobalProtect + AppAllow with Passcode +- Allow user to Disable GlobalProtect + AppAllow with Passcode +- Allow User to Uninstall GlobalProtect + AppAllow with Password + +## PAN-201910 + +PAN-OS security profiles might consume a +large amount of memory depending on the profile configuration and +quantity. In some cases, this might reduce the number of supported security +profiles below the stated maximum for a given platform. + +## PAN-197588 + +The PAN-OS ACC (Application Command Center) +does not display a widget detailing statistics and data associated +with vulnerability exploits that have been detected using inline +cloud analysis. + +## PAN-197419 + +```caveat +PA-1400 Series firewalls only +``` + +In NetworkInterfaceEthernet, the power over Ethernet +(PoE) ports do not display a Tag value. + +## PAN-197097 + +Large Scale VPN (LSVPN) does not support +IPv6 addresses on the satellite firewall. + +## PAN-196758 + +On the Panorama management server, pushing +a configuration change to firewalls leveraging SD-WAN erroneously +show the auto-provisioned BGP configurations for SD-WAN as being +edited or deleted despite no edits or deletions being made when +you Preview Changes (CommitPush to DevicesEdit Selections or CommitCommit and PushEdit Selections). + +## PAN-195968 + +```caveat +PA-1400 Series firewalls only +``` + +When using the CLI to configure power over Ethernet (PoE) on a non-PoE +port, the CLI prints an error depending on whether an interface +type was selected on the non-PoE port or not. If an interface type, such +as tap, Layer 2, or virtual wire, was selected before PoE was configured, +the error message will not include the interface name (eg. ethernet1/4). +If an interface type was not selected before PoE was configured, +the error message will include the interface name. + +## PAN-195342 + +On the Panorama management server, Context +Switch fails when you try to Context Switch from a managed firewall running +PAN-OS 10.1.7 or earlier release back to Panorama and the following +error is displayed: + +Could not find start token '@start@' + +## PAN-194978 + +```caveat +PA-1400 Series firewalls only +``` + +In NetworkInterfaceEthernet, hovering the mouse over +a power over Ethernet (PoE) Link State icon +does not display link speed and link duplex details. + +## PAN-194424 + +```caveat +PA-5450 firewall only +``` + +Upgrading +to PAN-OS 10.2.2 while having a log interface configured can cause +both the log interface and the management interface to remain connected +to the log collector. + +Workaround: Restart the log receiver service +by running the following CLI command: + +debug software restart process log-receiver + +## PAN-187685 + +On the Panorama management server, the Template Status +displays no synchronization status (PanoramaManaged DevicesSummary) +after a bootstrapped firewall is successfully added to Panorama. + +Workaround: After +the bootstrapped firewall is successfully added to Panorama, log in to the Panorama web interface and +select CommitPush +to Devices. + +## PAN-187407 + +The configured Advanced Threat Prevention +inline cloud analysis action for a given model might not be honored +under the following condition: If the firewall is set to Hold +client request for category lookup and the action set +to Reset-Both and the URL cache has been +cleared, the first request for inline cloud analysis will be bypassed. + +## PAN-186283 + +Templates appear out-of-sync on Panorama +after successfully deploying the CFT stack using the Panorama plugin for +AWS. + +Workaround: Use CommitPush to Devices to synchronize +the templates. + +## PAN-184708 + +```caveat +Panorama managed firewalls +``` + +Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: + +- A scheduled report email contains + a Report Group (MonitorPDF + ReportsReport Group) + which includes a SaaS Application Usage report. +- A scheduled report contains only a SaaS Application Usage Report. + +Workaround: To +receive a scheduled report email for all other PDF report types: + +1. Select MonitorPDF ReportsReport Groups and + remove all SaaS Application Usage reports from all Report Groups. +2. Select MonitorPDF + ReportsEmail Scheduler and + edit the scheduled report email that contains only a SaaS Application Usage + report. For the Recurrence, select Disable and + click OK. + Repeat this step for all scheduled + report emails that contain only a SaaS Application Usage report. +3. Commit. + () + Select CommitCommit + and Push + +## PAN-184406 + +Using the CLI to add a RAID disk pair to +an M-700 appliance causes the dmdb process to crash. + +Workaround: Contact +customer support to stop the dmdb process before adding a RAID disk +pair to a M-700 appliance. + +## PAN-183404 + +Static IP addresses are not recognized when +"and" operators are used with IP CIDR range. + +## PAN-181933 + +If you use multiple log forwarding cards +(LFCs) on the PA-7000 series, all of the cards may not receive all +of the updates and the mappings for the clients may become out of sync, +which causes the firewall to not correctly populate the Source User +column in the session logs. + +## PAN-171938 + +No results are displayed when you Show Application +Filter for a Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). + +## PAN-164885 + +On the Panorama management server, pushes to managed firewalls (CommitPush to Devices or Commit and Push) may fail +when an EDL (ObjectsExternal Dynamic Lists) is configured to Check for +updates every 5 minutes due to the commit and EDL +fetch processes overlapping. This is more likely to occur when +multiple EDLs are configured to check for updates every 5 +minutes. diff --git a/web/data/issues/PAN-OS/known/11.0.6_2026-03-16.md b/web/data/issues/PAN-OS/known/11.0.6_2026-03-16.md new file mode 100644 index 0000000..1121b41 --- /dev/null +++ b/web/data/issues/PAN-OS/known/11.0.6_2026-03-16.md @@ -0,0 +1,471 @@ +--- +type: Known +product: PAN-OS +version: 11.0.6 +--- + +## WF500-5632 + +The number of registered WildFire appliances +reported in Panorama (PanoramaManaged WildFire AppliancesFirewalls ConnectedView) does not accurately reflect the +current status of connected WildFire appliances. + +## PAN-260851 + +From the NGFW or Panorama CLI, you can override the existing +application tag even if Disable Override is enabled for the +application (ObjectsApplications) tag. + +## PAN-250062 + +Device telemetry might fail at configured intervals due to bundle generation issues. + +## PAN-234015 + +The X-Forwarded-For (XFF) value is not displayed in traffic logs. + +## PAN-252744 + +After upgrading PA-3200 Series, PA-5200 Series, or PA-7000 Series +firewalls that are equipped with OCTEON 7x00 dataplane chips to +PAN-OS 11.0.4 or 11.0.4-h1, the firewall might see continuous +crashes, reboot repeatedly, and/or go into a non-functional +state. + +Workaround: If you have already upgraded to one of those +releases, downgrade to an earlier release or upgrade to PAN-OS +11.0.4-h2. + +## PAN-241041 + +On the Panorama management server exporting template or template +stack variables (PanoramaTemplates) in CSV format results in an empty CSV file. + +## PAN-234929 + +The tabs in the ACC, such as +Network Activity, Threat +Activity, and Blocked +Activity, may not display any data when you apply a +Time filter for the Last 15 minutes, Last Hour, Last 6 Hours, or +Last 12 Hours. With the Last 24 Hours filter, the data displayed may +not be accurate. Additionally, reports run against summary logs may +not display accurate results. + +## PAN-225886 + +If you enable explicit proxy mode for the web proxy, intermittent +errors and unexpected TCP reconnections may occur. + +## PAN-233677 + +```caveat +PA-3410, PA-3420, PA-3430, PA-3440, PA-5410, PA-5420, PA-5430, and PA-5440 firewalls +``` + +By enabling Lockless QoS feature, a +slight degradation in App-ID and Threat performance is expected. + +## PAN-222586 + +On PA-5410, PA-5420, PA-5430, and PA-5440 firewalls, the Filter +dropdown menus, Forward Methods, and Built-In Actions for +Correlation Log settings (DeviceLog Settings) are not displayed and cannot be configured. + +## PAN-220176 + +```caveat +PAN-OS 11.0.1-h2 hotfix +``` + +System process crashes might occur +with VoIP traffic when NAT is enabled with Persistent Dynamic IP and +Port settings. + +## PAN-216314 + +Upon upgrade or downgrade to or from PAN-OS 10.1.9 or 10.1.9-h1, +offloaded application traffic sessions may disconnect after a period +of time even if a session is active. The disconnect occurs after the +application's default session timeout value is exceeded. This +behavior affects only PAN-OS 10.1.9 and 10.1.9-h1. If you are on +PAN-OS 10.1.9 and 10.1.9-h1, please use the following workaround. If +you have already upgraded or downgraded to another PAN-OS version, +use the following workaround in that version. + +Workaround: Run the CLI command debug dataplane +internal pdt fe100 csr wr_sem_ctrl_ctr_scan_dis value +0 to set the value to zero (0). + +## PAN-216214 + +For Panorama-managed firewalls in an Active/Active High Availability +(HA) configuration where you configure the firewall HA settings (DeviceHigh Availability) in a template or template stack (PanoramaTemplates), performing a local commit on one of the HA +firewalls triggers an HA config sync on the peer firewall. This +causes the HA peer configuration to go Out of +Sync. + +## PAN-213746 + +On the Panorama management server, the Hostkey +displayed as undefined undefined if you +override an SSH Service Profile (DeviceCertificate ManagementSSH Service Profile) Hostkey configured in a Template from the Template +Stack. + +## PAN-213119 + +PA-5410 and PA-5420 firewalls display the following error when you +view the Block IP list (MonitorBlock IP): + +show -> dis-block-table is +unexpected + +## PAN-212978 + +The Palo Alto Networks firewall stops responding when executing an +SD-WAN debug operational CLI command. + +## PAN-212889 + +On the Panorama management server, different threat names are used +when querying the same threat in the Threat Monitor (MonitorApp ScopeThreat Monitor) and ACC. This results in the +ACC displaying no data to display when +you are redirected to the ACC after clicking a threat name in the +Threat Monitor and filtering the same threat name in the Global +Filters. + +## PAN-211531 + +On the Panorama management server, admins can still +perform a selective push to managed firewalls when Push All +Changes and Push for Other Admins +are disabled in the admin role profile (PanoramaAdmin Roles). + +## PAN-207770 + +Data filtering logs (MonitorLogsData Filtering) +incorrectly display the traffic Direction as server-to-client instead +of client-to-server for upload traffic +that matches Enterprise data loss prevention (DLP) data patterns (ObjectsDLPData +Filtering Patterns) in an Enterprise DLP data +filtering profile (ObjectsDLPData Filtering Profiles). + +## PAN-207733 + +When a DHCPv6 client is configured on HA +Active/Passive firewalls, if the DHCPv6 server goes down, after +the lease time expires, the DHCPv6 client should enter SOLICIT state +on both the Active and Passive firewalls. Instead, the client is +stuck in BOUND state with an IPv6 address having lease time 0 on +the Passive firewall. + +## PAN-207616 + +On the Panorama management server, after +selecting managed firewalls and creating a new Tag (PanoramaManaged DevicesSummary) the managed firewalls are +automatically unselected and any new tag created is applied to the +managed firewalls for which you initially created the new tag. + +Workaround: Select +and then unselect the managed firewalls for which you created a +new tag. + +## PAN-207611 + +When a DHCPv6 client is configured on HA +Active/Passive firewalls, the Passive firewall sometimes crashes. + +## PAN-207442 + +For M-700 appliances in an active/passive high availability (PanoramaHigh Availability) configuration, the +active-primary HA peer +configuration sync to the +secondary-passive HA peer may fail. +When the config sync fails, the job Results is +Successful +(Tasks), however the sync status on the +Dashboard displays as Out +of Sync for both HA peers. + +Workaround: Perform a local commit on the +active-primary HA peer and then +synchronize the HA configuration. + +1. Log in to the Panorama + web interface of the + active-primary HA peer. +2. Select Commit and Commit to + Panorama. +3. In the active-primary HA peer + Dashboard, click Sync + to Peer in the High Availability widget. + +## PAN-207040 + +If you disable Advanced Routing, remove +logical routers, and downgrade from PAN-OS 11.0.0 to a PAN-OS 10.2.x +or 10.1.x release, subsequent commits fail and SD-WAN devices on +Panorama have no Virtual Router name. + +## PAN-206913 + +When a DHCPv6 client is configured on HA +Active/Passive firewalls, releasing the IPv6 address from the client +(using Release in the UI or using the request dhcp client ipv6 release all CLI +command) releases the IPv6 address from the Active firewall, but +not the Passive firewall. + +## PAN-206909 + +The Dedicated Log Collector is unable to +reconnect to the Panorama management server if the configd process +crashes. This results in the Dedicated Log Collector losing connectivity +to Panorama despite the managed collector connection Status (PanoramaManaged Collector) +displaying connected and the managed colletor Health status displaying +as healthy. + +This results in the local Panorama config and +system logs not being forwarded to the Dedicated Log Collector. +Firewall log forwarding to the disconnected Dedicated Log Collector +is not impacted. + +Workaround: Restart the mgmtsrvr process +on the Dedicated Log Collector. + +1. Log in to the Dedicated Log Collector + CLI. +2. Confirm the Dedicated Log Collector is disconnected from + Panorama. + admin> show panorama-status + Verify + the Connected status is no. +3. Restart the mgmtsrvr process. + admin> debug software restart process management-server + +## PAN-206416 + +On the Panorama management server, no data +filtering log (MonitorLogsData Filtering) is generated +when the managed firewall loses connectivity to the following cloud services, +and as a result fails to forward matched traffic for inspection. + +- DLP cloud service +- Advanced Threat Protection inline cloud analysis service +- Advanced URL Filtering cloud service + +## PAN-206315 + +```caveat +PA-1420 firewall only +``` + +In an active/passive high +availability (HA) configuration, the show session info CLI +command shows that the passive firewall has packet rate and throughput +values. The packet rate and throughput of the passive firewall should +be zero since it is not processing traffic. + +## PAN-205009 + +```caveat +PA-1420 firewall only +``` + +In an active/passive high +availability (HA) configuration, the show interface all, show-high availability interface ha2, +and show high-availability all CLI +commands display the HSCI port state as unknown on both the active +and passive firewalls. + +## PAN-204689 + +Upon upgrade to PAN-OS 11.0.1, the following GlobalProtect settings +do not work: + +- Allow user to disconnect GlobalProtect + AppAllow with Passcode +- Allow user to Disable GlobalProtect + AppAllow with Passcode +- Allow User to Uninstall GlobalProtect + AppAllow with Password + +## PAN-201910 + +PAN-OS security profiles might consume a +large amount of memory depending on the profile configuration and +quantity. In some cases, this might reduce the number of supported security +profiles below the stated maximum for a given platform. + +## PAN-197588 + +The PAN-OS ACC (Application Command Center) +does not display a widget detailing statistics and data associated +with vulnerability exploits that have been detected using inline +cloud analysis. + +## PAN-197419 + +```caveat +PA-1400 Series firewalls only +``` + +In NetworkInterfaceEthernet, the power over Ethernet +(PoE) ports do not display a Tag value. + +## PAN-197097 + +Large Scale VPN (LSVPN) does not support +IPv6 addresses on the satellite firewall. + +## PAN-196758 + +On the Panorama management server, pushing +a configuration change to firewalls leveraging SD-WAN erroneously +show the auto-provisioned BGP configurations for SD-WAN as being +edited or deleted despite no edits or deletions being made when +you Preview Changes (CommitPush to DevicesEdit Selections or CommitCommit and PushEdit Selections). + +## PAN-195968 + +```caveat +PA-1400 Series firewalls only +``` + +When using the CLI to configure power over Ethernet (PoE) on a non-PoE +port, the CLI prints an error depending on whether an interface +type was selected on the non-PoE port or not. If an interface type, such +as tap, Layer 2, or virtual wire, was selected before PoE was configured, +the error message will not include the interface name (eg. ethernet1/4). +If an interface type was not selected before PoE was configured, +the error message will include the interface name. + +## PAN-195342 + +On the Panorama management server, Context +Switch fails when you try to Context Switch from a managed firewall running +PAN-OS 10.1.7 or earlier release back to Panorama and the following +error is displayed: + +Could not find start token '@start@' + +## PAN-194978 + +```caveat +PA-1400 Series firewalls only +``` + +In NetworkInterfaceEthernet, hovering the mouse over +a power over Ethernet (PoE) Link State icon +does not display link speed and link duplex details. + +## PAN-194424 + +```caveat +PA-5450 firewall only +``` + +Upgrading +to PAN-OS 10.2.2 while having a log interface configured can cause +both the log interface and the management interface to remain connected +to the log collector. + +Workaround: Restart the log receiver service +by running the following CLI command: + +debug software restart process log-receiver + +## PAN-187685 + +On the Panorama management server, the Template Status +displays no synchronization status (PanoramaManaged DevicesSummary) +after a bootstrapped firewall is successfully added to Panorama. + +Workaround: After +the bootstrapped firewall is successfully added to Panorama, log in to the Panorama web interface and +select CommitPush +to Devices. + +## PAN-187407 + +The configured Advanced Threat Prevention +inline cloud analysis action for a given model might not be honored +under the following condition: If the firewall is set to Hold +client request for category lookup and the action set +to Reset-Both and the URL cache has been +cleared, the first request for inline cloud analysis will be bypassed. + +## PAN-186283 + +Templates appear out-of-sync on Panorama +after successfully deploying the CFT stack using the Panorama plugin for +AWS. + +Workaround: Use CommitPush to Devices to synchronize +the templates. + +## PAN-184708 + +```caveat +Panorama managed firewalls +``` + +Scheduled report emails (MonitorPDF ReportsEmail Scheduler) are not emailed if: + +- A scheduled report email contains + a Report Group (MonitorPDF + ReportsReport Group) + which includes a SaaS Application Usage report. +- A scheduled report contains only a SaaS Application Usage Report. + +Workaround: To +receive a scheduled report email for all other PDF report types: + +1. Select MonitorPDF ReportsReport Groups and + remove all SaaS Application Usage reports from all Report Groups. +2. Select MonitorPDF + ReportsEmail Scheduler and + edit the scheduled report email that contains only a SaaS Application Usage + report. For the Recurrence, select Disable and + click OK. + Repeat this step for all scheduled + report emails that contain only a SaaS Application Usage report. +3. Commit. + () + Select CommitCommit + and Push + +## PAN-184406 + +Using the CLI to add a RAID disk pair to +an M-700 appliance causes the dmdb process to crash. + +Workaround: Contact +customer support to stop the dmdb process before adding a RAID disk +pair to a M-700 appliance. + +## PAN-183404 + +Static IP addresses are not recognized when +"and" operators are used with IP CIDR range. + +## PAN-181933 + +If you use multiple log forwarding cards +(LFCs) on the PA-7000 series, all of the cards may not receive all +of the updates and the mappings for the clients may become out of sync, +which causes the firewall to not correctly populate the Source User +column in the session logs. + +## PAN-171938 + +No results are displayed when you Show Application +Filter for a Security policy rule (PoliciesSecurityApplicationValueShow Application Filter). + +## PAN-164885 + +On the Panorama management server, pushes to managed firewalls (CommitPush to Devices or Commit and Push) may fail +when an EDL (ObjectsExternal Dynamic Lists) is configured to Check for +updates every 5 minutes due to the commit and EDL +fetch processes overlapping. This is more likely to occur when +multiple EDLs are configured to check for updates every 5 +minutes. diff --git a/web/data/products.json b/web/data/products.json index 7d4fc49..2472ff8 100644 --- a/web/data/products.json +++ b/web/data/products.json @@ -211,7 +211,15 @@ "11.0.6_2026-03-16.md", "11.0.6-h1_2026-03-16.md" ], - "known": [] + "known": [ + "11.0.0_2026-03-16.md", + "11.0.1_2026-03-16.md", + "11.0.2_2026-03-16.md", + "11.0.3_2026-03-16.md", + "11.0.4_2026-03-16.md", + "11.0.5_2026-03-16.md", + "11.0.6_2026-03-16.md" + ] } }, "10": {