Add PANOS 11.2 addressed issues

This commit is contained in:
2026-03-16 11:48:06 -05:00
parent 91bd3ba31d
commit 624befbe02
45 changed files with 7422 additions and 1 deletions
@@ -0,0 +1,9 @@
---
type: Addressed
product: PAN-OS
version: 11.2.0-h1
---
## PAN-272809
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and CVE-2024-9474.
@@ -0,0 +1,117 @@
---
type: Addressed
product: PAN-OS
version: 11.2.0
---
## PLUG-16383
```caveat
VM-Series firewalls only
```
Fixed an issue where the PAN_NET_FILE_TMP was not found after an upgrade, which caused the firewall to enter maintenance mode.
## PAN-240174
Fixed an issue where, when LSVPN serial numbers and IP address authentication were enabled, IPv6 address ranges and complete IPv6 addresses that were manually added to the IP address allow or exclude list were not usable after a restart of the gp_broker process or the firewall.
## PAN-230362
Fixed an issue where the firewall truncated the payload of a TCP Out of Order segment with a FIN flag.
## PAN-228386
Fixed an issue with session caching where the reportd process stopped responding due to null values.
## PAN-227344
Fixed an issue on Panorama where PDF Summary Reports (Monitor > PDF Reports > Manage PDF Summary) displayed no data and were blank when predefined widgets were included in the summary report.
## PAN-227305
Fixed an issue where SCEP certificate generation failed when a service route was used to reach the SCEP server.
## PAN-227224
```caveat
PA-1400 Series firewalls
```
Fixed an issue where the firewall was unable to handle GRE packets for Point-to-Point Tunneling Protocol (PPTP) connections.
## PAN-226626
Fixed an issue where the firewall generated numerous logrcvr error messages related to netflow.
## PAN-225394
Fixed an issue on the firewall where SNMP incorrectly reported high packet descriptor usage.
## PAN-225240
Fixed an issue where the OSPF neighbor state remained in exstart when the OSPF network had more than 40 routes.
## PAN-225183
Fixed an issue where SSH tunnels were unstable due to ciphers used as part of the high availability SSH configuration.
## PAN-224772
Fixed a high memory usage issue with the mongodb process that caused an OOM condition.
## PAN-224365
Fixed an issue where excessive network path monitoring messages were generated in the system logs.
## PAN-224067
Fixed an issue where cookie authentication did not work for GlobalProtect when an authentication override domain was configured in the SAML authentication profile.
## PAN-223501
Fixed an issue where diagnostic information for the dataplane in the dp-monitor.log file was not complete.
## PAN-223365
Fixed an issue where Panorama was unbale to query any logs if the Elasticsearch health status for any log collector was degraded.
## PAN-220881
Fixed an issue where the CLI command show logging-status did not correctly display the last log created and forwarded timestamps.
## PAN-220640
```caveat
PA-220 firewalls only
```
Fixed an issue where the firewall CPU percentage was miscalculated, and the values that were displayed were incorrect.
## PAN-219768
Fixed an issue where you were unable to filter Data Filtering logs with Threat ID/NAME for custom data patterns created over Panorama.
## PAN-219585
Fixed an issue where enabling syslog-ng debugs from the root caused 100% disk utilization.
## PAN-217510
Fixed an issue where inbound DHCP packets received by a DHCP client interface that were not addressed to itself were silently dropped instead of forwarded.
## PAN-208567
Fixed an issue with email formatting where, when a scheduled email contained two or more attachments, only one attachment was visible.
## PAN-207003
Fixed an issue where the logrcvr process netflow buffer was not reset which resulted in duplicate netflow records.
## PAN-202095
Fixed an issue on the web interface where the language setting is not retained.
## PLUG-16385
Fixed an issue where the file PAN_NET_FILE_TMP was missing after the upgrade causing the VM-Series firewall to go into maintenance mode.
@@ -0,0 +1,9 @@
---
type: Addressed
product: PAN-OS
version: 11.2.1-h1
---
## PAN-272809
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and CVE-2024-9474.
@@ -0,0 +1,21 @@
---
type: Addressed
product: PAN-OS
version: 11.2.10-h1
---
## PAN-306534
Fixed an issue were the all_task process repeatedly restarted due to memory pool corruption when processing fragmented DNS over HTTPs (DoH) JSON queries. This occurred due to incorrect buffer length calculations during memory deallocation when the query name field spanned multiple packets.
## PAN-305480
Fixed an issue where the pan_task process stopped responding while processing DoH JSON format traffic with DoH Security enabled, which caused missing cross-packet bytes in the decoded DNS query type field, and the dataplane went down.
## PAN-305301
Fixed an issue where GlobalProtect notifications in tunnels caused processes to stop responding and the dataplane to restart due to the session lookup returning an incorrect session, which resulted in the data being sent through the wrong tunnel.
## PAN-303836
Fixed an issue where the AIRS VM on session table reset intermittently dropped packets, which resulted in packet loss on responses to egress traffic.
@@ -0,0 +1,89 @@
---
type: Addressed
product: PAN-OS
version: 11.2.10-h2
---
## PAN-306306
```caveat
Panorama appliances in FIPS-CC mode only
```
Fixed interdevice TLS communication failures that occurred with RSA and RSA-PSS signature algorithms across multiple layer 7 application services.
## PAN-303051
Fixed an issue on Panorama where a memory leak occurred related to the reportd process due to retaining memory that was temporarily used for report generation instead of releasing the memory for reuse, which resulted in continuous accumulation and memory exhaustion.
## PAN-302927
Fixed an issue where, after upgrading Panorama, the Push to Devices option did not display selected devices, and the OK and Cancel buttons did not function as expected. Selecting OK did not close the window, and selecting Cancel returned to the main push screen with the push selected devices displaying as empty. Despite this, selecting Push or Validate Device Group Push still pushed to the previously canceled, non-displayed devices.
## PAN-301801
Fixed an issue on Log Collectors where the Elasticsearch process fluctuated intermittently between green and red states, which led to interruptions in log collection. This issue occurred when the number of shards exceeded the cluster's maximum supported threshold of greater than 1000 shards per Elasticsearch instance.
## PAN-301691
Fixed an issue where BGP stopped responding with the error message Too many open files when pushing 1000 eBGP (External BGP) neighbor configurations. With this fix, the number of file descriptors for the BGP process is increased from 1024 to 8192.
## PAN-301456
Fixed an issue on Panorama where the debug system reset-ztp CLI command was unavailable.
## PAN-300216
Fixed an issue where, when SD-WAN Direct Internet Access was configured and traffic traversed the cellular interface without a NAT policy rule, intermittent cellular modem connectivity issues occurred, which caused the firewall to disconnect and reconnect to the cellular network.
To use this fix, run the CLI command set session teardown-upon-fwd-zonechange yes.
## PAN-300138
Fixed an issue where DNS queries stalled or repeatedly time out due to multiple DNS responses with different CNAME values causing evasion false positive alerts.
## PAN-299815
Fixed an issue on multi-vsys firewalls where a host was not removed from the quarantine list after receiving a redistribution message from Panorama. This occurred when Panorama was configured to redistribute quarantine messages to a firewall cluster, and the GlobalProtect configuration and redistribution were built out in a vsys other than vsys1.
## PAN-298387
Fixed an issue on the firewall where the source and destination NAT IP addresses did not display in traffic and threat logs.
## PAN-297610
Fixed an issue where the firewall became unresponsive after an upgrade due to the fsck command scanning drive partitions in parallel with the root partition, which caused the process to take an extended amount of time.
## PAN-297005
Fixed an issue where exporting custom reports resulted in empty CSV files.
## PAN-296977
Fixed an issue where the web interface became unresponsive when attempting to view Ethernet interface details after applying a filter in NetworkInterfaces
## PAN-296694
Fixed an issue where the firewall rebooted due to the useridd process repeatedly restarting during an IP-port data type writes to the redis from multiple sources such as TSA or XML in a scale environment.
## PAN-296535
Fixed an issue on the firewall where BGP peers disconnected when more than 500 BGP neighbors were configured in a single Logical Router
## PAN-295899
Fixed an issue where DNS resolution failed on Linux machines running GlobalProtect client version 6.2.6 when connected with DNS Security enabled. This occurred because the firewall incorrectly discarded DNS packets when processing multiple DNS requests or responses over the same session, even when no malicious verdict was received.
## PAN-276525
Resolved multiple issues affecting IPSec tunnels using NAT Traversal (NAT-T) when a Dynamic NAT policy was configured (including Dynamic NAT or DIPP). During rekey events, tunnels could go down or flap due to incorrect session handling. This issue impacted both cluster and standalone deployments.
## PAN-209516
Fixed an issue where, when creating an interface, an error occurred when you clicked OK without providing a value in the Tag field even though the field was not displayed as mandatory.
## PAN-185731
Fixed an issue where the firewall was unable to parse the URL path and host when the host header was located in a different packet, which resulted in the firewall not logging the URL path in the first packet.
The fix is disabled by default. The following CLI commands can be used to enable/disable the feature: set system setting ctd url-crosspkt-host-path-caching enable set system setting ctd url-crosspkt-host-path-caching disable set system setting ctd url-crosspkt-host-path-caching default
@@ -0,0 +1,61 @@
---
type: Addressed
product: PAN-OS
version: 11.2.10-h3
---
## PAN-307901
Fixed an issue where a leak in decryption counters caused resource exhaustion, which led to a GlobalProtect service outage.
## PAN-307702
```caveat
Firewalls in HA configurations only
```
Fixed an issue where traffic passing through AE layer 2 interfaces was interrupted during HA failovers.
## PAN-306451
```caveat
VM-Series firewalls on AWS environments only
```
Fixed an issue where, after upgrading the firewall to an affected release, GlobalProtect clients did not connect with IPSec and instead connected using SSL due to traffic flow being disabled when checking for health check packets.
## PAN-306103
```caveat
PA-3400 and PA-5400 Series firewalls only
```
Fixed an issue where the firewall dataplane frequently restarted when lockless QoS was enabled
## PAN-303959
Fixed an issue where traffic was incorrectly identified as unknown-tcp/unknown-udp due to App-ID resource leak and eventually dropped.
## PAN-301409
Fixed an issue where Panorama failed to perform a selective push to a managed device when device tags were added or modified on the policy rules. The selective push failed with the error message Failed to generate selective push configuration. Schema validation failed. Please try a full push.
## PAN-301222
Fixed an issue where DNS Security logs incorrectly displayed a sinkhole action for benign DNS categories due to the firewall saving the drop or sinkhole action in session flags without discarding the session.
## PAN-300638
```caveat
VM-Series firewalls only
```
Fixed an issue where the firewall stopped responding due to an out-of-bounds read when parsing TLS 1.3 clientHello messages with large TLS clientHello extensions where the supported_versions extension fell outside the first TCP segment.
## PAN-295803
Addressed a memory leak issue under sc3 and automatic commit recovery (ACR) code path.
## PAN-289723
Fixed an issue where the firewall web interface continuously loaded and not display any output when viewing the Route Table or FIB table (More Runtime Stats). This issue occurred when L3 configurations were added to ethernet and AE interfaces.
@@ -0,0 +1,61 @@
---
type: Addressed
product: PAN-OS
version: 11.2.10-h4
---
## PAN-308902
Fixed an issue where, after upgrading to an affected release, the firewall did not add mTLS websites that required client certificate authentication via DN list to the ssl-decrypt exclude-cache list.
## PAN-308654
Fixed an issue where the Elasticsearch Close Indices process closed more indices than expected and dropped the number of open shards below the minimum of 800 per Elasticsearch instance. This occurred because the process did not correctly account for the number of Elasticsearch instances when calculating the maximum number of allowed open shards.
## PAN-304718
Fixed an issue where OSPF and BGP outages occurred due to an all_task process restart during clientless VPN content rewrite processing.
## PAN-304576
Fixed an issue where the firewall entered a non-functional state due to segmentation fault within the all_pktproc process that was caused by a session that involved http2 cleartext traffic
## PAN-304496
Fixed an issue where, after unregistering an IP tag and registering a different IP tag for the same IP address via XML API, the dynamic address group membership was not updated on the dataplane, which resulted in Security policy rules being enforced incorrectly.
## PAN-303722
Fixed an issue on the firewall where configuring spyware and vulnerability profiles in Security policy rules caused a memory leak in the devsrvr process with each configuration commit.
## PAN-302790
Fixed an issue where, with Sender Side Loop Detection enabled, BGP WITHDRAWAL updates were not sent to peers after a route was removed, which caused stale routes to persist in the BGP table of neighboring firewalls.
## PAN-288001
Fixed an issue where devices with 5G cellular modems did not support the ATT FirstNet auto Access Point Name (APN).
## PAN-285181
Fixed an issue where the wifclient was not configured to utilize the GOMEMLIMIT feature.
## PAN-278688
Fixed an issue where DNS Security threat logs were not displayed on the firewall when packet capture was enabled and the domain name length was 62 characters.
## PAN-273158
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where an incorrect ASIC configuration caused silent packet drops or application slowness when receiving a mix of jumbo and non-jumbo packets.
## PAN-269228
Fixed an issue where the all_task process stopped responding, which caused a split brain condition.
## PAN-267614
Fixed an issue where the Panorama web interface was slower than expected due to high CPU utilization on the mongodb process.
@@ -0,0 +1,321 @@
---
type: Addressed
product: PAN-OS
version: 11.2.10
---
## PAN-304088
Fixed an issue where TCP traffic stopped working from Prisma Access clients to TCP services behind the Service Connection (SC) after a dataplane upgrade.
## PAN-304075
Fixed an issue where the firewall did not detect evasions due to TCP checksum offloading not being enabled.
## PAN-303737
Fixed an issue where XML API commands failed with a Method not found (policy_xml) error in dagger.log. The issue was due to session-distribution commands in dagger files handling.
## PAN-303559
Fixed an issue where, after manuallly creating a device telemetry bundle, the hour_cli_output.txt file within the bundle had a file size of 0 bytes. This occurred when checking the bundle content after enabling device telemetry and setting the device telemetry upload endpoint.
## PAN-301828
Fixed an issue where, when a firewall was managed by Strata Cloud Manager and configured to use a proxy server for external connections, the management server did not use the configured settings to connect to the Cloud Management service.
## PAN-300906
Fixed an issue where XML API commands failed with a Method not found (policy_xml) error in dagger.log. The issue was due to missing XML-related functions for inline-cloud-proxy.
## PAN-300096
Fixed an issue where a local commit on a firewall breaks template stack overrides, preventing the enabling of LACP (Link Aggregation Control Protocol). After a local commit, the LACP enable check was unexpectedly unchecked, causing an outage. Attempting to re-enable LACP through the web interface was unsuccessful, requiring manual removal of the LACP configuration from the Panorama CLI.
## PAN-299785
```caveat
PA-7500 and PA-5450 firewalls in FIPS-CC mode
```
Fixed an issue where the affected firewalls would boot into maintenance mode when a reboot was initiated from the web interface. This was due to a device reboot triggering a power down to all slots, leading to maintenance mode. A hard reboot would allow the firewall to boot normally.
## PAN-299772
```caveat
VM-Series firewalls in active/passive configurations only
```
Fixed an issue where, after an HA failover event, the newly active firewall DHCP client interfaces failed to obtain IP addresses automatically. This occurred because the DHCP client processes did not initiate the necessary DHCP discover or renew requests
## PAN-298872
```caveat
PA-400 Series firewalls in HA configurations only
```
Fixed an issue where ports went down after an HA failover.
## PAN-298684
Fixed an issue where an Application Override policy rule was not applied using an IPv4 source IP address with IPv6 enabled and Network > Zones > Pre-NAT Identification enabled.
## PAN-298654
Fixed an issue where the firewall generated false positive threat logs during updates to a large domain list (EDL) when a DNS lookup for a domain being added or removed occurred during the update process. This resulted in a threat log being generated for a different, unrelated domain that remained on the list.
## PAN-298505
Fixed an issue where, after upgrading an HA pair of PA-7050 firewalls, the vsys ID changed in sequence, causing autocommit failures with validation errors. This occurred when the multi-vsys firewall had virtual systems created and pushed from Panorama, and the vsys ID was not in a correct sequence because the unused vsys was deleted from Panorama and pushed to devices.
## PAN-298252
Fixed an issue where Data Loss Prevention (DLP) inspection of chunked transfer encoding over TLS resulted in incomplete file downloads on Outlook Web App (OWA) due to the WIF page size limit, which led to corrupted or incomplete PDF attachments.
## PAN-298241
Fixed an issue where the NAT IP address pool was exhausted, which led to intermittent connectivity issues with call applications and outbound call failures. This occurred due to the firewall not properly releasing NAT dynamic ports back to the address pool.
## PAN-297976
Fixed an issue where the firewall experienced extended boot times after a reboot due to the configd process needing to rebuild the ACE catalog after detecting discrepancies that were caused by duplicate application checking between the ACE catalog and content.
## PAN-297975
Fixed an issue where Panorama was unable to push the Trusted Root CA configuration to Log Collectors via a Collector Group push due to the Log Collector not supporting the trusted-root-CA configuration.
## PAN-297797
Fixed an issue where, during a refresh of a large External Dynamic List (EDL), traffic that matched a domain on the list was incorrectly identified as a different domain, which resulted in false positive threat logs.
## PAN-297775
Fixed an issue where, after upgrading to an affected PAN-OS release, the Visible Virtual System field referenced the vsys name instead of the vsys ID, which caused inter-vsys routing to fail. This occurred when a vsys display name matched one of the vsys IDs. If you're using a multivsys environment, you must upgrade your firewalls to a fixed PAN-OS version. The best practice is to upgrade both the firewalls and Panorama to a fixed PAN-OS version.
If you don't upgrade Panorama to a fixed version, you'll encounter PAN-245064, where a commit on a multivsys firewall fails with the message "vsys name should end with a number vsys is invalid" after you "Export or push device config bundle" from 11.1.1 Panorama.
After you upgrade Panorama to a fixed version, you'll encounter PAN-214177, which causes an "Export or Push device config bundle" from Panorama to the firewall to fail. The workaround for PAN-214177 is to first push only the template configuration and then push the device group configurations.
## PAN-297321
```caveat
Firewalls in active/active HA configurations only
```
Fixed an issue where return packets from a phone gateway looped between the HA pair instead of being encapsulated into the GlobalProtect tunnel. This occurred when the inner session and the outer IPSec tunnel terminated on different nodes, which led to excessive retries and packet drops.
## PAN-297295
```caveat
VM-Series firewalls in Microsoft Azure environments only
```
Fixed an issue where the firewall repeatedly restarted due to high packet rates on the synthetic path in DPDK mode.
## PAN-296752
Fixed an issue where the firewall experienced high management CPU usage and repeatedly rebooted when attempting to retrieve SMART data.
## PAN-296490
```caveat
Firewalls with FIPS-CC mode enabled only
```
Fixed an issue where Panorama on GCP rebooted every hour after upgrading.
## PAN-296453
Fixed an issue where decryption exclusion lists were not working for untrusted certificates, and SSL sessions were still being decrypted even after adding them to the exclusion list. This occurred because the firewall was not adding sessions to the exclude cache until after receiving a non-RFC alert (BadCertificate) from the server. The fix ensures that the first session is added to the exclude cache, allowing subsequent sessions to skip decryption. This issue affects firewalls configured as clients in server-client communication.
## PAN-295644
Fixed an issue where Strata Logging Service (SLS) log forwarding streams intermittently displayed as inactive.
## PAN-295560
Fixed an issue where, after upgrading Panorama and Log Collectors, tunnel logs were not visible in Panorama or Splunk even though traffic and threat logs were received.
## PAN-295385
Fixed an issue where syslog forwarding dropped due to FQDN resolution failures.
## PAN-295257
Fixed an issue where, after onboarding a firewall to Panorama, IPsec tunnels displayed IKEv2 in Panorama, even though the tunnels were configured with IKEv1 locally on the firewall.
## PAN-295221
Fixed an issue where, after upgrading Panorama and Log Collectors, Traffic and Threat logs were not forwarded to a Splunk server over UDP.
## PAN-294893
Fixed an issue where firewalls with the Send handshake messages to CTD for inspection setting enabled caused incorrect security policy rules to be matched. Specifically, traffic not identified as openai-base or openai-chatgpt applications was incorrectly matched by the ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected response page for blocked URLs was not displayed.
## PAN-294770
```caveat
Firewalls in active/passive HA configurations
```
Fixed an issue on firewalls where, after failover, certain subnets were missing from the Link State Database, which prevented OSPF routes from being immediately learned due to a Type-7 to Type-5 LSA translation conflict in the ABR when the same LSA was advertised by two peers in the NSSA area.
## PAN-294524
Fixed an issue where firewalls and Panorama management servers were unable to view or download WildFire reports from a WF-500 appliance, resulting in a 401 error in the report tab.
## PAN-294161
Fixed an issue where the firewall rebooted unexpectedly due to the useridd process restarting and causing an HA failover. This occurred due to the configd process timing out when running the CLI command show user user-id-agent config all.
## PAN-293985
Fixed an issue with the Panorama web interface where admin users were unable to log in and received the error message 504: Gateway Timeout.
## PAN-293877
```caveat
Firewalls with Hub vsys (virtual system) configurations enabled only
```
Fixed an issue where, when using the Hub vsys feature to redistribute Host Information Profiles (HIP) to a non-Hub vsys, HIP policy enforcement failed intermittently on the active secondary firewall. This occurred when traffic destined for specific non-Hub vsys was routed to the active secondary, and the HIP query was not triggered due to an incorrect check for the HIP mask in the Hub vsys.
## PAN-293848
Fixed an issue where Panorama failed to push the default value of None for the secondary NTP server address to managed firewalls, resulting in a commit validation error. This occurred even when configuring the secondary NTP server address as None in Panorama's web interface, and affected both newly deployed and long-standing production firewalls after upgrading.
## PAN-293511
Fixed an issue where renaming a BGP filtering profile in Panorama does not update the corresponding BGP peer group in the virtual router, leading to commit failures.
## PAN-293440
Fixed an issue where setting the logdb-quota for the desum log type to 0 caused the /opt/panlogs partition to reach capacity.
## PAN-292447
Fixed an issue where Panorama did not display data in the Feature Adoption tab in Strata Cloud Manager due to the system creating and deleting a CLI user for each interval instead of reusing a permanent CLI user for telemetry.
## PAN-292393
Fixed an issue where TFTP file transfers intermittently timed out in active-active HA pairs when the TFTP control channel was processed by one firewall and the data channel was processed by the other. This occurred because the firewall receiving the data channel failed to match the predicted session due to asynchronous processing of HA messages.
## PAN-292261
Fixed an issue where the firewall repeatedly reported an unreachable syslog server as back online when the server remained unavailable. This resulted in misleading alternating connection status messages in the system logs.
## PAN-292242
Fixed an issue on M-200 and logging appliances where traffic logs were intermittently truncated when forwarded using a TCP syslog configuration. This issue occurred during the log forwarding stage due to intermittent syslog drops caused by exceeding the forwarding queue capacity.
## PAN-292228
Fixed an issue where, after configuring dual stack GlobalProtect with both IPv4 and IPv6 address pools, IPv6 return traffic was dropped with the error message flow-basic error; packet dropped, tunnel resolution failure.
## PAN-292019
Fixed an issue on the Panorama web interface where cloud applications were not displayed under Objects > Applications after a new content upgrade and Cloud App Catalog download, and were only visible in application groups, security policy rules, and the CLI.
## PAN-291883
Fixed an issue where Prisma Access logs were not visible in the Security Logging Service (SLS) and Panorama.
## PAN-291792
```caveat
PA-7050 firewalls on vwire instances only
```
Fixed an issue where Bidirectional Forwarding Detection (BFD) echo packets were dropped due to the firewall dropping packets with the same source and destination IP addresses.
## PAN-291716
Fixed an issue where during a commit, the firewall experienced an out-of-memory (OOM) condition due to a memory leak and displayed an error message. This issue caused the device to stop responding and reboot unexpectedly.
## PAN-291661
Fixed an issue on Panorama appliances and Log Collectors where, after an upgrade, Elasticsearch intermittently entered into a Red state before automatically recovering.
## PAN-291660
Fixed an issue where the firewall incorrectly reported the speed of 25G interfaces as 1G when queried using SNMP for the ifHighSpeed OID.
## PAN-291653
Fixed an issue where the GlobalProtect host ID field was intermittently blank in traffic logs on Prisma Access, even when the user was connected and had the correct host ID information. This occurred when the IP address to host ID entry expired and the entry was re-insterted without the dataplane flag being set.
## PAN-291635
Fixed an issue where cookie surrogate cache entries remained unresolved after an idmgr process reset due to the request not being retransmitted. This occurred because the timestamp in the cache entry was refreshed even when the UID was 0, which prevented the retransmission of the request if the initial response was not received.
## PAN-291067
Fixed an issue where the devsrvr process periodically exceeded its virtual memory limit and restarted, which led to intermittent outages.
## PAN-290665
Fixed an issue with firewalls enabled with Security profiles where certain traffic conditions caused high dataplane CPU utilization and packet buffer exhaustion, which caused LACP flapping conditions.
## PAN-290640
```caveat
VM-Series firewalls on Microsoft Azure environments in HA configurations only
```
Fixed an issue where, when an interface was configured with IPv6, the firewall displayed the message Unknown error during validation after the client secret expired, which caused DNS resolution to fail when resolving FQDNs and HA failovers to occur.
## PAN-290455
Fixed an issue where the Pprof path was missing in the logrcvr script, which prevented the conversion and decoding of addresses in the resulting stack when running Pprof against Logrcvr.
## PAN-289716
Fixed an issue where return traffic was dropped on service connection firewalls due to routing failover and asymmetric return in service connection firewalls.
## PAN-288388
Fixed an issue where, after an EDL certificate update or repository migration, authentication failures caused the firewall to not fall back to the last successfully cached EDL entries, which led to policy rules that referenced the EDL to not be enforced.
## PAN-287803
Fixed an issue where, after upgrading the firewall, certain websites weren't accessible when the accumulation proxy was enabled. The proxy did not use the same DF bit state as the original traffic, causing it to be fragmented and dropped elsewhere in the network.
## PAN-287782
Fixed an issue where firewalls configured in vwire mode modified DSCP values from AF11 to CS0 on traffic passing through the firewall, even when QoS policy rules and DSCP rewrite settings were not configured.
## PAN-287693
Fixed an issue where Panorama did not use the configured proxy settings to check WildFire private cloud content and instead connected directly to the WildFire device using the management interface. This occurred even when Use Proxy Settings for Private Cloud was enabled.
## PAN-287622
Fixed an issue where IPv6 traffic was affected after upgrading the firewall to PAN-OS 11.1.6-h4 and later versions. With SSL decryption enabled and a decryption policy configured for the traffic, the firewall dropped packets due to receiving a Packet Too Big ICMP message. This occurred because the PathMTU information update was incorrect for the TCB (pan-server) when the firewall was acting as a server. Additionally, the flow label under the IPv6 header was set to zero while the packet was being transmitted out of the firewall.
## PAN-287387
Fixed an issue on Panorama where API jobs failed with the error message Server error: Timed out while getting config lock. This occurred due to slow set request performance when setting a large number of address objects in a single set call.
## PAN-285169
Fixed an issue on Panorama where Kerberos superusers were unable to edit policy rules because the target device tab was grayed out.
## PAN-283053
Fixed an issue where the firewall experienced high disk space utilization, which caused the firewall to become non-functional.
## PAN-282961
Fixed an issue where the firewall rebooted unexpectedly after a commit due to a memory leak related to the rasmgr process and displayed the error message Management server failed to send phase 1 to client l2ctrld before rebooting.
## PAN-282956
Fixed an issue on firewalls running PAN-OS 11.1 and later PAN-OS releases where the portal and gateway configuration view did not display rows and columns.
## PAN-267450
Fixed an issue where the reportd process stopped responding with a SIGSEGV at schedule_report_es_response.
## PAN-263422
Fixed an issue where SaaS Policy Recommendations policy rules created at the tenant level were not displayed on the firewall.
@@ -0,0 +1,49 @@
---
type: Addressed
product: PAN-OS
version: 11.2.1
---
## PAN-257919
Fixed an issue where, when using explicit proxy with SAML authentication, initiating SAML authentication with a non-GET request resulted in a 302 redirect response instead of the expected 200 ok response.
## PAN-256343
Fixed an issue where, when Advanced Routing Engine was enabled and OSPFv3 was configured, the CLI command show advanced-routing ospf interface caused traffic to be disrupted, and the interface and area information did not display in CLI or the web interface.
## PAN-255868
```caveat
PA-3400 Series firewalls only
```
Fixed an issue where the firewall entered maintenance mode after enabling kernel data collection during the silent reboot.
## PAN-252661
Fixed an issue where changes to the gp-ip-mgmt service route did not take effect after a commit.
## PAN-255227
Fixed an issue where the the MAC address was sent to the DHCP server instead of the hostname on macOS endpoints.
## PAN-254236
Fixed an issue where Client Hello packets were dropped when SSL/TLS handshake inspection was enabled.
## PAN-249292
```caveat
VM-Series firewalls on Microsoft Azure environments only
```
Fixed an issue where CPU usage was higher than expected after a hotplug event when Accelerated Networking was enabled for the management interface.
## PAN-236909
Fixed an issue where, when you committed the first configuration change after booting up the firewall, the external dynamic list file download failed until the list was refreshed. This occurred when the configuration was pushed with a certificate profile.
## PAN-164885
Fixed an issue on Panorama where Commit and Push or Push to Devices operations failed when an external dynamic list was configured to check for updates every 5 minutes due to the commit and external dynamic fetch processes overlapping.
@@ -0,0 +1,9 @@
---
type: Addressed
product: PAN-OS
version: 11.2.2-h1
---
## PAN-263349
Fixed an error in the bundling of software components.
@@ -0,0 +1,9 @@
---
type: Addressed
product: PAN-OS
version: 11.2.2-h2
---
## PAN-272809
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and CVE-2024-9474.
@@ -0,0 +1,33 @@
---
type: Addressed
product: PAN-OS
version: 11.2.2
---
## PAN-258702
```caveat
WF-500 appliances only
```
Fixed an issue where the varrcvr process stopped responding when files were being forwarded to the WildFire cloud.
## PAN-255773
Fixed an issue where errors related to applications in Content-preview caused commit failures.
## PAN-248508
```caveat
VM-Series firewalls on Amazon Web Services (AWS) environments only
```
Fixed an issue where the firewall did not perform MSS clamping when GWLB endpoints were mapped to static subinterfaces.
## PAN-247099
Fixed an issue where the firewall decrypted traffic unexpectedly when the client hello was spread across multiple packets.
## PAN-251929
Fixed an issue where inbound decryption did not work when FIPS self tests were turned on.
@@ -0,0 +1,21 @@
---
type: Addressed
product: PAN-OS
version: 11.2.3-h3
---
## PAN-272809
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and CVE-2024-9474.
## PAN-247230
Fixed an issue where the syslog forwarding configuration did not include the full path for Security policy rules.
## PAN-259997
```caveat
PA-3410, PA-3420, and PA-3430 firewalls only
```
Fixed an issue where the install failed when upgrading from PAN-OS 10.2.3-h3 and later 10.2 releases to PAN-OS 10.2.10 due to the number of configured vsys zones exceeding the zone limit in PAN-OS 10.2.10.
@@ -0,0 +1,29 @@
---
type: Addressed
product: PAN-OS
version: 11.2.3-h5
---
## PAN-273215
Fixed an issue where a syntax error in the index generation script caused a high management plane CPU load after upgrading.
## PAN-271613
Fixed an issue where configuration pushes from Panorama to the firewall failed due to an OOXML commit error.
## PAN-269404
Fixed an issue where the firewall did not reset the maximum latency timer for hold mode.
## PAN-268823
Fixed an issue where Monitor > Log Display did not display all logs when you applied a filter.
## PAN-264549
Fixed an issue where, after modifying a policy rule on Panorama, pushes to the Cloud NGFW failed with the error saas-user-list unexpected here.
## PAN-259078
Fixed an issue where WildFire Analysis reports were not generated and the following error message was displayed: Error 500: Internal Server Error.
@@ -0,0 +1,565 @@
---
type: Addressed
product: PAN-OS
version: 11.2.3
---
## PAN-263387
Fixed an issue where the firewall web interface was blank after logging in.
## PAN-263226
Fixed an issue where decryption based traffic failed on Explicit Proxy nodes.
## PAN-262593
Fixed an issue where traffic to websites failed on the Google Chrome web browser on Secure Web Gateway (SWG) nodes.
## PAN-262287
Fixed an issue where dereferencing a NULL pointer that occurred when App-ID stopped responding caused the firewall to restart.
## PAN-262013
Fixed an issue where Prisma Access mobile users did not receive no such name DNS responses from the firewall and were timed out.
## PAN-261991
Fixed an issue where traffic that did not match a decryption policy rule, or matched a no-decrypt policy rule, failed when accumulation proxy was enabled and a Zone Protection profile was configured with syn-cookies enabled.
## PAN-261917
Fixed an issue where websites with a no-decrypt policy rule were decrypted in the traffic log when using a Google Chrome browser with PQC enabled.
## PAN-261797
Fixed an issue where fragmented IP packets were dropped silently.
## PAN-261270
Fixed an issue where the firewall decremented the TTL/Hop limit for BGPv6 packets by 1 after IPSec decryption.
## PAN-260059
Fixed an issue where Device Telemetry Regions did not show up with the latest content due to content files not being parsed for the region list when Telemetry was turned off.
## PAN-259964
Fixed an issue where the firewall was not able to handle a high traffic load, which caused some logs to be lost.
## PAN-259769
Fixed an issue where the GlobalProtect portal was not accessible via a web browser and displayed the error ERR_EMPTY_RESPONSE.
## PAN-259733
Fixed an issue where a custom report was not deleted on Panorama when expected.
## PAN-259480
Fixed an issue where the varrcvr process stopped responding after running out of memory due to how the process queued and dequeued files for WildFire file forwarding when a WildFire Analysis Security profile was enabled.
## PAN-259473
```caveat
PA-5450 firewalls only
```
Fixed an issue where the chassis shut down when FAN1 was removed.
## PAN-259151
Fixed an issue where unused objects were pushed to the firewall, which caused configuration pushes to fail with the error Number of address groups exceed platform capacity.
## PAN-258442
Fixed an issue where changes made to the split tunnel configuration on the Prisma Access gateway were not reflected on the GlobalProtect client.
## PAN-257957
```caveat
Firewalls and Panorama appliances in FIPS-CC mode only
```
Fixed an issue where the authd process restarted if RADIUS PAP/CHAP authentication was used.
## PAN-257925
```caveat
CN-Series firewalls only
```
Fixed an issue where the CLI command show system setting ctd state did not work as expected.
## PAN-257624
Fixed an issue where the firewall web interface was blank after logging in.
## PAN-257615
Fixed an issue on Panorama where logs did not display or displayed intermittently on the web interface.
## PAN-257563
Fixed an issue where the logrcvr component for SASE and MCW displayed incorrect zones in the traffic flow.
## PAN-257515
Fixed an issue where Possible Domain Fronting Detection for HTTP/2 generated false positives. With this change, domain fronting is limited to HTTP/1.
## PAN-257462
Fixed an issue related to the varrcvr process where the management plane CPU was higher than expected.
## PAN-257432
Fixed an issue on Panorama where the reportd process stopped responding, which caused a log query issue.
## PAN-257390
```caveat
PA-5250 firewalls only
```
Fixed an issue where the logrcvr process stopped responding due to a segmentation fault.
## PAN-257355
Fixed an issue where a false positive HTTP/TLS evasion alert was generated when the domain had DNS load balance.
## PAN-257197
Fixed an issue where ifType and ifSpeed were not populated in asynchronous mode of SNMP operations.
## PAN-256939
Fixed an issue on the firewall where disk space was low in /opt/pancfg/, which caused dynamic content installation to fail.
## PAN-256765
Fixed an issue where you were unable to push variables from Panorama in service routes for non-cluster templates.
## PAN-256738
```caveat
VM-Series firewalls in HA configurations only
```
Fixed an issue where BGP routes from the active firewall were lost when the passive firewall was rebooted.
## PAN-256666
Fixed an issue where the configd process stopped responding when Commit and Push operations were performed on multiple device groups.
## PAN-256385
```caveat
CN-Series firewalls only
```
Fixed an issue where communication was broken between the management plane and the dataplane when Anti-Spyware profiles were configured in a Security policy rule.
## PAN-256327
```caveat
Panorama virtual appliances on Microsoft Azure environments only
```
Fixed an issue where the logd process repeatedly restarted due to a buffer overflow when generating a traffic summary from a traffic log.
## PAN-256249
Fixed an issue on the web interface that occurred when changing the pre-shared key to a variable (Network > Network Profiles > IKE Gateways).
## PAN-256223
Fixed an issue where device telemetry log collection filled the root partition.
## PAN-256181
Fixed an issue where the management interface and front panel port interface statistics were not populated in asynchronous mode of SNMP operations.
## PAN-255895
Fixed an issue where Panorama administrators with the Panorama Administrator dynamic administrator type were not able to create or modify BGP timer profiles or BGP dampening profiles.
## PAN-255820
Fixed an issue where the WildFire signature generation check box in Panorama did not register a change in the configuration.
## PAN-255711
Fixed an issue where the firewall displayed a malformed request error when selecting a custom format and clicking OK on the configuration window due to the log type Correlation incorrectly being displayed (Device > Log Setting - Correlation > Syslog Server Profile > Custom Log Format > Correlation).
## PAN-255611
Fixed an issue on the firewall where newly added routes were not automatically sorted based on subnets when added to a redistribution profile.
## PAN-255441
Fixed an issue where BGP-ARE routes were not advertised due to a peer route map filter.
## PAN-255396
Fixed an issue where, when using serial number and IP address authentication, and multiple gateways were configured, the portal returned the last gateway in the list and disregarded the satellite assignment by serial number.
## PAN-255391
Fixed an issue where the firewall was unable to filter logs using the ISO 8601 timestamp format after upgrading to PAN-OS 11.0.4 or a later release.
## PAN-255266
Fixed an issue where you were unable to clone a template stack with the Pre-Shared Key variable.
## PAN-255252
Fixed an issue where Panorama administrators with the type Dynamic were unable to create, modify, or delete BGP Dampening profiles.
## PAN-255163
```caveat
CN-Series firewalls only
```
Fixed an issue where the system database key that stored the configuration status of the dataplane pod was not updated frequently.
## PAN-254826
Fixed an issue where the firewall stopped responding when processing traffic.
## PAN-254629
Fixed an issue on the Management Processing Card where excessive logs were generated for an error.
## PAN-254621
Fixed an issue where the firewall frequently rebooted due to the brdagent process not responding.
## PAN-254577
Fixed an issue where a core file was created on the Log Forwarding Card (LFC) due to a third-party software issue.
## PAN-254425
Fixed an issue where the firewall did not restrict port 9905 to localhost.
## PAN-254423
Fixed an issue on Panorama where custom role-based admin users with read-only access were able to make changes to configurations.
## PAN-254422
Fixed an issue where the firewall required a restart when an SD-WAN policy rule was pushed from Panorama.
## PAN-254411
Fixed an issue where the configd process stopped responding, which caused ERR_CONNECTION_REFUSED error messages to be displayed in admin sessions.
## PAN-254373
Fixed an issue where the firewall did not handle error code 500 responses from the WildFire cloud correctly.
## PAN-254241
Fixed an issue where the firewall stopped responding due to a high number of SD-WAN probes being sent.
## PAN-254181
```caveat
CN-Series firewalls only
```
Fixed an issue where firewall pods and application pods repeatedly restarted.
## PAN-253829
Fixed an issue where the CLI command show running security-policy timed out when the Security policy was large.
## PAN-253819
Fixed an issue where a User Activity Report was not generated by Run Now or not emailed through the Email Schedule when the locale setting was not English.
## PAN-253452
Fixed an issue where GlobalProtect users were unable to connect to the GlobalProtect gateway and received the error Gateway does not exist.
## PAN-253317
```caveat
VM-Series firewalls on Microsoft Azure environments only
```
Fixed an issue where you were unable to log in to the firewall after a private data reset.
## PAN-252867
Fixed an issue where an incorrect memory reference in an IoT API caused the wifclient process to stop responding.
## PAN-252517
Fixed an issue where SNMP failed to respond to multiple Object Identifier (OID) queries in a single SNMP GET request.
## PAN-252411
Fixed an issue where, when log files were purged from the rollup summary logs, the summary report still used the rollup summary data, which resulted in the summary report displaying less data.
## PAN-251909
Fixed an issue where a Panorama pushed configuration failed to commit on the firewall due to the address object referenced by the interface not being shared with the firewall.
## PAN-251732
Fixed an issue where Oracle traffic over generic routing encapsulation (GRE) was dropped when the traffic passed through the firewall using ttunnel content inspection (TCI).
## PAN-251676
Fixed an issue on Panorama appliances in large-scale deployments where configd process core files consumed more space in the /opt/panlogs partition than was available.
## PAN-251661
Fixed an issue where a memory overwrite occurred during HTTP/2 header inflation.
## PAN-251656
Fixed an issue where enabling lockless QoS caused traffic disruptions.
## PAN-251655
Fixed an issue where the firewall stopped forwarding files to the WildFire cloud and a restart of the varrcvr process was required.
## PAN-251446
Fixed an issue where a critical system log was generated for a SAML authenticated user whose username length was greater than 32 characters.
## PAN-251047
Fixed an issue where the useridd process logs were flooded with an error message related to service profiles.
## PAN-250948
Fixed an issues where GlobalProtect on Microsoft Windows devices did not attempt CNAME resolution for sinkhole.paloaltonetworks.com.
## PAN-250909
Fixed an issue where, when creating a Security policy rule via the CLI, validation was not implemented and the same object was able to be referenced in the policy twice.
## PAN-250787
Fixed an issue where network issues between the firewall and the log collector caused logrcvr process memory exhaustion.
## PAN-250597
Fixed an issue where Global Find for a Panorama pushed shared address object displayed Others in the results.
## PAN-250462
Fixed an issue where the session logout time for the firewall was incorrect when viewing via context switch from Panorama.
## PAN-250419
Fixed an issue where XML API explorer inserted a plus (+) character in the Xpath when a space was used in the object name.
## PAN-250405
```caveat
CN-Series firewalls only
```
Fixed an issue on the firewall where websrvr related messages displayed repeatedly.
## PAN-250311
Fixed an issue where the domain was not mapped when using certificate profile authentication on GlobalProtect.
## PAN-250258
Fixed an issue on the firewall where the Certificate Name character limit was 31 characters instead of 63 characters.
## PAN-250127
Fixed an issue where commits failed with the error message set is not allowed when default originate was enabled with a route map that included a set action.
## PAN-250024
Fixed an issue related to the reportd process where you were unable to log in to Panorama via the web interface and received a 500 error.
## PAN-250021
Fixed an issue where Change Summary and Preview Changes displayed inconsistent information when changing an admin user password.
## PAN-250005
Fixed an issue where the Advanced Routing migration script did not migrate BGP import policy rules correctly when the policy rule was configured with an exact match condition.
## PAN-249855
Fixed an issue where the firewall dropped the active source of the Multicast source via MSDP when they were not received from the MSDP peer firewall.
## PAN-249404
Fixed an issue on the Panorama web interface where the commit lock for a device group and template with the same name was not visible.
## PAN-249266
Fixed an issue where the config process virtual memory was exceeded due to delays in post-commit processing.
## PAN-248975
Fixed an issue on the Panorama web interface where no content was displayed after logging in.
## PAN-248841
Fixed an issue where the SSL response time was not displayed in the GlobalProtect log.
## PAN-248542
Fixed an issue where the NPB policy type was missing from configuration policy updates, which caused error messages to incorrectly display in the system logs.
## PAN-248211
Fixed an issue on Panorama where commits failed when Advanced Routing was enabled.
## PAN-248130
Fixed an issue where the AND operation under a Dynamic Address Group comparison did not work after upgrading the AWS plugin to 3.0.1.
## PAN-247857
```caveat
PA-7050 firewalls in HA configurations only
```
Fixed an issue on the firewall where a dataplane process restarted when updating the routing table.
## PAN-247754
Fixed an issue where successful Commit and Push operations performed by SAML authenticated users were not reflected on the firewall.
## PAN-247575
Fixed an issue where the error message import of <issuecert> failed. Please check the validity of the key pair and try again for unmatched keys for EC certificates.
## PAN-247426
Fixed an issue where a proxy server was used for External Dynamic List communication even when the dataplane interface was configured through service routes.
## PAN-247257
Fixed an issue where the useridd process stopped responding, which caused the firewall to reboot.
## PAN-247230
Fixed an issue where the syslog forwarding configuration did not include the full path for Security policy rules.
## PAN-246772
Fixed an issue on the firewall where the dataplane went down due to a path monitor failure caused by an out-of-memory (OOM) condition related to the pan_task process.
## PAN-246769
Fixed an issue on Panorama where deny logs were not displayed.
## PAN-246220
Fixed an issue where a dynamic peer connection was rejected when using an FQDN for the peer address.
## PAN-246056
Fixed an issue where single TLS session packets were sent to multiple firewalls when off-loading was enabled and ECMP was disabled.
## PAN-245892
Fixed an issue where Log Filtering (Monitor > Logs) was slower than expected.
## PAN-245556
Fixed an issue where the firewall dropped VxLAN packets via v-wire after upgrading to PAN-OS 10.1.10 or a later release, which impacted SMB traffic and resulted in silent packet drops.
## PAN-244746
Fixed an issue where changes committed on Panorama were not reflected on the firewall after a successful push.
## PAN-243957
Fixed an issue where the firewall TLS/SSL service profile exclusion settings were not correctly applied on the captive portal.
## PAN-243387
Fixed an issue where sessions ended with the message resources-unavailable when traffic hit a Security profile.
## PAN-243240
Fixed an issue where the using QoS caused packet buffer utilization to increase exponentially and the PKI POOL DFLT pool depleted until a reboot was performed.
## PAN-243098
Fixed an issue with corrupted images when SSL decryption and Security profiles were configured.
## PAN-243081
Fixed an issue on the firewall where log filtering with special characters in the username incorrectly returned results.
## PAN-242958
Fixed an issue where the firewall intermittently logged connect-agent-failure messages for service connection instances due to bi-directional host ID redistribution.
## PAN-242331
Fixed an issue where Prisma Access remote network firewalls intermittently created incorrect user-to-IP-address mappings.
## PAN-242147
```caveat
PA-1410 firewalls only
```
Fixed an issue where the firewall did not block STP packets when the ports on the connected routers were in access mode.
## PAN-241781
Fixed an issue where partial commit and commit-all operations took more time than expected to create the job ID.
## PAN-241044
Fixed an issue where traffic was denied by the interzone-default policy rule when a Security policy rule with an FQDN destination was configured.
## PAN-239246
Fixed an issue where the CLI command debug user-id dump hip-based-profile-database-entry returned an incorrect value in the output for the total size of hip reports.
## PAN-237582
Fixed an issue where logs were intermittently missing on the log collector due to missing aliases for some indices.
## PAN-236497
Fixed an issue where the firewall was unable to purge expired GTP-U sessions that remained as allocated sessions even after the TTL was expired.
## PAN-235110
```caveat
PA-220 firewalls only
```
Fixed an issue where the web interface did not load after an upgrade.
## PAN-234560
Fixed an issue where the daily summary report displayed IPv6 addresses instead of IPv4 addresses.
## PAN-232550
Fixed an issue where SNMPv3 authentication failed when using SHA-512 Auth protocol.
## PAN-231642
Fixed an issue on the Panorama web interface where users that were logged in through multiple sessions were able to see an active lock on only one session.
## PAN-230326
Fixed an issue where the Network Packet Broker (NPB) user interface was incorrectly displayed on unsupported platforms.
## PAN-226785
Fixed an issue where accessing websites with HTTP to HTTPS redirect failed via explicit proxy.
@@ -0,0 +1,235 @@
---
type: Addressed
product: PAN-OS
version: 11.2.4-h10
---
## PAN-292503
Fixed an issue on the firewall where the source and destination NAT IP addresses did not display in traffic & threat logs.
## PAN-290996
Fixed an issue where SNMP walks returned a value of 0 for the CPS (Connections Per Second) per vsys on firewalls after upgrading to PAN-OS 11.1.6-h3, even when active connections were present.
## PAN-290088
Fixed an issue where a memory leak occurred related to the configd process when pushing configurations from Panorama to a firewall. This occurred when the configurations contained shared policy rules.
## PAN-287838
```caveat
Panorama appliances only
```
Fixed an issue on the web interface where resetting the rule hit counter for multiple policy rules failed with the error message Failed to reset rule-hit job.
## PAN-287056
Fixed an issue where BGP export policy rules with next-hop matching failed to block the advertisement of static routes, and the firewall incorrectly matched the egress interface IP address instead of the original next-hop IP address of the static route, which caused the deny rule to fail.
## PAN-287023
Fixed an issue where a large number of logs caused the logrcvr process to stop responding.
## PAN-286848
Fixed an issue where ECMP incorrectly balanced sessions across links based on the configured metric, which led to an imbalance in traffic distribution and resulted in traffic assignment shifting disproportionately to routes with lower metrics.
## PAN-286306
Fixed an issue where, when getting transceiver information from ESCC for SFP 25G modules, the transceiver code was incorrectly updated with Unknown instead of 25GBase-SR.
## PAN-284117
```caveat
Panorama appliances in Log Collector mode only
```
Fixed an issue where the vm_agent process restarted after an upgrade.
## PAN-284073
Fixed an issue on the firewall that caused commits to fail and the web interface to become inaccessible.
## PAN-284003
Fixed an issue where clients did not receive a valid response when searching a website due to a compression error.
## PAN-282391
```caveat
Panorama appliances and Log Collectors only
```
Fixed an issue where a VLD memory leak caused increased memory use, which resulted in OOM errors.
## PAN-282359
Fixed an issue where the Panorama web interface was slower than expected.
## PAN-281649
Fixed an issue where the index size limit was incorrectly calculated and indices rolled over earlier than expected, which resulted in high memory and OOM errors.
## PAN-281509
```caveat
Panorama appliances only
```
Fixed an issue where log exports were slower than expected or failed when filtering logs after an upgrade, which resulted in timeouts or delays in displaying logs on the web interface.
## PAN-279500
Fixed an issue where TLS connections failed to establish in asymmetric routing environments if the firewall did not see server-to-client (s2c) packets of the TLS handshake.
To use this fix, run the following CLI command: debug dataplane set ssl-decrypt accumulate-client-hello asym-disable yes.
## PAN-279415
Fixed an issue where service routes configured to use a data plane interface incorrectly used the management plane interface for traffic transmission. This issue affected syslog and CRL status traffic when a custom service route was not configured.
## PAN-278812
Fixed an issue where authentication to GlobalProtect failed with the error message User not in allowed list.
## PAN-278150
Fixed an issue where the firewall removed the Authentication Key Identifier (AKID) from the certificate during SSL decryption, which caused Python 3.13 to fail with a certificate verification error.
## PAN-277417
Fixed an memory leak issue related to TLS inbound decryption.
## PAN-277147
Fixed an issue where daily scheduled reports were not generated and emailed.
## PAN-276920
Fixed an issue where web-advertisement traffic was not immediately blocked which resulted in pages loading indefinitely.
## PAN-276616
Fixed an issue on the firewall where half-duplex settings on Ethernet were not visible.
## PAN-276276
```caveat
PA-450 firewalls only
```
Fixed an issue where, after an upgrade, data that was excluded using the query builder in a custom report was still visible in the report, and the logs displayed errors related to invalid threat names being queried.
## PAN-275047
```caveat
VM-Series firewalls only
```
Fixed an issue where, after an upgrade, the firewall was unable to send logs to the Strata Logging Service (SLS) when using a specific proxy server, and the SSL connection status displayed as failed when attempting to forward logs through the web proxy.
## PAN-275032
```caveat
M-600 appliances only
```
Fixed an issue where the Elasticsearch cluster certificate (CC) status displayed with a past expiration date, which caused all shards to be unassigned.
## PAN-274671
Fixed an issue where empty traffic logdb folders were generated for each day even when trafcfic logs were not received by the logrcvr process.
## PAN-272812
Fixed an issue where SNMP monitoring of tunnel interfaces displayed zero values for received bytes and packets.
## PAN-271810
Fixed an issue where auto-negotiation advertised and negotiated 10/100 half and full duplex.
## PAN-271700
Fixed an issue where User-ID connections were lost after an HA failover.
## PAN-271560
Fixed an issue where DNS requests to malware sites were not blocked as expected, and the dns-security-categories log-level and action displayed default values instead of unavailable.
## PAN-270849
Fixed a memory leak issue related to the configd process that occurred when running consecutive commits for multiple days.
## PAN-269899
Fixed an issue where the Panorama web interface was slower than expected when querying for device tags.
## PAN-269731
Fixed an issue where Panorama did not display logs from firewalls after upgrading to PAN-OS 10.2.11 on devices due to Elasticsearch (ES) getting restarted continuously.
## PAN-268787
Fixed an issue where users were unable to log in to Panorama and the following error message was displayed: Timed out while getting config lock. Please try again. This occurred when pushing configurations to a large number of devices.
## PAN-267535
Fixed an issue where all_task processes stopped responding on the remote network firewall, which caused tunnels to go down and the pan_task CPU usage to approach 100%.
## PAN-267091
Fixed an issue on Panorama where Elasticsearch repeatedly restarted.
## PAN-266639
Fixed an issue where administrators were unable to edit or add virtual router configurations when a filter was applied to the viewer.
## PAN-263369
Fixed an issue where commits from Panorama to Panorama virtual appliances failed with the error message Internal error during commit processing. Commit/Validate failed after upgrading Panorama.
## PAN-261209
```caveat
Firewalls in active/active HA configuration only
```
Fixed an issue where the firewall displayed the HA2 status as down when the HSCI port was used for both HA2 and HA3.
## PAN-260604
Fixed an issue where the firewall displayed inaccurate throughput utilization stats in NetFlow analyzer tools.
## PAN-259881
Fixed an issue on Panorama where traffic log details were not displayed under detailed log view.
## PAN-258757
Fixed an issue on Panorama where upgrades failed with validation errors.
## PAN-255860
```caveat
PA-5200 firewalls only
```
Fixed an issue where the all_pktproc process stopped responding when the firewall was under a heavy traffic load.
## PAN-249384
Fixed an issue on Panorama where configuration locks were observed during a partial rulebase commit.
## PAN-246699
Fixed an issue on Panorama where Rule Usage and Apps Seen under Security policy rules stopped incrementing.
## PAN-245064
```caveat
Multi-vsys firewalls only
```
Fixed an issue where commits failed on the firewall after selecting Export or push device config bundle on Panorama and a force push was required.
@@ -0,0 +1,57 @@
---
type: Addressed
product: PAN-OS
version: 11.2.4-h11
---
## PAN-291499
```caveat
VM-Series firewalls on Amazon Web Services (AWS) environments only
```
Fixed an issue where newly deployed firewalls were unable to connect to the Palo Alto Networks Software License Server (SLS) until after a reboot, license fetch, or management server restart.
## PAN-290803
```caveat
VM-Series firewalls on Microsoft Azure environments only
```
Fixed an issue where firewall failed to bootstrap with a custom image, and VM-Series plugin information was not displayed in the system information.
## PAN-290241
Fixed an issue where the useridd process became unresponsive, which caused User ID CLI commands to time out.
## PAN-288939
Fixed an issue where the logrcvr process stopped responding due to an invalid SSL context being used for socket communication, which caused commits to fail.
## PAN-287688
Fixed an issue where the firewall failed to connect to the Palo Alto Networks update server when using a customized service route with the source interface as MGT.
## PAN-279901
Fixed an issue where the firewall dropped client hello packets when decryption was enabled, which prevented access to certain websites. This occurred when the client hello packet was truncated, the accumulation proxy assumed that the first packet contains at least 5 bytes, or out-of-order packets were waiting in L4 TCP.
## PAN-268680
Fixed an issue where the configd process stopped responding when a configuration merge operation changed.
## PAN-268522
Fixed an issue where the firewall failed to connect to the update server with a customized service route when the source interface was set to MGT and the source address was set as IPv4.
## PAN-255914
```caveat
VM-Series firewalls on Amazon Web Services (AWS) environments only
```
Fixed an issue where a newly bootstrapped firewall required a management server restart, relicensing, or license push from Panorama to invoke the device certificate.
## PAN-241230
Fixed an issue where the SNMP get request status value for Panorama connections was incorrect.
@@ -0,0 +1,125 @@
---
type: Addressed
product: PAN-OS
version: 11.2.4-h12
---
## PAN-296519
Fixed an issue where a stream receiving a reconnect signal with an associated error in Wifclient caused the entire pool to close, which resulted in a complete disconnection.
## PAN-295560
Fixed an issue where, after upgrading Panorama and Log Collectors, tunnel logs were not visible in Panorama or Splunk even though traffic and threat logs were received.
## PAN-293673
Fixed an issue where the firewall stopped all tasks due to an OOM condition caused by a scheduled log export using FTP to an external FTP server.
## PAN-292229
Fixed an issue where Panorama was unable to retrieve userid logs from the firewall for subscribed user-ip-mappings after Panorama was rebooted.
## PAN-292202
Fixed an issue where the system logs repeatedly displayed the alert Clearing snmpd.log due to log overflow due to the SNMP counters rolling over.
## PAN-291716
Fixed an issue where PA-460 firewalls experienced out-of-memory (OOM) conditions, leading to device crashes and reboots.
## PAN-291631
```caveat
VM-Series firewalls only
```
Fixed an issue where the firewall frequently rebooted.
## PAN-291288
Fixed an issue where the firewall rebooted unexpectedly due to a pan_task process restart related to page allocation failures.
## PAN-291094
Fixed an issue the firewall experienced packet descriptor on chip and buffer spikes, which led to dropped traffic due to an unidentified traffic pattern.
## PAN-291067
Fixed an issue where the devsrvr process periodically exceeded its virtual memory limit and restarted, which led to intermittent outages.
## PAN-290542
Fixed an issue where the all_task process stopped responding when an additional header logging HTTP header was split across 2 packets.
## PAN-290449
Fixed an issue where, when multiple scheduled vulnerability reports were sent in the same email, only the first attached report was displayed.
## PAN-287818
Fixed an issue where sessions timed out sooner than expected due to the pan_proxy_accumulation_restore_timeout not initiating when the accumulation session_init failed.
## PAN-287803
Fixed an issue where, after upgrading firewalls to PAN-OS 11.1.6-h1, certain websites weren't accessible when the accumulation proxy was enabled. The proxy did not use the same DF bit state as the original traffic, causing it to be fragmented and dropped elsewhere in the network.
## PAN-287782
Fixed an issue where firewalls configured in vwire mode modified DSCP values from AF11 to CS0 on traffic passing through the firewall, even when QoS policy rules and DSCP rewrite settings were not configured.
## PAN-287622
Fixed an issue where IPv6 traffic was affected after upgrading the firewall to PAN-OS 11.1.6-h4 and later versions. With SSL decryption enabled and a decryption policy configured for the traffic, the firewall dropped packets due to receiving a Packet Too Big ICMP message. This occurred because the PathMTU information update was incorrect for the TCB (pan-server) when the firewall was acting as a server. Additionally, the flow label under the IPv6 header was set to zero while the packet was being transmitted out of the firewall.
## PAN-287601
Fixed an issue on Panorama where commits took longer than expected.
## PAN-287423
Fixed an issue where content loading issues occurred on IPv6 websites due to the firewall incorrectly setting the IPv6 header flow label to 0.
## PAN-286299
Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the Network and Device tabs became read-only.
## PAN-285285
Fixed an issue where commits remained at 98% completion when static route configuration cleanup was in progress.
## PAN-286231
Fixed an issue where a simultaneous selective push from Panorama to multiple firewalls with different base configurations resulted in configuration corruption, which caused the firewall to go down.
## PAN-280698
Fixed an issue where the firewall removed the TCP timestamp from client hello messages that did not fit in a single packet, which resulted in connection issues.
## PAN-279706
```caveat
M-600 appliances only
```
Fixed an issue where Panorama did not update all panreplay database entries after performing a commit and full push to all devices.
## PAN-276484
Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (Device Deployment > Licenses) due to the inability to perform batch-license refreshes.
## PAN-273453
Fixed an issue where restarting the firewall did not initiate an autocommit job, which caused the firewall to stop responding and the HA interface to go down.
## PAN-273300
Fixed an issue on Panorama where upgrading to PAN-OS 11.0.4-h2 failed with a validation error.
## PAN-265044
Fixed an issue where the default software packet buffer size for the Advanced Header Learning (AHL) feature was excessively large, which led to inefficient use of software packet buffers.
## PAN-260015
Fixed an issue on the firewall where enabling Inline Cloud Analysis features might cause the firewall to unexpectedly reboot, due to an issue related to loopback data handling.
@@ -0,0 +1,129 @@
---
type: Addressed
product: PAN-OS
version: 11.2.4-h14
---
## PAN-303559
Fixed an issue where, after manually creating a device telemetry bundle, the hour_cli_output.txt file within the bundle had a file size of 0 bytes. This occurred when checking the bundle content after enabling device telemetry and setting the device telemetry upload endpoint.
## PAN-301456
Fixed an issue on Panorama where the debug system reset-ztp CLI command was unavailable.
## PAN-300216
Fixed an issue where, when SD-WAN Direct Internet Access was configured and traffic traversed the cellular interface without a NAT policy rule, intermittent cellular modem connectivity issues occurred, which caused the firewall to disconnect and reconnect to the cellular network. To use this fix, run the CLI command set session teardown-upon-fwd-zonechange yes.
## PAN-298462
Fixed an issue where the firewall experienced extended boot times after a reboot due to the configd process needing to rebuild the ACE catalog after detecting discrepancies that were caused by duplicate application checking between the ACE catalog and content.
## PAN-297976
Fixed an issue where the firewall experienced extended boot times after a reboot due to the configd process needing to rebuild the ACE catalog after detecting discrepancies that were caused by duplicate application checking between the ACE catalog and content.
## PAN-297972
Fixed an issue where a dataplane crash occurred when traffic matched Inline Cloud Analysis prefiltering signatures, even when Inline Cloud Analysis features were not enabled.
## PAN-297775
Fixed an issue where, after upgrading to an affected PAN-OS release, the Visible Virtual System field referenced the vsys name instead of the vsys ID, which caused inter-vsys routing to fail. This occurred when a vsys display name matched one of the vsys IDs. If you're using a multivsys environment, you must upgrade your firewalls to a fixed PAN-OS version. The best practice is to upgrade both the firewalls and Panorama to a fixed PAN-OS version.
If you don't upgrade Panorama to a fixed version, you'll encounter PAN-245064, where a commit on a multivsys firewall fails with the message vsys name should end with a number vsys is invalid after you Export or push device config bundle from 11.1.1 Panorama.
After you upgrade Panorama to a fixed version, you'll encounter PAN-214177, which causes an Export or Push device config bundle from Panorama to the firewall to fail. The workaround for PAN-214177 is to first push only the template configuration and then push the device group configurations.
## PAN-296752
```caveat
PA-1410 Firewalls only
```
Fixed an issue where the firewall experienced high management CPU usage and repeatedly rebooted when attempting to retrieve SMART data.
## PAN-296694
Fixed an issue where the firewall rebooted due to the useridd process repeatedly restarting during an IP-port data type writes to the redis from multiple sources such as TSA or XML in a scale environment.
## PAN-296535
Fixed an issue on the firewall where BGP peers disconnected due to frr_ns1_bgpd restarting.
## PAN-294436
```caveat
PA-410, PA-440, PA-450, and PA-460 firewalls only
```
Fixed an issue where, after upgrading to PAN-OS 11.1.6-h6 the Eth1/2, Eth1/3, Eth1/8, and HA interfaces failed to display counters and statistics in the CLI and SNMP.
## PAN-292447
Fixed an issue where Panorama did not display data in the Feature Adoption tab in Strata Cloud Manager due to the system creating and deleting a CLI user for each interval instead of reusing a permanent CLI user for telemetry.
## PAN-291940
Fixed an issue where the firewall established multiple TCP connections to a syslog server, which caused logs to be dropped. This occurred because the firewall established a new TCP session for each transfer and the sessions were not closed, which resulted in a continuous increase in connections over time.
## PAN-291661
Fixed an issue on Panorama appliances and Log Collectors where, after an upgrade, Elasticsearch intermittently entered into a Red state before automatically recovering.
## PAN-289249
Fixed an issue where a memory leak occurred on the reportd process when a WildFire update was initiated while device telemetry data collection was in progress. This resulted in an OOM condition.
## PAN-289109
Fixed an issue where the Panorama web interface was slower than expected during configuration operations and a configuration lock time out occurred during a commit.
## PAN-287387
Fixed an issue on Panorama where API jobs failed with the error message Server error: Timed out while getting config lock. This occurred due to slow set request performance when setting a large number of address objects in a single set call.
## PAN-284279
Fixed an issue where the policy destination always defaulted to any, even when specific IP addresses and FQDNs were specified during policy import.
## PAN-284067
Fixed a cumulative memory leak in the devsrvr process that occurred whenever the CLI command show running application statistics was issued. This memory leak would gradually consume system memory and produce an OOM condition, causing the firewall to reboot.
## PAN-281776
Fixed an issue on the Panorama web interface where the error message PPPoEv6 Client Interface cannot be enabled with DHCPv6 client was generated when overriding aggregate interfaces even when no DHCPv6 or PPPoE was configured.
## PAN-279829
Fixed an issue where NAT pool leaks occurred during a test when RTSP traffic hit NAT rules.
## PAN-272746
```caveat
PA-440 firewalls only
```
Fixed an issue where the firewall entered an unstable state after committing changes or onboarding to Panorama.
## PAN-272605
Fixed an issue where the firewall did not display VPC endpoints when there was a large amount of VPC endpoints to interface mappings.
## PAN-272245
Fixed an issue where the dnsproxy process stopped responding due to memory corruption caused by a race condition when the allow list downloading was impacted by a configuration change.
## PAN-267450
Fixed an issue where the reportd process stopped responding with a SIGSEGV at schedule_report_es_response.
## PAN-266312
Fixed an issue where BFD sessions took longer than expected to establish after an HA failover due to BGP.
## PAN-264131
Fixed an issue where the routed process core failed the automation run.
@@ -0,0 +1,9 @@
---
type: Addressed
product: PAN-OS
version: 11.2.4-h15
---
## PAN-000000
A fix was made to address CVE-2026-0227.
@@ -0,0 +1,9 @@
---
type: Addressed
product: PAN-OS
version: 11.2.4-h1
---
## PAN-272809
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and CVE-2024-9474.
@@ -0,0 +1,21 @@
---
type: Addressed
product: PAN-OS
version: 11.2.4-h2
---
## PAN-273215
Fixed an issue where a syntax error in the index generation script caused a high management plane CPU load after upgrading.
## PAN-271613
Fixed an issue where configuration pushes from Panorama to the firewall failed due to an OOXML commit error.
## PAN-269404
Fixed an issue where the firewall did not reset the maximum latency timer for hold mode.
## PAN-259078
Fixed an issue where WildFire Analysis reports were not generated and the following error message was displayed: Error 500: Internal Server Error.
@@ -0,0 +1,105 @@
---
type: Addressed
product: PAN-OS
version: 11.2.4-h4
---
## PAN-276130
Fixed an issue where, when a new IKEv2 was created on Panorama on a PAN-OS 11.2 release using the default IKE version (IKEv2) and IPSec crypto profiles with no specific changes to the crypto profile parameters, and the configuration was pushed to a firewall on PAN-OS 11.2.0 to PAN-OS 11.2.4, the firewall interpreted the IKEv2 gateway as IKEv1.
## PAN-274029
Fixed an issue where upgrading Panorama and pushing configurations to the firewall caused an IKE version mismatch, which resulted in IPSec tunnel failure with the peer device.
## PAN-273994
A fix was made to address CVE-2025-0111.
## PAN-273971
A fix was made to address CVE-2025-0108.
## PAN-273278
A fix was made to address CVE-2025-0109.
## PAN-273197
Fixed an issue where the endpoint ID was not populated in logs when the least significant word of the Geneve header was 0.
## PAN-273165
Fixed an issue where HTTP/2 sessions failed on the firewall when Dynamic Memory Management was enabled.
## PAN-273085
Fixed an issue on the web interface where you were unable to edit or create policy rules.
## PAN-273019
Fixed an intermittent issue where SSL decryption failed.
## PAN-272021
```caveat
M-300 Appliances only
```
Fixed an issue where a split brain condition was not triggered during an inter-Log Collector disconnect between DLC firewalls in an Elasticsearch cluster, which resulted in missing logs.
## PAN-271926
Fixed an issue where TLS 1.3 decryption failed with a bad record MAC error when the firewall was configured to decrypt and inspect TLS traffic.
## PAN-271828
Fixed an issue where, after an accumulation proxy changed to no-decrypt or no proxy, only the Client Hello was sent to Content Threat Detection.
## PAN-270549
Fixed an issue where some TLS connections were not handled correctly, which led to instability in the dataplane.
## PAN-270248
Fixed an issue where the firewall failed to forward logs to a SNMP trap server if the SNMP manager IP address was unable to be resolved.
## PAN-268815
Fixed an issue where the firewall entered a non-functional state due to duplicate entries in the shared memory.
## PAN-268727
Fixed an issue where traffic was dropped when the accumulation proxy was enabled and header insertion modified packets.
## PAN-268229
Fixed an issue where the firewall stopped responding during session setup for ECMP hit-count updates.
## PAN-268215
```caveat
Panorama appliances in HA configurations only
```
Fixed an issue where, when Elasticsearch was forming a cluster and the port was disabled or disconnected and then reconnected, Elasticsearch did not reform the cluster
## PAN-267781
Fixed an issue where Panorama did not display the Source Dynamic Address Group.
## PAN-267671
Fixed an issue where the firewall rebooted unexpectedly due to the all_task process restarting and repeated OOM conditions occurring on the pan_task process.
## PAN-265742
Fixed an issue on the Panorama web interface where the OK button on the GlobalProtect gateway configuration dialog box was not clickable.
## PAN-263987
Fixed an issue on the firewall where, when a NAT transversal IPSec tunnel was terminated, and the NAT rule that was applied to the NAT-T IPSec tunnel was on the same firewall, traffic flowing through the tunnel was not correctly translated.
## PAN-252036
Fixed an issue where, when the GlobalProtect portal was not configured, accessing the GlobalProtect gateway still loaded a portal malformed page.
@@ -0,0 +1,37 @@
---
type: Addressed
product: PAN-OS
version: 11.2.4-h5
---
## PAN-279604
Fixed an issue where scheduled SaaS application usage reports were generated incorrectly, and the login page was displayed instead of the report content.
## PAN-276177
Fixed an issue where App Acceleration did not work with Oracle databases.
## PAN-274791
Fixed an issue where the firewall rebooted when Shared Pool Type 32 was depleted and traffic matched advanced features.
## PAN-269499
Fixed an issue where the firewall stopped responding when receiving a high number of logs.
## PAN-252224
Fixed an issue where Panorama did not forward logs to a syslog server over an SSL connection using CRL as a revocation verification method.
## PAN-234082
```caveat
Panorama virtual appliances only
```
Fixed an issue where Saas reports were generated with a report period of 0 days.
## PAN-216054
Fixed an issue that caused the firewall's fan speed to increase while it was idle.
@@ -0,0 +1,177 @@
---
type: Addressed
product: PAN-OS
version: 11.2.4-h6
---
## PAN-284036
```caveat
PA-450R and PA-450R-5G firewalls only
```
Fixed an issue where the maximum temperature threshold and shutdown threshold were not set correctly.
## PAN-282236
Fixed an issue where large IPv6 packets were reassembled incorrectly on the firewall when the packets arrived fragmented over an IPv4 tunnel.
## PAN-282206
Fixed an issue where configuring Secure Web Gateway (SWG) in no-auth mode led to latency when no decryption policy rules or No-decrypt policy rules were present.
## PAN-282022
Fixed the support limitation for the Panorama M-600 and M-700 appliances.
## PAN-280471
Fixed an issue where navigating Panorama > Monitor > Logs was slower than expected.
## PAN-279746
Fixed an issue where SMTP packets were not sent out when the Client Hello arrived at the firewall in multiple out-of-order segments and the traffic was not subject to SSL decryption.
## PAN-279197
```caveat
PA-450R-5G firewalls only
```
Fixed an issue where the firewall stopped responding and displayed the error message `Thermal temperature exceeds system threshold! Shutting down NOW` even when the firewall was within the threshold.
## PAN-278684
```caveat
PA-445 firewalls only
```
Fixed an issue where the firewall did not properly power cycle during a reboot.
## PAN-278296
Fixed an issue where the system MAC address of the aggregate interface was the same on the active firewall and the passive firewall after an upgrade.
## PAN-276546
Fixed an issue where a session lost the PBF rule mapping after a configuration change or commit.
## PAN-275905
Fixed an issue where the Panorama web interface was slower than expected and Elasticsearch CPU usage was high.
## PAN-273949
Fixed an issue where the firewall generated the following error message in the snmpd logs: pan_get_keystr_from_cryptod(pan_snmpinterface.c:181): Key X2F1dGhfa2V5 import from cryptod failed.
## PAN-273026
Fixed an issue where traffic logs did not display correctly when filters were applied.
## PAN-273021
Fixed an issue where 25G port links did not come up due to a change in the handling of 25G DAC modules.
## PAN-272849
Fixed an issue where log forwarding to a UDP syslog server stopped when an unreachable TCP syslog server was configured and applied.
## PAN-272538
Fixed an issue where the configd process stopped responding during a commit-all validation when there were uncommitted changes and share-unused-objects-with-devices was set to off.
## PAN-272085
Fixed an issue where the firewall might crash and reboot when DoH is enabled for DNS Security and multiple DoH transactions are sent in a single HTTP/1 connection.
## PAN-271912
Fixed an issue on Panorama where the configd process stopped responding when filtering in the configuration audit window after upgrading to PAN-OS 11.1.3.
## PAN-271351
A fix was made to address CVE-2025-0116.
## PAN-270224
Fixed an issue where indices were not opened after a query.
## PAN-269956
Fixed an issue where the all_pktproc process stopped responding, which caused internal path monitor failures.
## PAN-269291
Fixed an issue where the scheduled report generation script did not return debug information.
## PAN-269106
Fixed an issue where the wifclient stopped responding during server certificate verification for MICA gRPC connections and caused the dataplane to restart when using a cloud-based ML detection engine (MICA). On certain platforms, this caused the firewall to reboot periodically.
## PAN-269091
Fixed an issue where the varrcvr process stopped responding.
## PAN-268501
Fixed an issue where the firewall was unable to generate a TSF file due to a full root partition.
## PAN-267430
Fixed an issue where Panorama was unable to return logs for queries that were longer than 64,000 characters.
## PAN-265179
Fixed an issue where a kernel race condition caused the firewall to reboot with a kernel panic.
## PAN-263208
```caveat
PA-5440 and PA-5445 firewalls only
```
Fixed an issue where interrupts were generated at a certain packet rate, and dataplane processes missed heartbeats, which caused the dataplane to go down.
## PAN-262383
Fixed an issue where the firewall was unable to decompress the HTTP2 header, which caused the session to be classified as unknown-tcp instead of web-browsing.
## PAN-261739
```caveat
VM-Series firewalls in Microsoft Azure environments only
```
Fixed an issue where the firewall displayed 0 for the physical port counters read from MAC.
## PAN-261484
Fixed an issue on the firewall where DPDK allocated twice the amount of memory as requested for pre-allocation.
## PAN-258736
Fixed an issue where policy rule configurations pushed from Panorama were not reflected on the firewall if the rule had 63 characters.
## PAN-258570
Fixed an issue where the firewall might reboot unexpectedly due to the varrcvr process progressively using more memory when WildFire file forwarding is handling PE files.
## PAN-257619
Fixed an issue on Panorama where the Task Manager took longer than expected to display managed firewall report tasks.
## PAN-257028
```caveat
Firewalls in active/passive HA configurations only
```
Fixed an issue where firewalls entered a non-functional state and displayed the error message Dataplane down: path monitor failure during the fail-over.
## PAN-255323
```caveat
PA-7050 firewalls only
```
Fixed an issue where the Network Processing Card (NPC), Data Processing Card (DPC), and Log forwarding Card (LFC) remained in a starting state after an unexpected power cycle.
@@ -0,0 +1,41 @@
---
type: Addressed
product: PAN-OS
version: 11.2.4-h7
---
## PAN-286255
Fixed an issue where, when the firewall received an unexpected termination request for SSL sessions, the dataplane experienced a slow buffer resource leak.
## PAN-282968
Fixed an issue where the firewall did not identify the test threat file when the content was installed via a traditional bootstrap.
## PAN-278322
```caveat
VM-Series firewalls on Amazon Web Services (AWS) Gateway Load Balancer (GWLB) deployments only
```
Fixed an issue where the firewall did not display the correct source user in traffic logs and session details.
## PAN-277629
Fixed an issue where the firewall did not match the correct policy for SSL forward decrypted HTTP/2 traffic when upgrading from PAN-OS 10.2.9-h1 to PAN-OS 11.2.3.
## PAN-268474
Fixed an issue on the firewall where the PAN-DB URL Filtering license displayed as Valid even when the firewall did not have the license, which caused traffic to drop.
## PAN-261999
```caveat
VM-Series firewalls in Microsoft Azure environments only
```
Fixed an issue where enabling flow basic on firewalls caused ARP entries to be removed on both firewalls.
## PAN-260290
Added support for new content size requirements on fixed model licenses.
@@ -0,0 +1,13 @@
---
type: Addressed
product: PAN-OS
version: 11.2.4-h8
---
## PAN-267444
Fixed an issue where large file downloads or uploads failed or remained in an incomplete state when using DLP HTTP2 mirror mode.
## PAN-255619
Fixed an intermittent issue where file downloads from websites failed when decrypting HTTP/2 traffic.
@@ -0,0 +1,193 @@
---
type: Addressed
product: PAN-OS
version: 11.2.4-h9
---
## PAN-290239
```caveat
PA-455 firewalls in active/passive high availability (HA) configurations only
```
Fixed an issue where, after an upgrade, the TCP session for syslog forwarding did not resume after the syslog server service was disabled and then re-enabled, which caused logs to be dropped. This occurred when the syslog server was down for more than 16 minutes.
## PAN-289102
```caveat
PA-7500 Series, PA-5410, PA-5420, PA-5430, PA-5440, PA-5445, PA-3400 Series, PA-1400 Series, PA-400 Series, VM-Series, and CN-Series firewalls only
```
Fixed a race condition issue related to predict processing, which resulted in a dataplane restart and traffic loss.
## PAN-287002
A fix was made to address CVE-2025-0133.
## PAN-285894
Fixed an issue where the all_task process stopped responding, which caused the firewall to reboot unexpectedly, and traffic failures occurred.
## PAN-285651
```caveat
Panorama appliances in active/passive HA configurations on Microsoft Azure environments only
```
Fixed an issue on Panorama that caused firewalls to disconnect unexpectedly.
## PAN-285590
```caveat
VM-Series firewalls on Amazon Web Services (AWS) GWLB environments only
```
Fixed an issue where the firewall CPU usage reached 100% after upgrading to PAN-OS 11.1.6-h1.
## PAN-284066
Fixed an issue where, after an upgrade, the SNMP polled values for IF-MIB::ifInErrors displayed a high number of errors that did not match the values in the CLI show interface command.
## PAN-283789
```caveat
Firewalls in HA configurations only
```
Fixed an issue where, after an upgrade, the mac receive error counter in receive incoming errors increased, which resulted in SNMP alerts.
## PAN-283467
```caveat
PA-3400 Series firewalls only
```
Fixed an issue where the firewall unexpectedly rebooted and entered maintenance mode due to a ctd-agent out-of-memory (OOM) condition. This occurred during advanced services load testing and a high volume of IoT EAL log forwarding.
## PAN-283331
Fixed an issue where selective pushes to managed devices failed when the User ID Master Device was configured.
## PAN-282069
Fixed an issue on Panorama where Security policy rules were removed from device groups when you cloned or edited Security policy rules that used more than 63 characters.
## PAN-280532
Fixed an issue where, after disabling and re-enabling the external syslog server, the TCP session was not resumed, which caused all logs that were forwarded to the syslog server to be dropped.
## PAN-279621
Fixed an issue where processes stopped responding when HTTPS Forward traffic was run.
## PAN-275077
Fixed an issue where DNS Security intermittently logs malicious domain URLs as Alert instead of taking a Sinkhole action, even when configured to Sinkhole malicious DNS domains.
## PAN-274570
Fixed an issue where the devsrvr process restarted after a failed commit due to an invalid memory access.
## PAN-274314
```caveat
PA-1400 Series, PA-3400 Series, and PA-5400 Series firewalls only
```
Fixed an issue where, when the pan_task process restarted, control plane packets were dropped, which could impact LACP and pings to host interfaces.
## PAN-272006
Fixed an issue where the firewall did not trigger a kernel core dump as a large core when the CPLD (Complex Programmable Logic Device) sent a Non-Maskable Interrupt (NMI) to the CPU.
## PAN-271913
Fixed an issue on firewalls in HA configurations where, when using the Cloud Identity Engine (CIE), the firewall experienced consistent memory leaks on the active firewall, which caused unexpected failovers.
## PAN-271273
Fixed an issue where dynamic update downloads failed when IPv6 firewalling was enabled on the firewall and both IPv4 and IPv6 were configured on the management interface.
## PAN-270379
Fixed an issue where socket files created in the /tmp directory were not cleared.
## PAN-269052
Fixed an issue where traffic was blocked by a URL filtering profile even though the Security policy rule did not have a URL filtering profile configured.
## PAN-269027
Fixed an issue related to external dynamic lists that caused commit times on the firewall to be higher than expected.
## PAN-268708
Fixed an issue where PDF summary and email reports displayed IPv6 addresses instead of IPv4 addresses.
## PAN-268705
Fixed an intermittent issue where the firewall failed to process FTP traffic after upgrading to PAN-OS 10.1.14.
## PAN-268127
Fixed an issue where tagging devices in Panorama did not work as expected.
## PAN-267444
Fixed an issue where large file downloads or uploads failed or remained in an incomplete state when using DLP HTTP2 mirror mode.
## PAN-266900
Fixed an issue on the Panorama web interface where you were unable to click OK after selecting an install package type and file from the dropdown and selecting a firewall.
## PAN-265745
Fixed an issue where the firewall displayed incorrect MAC receive error counters for VMWare devices hosted in ESXi.
## PAN-263973
Fixed an issue where log collectors had a low incoming log rate.
## PAN-261825
Fixed an issue where traffic was dropped when Data Loss Prevention or Advanced URL Filtering were enabled. This occurred when the payload size was greater than 3.5 KB.
## PAN-261673
```caveat
VM-Series firewalls on Microsoft Azure environments only
```
Fixed an issue where, when Accelerated Networking was enabled, traffic was dropped because of the flow_parse_ip_hdr counter related to an Nvidia driver issue.
## PAN-261429
Fixed an issue where the show auth radius-require-msg-authentic CLI command displayed no output.
## PAN-259706
Fixed an issue on Panorama where the web interface was slower than expected or unresponsive when monitoring definitions were added in the Kubernetes plugin.
## PAN-258680
Fixed an issue on Panorama where, when you removed Security profile groups from a Security policy rule via the CLI and committed the change, the Security policy rule was deleted.
## PAN-257267
```caveat
VM-Series firewalls only
```
Fixed an issue where a warning message was displayed after a commit, and a critical system log was generated when the configuration size exceeded the maximum size.
## PAN-255619
Fixed an intermittent issue where file downloads from websites failed when decrypting HTTP/2 traffic.
## PAN-254901
Fixed an issue where GlobalProtect user-to-IP address mapping was removed even though the tunnel for the specific user was up and traffic was being passed.
## PAN-252669
Fixed an issue where the ikemgr process stopped responding with a SIGSEGV error.
@@ -0,0 +1,173 @@
---
type: Addressed
product: PAN-OS
version: 11.2.4
---
## PAN-270802
Fixed an issue where, after modifying a policy rule on Panorama, pushes to the Cloud NGFW failed with the error saas-user-list unexpected here.
## PAN-268823
Fixed an issue where Monitor > Log Display did not display all logs when you applied a filter.
## PAN-267386
Fixed an issue where VPC IDs and Security keys were not mapped to the correct interfaces for Google IPS.
## PAN-266769
Fixed an issue where the GlobalProtect gateway did not handle IP address changes of the inner gateway when the NGPA new protocol was enabled.
## PAN-266581
Fixed an issue where a failed SSL connection to a syslog server resulted in a /tmp/srvr.crt.xxxxxx file not being removed, which caused index node (inode) exhaustion.
## PAN-266114
Fixed an issue where, when a new set of URL logs came in, the content of the earlier URL and traffic logs were lost.
## PAN-265785
Fixed an issue where the firewall rebooted due to a sysd variable being modified before it was created.
## PAN-264249
Fixed an issue on the firewall where SNMP queries timed out when using SNMP.
## PAN-264246
Fixed an issue where the Authentication Portal did not work properly with session cookies when the request to the portal contained the header Sec-Fetch-Site=cross-site.
## PAN-263680
Fixed an issue where Prisma Access gateways consistently stopped responding with process restarts.
## PAN-263559
Fixed an issue where the dataplane stopped responding and the firewall unexpectedly rebooted due to multiple process restarts.
## PAN-263287
The PAN-COMMON-MIB.my file was updated to support new object identifiers (OID) to poll interface use via SNMP with table identifiers.
## PAN-262340
Fixed an issue where FQDN resolution failed for address objects, and all FQDN traffic was denied by the interzone-default policy rule.
## PAN-262254
Fixed an issue where the firewall experienced an OOM condition and the useridd process stopped responding, which caused the firewall to drop interfaces from their respective aggregate groups.
## PAN-261489
Fixed an issue where an out-of-memory (OOM) condition caused a firewall outage.
## PAN-260662
Fixed an issue where large file downloads were slower than expected when private IP address visibility was enabled.
## PAN-260512
Fixed an issue where accessing the IP address of the device address group objects from the user interface caused the configd process to stop responding.
## PAN-260316
Fixed an issue where the all_task process stopped responding and the firewall rebooted.
## PAN-259910
Fixed an issue where the firewall reported the same value over consecutive SNMP polls when asynchronous mode was enabled.
## PAN-259767
Fixed an issue where GlobalProtect users were unable to connect when the option Block sessions if the certificate was not issued to the authenticating device was enabled in the certificate profile.
## PAN-259002
Fixed an issue where frequent external dynamic list updates caused the configd process to restart.
## PAN-257736
```caveat
PA-5450 firewalls only
```
Fixed an issue where traffic to benign applications was was impacted by holding TCP sequential segments for MLC inspection and not releasing the full chain after a benign verdict was received.
## PAN-257601
```caveat
PA-5450 firewalls only
```
Fixed an issue where Networking Cards (NC) experienced an internal link fault which caused path monitoring failure on the Dataplane Processing Card (DPC).
## PAN-257327
```caveat
PA-5440 firewalls only
```
Fixed an issue where a failover event occurred unexpectedly on the firewall.
## PAN-256077
Fixed an issue where the GlobalProtect client would disconnect consistently due to keep-alive timeouts when using an SSL-only tunnel.
## PAN-254704
```caveat
LSVPN Portal firewalls in active/passive HA configurations only
```
Fixed an issue where the satellite cookie key did not sync between LSVPN portal HA firewalls, which resulted in re-authentication of satellites with the portal during the event of HA failover.
## PAN-251973
Fixed an issue where the firewall did not detect evasions due to TCP checksum offloading not being enabled.
## PAN-250394
Fixed an issue where a large amount of group data caused serialization errors and prevented synchronization.
## PAN-250371
Fixed an issue where the logrcvr process stopped responding, which caused commits to fail with the error message Management server failed to send phase 1 to client logrcvr.
## PAN-240990
Fixed an issue where l3svc.py displayed incorrect logs.
## PAN-239952
```caveat
Firewalls in active/passive HA configurations only
```
Fixed an issue where HA sync messages from the active firewall took longer than expected to reach the passive firewall.
## PAN-230893
Added a CLI command to address an issue where system lock files blocked authentication.
## PAN-230825
Fixed an issue where link flaps occurred on Panorama appliances in HA configurations.
## PAN-225213
Fixed an issue where Push All Changes displayed changes that were already committed in the push scope for another device group after performing a selective commit and selective push to the first device group.
## PAN-222542
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where Log Forward Cards (LFC) were incorrectly identified as distribution policies, which caused packet loss due to traffic, BFD, and other control packets being forwarded to the LFC.
## PAN-214773
Fixed an issue where RTP packets traversing inter-vsys were dropped on the outgoing vsys.
@@ -0,0 +1,9 @@
---
type: Addressed
product: PAN-OS
version: 11.2.5-h2
---
## PAN-282022
Fixed the support limitation for the Panorama M-600 and M-700 appliances.
@@ -0,0 +1,929 @@
---
type: Addressed
product: PAN-OS
version: 11.2.5
---
## PAN-275905
Fixed an issue where the Panorama web interface was slower than expected and Elasticsearch CPU usage was high.
## PAN-274029
Fixed an issue where upgrading Panorama and pushing configurations to the firewall caused an IKE version mismatch, which resulted in IPSec tunnel failure with the peer device.
## PAN-273215
Fixed an issue where a syntax error in the index generation script caused a high management plane CPU load after upgrading.
## PAN-273197
Fixed an issue where the endpoint ID was not populated in logs when the least significant word of the Geneve header was 0.
## PAN-272085
Fixed an issue where the firewall might crash and reboot when DoH is enabled for DNS Security and multiple DoH transactions are sent in a single HTTP/1 connection.
## PAN-271913
Fixed an issue on firewalls in HA configurations where, when using the Cloud Identity Engine (CIE), the firewall experienced consistent memory leaks on the active firewall, which caused unexpected failovers.
## PAN-271828
Fixed an issue where, after an accumulation proxy changed to no-decrypt or no proxy, only the Client Hello was sent to Content Threat Detection.
## PAN-271613
Fixed an issue where configuration pushes from Panorama to the firewall failed due to an OOXML commit error.
## PAN-270569
Fixed an issue where the userid process stopped responding due to memory was being reset to NULL when it was freed.
## PAN-270549
Fixed an issue where some TLS connections were not handled correctly, which led to instability in the dataplane.
## PAN-270224
Fixed an issue where indices were not opened after a query.
## PAN-269899
Fixed an issue where the Panorama web interface was slower than expected when querying for device tags.
## PAN-269673
Fixed an issue where ElasticSearch was not set up after an upgrade.
## PAN-269539
Fixed an issue where whitespace was added before the timestamp in syslog logs forwarded from Panorama.
## PAN-269499
Fixed an issue where the firewall stopped responding when receiving a high number of logs.
## PAN-269106
Fixed an issue where the wifclient might crash during server cert verification for MICA gRPC connections and cause the dataplane to restart when using a cloud-based ML detection engine (MICA). On certain platforms, this caused the firewall to reboot periodically.
## PAN-269027
Fixed an issue related to external dynamic lists that caused commit times on the firewall to be higher than expected.
## PAN-269000
Fixed an issue where the firewall stopped responding due to a NULL pointer dereference when path monitoring failed.
## PAN-268972
Fixed an issue where Panorama was slower than expected when using a high number of device group tags in a non-shared context.
## PAN-268909
Fixed an issue where IP address tags were removed from firewalls after a management server or userid process restart. This occurred when a Panorama serial-number based configuration was used for User-ID redistribution.
## PAN-268815
Fixed an issue that caused the firewall to reboot due to the wifclient exiting multiple times when using IoT Security.
## PAN-268727
Fixed an issue where traffic was dropped when the accumulation proxy was enabled and header insertion modified packets.
## PAN-268501
Fixed an issue where the firewall was unable to generate a TSF file due to a full root partition.
## PAN-268474
Fixed an issue on the firewall where the PAN-DB URL Filtering license displayed as Valid even when the firewall did not have the license, which caused traffic to drop.
## PAN-268419
Fixed an issue where Managed Devices > Summary displayed incorrect subcolumns.
## PAN-268229
Fixed an issue where the firewall stopped responding during session setup for ECMP hit-count updates.
## PAN-268228
Fixed an issue where Panorama administrators were unable to select Edit Selection when pushing changes to devices if they logged in using TACACS authentication.
## PAN-268127
Fixed an issue where tagging devices in Panorama did not work as expected.
## PAN-268118
Fixed an issue on firewalls in active/passive HA configurations where, after a failover, irrelevant routing FIB entries were seen in the routing table on the newly active firewall.
## PAN-268002
Fixed an issue where URL filtering response pages were not displayed for sites that were blocked as a result of SSL/TLS handshake inspection.
## PAN-267934
Fixed an issue where commits remained at 98%, which resulted in the BGP connection flapping.
## PAN-267707
Fixed an issue where BFD sessions did not come up even when BGP peering was established.
## PAN-267660
Fixed an issue where UserID stopped working when the show object registered user CLI command was used with start-point and limit options.
## PAN-267535
Fixed an issue where all_task processes stopped responding on the remote network firewall, which caused tunnels to go down and the pan_task CPU usage to approach 100%.
## PAN-267285
Fixed an issue where a port was able to be connected from outside the network. With this fix, the port is restricted to the local interface.
## PAN-267091
Fixed an issue on Panorama where Elasticsearch repeatedly restarted.
## PAN-267001
Fixed an issue where multicast streams were unstable with ECMP and dropped every 30 seconds.
## PAN-266900
Fixed an issue on the Panorama web interface where you were unable to click OK after selecting an install package type and file from the dropdown and selecting a firewall.
## PAN-266704
Fixed an issue where filtering BGP routes by peer name in Advanced Routing Engine (ARE) did not display the correct routes.
## PAN-266695
Fixed an issue on Panorama where a cyclic nested address group configuration caused the configd process to stop responding after a commit.
## PAN-266653
Fixed an issue where unexpected path monitor failures caused the firewall to stop responding.
## PAN-266639
Fixed an issue where administrators were unable to edit or add virtual router configurations when a filter was applied to the viewer.
## PAN-266391
Fixed an issue where the number of hints values were not updated even when there were no hint files on the system.
## PAN-266354
Fixed an issue where Hybrid-SWG explicit proxy connections failed when the number of destination domains exceeded 1024.
## PAN-266328
Fixed an issue where the firewall was unable to establish a connection.
## PAN-266312
Fixed an issue where BFD sessions took longer than expected to establish after an HA failover due to BGP.
## PAN-266167
Fixed an issue where the restart option for IPSec tunnels was greyed out (Network > IPSec Tunnels > IKE Info).
## PAN-266003
Fixed an issue on the firewall where a configuration policy push caused both active and passive firewalls to go down when a high number of spyware profiles and vulnerability profiles were pushed to the dataplane.
## PAN-265973
Fixed an issue where administrator sessions were logged out with an ERR_CONNECTION_REFUSED error on the browser.
## PAN-265963
Fixed an issue where the escd process caused a memory leak when session resiliency was enabled on the firewall.
## PAN-265931
Added debug functionality in the packet-diag log to address an issue regarding policy rule matching.
## PAN-265742
Fixed an issue on the Panorama web interface where the OK button on the GlobalProtect gateway configuration dialog box was not clickable.
## PAN-265621
Fixed an issue where the restart option for IPSec tunnels was greyed out when you attempted to restart the tunnel from Network > IPSec Tunnels > IKE Info.
## PAN-265462
Fixed an issue where you were unable to download PDFs when connected via a Clientless VPN.
## PAN-265434
Fixed an issue where the flow process restarted with the error message SIGABRT __GI_raise __GI_abort __libc_message malloc_printer.
## PAN-265399
Fixed an issue where DNS queries for uppercase internal domain (SRV record) timed out when DNS Security was enabled.
## PAN-265349
Fixed an issue where multiple segments of HTTP proxy connect messages were not handled correctly by proxy.
## PAN-265344
Fixed an issue where Import GlobalProtect Client Package did not work after clicking OK after selecting a valid package under Device > GlobalProtect Client > Upload).
## PAN-265179
Fixed an issue where a kernel race condition caused the firewall to reboot with a kernel panic.
## PAN-265160
Fixed an issue where the firewall created multiple connections to a syslog server and remained in the FINWAIT1 state, which caused logs to drop while being forwarded to the syslog server.
## PAN-264981
Fixed an issue on the Panorama web interface where it took longer than expected to edit Security policy rules.
## PAN-264871
Fixed an issue on Panorama where the configd process stopped responding when viewing IP addresses on dynamic address groups with a large number of IP addresses.
## PAN-264806
```caveat
PA-3440 firewalls only
```
Fixed an issue where the firewall was unable to validate or commit a configuration when it was imported from another firewall model.
## PAN-264794
Fixed an issue where OSPF adjacencies failed to come up when using a subinterface ID with more than 3 digits on Ethernet ports 1/10 and higher.
## PAN-264680
```caveat
PA-220 firewalls only
```
Fixed an issue where Device > Setup was not displayed on the web interface.
## PAN-264678
Fixed an issue where Preview Changes did not display configuration changes in Commit and push > Push Scope.
## PAN-264662
Fixed an issue where HTTP POST requests were blocked for URLs that had the block-continue category configured.
## PAN-264289
Fixed an issue where the CLI and XML API values for the show system environment command did not match.
## PAN-264169
```caveat
PA-5400 Series firewalls only
```
Fixed an issue where the firewall sent correlated event logs to the syslog server using the management interface instead of the log interface.
## PAN-263987
Fixed an issue on the firewall where, when a NAT transversal IPSec tunnel was terminated, and the NAT rule that was applied to the NAT-T IPSec tunnel was on the same firewall, traffic flowing through the tunnel was not correctly translated.
## PAN-263973
Fixed an issue where log collectors had a low incoming log rate.
## PAN-263956
```caveat
PA-440 firewalls only
```
Fixed an issue where a firewall running PAN-OS 11.1.2-h3 only displayed the Auto option for the interface duplex setting.
## PAN-263843
```caveat
VM-Series firewalls only
```
Fixed an issue where the firewall received no-license packet buffers instead of memory based packet buffer numbers.
## PAN-263749
Fixed an issue where disk space that was used by file descriptors was not freed, which caused the root partition to become full and Panorama to be inaccessible.
## PAN-263505
```caveat
PA-850 firewalls only
```
Fixed an issue where the firewall stopped responding and rebooted after upgrading to PAN-OS 11.1.4.
## PAN-263369
Fixed an issue where commits from Panorama to Panorama virtual appliances failed with the error message Internal error during commit processing. Commit/Validate failed after upgrading Panorama.
## PAN-263291
Fixed an issue where Microsoft Outlook did not work as expected when the GlobalProtect clientless VPN was configured.
## PAN-263278
Fixed an issue where the management interface flapped when IPv6 was disabled and DHCPv6 was enabled.
## PAN-263208
```caveat
PA-5440 and PA-5445 firewalls only
```
Fixed an issue where interrupts were generated at a certain packet rate, and dataplane processes missed heartbeats, which caused the dataplane to go down.
## PAN-263164
Fixed an issue where Netflow User ID information was truncated to 31 characters.
## PAN-263086
```caveat
PA-455 firewalls in HA configurations only
```
Fixed an issue where the HA LED light on the front panel did not turn on even when HA was enabled.
## PAN-263012
Fixed an issue where commits failed from a Panorama appliance with a default master key to a firewall with a master key configured and a VM Information source configured.
## PAN-262973
Fixed an issue where changes made by a custom role Panorama administrator did not display in the push scope for other custom role administrators when a full commit was performed.
## PAN-262902
Fixed an issue on the web interface where cloning region objects did not work.
## PAN-262511
Fixed an issue on firewalls in HA configurations where OSPF neighbors were not established after an HA failover.
## PAN-262415
Fixed an issue where a partial configuration load failed for configuration files that contained regenerate-hostkeys.
## PAN-261997
Fixed an issue where the firewall displayed incorrect statistics for mac_transmit_err and send_deffered on PA-440 appliances running PAN-OS 10.1.9-h3.
## PAN-261909
Fixed an issue where the GlobalProtect client did not display the dialog box for an MFA verification code.
## PAN-261831
```caveat
Firewalls in HA configuration only
```
Fixed an issue where link-down events did not occur after an HA failover.
## PAN-261673
```caveat
VM-Series firewalls on Microsoft Azure environments only
```
Fixed an issue where, when Accelerated Networking was enabled, traffic was dropped because of the 'flow_parse_ip_hdr' counter related to an Nvidia driver issue.
## PAN-261671
Fixed an issue where GlobalProtect clients randomly fell back to the SSL tunnel as the gateway dropped the initial three keepalive packets.
## PAN-261639
Fixed an issue where the firewall incorrectly logged the XFF IP in threat logs when a single HTTP header was used.
## PAN-261570
```caveat
Firewalls in active/active HA configurations only
```
Fixed an issue where packet loss occurred when dataport was used for HA3 for asymmetrically routed traffic during commits and a virtual wire was configured .
## PAN-261485
Fixed an issue where the firewall dropped the Real Time Transport Protocol (RTP) session for the second SIP call on Persistent-DIPP connections when the source port of the client device was reset.
## PAN-261484
Fixed an issue on the firewall where DPDK allocated twice the amount of memory as requested for pre-allocation.
## PAN-261371
```caveat
PA-5410 firewalls in active/passive HA configurations only
```
Fixed an issue where the reportd process restarted, which caused the firewall to reboot.
## PAN-261209
```caveat
Firewalls in active/active HA configuration only
```
Fixed an issue where the firewall displayed the HA2 status as down when the HSCI port was used for both HA2 and HA3.
## PAN-261174
Fixed an issue on Panorama where importing a certificate for a template stack configuration incorrectly prompted for a passphrase as a required field.
## PAN-261028
Fixed an issue where the firewall did not autocommit after a reboot when the cellular interface was configured as a local interface for the IPSec Satellite and the IP address was allocated dynamically.
## PAN-261001
Fixed an issue where GlobalProtect users were unable to switch gateways after upgrading to GlobalProtect version 6.2.3.
## PAN-260842
A CLI command was introduced to address an issue where TCP packets were out of order.
## PAN-260796
Fixed an issue where servers were not accessible through an active SSL GlobalProtect VPN tunnel until a new connection was established or the session was cleared on the firewall.
## PAN-260738
Fixed an issue on the Panorama web interface where the progress bar did not complete when importing a vulnerability profile configuration through an XML file.
## PAN-260633
Fixed an issue where the firewall did not send a client certificate after a TLS Certificate Request when establishing a secure syslog connection.
## PAN-260604
Fixed an issue where the firewall displayed inaccurate throughput utilization stats in NetFlow analyzer tools.
## PAN-260564
Fixed an issue on firewalls in HA configurations where a network loop was detected by switches after suspending HA on the active firewall.
## PAN-260549
Fixed an issue where the management plane CPU usage was not calculated correctly on firewalls with integrated an dataplane and management plane.
## PAN-260546
```caveat
PA-440 firewalls only
```
Fixed an issue where the system clock reset to the epoch date and time after 8 to 12 weeks of shelf life or no power.
## PAN-260417
Fixed an issue on Panorama where UpdateLicDB was triggered every few minutes when firewalls with PAYG licenses were onboarded.
## PAN-260358
Fixed an issue where the firewall did not include the NAS-ID and NAS-IP attributes in the RADIUS Access-Request message when using PEAP-MSCHAPv2 authentication.
## PAN-260290
Fixed an issue for fixed model licenses to support new content size requirements by reducing the total sessions supported to be equivalent to their flex memory counterpart
## PAN-260279
Fixed an issue where selective push operations failed with the error message: Failed to generate selective push configuration. Schema validation failed. Please try a full push.
## PAN-260218
Fixed an issue where BGP Aggregate Advertise filters did not work as expected when the summary option was enabled, and only summarized routes were advertised.
## PAN-260193
Fixed an issue where GlobalProtect on macOS clients did not connect when using a client certificate and the X.509 policy was set to Use System Default.
## PAN-260149
Fixed an issue where the management plane DNS cache size was lower than expected.
## PAN-260132
Fixed an issue where secondary IP addresses with a /32 prefix configured on Layer 3 interfaces were not reachable in FRR mode.
## PAN-260131
Fixed an issue where the firewall consumed a large amount of memory when forwarding raw logs.
## PAN-260114
Fixed an issue where the firewall generated a devsrvr core file when processes were restarted.
## PAN-259883
Fixed an issue where the firewalls behind an Amazon Web Services (AWS) Gateway Load Balancer (GWLB) stopped responding when processing GENEVE packets with the reserved bit set.
## PAN-259881
Fixed an issue on Panorama where traffic log details were not displayed under detailed log view.
## PAN-259870
```caveat
PA-7000b firewalls only
```
Fixed an issue where Luna Network Hardware Security Modules (HSM) did not work after an upgrade or downgrade.
## PAN-259802
```caveat
Panorama appliances in HA clusters only
```
Fixed an issue where, after replacing a secondary Panorama appliance in a Panorama HA cluster, the ElasticSearch cluster was unable to establish SSL tunnels due to SSLHandshakeException errors.
## PAN-259706
Fixed an issue on Panorama where the web interface was slower than expected or unresponsive when monitoring definitions were added in the Kubernetes plugin.
## PAN-259200
Fixed an issue where the firewall displayed truncated zone names in the Block IP List log when a zone name contained more than 14 characters.
## PAN-259078
Fixed an issue where WildFire Analysis reports were not generated and the following error message was displayed: Error 500: Internal Server Error.
## PAN-258996
Fixed an issue where the firewall displayed the SFP ports as PowerDown when the SFP transceiver was removed and reinserted or the port was shut down and brought back up on the peer device.
## PAN-258757
Fixed an issue on Panorama where upgrades failed with validation errors.
## PAN-258736
Fixed an issue where policy rule configurations pushed from Panorama were not reflected on the firewall if the rule had 63 characters.
## PAN-258734
Fixed an issue where virtual wire ports did not go down when moving from an active state to a suspended state.
## PAN-258680
Fixed an issue on Panorama where, when you removed Security profile groups from a Security policy rule via the CLI and committed the change, the Security policy rule was deleted.
## PAN-258576
Fixed an issue on the Panorama web interface where products in HIP objects were not displayed correctly.
## PAN-258570
Fixed an issue where the firewall might reboot unexpectedly due to the varrcvr process progressively using more memory when WildFire file forwarding is handling PE files.
## PAN-258240
```caveat
Firewalls in HA configurations only
```
Fixed an issue where HA path monitoring did not work as expected when using vwire.
## PAN-258225
Fixed an issue on the Panorama web interface where Security policy rules loaded more slowly than expected.
## PAN-258188
Fixed an issue on Panorama Template where the virtual wire subinterface page did not display all fields and the OK button did not work.
## PAN-258149
Fixed an issue where the firewall dropped the SYN-ACK when using the TCP Fast Open option.
## PAN-257961
Fixed an issue on Panorama where Test Security Policy Match failed when the From or To zone fields were populated.
## PAN-257912
Fixed an issue where the firewall stopped responding when it received RADIUS traffic and user equipment (UE) traffic at the same time on a Network Processing Card (NPC)
## PAN-257660
Fixed an issue where show commands were hidden for superusers in read-only roles.
## PAN-257600
Fixed an issue where the firewall returned a 404 error for all sites accessed through the clientless VPN portal.
## PAN-257267
```caveat
VM-Series firewalls only
```
Fixed an issue where observed warning message during commit completion & critical system log when configuration size exceeded the maximum recommended configuration size.
## PAN-257117
Fixed an issue where CSV or PDF exports of zones did not contain all zones.
## PAN-257028
```caveat
Firewalls in active/passive HA configurations only
```
Fixed an issue where firewalls entered a non-functional state and displayed the error message Dataplane down: path monitor failure during the fail-over.
## PAN-257021
"Fixed an issue on the web interface where Match Evidence log details for Monitor > Correlated events did not populate."
## PAN-256960
Fixed an issue where a custom portal login page was not displayed correctly in the GlobalProtect portal when using a customized portal landing page.
## PAN-256725
Fixed an issue on the Panorama interface where Traffic and Unified event details loaded more slowly than expected.
## PAN-256669
Fixed an issue where the memory usage reported by SNMP did not match the memory usage reported by the top command.
## PAN-256518
Fixed an issue where Panorama was unable to push firmware updates to a VM-Series firewall with a PAYG license.
## PAN-256449
Fixed an issue where DHCPv6 relay was not working in Advanced Routing mode when the firewall was configured as a DHCP relay agent.
## PAN-256350
Fixed an issue where, when you cloned an admin role or an LDAP server profile and then changed the name of the clone, the configuration change was not reflected on the managed firewall after pushing the configuration from Panorama.
## PAN-256320
```caveat
Firewalls in active/passive HA configurations only
```
Fixed an issue where GTP sessions remained as allocated sessions on the passive firewall even when there were no active sessions.
## PAN-256115
Fixed an issue where, after replacing a Panorama appliance or log collector, the secondary Panorama appliance or log collector displayed a disconnected status for the inter-log collector connection.
## PAN-255930
Fixed an issue where persistent DIPP NAT entries were deleted even when being used during an active session.
## PAN-255915
Fixed an issue where a memory leak in the sslmgr process caused the firewall to restart.
## PAN-255747
Fixed an issue on the firewall where CLI commands returned Server error: op command for client dagger timed out as client is not available.
## PAN-255360
Fixed an issue where the firewall booted into maintenance mode when there was no connectivity to the specified hardware security module (HSM).
## PAN-254901
Fixed an issue where GlobalProtect user-to-IP address mapping was removed even though the tunnel for the specific user was up and traffic was being passed.
## PAN-254797
```caveat
PA-5400 Series firewalls only
```
Fixed an issue where you were unable to use SNMP polling o monitor the status of power supply units.
## PAN-254794
Fixed an issue where the Panorama management server stopped responding.
## PAN-254671
Fixed an issue where excessive Timed out while getting config lock error messages were generated when making bulk changes via XML API.
## PAN-254301
Fixed an issue where GlobalProtect logs showed the public IPv4 address in the private IPv4 address field for logs generated during portal/gateway negotiation.
## PAN-254124
```caveat
PA-7050 firewalls with DPC and 100G NPCs only
```
Fixed an issue on the firewall where you were unable to change the flow key type from tag to tuple.
## PAN-253626
Fixed an issue on Panorama where unused objects were pushed to the firewall, which caused the push operations to intermittently fail.
## PAN-253584
Fixed an issue where ikemgr process unexpectedly stopped due to a memory mapping in an incorrect location.
## PAN-253485
```caveat
Firewalls in active/passive HA configurations only
```
Fixed an issue where dataplane packet capture filter configuration failed on the active firewall with the error op command for client dagger timed out as client is not available.
## PAN-252816
Fixed an issue where multiple SSHD process restarts triggered a firewall reboot when the login banner and SSH host keys were updated at the same time.
## PAN-252801
Fixed an issue where the LSVPN tunnel monitoring status displayed as No data available after re-key events.
## PAN-252604
Fixed an issue where the clientless VPN did not carry authentication to other tabs.
## PAN-252370
Fixed an issue where services with the reserved keyword application-default were allowed.
## PAN-252300
Fixed an issue where you were unable to select device groups in the push scope for user accounts.
## PAN-252270
Fixed an issue on the firewall where changes were incorrectly applied after a reboot or a restart of the configd process.
## PAN-252224
Fixed an issue where Panorama did not forward logs to a syslog server over an SSL connection using CRL as a revocation verification method.
## PAN-252036
Fixed an issue where, when the GlobalProtect portal was not configured, accessing the GlobalProtect gateway still loaded a portal malformed page.
## PAN-252029
Fixed an issue where the firewall stopped responding when processing authentication requests.
## PAN-251484
Fixed an issue where the firewall web interface displayed incorrect PPPoE configuration options under the subinterface of an Aggregate Ethernet interface.
## PAN-250928
```caveat
PA-5450 firewalls in active/active HA configurations only
```
Fixed an issue where firewall traffic was silently dropped when sent to the peer owner.
## PAN-250703
Fixed an issue where the task manager failed with a 504 error when a large number of previous jobs or tasks were present.
## PAN-250443
```caveat
VM-Series firewalls only
```
Fixed an issue where multiple processes exited due to an OOM condition and caused a network outage.
## PAN-249581
Fixed an issue where stale BGP routes were advertised to peers even when they were not present in the local RIB table.
## PAN-249533
Fixed an issue where an internal error message was displayed when you selected Exclude video traffic from the tunnel (Windows and macOS only).
## PAN-249384
Fixed an issue on Panorama where configuration locks were observed during a partial rulebase commit.
## PAN-249072
Fixed an issue where content upgrade installation failed with the error Error: can't find cert &lt;cert&gt; when using cloud interfaces.
## PAN-247052
Fixed an intermittent issue where the OSPF ABR option was disabled when a static route was added.
## PAN-246567
Fixed an issue where a firewall with a copper SFP transceiver (PAN-SFP-CG) flapped during a commit.
## PAN-246304
Fixed an issue on Panorama where commits failed due to a timeout in the sysd process during decryption.
## PAN-245545
Fixed an issue where, when you were connected to the VPN and enabled the client accelerator, you were disconnected from the VPN.
## PAN-245058
Fixed an issue on the Panorama web interface where tagging a new user failed the error message Tags addition failed.
## PAN-244743
Fixed an issue where intermittent 500 errors occurred when making API calls to the firewall.
## PAN-244708
Fixed an issue where the GlobalProtect VPN connection inactivity TTL value became negative, which caused the VPN to disconnect when the system time was changed back to the past time.
## PAN-244039
```caveat
PA-5450 firewalls only
```
Fixed an issue where the firewall dropped packets when attempting to reuse a TCP session.
## PAN-243786
Fixed an issue on Panorama where custom GlobalProtect reports displayed inaccurate values.
## PAN-242991
Fixed an issue where the web interface stopped responding when you searched for members in an address group that contained more than 500 members.
## PAN-242957
Fixed an issue where the Rule usage columns of overridden default policy rules on the Security policy page stopped responding.
## PAN-242602
Fixed an issue where GlobalProtect clients experienced slow SMB-V3 download throughput when passing through a Prisma IPSec tunnel and the firewall and the SMB-V3 session owner dataplane was the same as the IPSec-ESP tunnel on the multi-dataplane firewall.
## PAN-238793
```caveat
Panorama virtual appliances in Microsoft Azure environments only
```
Fixed an issue where a bootstrapped Panorama appliance did not automatically retrieve the CDL license, which resulted in the firewall not automatically sending logs to CDL.
## PAN-238741
Fixed an issue where, after a selective push of the configuration, a parent device group object with multiple child device groups was not shown in the device group's push scope.
## PAN-221096
Fixed an issue where IPSec transport mode failed when the firewall was the initiator.
## PAN-216054
Fixed an issue that caused the firewall's fan speed to increase while it was idle.
## PAN-214430
Fixed an issue where some commands did not have executable permissions.
## PAN-212889
Fixed an issue on Panorama where different threat names were used when querying a threat under Threat Monitor (Monitor > App Scope) and the ACC. This resulted in the ACC displaying no data after clicking a threat name in Threat Monitor and filtering it in the global filters.
## PAN-199141
Fixed an issue where renaming a device group and then performing a partial commit led to the device group hierarchy being incorrectly changed.
## PAN-192176
Fixed an issue where the management server access log file did not rotate, which caused the root partition to become full and led to system instability.
## PAN-76904
```caveat
PA-5410 firewalls only
```
Fixed an issue where the management interface went down and an error message displayed in the show interface management CLI command output.
@@ -0,0 +1,395 @@
---
type: Addressed
product: PAN-OS
version: 11.2.6
---
## PAN-287812
Fixed an intermittent issue where the dataplane stopped responding when advanced DNS was enabled.
## PAN-286255
Fixed an issue where, when the firewall received an unexpected termination request for SSL sessions, the dataplane experienced a slow buffer resource leak.
## PAN-284908
Fixed an issue where retrieving filenames from OneDrive resulted in a cache miss.
## PAN-284116
Fixed an issue where mTLS decryption bypass did not work when the decryption profile was configured with the maximum TLS version as TLS 1.3.
## PAN-284036
```caveat
PA-450R and PA-450R-5G firewalls only
```
Fixed an issue where the maximum temperature threshold and shutdown threshold were not set correctly.
## PAN-283467
```caveat
PA-3400 Series firewalls only
```
Fixed an issue where the firewall unexpectedly rebooted and entered maintenance mode due to a ctd-agent out-of-memory (OOM) condition. This occurred during advanced services load testing and a high volume of IoT EAL log forwarding.
## PAN-282968
Fixed an issue where the firewall did not identify the test threat file when the content was installed via a traditional bootstrap.
## PAN-282236
Fixed an issue where large IPv6 packets were reassembled incorrectly on the firewall when the packets arrived fragmented over an IPv4 tunnel.
## PAN-282206
Fixed an issue where configuring Secure Web Gateway (SWG) in no-auth mode led to latency when no decryption policy rules or No-decrypt policy rules were present.
## PAN-282069
Fixed an issue on Panorama where Security policy rules were removed from device groups when you cloned or edited Security policy rules that used more than 63 characters.
## PAN-282022
Fixed the support limitation for the Panorama M-600 and M-700 appliances.
## PAN-280700
Fixed an Issue where commits failed with the error invalid IPv6 x:x - must be global/link-local unicast when the management IPv6 address had a specific value.
## PAN-280471
Fixed an issue where navigating Panorama > Monitor > Logs was slower than expected.
## PAN-279983
```caveat
PA-1400 Series firewalls only
```
Fixed an issue on the web interface where Enable Bonjour Reflector was not displayed (Network > Interfaces > Ethernet Interface).
## PAN-279746
Fixed an issue where SMTP packets were not sent out when the Client Hello arrived at the firewall in multiple out-of-order segments and the traffic was not subject to SSL decryption.
## PAN-279621
Fixed an issue where processes stopped responding when HTTPS Forward traffic was run.
## PAN-279197
```caveat
PA-450R-5G firewalls only
```
Fixed an issue where the firewall stopped responding and displayed the error message Thermal temperature exceeds system threshold! Shutting down NOW even when the firewall was within the threshold.
## PAN-279191
Fixed an issue where a GlobalProtect gateway stopped responding when handling HTTP/1.1 traffic with web inspection enabled.
## PAN-278684
```caveat
PA-445 firewalls only
```
Fixed an issue where the firewall did not properly power cycle during a reboot.
## PAN-278322
```caveat
VM-Series firewalls on Amazon Web Services (AWS) Gateway Load Balancer (GWLB) deployments only
```
Fixed an issue where the firewall did not display the correct source user in traffic logs and session details.
## PAN-278296
Fixed an issue where the system MAC address of the aggregate interface was the same on the active firewall and the passive firewall after an upgrade.
## PAN-277762
```caveat
VM-Series firewalls only
```
Fixed an issue where unexpected failovers occurred on firewalls running PAN-OS 11.2.2-h2.
## PAN-277751
Fixed an issue where a policy-based forwarding (PBF) rule with an action of no-pbf and a service of TCP-22 did not match traffic after upgrading to PAN-OS 11.1.5-h1. As a result, traffic was matched by a lower rule with a service of any and an action of forward.
## PAN-277629
Fixed an issue where the firewall did not match the correct policy for SSL forward decrypted HTTP/2 traffic when upgrading from PAN-OS 10.2.9-h1 to PAN-OS 11.2.3.
## PAN-277417
Fixed an memory leak issue related to TLS inbound decryption.
## PAN-277135
Fixed an issue where the firewall stopped responding when a DNS client closed or reset a TCP connection while the firewall was sending a response.
## PAN-276822
Fixed an issue where the packet buffer size increased significantly when WildFire File Forwarding was continued after a threat detection and then canceled.
## PAN-276607
Fixed an issue where GlobalProtect users experienced DNS resolution timeouts when using Prisma Access.
## PAN-276546
Fixed an issue where a session lost the PBF rule mapping after a configuration change or commit.
## PAN-276177
Fixed an issue where App Acceleration did not work with Oracle databases.
## PAN-276090
Fixed an issue where the DLP feature did not work as expected and performance issues occurred when uploading files. This was caused by incomplete error handling when writing CTD WIF messages to shared memory and incomplete checking of parameters when freeing entries in the shared memory.
## PAN-276016
Fixed an issue where Prisma Access cap700 instances did not insert HTTP headers when accessing certain Google domains if the 32 byte pool size was low.
## PAN-275032
```caveat
M-600 appliances only
```
Fixed an issue where the Elasticsearch cluster certificate (CC) status displayed with a past expiration date, which caused all shards to be unassigned.
## PAN-274592
```caveat
Firewalls in high availability (HA) configurations only
```
Fixed an issue where the firewall did not fail over when the active firewall experienced data plane issues.
## PAN-274314
```caveat
PA-1400 Series firewalls, PA-3400 Series firewalls, and PA-5400 Series firewalls only
```
Fixed an issue where, when the pan_task process restarted, control plane packets were dropped, which could impact LACP and pings to host interfaces.
## PAN-273949
Fixed an issue where the firewall generated the following error message in the snmpd logs: pan_get_keystr_from_cryptod(pan_snmpinterface.c:181): Key X2F1dGhfa2V5 import from cryptod failed.
## PAN-273727
Fixed an issue where the firewall skipped the DNS policy rule of a domain external dynamic list (EDL) during an EDL refresh.
To use this fix, run the following CLI command and commit: set deviceconfig setting ctd custom-edl-domains-continuous-reload yes/no
## PAN-273195
Fixed an issue where the firewall did not log the correct NAT IP address and source zone for HTTP2 traffic with SSL decryption enabled on RNHP nodes.
## PAN-273129
Fixed an issue on the web interface where the negate option was visible when you clicked on the rule name, but not when you viewed the target options from the rulebase attribute.
## PAN-273026
Fixed an issue where traffic logs did not display correctly when filters were applied.
## PAN-273021
Fixed an issue where 25G port links did not come up due to a change in the handling of 25G DAC modules.
## PAN-272959
Fixed an issue where the firewall generated BGP update packets larger than 1500 bytes when the interface MTU was 1500 bytes and jumbo frames were enabled globally.
## PAN-272849
Fixed an issue where log forwarding to a UDP syslog server stopped when an unreachable TCP syslog server was configured and applied.
## PAN-272538
Fixed an issue where the configd process stopped responding during a commit-all validation when there were uncommitted changes and share-unused-objects-with-devices was set to off.
## PAN-272171
Fixed an issue where the firewall dropped the AAAA DNS server response and caused delays in traffic from Ubuntu or Linux clients when DNS Security was enabled.
## PAN-272085
Fixed an issue where the firewall unexpectedly stopped responding and rebooted when DoH was enabled for DNS Security and multiple DoH transactions were sent in a single HTTP/1 connection.
## PAN-271912
Fixed an issue on Panorama where the configd process stopped responding when filtering in the configuration audit window after upgrading to PAN-OS 11.1.3.
## PAN-271701
Fixed an issue where Advanced Services, App-ID Cloud Engine (ACE), and Enhanced Application Log stopped working due to incorrect memory usage accounting, which caused memory usage to remain at 99% after an extended period of time.
## PAN-271314
Fixed an issue where pushing changes to a prefix list used for BGP from Panorama affected OSPF routes.
## PAN-271273
Fixed an issue where dynamic update downloads failed when IPv6 firewalling was enabled on the firewall and both IPv4 and IPv6 were configured on the management interface.
## PAN-271181
Fixed an issue where committing changes to Advanced Routing and redistribution profiles failed while pushing the configuration from SCM.
## PAN-271152
```caveat
7000-Series firewalls in HA configurations only
```
Fixed an issue where the firewall failed over into a non-functional state, and the LFC LED was blinking on the passive firewall.
## PAN-270607
```caveat
Firewalls in active/passive HA configurations only
```
Fixed an issue where OSPF failed to establish after a failover from the active firewall to the passive firewall.
## PAN-270471
```caveat
Firewalls in active/active configurations only
```
) Fixed an issue where the firewall did not detect configuration changes when only the interface of an IKE gateway was changed, which caused IPSec tunnels to not come up after migrating the IKE gateway IP address from a subinterface to a physical interface.
## PAN-269956
Fixed an issue where the all_pktproc process stopped responding, which caused internal path monitor failures.
## PAN-269731
Fixed an issue where Panorama did not display logs from firewalls after upgrading to PAN-OS 10.2.11 on devices due to Elasticsearch (ES) getting restarted continuously.
## PAN-269291
Fixed an issue where the scheduled report generation script did not return debug information.
## PAN-269052
Fixed an issue where traffic was blocked by a URL filtering profile even though the Security policy rule did not have a URL filtering profile configured.
## PAN-268705
Fixed an intermittent issue where the firewall failed to process FTP traffic after upgrading to PAN-OS 10.1.14.
## PAN-268168
Fixed an issue where uploading files that were 5GB or larger to Google Drive or YouTube failed when a decryption policy rule for http2 was enabled.
## PAN-267662
Fixed an issue where the firewall experienced a memory out-of-bounds access when the firewall was configured with SD-WAN and the SD-WAN plugin was loading, which caused the firewall to stop responding and drop VPN tunnels.
## PAN-267580
Fixed an issue where an External Dynamic List (EDL) IP address in an unsupported format was recognized as valid on the firewall.
## PAN-267489
Fixed an issue where firewalls on PAN-OS 11.2 releases were not able to successfully onboard to SCM with ZTP due to a commit failure in the bootstrap process.
## PAN-267444
Fixed an issue where large file downloads or uploads failed or remained in an incomplete state when using DLP HTTP2 mirror mode.
## PAN-265219
```caveat
VM-Series firewalls only
```
Fixed an issue where GRE traffic did not work properly.
## PAN-265021
Fixed an issue where the firewall did not inspect NXDomain responses and follow the regular traffic inspection flow.
## PAN-261998
Fixed an issue where the firewall configuration process restarted during an External Dynamic List refresh or a commit and push operation.
## PAN-261825
Fixed an issue where traffic was dropped when Data Loss Prevention or Advanced URL Filtering were enabled. This occurred when the payload size was greater than 3.5 KB.
## PAN-261429
Fixed an issue where the show auth radius-require-msg-authentic command CLI displayed no output.
## PAN-260300
```caveat
PA-5410, PA-5420, PA-5430, PA-5440 and PA-5445 firewalls only
```
Fixed an issue related to the all_pktproc process where DPC slot 3 stopped responding.
## PAN-260235
Fixed an issue where the firewall sent Threat logs and URL logs to an external syslog server without Security profile settings when Enhanced Application Logging was enabled.
## PAN-260090
Fixed an issue where commit all operations failed when the application openair-psa was used as a keyword on a remote network instance that was upgraded to PAN-OS 10.2.4-h20.
## PAN-260015
Fixed an issue on the firewall where enabling Inline Cloud Analysis features might cause the firewall to unexpectedly reboot, due to an issue related to loopback data handling.
## PAN-259076
Fixed an issue where the firewall displayed an OCSP/CRL check failure when accessing websites.
## PAN-257619
Fixed an issue on Panorama where the Task Manager took longer than expected to display managed firewall report tasks.
## PAN-255914
```caveat
VM-Series firewalls on AWS environments only
```
Fixed an issue where a newly bootstrapped firewall required a management server restart, relicensing, or license push from Panorama to invoke the device certificate.
## PAN-255619
Fixed an intermittent issue where file downloads from websites failed when decrypting HTTP/2 traffic.
## PAN-252381
Fixed an issue where the Panorama web interface was slower than expected when opening interfaces, virtual routers, and zones in a template or template stack.
## PAN-245064
```caveat
Multi-vsys firewalls only
```
Fixed an issue where commits failed on the firewall after selecting Export or push device config bundle on Panorama and a force push was required.
## PAN-233647
Fixed an issue where Panorama management servers generated duplicate configuration logs.
@@ -0,0 +1,89 @@
---
type: Addressed
product: PAN-OS
version: 11.2.7-h10
---
## PAN-310868
Fixed an issue where PA Explicit proxy blocked ICMP packets from flowing towards Envoy for Geneve due to the router not camping MSS when the MTU was lower in the path.
## PAN-307901
Fixed an issue where a leak in decryption counters caused resource exhaustion, which led to a GlobalProtect service outage.
## PAN-306502
Fixed two issues that impacted TLSv1.2 or earlier sessions when the traffic matched a decryption policy rule with the no-decrypt action:
Connections failed when both HTTP header insertion (Objects > Security Profiles > URL Filtering > HTTP Header Insertion) and Send handshake messages to CTD for inspection (Device > Setup > Session > Decryption Settings > SSL Decryption Settings) were enabled.
New sessions failed due to software packet buffer resource depletion, which occurred when Log Successful SSL Handshake was disabled in the decryption policy rule and the decryption profile attached to the rule had both Block sessions with expired certificates and Block sessions with untrusted issuers disabled.
## PAN-306103
```caveat
PA-3400 and PA-5400 Series firewalls only
```
Fixed an issue where the firewall dataplane frequently restarted when lockless QoS was enabled
## PAN-303959
Fixed an issue where traffic was incorrectly identified as unknown-tcp/unknown-udp due to App-ID resource leak and eventually dropped.
## PAN-302767
Fixed an issue where IPv6 IPsec WAN support was not available in Prisma Access.
## PAN-301222
Fixed an issue where DNS Security logs incorrectly displayed a sinkhole action for benign DNS categories due to the firewall saving the drop or sinkhole action in session flags without discarding the session.
## PAN-300638
```caveat
VM-Series firewalls only
```
Fixed an issue where the firewall stopped responding due to an out-of-bounds read when parsing TLS 1.3 clientHello messages with large TLS clientHello extensions where the supported_versions extension fell outside the first TCP segment.
## PAN-297295
```caveat
VM-Series firewalls in Microsoft Azure environments only
```
Fixed an issue where the firewall repeatedly restarted due to high packet rates on the synthetic path in DPDK mode.
## PAN-295803
Addressed a memory leak issue under sc3 and automatic commit recovery (ACR) code path.
## PAN-294488
```caveat
Subject Common Name
```
Fixed an issue where certificate data was missing in decryption logs for No decrypt policy rules and TLS1.2 traffic after upgrading, and the , Issuer Common Name, Certificate Start Date, Certificate End Date, Certificate Serial Number, and Certificate Fingerprint fields were blank in the decryption logs.
## PAN-283563
Fixed an issue where the GlobalProtect gateway firewall intermittently failed to assign an IP address to GlobalProtect clients from the DHCP server, even after successfully receiving a DHCP offer. This occurred when the DHCP retry and timeout settings were overwritten due to parsing results being stored in the same variable, which caused the last gateway configuration to take effect.
## PAN-271438
Fixed an issue where the firewall calculated available memory incorrectly on CENTOS devices, which caused the firewall to display high memory usage alerts even when sufficient memory was available.
## PAN-267328
Fixed an issue where the all_task process stopped responding, which caused the firewall to stop processing traffic.
## PAN-259853
Fixed an issue where, when the DHCP server was enabled for GlobalProtect, the commit error message was not properly displayed when Any was selected as the source interface in the service router configuration (DeviceSetupServiceService Router Configuration).
## PAN-258039
Fixed an issue where the firewall displayed the incorrect rule name when a threat log was generated for Inline Cloud Analyzed CMD Injection Traffic Detection.
@@ -0,0 +1,57 @@
---
type: Addressed
product: PAN-OS
version: 11.2.7-h11
---
## PAN-308902
Fixed an issue where, after upgrading to an affected release, the firewall did not add mTLS websites that required client certificate authentication via DN list to the ssl-decrypt exclude-cache list.
## PAN-308654
Fixed an issue where the Elasticsearch Close Indices process closed more indices than expected and dropped the number of open shards below the minimum of 800 per Elasticsearch instance. This occurred because the process did not correctly account for the number of Elasticsearch instances when calculating the maximum number of allowed open shards.
## PAN-304718
Fixed an issue where OSPF and BGP outages occurred due to an all_task process restart during clientless VPN content rewrite processing.
## PAN-304576
Fixed an issue where the firewall entered a non-functional state due to segmentation fault within the all_pktproc process that was caused by a session that involved http2 cleartext traffic
## PAN-304496
Fixed an issue where, after unregistering an IP tag and registering a different IP tag for the same IP address via XML API, the dynamic address group membership was not updated on the dataplane, which resulted in Security policy rules being enforced incorrectly.
## PAN-303722
Fixed an issue on the firewall where configuring spyware and vulnerability profiles in Security policy rules caused a memory leak in the devsrvr process with each configuration commit.
## PAN-288001
Fixed an issue where devices with 5G cellular modems did not support the ATT FirstNet auto Access Point Name (APN).
## PAN-285181
Fixed an issue where the wifclient was not configured to utilize the GOMEMLIMIT feature.
## PAN-278688
Fixed an issue where DNS Security threat logs were not displayed on the firewall when packet capture was enabled and the domain name length was 62 characters.
## PAN-273158
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where an incorrect ASIC configuration caused silent packet drops or application slowness when receiving a mix of jumbo and non-jumbo packets.
## PAN-269228
Fixed an issue where the all_task process stopped responding, which caused a split brain condition.
## PAN-267614
Fixed an issue where the Panorama web interface was slower than expected due to high CPU utilization on the mongodb process.
@@ -0,0 +1,101 @@
---
type: Addressed
product: PAN-OS
version: 11.2.7-h1
---
## PAN-294436
Fixed an issue where polling failed for ethernet interfaces due to the physical port counters read from the MAC being 0.
## PAN-293842
Fixed an issue where the hybrid-SWG service proxy stopped working after upgrading to PAN-OS 11.1.6-h13 due to the firewall failing to establish the listening interface.
## PAN-293673
Fixed an issue where the firewall stopped all tasks due to an OOM condition caused by a scheduled log export using FTP to an external FTP server.
## PAN-292503
Fixed an issue on the firewall where the source and destination NAT IP addresses did not display in traffic and threat logs.
## PAN-291060
Fixed an issue where commits failed due to the configured connected gateway IPv6 address in the NAT64 policy exceeding the 31 character limit.
## PAN-290996
Fixed an issue where SNMP walks returned a value of 0 for the CPS (Connections Per Second) per vsys on firewalls after upgrading to PAN-OS 11.1.6-h3, even when active connections were present.
## PAN-290088
Fixed an issue where a memory leak occurred related to the configd process when pushing configurations from Panorama to a firewall. This occurred when the configurations contained shared policy rules.
## PAN-289714
```caveat
Prisma Access only
```
Fixed an issue where persistent commit failures occurred due to a missing transformation script when downgrading from PAN-OS 10.2.0 to PAN-OS 10.1.0.
## PAN-289268
Fixed an issue where internet access through Secure Web Gateway (SWG) proxy nodes did not work when the default internet access policy rule source user was not known-user .
## PAN-288939
Fixed an issue where the logrcvr process stopped responding due to an invalid SSL context being used for socket communication, which caused commits to fail.
## PAN-284878
```caveat
Firewalls in active/passive HA configurations only
```
Fixed an issue where commits failed due the useridd process restarting.
## PAN-284003
Fixed an issue where clients did not receive a valid response when when searching a website due to a compression error.
## PAN-280409
Fixed an issue where the popup window did not appear as expected for Clientless VPN users.
## PAN-279901
Fixed an issue where the firewall dropped client hello packets when decryption was enabled, which prevented access to certain websites. This occurred when the client hello packet was truncated, the accumulation proxy assumed that the first packet contains at least 5 bytes, or out-of-order packets were waiting in L4 TCP.
## PAN-279690
Fixed an issue where the the all_pktproc process stopped responding, which caused the firewall to unexpectedly restart.
## PAN-279415
Fixed an issue where service routes configured to use a data plane interface incorrectly used the management plane interface for traffic transmission. This issue affected syslog and CRL status traffic when a custom service route was not configured.
## PAN-276616
Fixed an issue on the firewall where half-duplex settings on Ethernet were not visible.
## PAN-271810
Fixed an issue where auto-negotiation advertised and negotiated 10/100 half and full duplex.
## PAN-268787
Fixed an issue where users were unable to log in to Panorama and the following error message was displayed: Timed out while getting config lock. Please try again. This occurred when pushing configurations to a large number of devices.
## PAN-255860
```caveat
PA-5200 firewalls only
```
Fixed an issue where the all_pktproc process stopped responding when the firewall was under a heavy traffic load.
## PAN-252706
Fixed an issue where the URL filtering response page for Continue and Override did not work with IPv6 Router Advertisement (RA) or Multicast Listener Query (MLQ) for IPv6-to-IPv6 and IPv6-to-IPv4 traffic.
@@ -0,0 +1,37 @@
---
type: Addressed
product: PAN-OS
version: 11.2.7-h2
---
## PAN-291499
```caveat
VM-Series firewalls on Amazon Web Services (AWS) environments only
```
Fixed an issue where newly deployed firewalls were unable to connect to the Palo Alto Networks Software License Server (SLS) until after a reboot, license fetch, or management server restart.
## PAN-290241
Fixed an issue where the useridd process became unresponsive, which caused User ID CLI commands to time out.
## PAN-287688
Fixed an issue where the firewall failed to connect to the Palo Alto Networks update server when using a customized service route with the source interface as MGT.
## PAN-268680
Fixed an issue where the configd process stopped responding when a configuration merge operation changed.
## PAN-268522
Fixed an issue where the firewall failed to connect to the update server with a customized service route when the source interface was set to MGT and the source address was set as IPv4.
## PAN-241230
Fixed an issue where the SNMP get request status value for Panorama connections was incorrect.
## PAN-216770
Fixed an issue where, when a firewall was managed by Strata Cloud Manager and configured to use a proxy server for external connections, the management server did not use the configured settings to connect to the Cloud Management service.
@@ -0,0 +1,97 @@
---
type: Addressed
product: PAN-OS
version: 11.2.7-h3
---
## PAN-297458
Fixed an issue where the all_task_1 process crashed on the firewall when the wif service wasn't available because the wif detection ID was not in the current service table.
## PAN-297261
Fixed an issue where the proxy-protocol debug level was set to verbose on Prisma Access instances, even when it was not explicitly configured, which caused excessive logging by the pan_task process.
## PAN-296519
Fixed an issue where a stream receiving a reconnect signal with an associated error in Wifclient caused the entire pool to close, which resulted in a complete disconnection.
## PAN-296478
Fixed an issue where, after upgrading to PAN-OS 10.2.13-h10, GlobalProtect Clientless VPN on PA-3250 firewalls failed to execute JavaScript links, resulting in an authorization error. This occurred because the firewall was incorrectly injecting text into URLs when JavaScript buttons or dropdown menus were clicked within the Clientless VPN portal.
## PAN-295812
Fixed an issue where the throughput data on the Switch Card Module (SCM) was not accurately reported. This issue affected Standard SC USABN and USABN-2 when using Direct-IO deployment.
## PAN-294179
Fixed an issue on Panorama where commit versions did not display correct data in the config audit page even after a refresh.
## PAN-292202
Fixed an issue where the system logs repeatedly displayed the alert Clearing snmpd.log due to log overflow due to the SNMP counters rolling over.
## PAN-291631
```caveat
VM-Series firewalls only
```
Fixed an issue where the firewall frequently rebooted.
## PAN-291288
Fixed an issue where the firewall rebooted unexpectedly due to a pan_task process restart related to page allocation failures.
## PAN-290449
Fixed an issue where, when multiple scheduled vulnerability reports were sent in the same email, only the first attached report was displayed.
## PAN-288726
Fixed an issue where the useridd process stopped responding due to a Security policy rule ID being set to 0, which caused the last configuration retrieval to fail.
## PAN-287423
Fixed an issue where content loading issues occurred on IPv6 websites due to the firewall incorrectly setting the IPv6 header flow label to 0.
## PAN-286299
Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the Network and Device tabs became read-only.
## PAN-286231
Fixed an issue where a simultaneous selective push from Panorama to multiple firewalls with different base configurations resulted in configuration corruption, which caused the firewall to go down.
## PAN-285285
Fixed an issue where commits remained at 98% completion when static route configuration cleanup was in progress.
## PAN-284073
Fixed an issue on the firewall that caused commits to fail and the web interface to become inaccessible.
## PAN-279706
```caveat
M-600 appliances only
```
Fixed an issue where Panorama did not update all panreplay database entries after performing a commit and full push to all devices.
## PAN-277034
Fixed an issue where WildFire reports were not fully displayed and were not downloadable due to static resources not being found.
## PAN-276484
Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (Device Deployment > Licenses) due to the inability to perform batch-license refreshes.
## PAN-259741
Fixed an issue where the firewall dropped GRE keepalive packets that were encapsulated under another GRE tunnel.
## PAN-251442
Fixed an issue where the firewall rebooted into maintenance mode if the authentication process restarted repeatedly.
@@ -0,0 +1,177 @@
---
type: Addressed
product: PAN-OS
version: 11.2.7-h4
---
## PAN-304088
Fixed an issue where TCP traffic stopped working from Prisma Access clients to TCP services behind the Service Connection (SC) after a dataplane upgrade to an affected release.
## PAN-303559
Fixed an issue where, after manually creating a device telemetry bundle, the hour_cli_output.txt file within the bundle had a file size of 0 bytes. This occurred when checking the bundle content after enabling device telemetry and setting the device telemetry upload endpoint.
## PAN-301828
Fixed an issue where, when a firewall was managed by Strata Cloud Manager and configured to use a proxy server for external connections, the management server did not use the configured settings to connect to the Cloud Management service.
## PAN-300906
Fixed an issue where XML API commands failed with a Method not found (policy_xml) error in dagger.log. The issue was due to missing XML-related functions for inline-cloud-proxy.
## PAN-298505
Fixed an issue where, after upgrading an HA pair of PA-7050 firewalls, the vsys ID changed in sequence, causing autocommit failures with validation errors. This occurred when the multi-vsys firewall had virtual systems created and pushed from Panorama, and the vsys ID was not in a correct sequence because the unused vsys was deleted from Panorama and pushed to devices.
## PAN-298387
Fixed an issue on the firewall where the source and destination NAT IP addresses did not display in traffic and threat logs.
## PAN-297972
Fixed an issue where a dataplane crash occurred when traffic matched Inline Cloud Analysis prefiltering signatures, even when Inline Cloud Analysis features were not enabled.
## PAN-297775
Fixed an issue where, after upgrading, the Visible Virtual Systems field started to reference the vsys name instead of the vsys ID, which caused inter-vsys routing to fail. This occurred when a vsys display name matched one of the vsys IDs.
## PAN-297240
Fixed an issue where attempting to generate reports in a WildFire FIPS Private Cloud or WF-500 deployment returned 401 errors.
## PAN-295560
Fixed an issue where, after upgrading Panorama and Log Collectors, tunnel logs were not visible in Panorama or Splunk even though traffic and threat logs were received.
## PAN-295385
Fixed an issue where syslog forwarding dropped due to FQDN resolution failures.
## PAN-295257
Fixed an issue where, after onboarding a firewall to Panorama, IPsec tunnels displayed IKEv2 in Panorama, even though the tunnels were configured with IKEv1 locally on the firewall.
## PAN-295221
Fixed an issue where, after upgrading Panorama and Log Collectors, Traffic and Threat logs were not forwarded to a Splunk server over UDP.
## PAN-294893
Fixed an issue where firewalls with the Send handshake messages to CTD for inspection setting enabled caused incorrect security policy rules to be matched. Specifically, traffic not identified as openai-base or openai-chatgpt applications was incorrectly matched by the ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected response page for blocked URLs was not displayed.
## PAN-294524
Fixed an issue where firewalls and Panorama management servers were unable to view or download WildFire reports from a WF-500 appliance, resulting in a 401 error in the report tab.
## PAN-294320
Fixed an issue where the mprelay process repeatedly restarted.
## PAN-294161
Fixed an issue where the firewall rebooted unexpectedly due to the useridd process restarting and causing an HA failover. This occurred due to the configd process timing out when running the CLI command show user user-id-agent config all.
## PAN-292447
Fixed an issue where Panorama did not display data in the Feature Adoption tab in Strata Cloud Manager due to the system creating and deleting a CLI user for each interval instead of reusing a permanent CLI user for telemetry.
## PAN-291940
Fixed an issue where the firewall established multiple TCP connections to a syslog server, which caused logs to be dropped. This occurred because the firewall established a new TCP session for each transfer and the sessions were not closed, which resulted in a continuous increase in connections over time.
## PAN-291716
Fixed an issue where during a commit, the firewall experienced an out-of-memory (OOM) condition due to a memory leak and displayed an error message. This issue caused the device to crash and reboot unexpectedly.
## PAN-291653
Fixed an issue where the GlobalProtect host ID field was intermittently blank in traffic logs on Prisma Access, even when the user was connected and had the correct host ID information. This occurred when the IP address to host ID entry expired and the entry was re-insterted without the dataplane flag being set.
## PAN-291635
Fixed an issue where cookie surrogate cache entries remained unresolved after an idmgr process reset due to the request not being retransmitted. This occurred because the timestamp in the cache entry was refreshed even when the UID was 0, which prevented the retransmission of the request if the initial response was not received.
## PAN-291283
Fixed an issue on Panorama where a memory leak associated with the configd process occurred during commits, which caused the configd process to restart and the commit to fail.
## PAN-291067
Fixed an issue where the devsrvr process periodically exceeded its virtual memory limit and restarted, which led to intermittent outages.
## PAN-289859
```caveat
Panorama virtual appliances only
```
Fixed an issue where Panorama failed to mount logging disks larger than 2TB due to a partitioning error.
## PAN-289405
```caveat
VM-Series firewalls only
```
Added the CLI command no-refresh-discard-session to address an issue where the discarded session time to live (TTL) did not refresh at the default value.
## PAN-289383
Fixed an issue where the MPLS interface eth1/6 went down and remained down, even after replacing the SFP with a supported one and adjusting duplex and speed settings.
## PAN-289249
Fixed an issue where a memory leak occurred on the reportd process when a WildFire update was initiated while device telemetry data collection was in progress. This resulted in an OOM condition.
## PAN-289109
Fixed an issue where the Panorama web interface was slower than expected during configuration operations and a configuration lock time out occurred during a commit.
## PAN-288097
Fixed an issue where on the firewall where the routed process stopped responding after changing the MTU or any link state parameters when OSPF and PIM were enabled on the same interface.
## PAN-287803
Fixed an issue where, after upgrading, certain websites weren't accessible when the accumulation proxy was enabled. The proxy did not use the same DF bit state as the original traffic, causing it to be fragmented and dropped elsewhere in the network.
## PAN-287782
Fixed an issue where firewalls configured in vwire mode modified DSCP values from AF11 to CS0 on traffic passing through the firewall, even when QoS policy rules and DSCP rewrite settings were not configured.
## PAN-287622
Fixed an issue where IPv6 traffic was affected after upgrading the firewall. With SSL decryption enabled and a decryption policy configured for the traffic, the firewall dropped packets due to receiving a Packet Too Big ICMP message. This occurred because the PathMTU information update was incorrect for the TCB (pan-server) when the firewall was acting as a server. Additionally, the flow label under the IPv6 header was set to zero while the packet was being transmitted out of the firewall.
## PAN-287601
Fixed an issue on Panorama where commits took longer than expected.
## PAN-287387
Fixed an issue on Panorama where API jobs failed with the error message Server error: Timed out while getting config lock. This occurred due to slow set request performance when setting a large number of address objects in a single set call.
## PAN-283053
Fixed an issue where the firewall experienced high disk space utilization, which caused the firewall to become non-functional.
## PAN-282277
Fixed an issue where an OOM condition on the logrcvr process caused interface flapping, and the interface unexpectedly went down and then recovered without intervention.
## PAN-281776
Fixed an issue on the Panorama web interface where the error message PPPoEv6 Client Interface cannot be enabled with DHCPv6 client was generated when overriding aggregate interfaces even when no DHCPv6 or PPPoE was configured.
## PAN-278836
Fixed an issue where, after an upgrade, GlobalProtect attempted to use the embedded browser instead of the default browser for gateway authentication even when it was configured to use the default browser.
## PAN-272245
Fixed an issue where the dnsproxy process stopped responding due to memory corruption caused by a race condition when the allow list downloading was impacted by a configuration change.
## PAN-267450
Fixed an issue where the reportd process stopped responding with a SIGSEGV at schedule_report_es_response.
@@ -0,0 +1,21 @@
---
type: Addressed
product: PAN-OS
version: 11.2.7-h7
---
## PAN-306534
Fixed an issue were the all_task process repeatedly restarted due to memory pool corruption when processing fragmented DNS over HTTPs (DoH) JSON queries. This occurred due to incorrect buffer length calculations during memory deallocation when the query name field spanned multiple packets.
## PAN-305480
Fixed an issue where the pan_task process stopped responding while processing DoH JSON format traffic with DoH Security enabled, which caused missing cross-packet bytes in the decoded DNS query type field, and the dataplane went down.
## PAN-305301
Fixed an issue where GlobalProtect notifications in tunnels caused processes to stop responding and the dataplane to restart due to the session lookup returning an incorrect session, which resulted in the data being sent through the wrong tunnel.
## PAN-292344
Fixed an issue where the firewall rebooted multiple times after an upgrade if the config contained an EDL (External Dynamic List) that didn't have an associated certificate profile.
@@ -0,0 +1,149 @@
---
type: Addressed
product: PAN-OS
version: 11.2.7-h8
---
## PAN-308727
Fixed an issue where traffic logs for Remote Networks displayed the source zone as trust instead of the remote network name.
## PAN-308468
Fixed an issue where the firewall rebooted due to the all_task process restarting.
## PAN-303051
Fixed an issue on Panorama where a memory leak occurred related to the reportd process due to retaining memory that was temporarily used for report generation instead of releasing the memory for reuse, which resulted in continuous accumulation and memory exhaustion.
## PAN-302927
Fixed an issue where, after upgrading Panorama, the Push to Devices option did not display selected devices, and the OK and Cancel buttons did not function as expected. Selecting OK did not close the window, and selecting Cancel returned to the main push screen with the push selected devices displaying as empty. Despite this, selecting Push or Validate Device Group Push still pushed to the previously canceled, non-displayed devices.
## PAN-301801
Fixed an issue on Log Collectors where the Elasticsearch process fluctuated intermittently between green and red states, which led to interruptions in log collection. This issue occurred when the number of shards exceeded the cluster's maximum supported threshold of greater than 1000 shards per Elasticsearch instance.
## PAN-301691
Fixed an issue where BGP stopped responding with the error message Too many open files when pushing 1000 eBGP (External BGP) neighbor configurations. With this fix, the number of file descriptors for the BGP process is increased from 1024 to 8192.
## PAN-301456
Fixed an issue on Panorama where the debug system reset-ztp CLI command was unavailable.
## PAN-300216
Fixed an issue where, when SD-WAN Direct Internet Access was configured and traffic traversed the cellular interface without a NAT policy rule, intermittent cellular modem connectivity issues occurred, which caused the firewall to disconnect and reconnect to the cellular network.
To use this fix, run the CLI command set session teardown-upon-fwd-zonechange yes.
## PAN-300138
Fixed an issue where DNS queries stalled or repeatedly time out due to multiple DNS responses with different CNAME values causing evasion false positive alerts.
## PAN-299772
```caveat
VM-Series firewalls in active/passive configurations only
```
Fixed an issue where, after an HA failover event, the newly active firewall DHCP client interfaces failed to obtain IP addresses automatically. This occurred because the DHCP client processes did not initiate the necessary DHCP discover or renew requests
## PAN-297976
Fixed an issue where the firewall experienced extended boot times after a reboot due to the configd process needing to rebuild the ACE catalog after detecting discrepancies that were caused by duplicate application checking between the ACE catalog and content.
## PAN-297610
Fixed an issue where the firewall became unresponsive after an upgrade due to the fsck command scanning drive partitions in parallel with the root partition, which caused the process to take an extended amount of time.
## PAN-297005
Fixed an issue where exporting custom reports resulted in empty CSV files.
## PAN-296977
Fixed an issue where the web interface became unresponsive when attempting to view Ethernet interface details after applying a filter in NetworkInterfaces
## PAN-296752
```caveat
PA-1410 Firewalls only
```
Fixed an issue where the firewall experienced high management CPU usage and repeatedly rebooted when attempting to retrieve SMART data.
## PAN-296694
Fixed an issue where the firewall rebooted due to the useridd process repeatedly restarting during an IP-port data type writes to the redis from multiple sources such as TSA or XML in a scale environment.
## PAN-296535
Fixed an issue on the firewall where BGP peers disconnected when more than 500 BGP neighbors were configured in a single Logical Router
## PAN-295899
Fixed an issue where DNS resolution failed on Linux machines running GlobalProtect client version 6.2.6 when connected with DNS Security enabled. This occurred because the firewall incorrectly discarded DNS packets when processing multiple DNS requests or responses over the same session, even when no malicious verdict was received.
## PAN-295342
Fixed an issue where the pan_comm process stopped responding due to insufficient time allocated to read file descriptors when processing long messages.
## PAN-295049
Fixed an issue where the logrcvr process stopped responding due to memory allocation errors during Redis communication.
## PAN-293985
Fixed an issue with the Panorama web interface where admin users were unable to log in and received the error message 504: Gateway Timeout.
## PAN-292770
Fixed an issue where, after reinstalling the device certificate, delayed telemetry data was displayed in AIOPS.
## PAN-291661
Fixed an issue on Panorama appliances and Log Collectors where, after an upgrade, Elasticsearch intermittently entered into a Red state before automatically recovering.
## PAN-288388
Fixed an issue where, after an EDL certificate update or repository migration, authentication failures caused the firewall to not fall back to the last successfully cached EDL entries, which led to policy rules that referenced the EDL to not be enforced.
## PAN-287842
Fixed an issue where the comm process stopped responding due to missing heartbeats, which resulted in a system alert and HA communication loss on slot1.
## PAN-285169
Fixed an issue on Panorama where Kerberos superusers were unable to edit policy rules because the target device tab was grayed out.
## PAN-281797
Fixed an issue where firewalls became unstable and stopped responding, which resulted in an OOM condition.
## PAN-280917
Fixed an issue on Panorama where the WildFire cloud URL contained an extra period character, which prevented the retrieval of WildFire analysis reports.
## PAN-279829
Fixed an issue where NAT pool leaks occurred during a test when RTSP traffic hit NAT rules.
## PAN-270554
Fixed an issue where the GlobalProtect client (UWP) or metered hotspot connections triggered TLS resumption fo GlobalProtect portal authentication, which caused the portal authentication to fail with a valid cert required error.
## PAN-264131
Fixed an issue where the routed process core failed the automation run.
## PAN-209516
Fixed an issue where, when creating an interface, an error occurred when you clicked OK without providing a value in the Tag field even though the field was not displayed as mandatory.
## PAN-185731
Fixed an issue where the firewall was unable to parse the URL path and host when the host header was located in a different packet, which resulted in the firewall not logging the URL path in the first packet.
The fix is disabled by default. The following CLI commands can be used to enable/disable the feature: set system setting ctd url-crosspkt-host-path-caching enable set system setting ctd url-crosspkt-host-path-caching disable set system setting ctd url-crosspkt-host-path-caching default
@@ -0,0 +1,689 @@
---
type: Addressed
product: PAN-OS
version: 11.2.7
---
## PAN-290803
```caveat
VM-Series firewalls on Microsoft Azure environments only
```
Fixed an issue where firewall failed to bootstrap with a custom image, and VM-Series plugin information was not displayed in the system information.
## PAN-290542
Fixed an issue where the all_task process stopped responding when an additional header logging HTTP header was split across 2 packets.
## PAN-290239
```caveat
PA-455 firewalls in active/passive high availability (HA) configurations only
```
Fixed an issue where, after an upgrade, the TCP session for syslog forwarding did not resume after the syslog server service was disabled and then re-enabled, which caused logs to be dropped. This occurred when the syslog server was down for more than 16 minutes.
## PAN-289102
```caveat
PA-7500 Series, PA-5410, PA-5420, PA-5430, PA-5440, PA-5445, PA-3400 Series, PA-1400 Series, PA-400 Series, VM-Series, and CN-Series firewalls only
```
Fixed a race condition issue related to predict processing, which resulted in a dataplane restart and traffic loss.
## PAN-288930
Fixed an issue where traffic from cloud applications intermittently matched an incorrect cloud-apps policy rule when ACE (App-ID Cloud Engine) was enabled.
## PAN-287818
Fixed an issue where sessions timed out sooner than expected due to the pan_proxy_accumulation_restore_timeout not initiating when the accumulation session_init failed.
## PAN-286897
Fixed an issue where the pan_task process stopped responding when the firewall attempted to forward files to the WildFire public cloud, which caused the dataplane to experience heartbeat failures.
## PAN-286857
Fixed an issue where only failed Kerberos authentication events were logged in auth.log, and successful authentication events were not logged.
## PAN-286848
Fixed an issue where ECMP incorrectly balanced sessions across links based on the configured metric, which led to an imbalance in traffic distribution and resulted in traffic assignment shifting disproportionately to routes with lower metrics.
## PAN-286825
Fixed an issue where GlobalProtect User-ID mappings were lost after 5 minutes, which caused users to not match User-ID source-based policy rules. This occurred due to a mismatch between the GlobalProtect gateway connection settings and the device behavior and when the inactivity-logout setting was deleted and set to a different value.
## PAN-285894
Fixed an issue where the all_task process stopped responding, which caused the firewall to reboot unexpectedly, and traffic failures occurred.
## PAN-285651
```caveat
Panorama appliances in active/passive HA configurations on Microsoft Azure environments only
```
Fixed an issue on Panorama that caused firewalls to disconnect unexpectedly.
## PAN-285597
Fixed an issue where a routed process memory leak occurred when advanced routing was enabled.
## PAN-285590
```caveat
VM-Series firewalls on Amazon Web Services (AWS) GWLB environments only
```
Fixed an issue where the firewall CPU usage reached 100% after upgrading to PAN-OS 11.1.6-h1.
## PAN-284117
```caveat
Panorama appliances in Log Collector mode only
```
Fixed an issue where the vm_agent process restarted after an upgrade.
## PAN-284066
Fixed an issue where, after an upgrade, the SNMP polled values for IF-MIB::ifInErrors displayed a high number of errors that did not match the values in the CLI show interface command.
## PAN-283813
Fixed an issue on Panorama where the web interface performance was slower than usual when retrieving read-only configurations from Panorama.
## PAN-283789
```caveat
Firewalls in HA configurations only
```
Fixed an issue where, after an upgrade, the mac receive error counter in receive incoming errors increased, which resulted in SNMP alerts.
## PAN-283644
```caveat
Prisma Access only
```
Fixed an issue where URL log ingestion decreased after an upgrade, and secondary connections were lost.
## PAN-283331
Fixed an issue where selective pushes to managed devices failed when the User ID Master Device was configured.
## PAN-282697
Fixed an issue where traffic was delayed significantly when it used No Authentication Explicit Proxy and matched a decryption policy rule.
## PAN-282640
Fixed an issue where custom reports showed incomplete data when exported in CSV format from Panorama.
## PAN-282394
Fixed an issue where a firewall was only able to display a maximum of 14 permitted IP addresses from a Panorama Template Variable.
## PAN-282391
```caveat
Panorama appliances and Log Collectors only
```
Fixed an issue where a VLD memory leak caused increased memory use, which resulted in OOM errors.
## PAN-282359
Fixed an issue where the Panorama web interface was slower than expected.
## PAN-282240
Fixed an issue where, when attempting to modify an Anti-Spyware profile via the web interface under a shared location, clicking the OK button displayed a console exception error.
## PAN-281885
Fixed an issue where, when exporting and importing CSV files, the hash values of pre-shared key variables set at template and template stack levels changed inconsistently, which resulted in both variables displaying the same hash value.
## PAN-281882
Fixed an issue where OSPF redistributed connected routes beyond the intended loopback IP address.
## PAN-281649
Fixed an issue where the index size limit was incorrectly calculated and indices rolled over earlier than expected, which resulted in high memory and OOM errors.
## PAN-281540
Fixed an issue where the logd process repeatedly restarted when the SD-WAN site name was over 31 characters and contained certain XML escape characters.
## PAN-281509
```caveat
Panorama appliances only
```
Fixed an issue where log exports were slower than expected or failed when filtering logs after an upgrade, which resulted in timeouts or delays in displaying logs on the web interface.
## PAN-281269
```caveat
PA-5420 firewalls
```
Fixed an issue where the firewall management server memory usage continuously increased.
## PAN-281264
Fixed an issue where the routed process memory usage continuously increased when Advanced Routing was enabled.
## PAN-280942
Fixed an issue where the logrcvr process stopped responding.
## PAN-280698
Fixed an issue where the firewall removed the TCP timestamp from client hello messages that did not fit in a single packet, which resulted in connection issues.
## PAN-280532
Fixed an issue where, after disabling and re-enabling the external syslog server, the TCP session was not resumed, which caused all logs that were forwarded to the syslog server to be dropped.
## PAN-280505
Fixed an issue where the web interface did not display a message to commit prior changes before attempting a partial configuration load.
## PAN-280477
Fixed an issue on the web interface were you were unable to scroll up or down to view source zones in a NAT policy rule.
## PAN-280335
Fixed an issue with an SNMPv3 EngineBoots value discrepancy that prevented to SNMP server from logging.
## PAN-280243
Fixed an issue where the firewall lost the pre-shared key configuration assigned from a PSK variable when an unrelated device group configuration was loaded.
## PAN-279691
```caveat
Firewalls in active/passive HA configurations only
```
Fixed an issue where the firewall didn't synchronize IPSec SAs (security associations) to the passive firewall if the tunnel was not initially established by the active firewall.
## PAN-279500
Fixed an issue where TLS connections failed to establish in asymmetric routing environments if the firewall did not see server-to-client (s2c) packets of the TLS handshake.
To use this fix, run the following CLI command: debug dataplane set ssl-decrypt accumulate-client-hello asym-disable yes.
## PAN-279495
Fixed an issue where accessing a URL from the browser returned the error message ERR_RESPONSE_HEADERS_TRUNCATED when the firewall was configured with TLS 1.3.
## PAN-279400
Fixed an issue where, when Restrict Certificate Extensions was enabled on decryption profiles, the basic constraints extension was overwritten incorrectly.
## PAN-279336
Fixed an issue where the CLI did not display a message to commit prior changes before loading a partial configuration.
## PAN-279176
Fixed an issue where the configuration audit displayed inaccurate information after partially loading the configuration via the CLI, which caused the audit to flag the configuration as deleted or changed.
## PAN-279065
Fixed an issue where the firewall sent logs with connection succeeded to the syslog server every time a connection was established, which resulted in excessive logs.
## PAN-278981
Fixed an issue where DNS domain resolutions experienced intermittent delays due to the firewall not connecting to the DNS Security cloud.
To use this fix, enable DNS monitoring on the dataplane via the CLI command debug dnsproxyd enable-rtsig-health-monitor yes.
To show the current setting, run the CLI command debug dnsproxyd enable-rtsig-health-monitor show. If the cfg.general.dns-rtsig-monitor-interval shows a non-zero value, DNS monitoring is enabled.
## PAN-278812
Fixed an issue where authentication to GlobalProtect failed with the error message User not in allowed list.
## PAN-278461
```caveat
Firewalls deployed in Amazon Web Services (AWS) environments only
```
Fixed an issue where DNS Security retransmit packets were not re-encapsulated into Geneve, which caused DNS requests that were initiated from the firewall to be returned to AWS GWLB.
## PAN-278190
Fixed an issue on Panorama where a scheduled report with SLS data had an invalid translated-query.
## PAN-278150
Fixed an issue where the firewall removed the Authentication Key Identifier (AKID) from the certificate during SSL decryption, which caused Python 3.13 to fail with a certificate verification error.
## PAN-277808
Fixed an issue where the eproxy. process stopped responding when running a long duration test using IXload with hybrid SWG SAML authentication bypass for HTTPS payloads, which caused the proxy to become unreachable.
## PAN-277631
Fixed an issue where the logrcvr process discarded logs due to a full queue.
## PAN-277464
Fixed an issue with intermittent access and slower than expected loading times when accessing websites. This occurred when Anti-Spyware inline cloud analysis was enabled and the SSL Command and Control action was not either allow or alert and server hello packets were out of order.
## PAN-277234
Fixed an issue where a device group import resulted in a Security policy rule being created with Application set to none.
## PAN-277147
Fixed an issue where daily scheduled reports were not generated and emailed.
## PAN-276920
Fixed an issue where web-advertisement traffic was not immediately blocked which resulted in pages loading indefinitely.
## PAN-276678
Fixed an issue where Panorama became unresponsive while performing a dynamic address update without a lock.
## PAN-276276
```caveat
PA-450 firewalls only
```
Fixed an issue where, after an upgrade, data that was excluded using the query builder in a custom report was still visible in the report, and the logs displayed errors related to invalid threat names being queried.
## PAN-276062
Fixed an issue where importing a firewall with a large number of address objects into Panorama did not work and remained at 99% completion.
## PAN-275754
Added support for bootstrapping Panorama virtual appliances on ESXi.
## PAN-275718
Fixed an issue where Panorama stopped forwarding logs to a syslog server after upgrading to PAN-OS 11.1.5-h1.
## PAN-275713
Fixed an issue where the dscd process stopped responding when Endpoint Serial Number was enabled, which resulted in the **Active Directory* returning a list of serial numbers for a specific firewall from the Cloud Identity Engine.
## PAN-275133
Fixed an issue where HTTP 503 server errors occurred while browsing websites due to slow Secure Web Gateway (SWG) bypass rule lookup.
## PAN-275077
Fixed an issue where DNS Security intermittently logs malicious domain URLs as Alert instead of taking a Sinkhole action, even when configured to Sinkhole malicious DNS domains.
## PAN-275047
```caveat
VM-Series firewalls only
```
Fixed an issue where, after an upgrade, the firewall was unable to send logs to the Strata Logging Service (SLS) when using a specific proxy server, and the SSL connection status displayed as failed when attempting to forward logs through the web proxy.
## PAN-274806
```caveat
PA-5250 firewalls only
```
Fixed an issue where IPv6 pings experienced a high number of dropped packets when forwarded to another dataplane, which resulted in ping failures. This occurred when initiating a ping to the link local address of the firewall and the packet drop percentage depended on the number of dataplanes.
## PAN-274797
Fixed an issue where a DPC on slot 3 failed intermittently due to the pktlog_forwarding process restarting, which resulted in an unexpected HA failover.
## PAN-274750
Fixed an issue where the detailed log view in Panorama did not display all packet details for traffic logs received from the cloud.
## PAN-274726
Fixed an issue where Wildfire signature generation was enabled on all nodes in a cluster instead of only the active node.
## PAN-274697
Fixed an issue where push operations from Panorama failed on passive firewalls when an application was removed from a Security policy rule and the policy rule was referenced in a device group.
## PAN-274671
Fixed an issue where empty traffic logdb folders were generated for each day even when trafcfic logs were not received by the logrcvr process.
## PAN-274569
Fixed an issue where the QSPF transceiver interface displayed an incorrect range figure on the temperature alarm.
## PAN-274496
Fixed an issue where the root partition reached 100% which caused the system to become non-functional and failover even when aggressive cleaning was enabled.
## PAN-274146
Fixed an issue where the firewall rebooted continuously after upgrading to PAN-OS 11.1.5-h1 when a tunnel session was established in a Gateway Load Balancing (GWLB) scenario and no data packet was associated with the packet.
## PAN-273964
Fixed an issue where SNMP scans to a firewall timed out after upgrading to a PAN-OS 10.2 release.
## PAN-273694
Fixed an issue where the firewall rebooted due to an out-of-bounds memory access that occurred as a result of the SIP content length value being split across packets.
## PAN-273614
Fixed an issue where packets were dropped initially when a SYN cookie with activation threshold 0 was enabled.
## PAN-273597
Fixed an issue where logs in the cloud database displayed in the Not-Resolved category but not in the local database.
## PAN-273453
Fixed an issue where restarting the firewall did not initiate an autocommit job, which caused the firewall to stop responding and the HA interface to go down.
## PAN-273277
Fixed an issue where GlobalProtect clients on macOS devices were prompted to enter their username and password for Kerberos SSO authentication.
## PAN-273153
Fixed an issue where the Panorama web interface was slower than expected due to excessive polling of the MonitorDirect.getTasks API by the Task Manager.
## PAN-273141
Fixed an issue where GlobalProtect clients experienced slow file transfer download throughput when passing through an IPSec tunnel.
## PAN-272812
Fixed an issue where SNMP monitoring of tunnel interfaces displayed zero values for received bytes and packets.
## PAN-272746
```caveat
PA-440 firewalls only
```
Fixed an issue where the firewall entered an unstable state after committing changes or onboarding to Panorama.
## PAN-272605
Fixed an issue where the firewall did not display VPC endpoints when there was a large amount of VPC endpoints to interface mappings.
## PAN-272539
```caveat
Panorama appliances on Microsoft Azure environments only
```
Fixed an issue where user to IP address mapping was missing for some users connected to specific Prisma Access gateways, which caused the collection layer Azure firewall to not form the mapping.
## PAN-272395
Fixed an issue where informational logs caused the distributord process log file to be frequently overwritten.
## PAN-272175
Fixed an issue where session rematch caused ACE cloud application traffic to match the wrong policy.
## PAN-271700
Fixed an issue where User-ID connections were lost after an HA failover.
## PAN-271560
Fixed an issue where DNS requests to malware sites were not blocked as expected, and the dns-security-categories log-level and action displayed default values instead of unavailable.
## PAN-271498
```caveat
PA-7000 Series firewalls, PA-5200 firewalls, and PA-5400f firewalls in FIPS mode only
```
Fixed an issue where decrypted traffic repeatedly failed and frequent reboots were required.
## PAN-271425
```caveat
Firewalls in active/active HA configurations only
```
Fixed an issue with SSL inbound decryption on firewalls on a vwire setup with asymmetric routing.
To use this fix, enter the CLI command set system setting ssl-decrypt ha-vwire-mac-learn global yes on both firewalls in an HA pair.
## PAN-271184
Fixed an issue where Device Telemetry failed due to an issue with the encoding of characters in the log file path.
## PAN-271175
Fixed an issue where the all_task process stopped responding with a SIGABRT.
## PAN-271151
Fixed an issue where the GlobalProtect client did not automatically initiate a Kerberos SSO connection after logging in to Windows.
## PAN-270849
Fixed a memory leak issue related to the configd process that occurred when running consecutive commits for multiple days.
## PAN-270744
Fixed an issue where API calls to Panorama failed with the error Server error : Timed out while getting config lock. Please try again.
## PAN-270379
Fixed an issue where socket files created in the /tmp directory were not cleared.
## PAN-270193
Fixed an issue where the Panorama management server changed its certificate authority (CA) unexpectedly, which caused managed firewalls to disconnect.
## PAN-270192
Fixed an issue where Panorama did not display the management IP address of devices onboarded via ZTP.
## PAN-269700
Fixed an issue where commits to service connection firewalls from Panorama failed.
## PAN-269677
Fixed an issue where Panorama did not check for a NULL pointer when querying logs, which caused logs to not display on the web interface.
## PAN-269624
Fixed an issue where GlobalProtect clients failed to connect with the error message The device or feature requires a GlobalProtect subscription license.
## PAN-269193
Fixed an issue where the firewall redirected the user to the first application instead of the portal page with a list of applications when multiple applications were configured for GlobalProtect clientless VPN along with any user match.
## PAN-269139
```caveat
Firewalls with DPDK enabled in Azure, GCP, AWS, and KVM environments only
```
Fixed an issue where, after an upgrade to PAN-OS 11.1.4, the mac receive error counter increased without an error even though traffic was not impacted.
## PAN-268708
Fixed an issue where PDF summary and email reports displayed IPv6 addresses instead of IPv4 addresses.
## PAN-268614
Fixed an issue on the web interface where, when all rules were highlighted when a read-only admin user clicked the Highlight Unused Rules checkbox.
## PAN-268489
Fixed a Threat log PCAP ID overwrapping issue.
## PAN-268465
Fixed an issue with firewalls in active/passive HA configurations where the total user count in the registered users was different between the active and passive firewall.
## PAN-268279
Fixed an issue where autocommits failed if the management IPv6 gateway was the same as the dataplane interface IP address.
## PAN-267759
Fixed an issue where Prisma Access gateway downloads were slower than expected.
## PAN-267518
Fixed an issue where WildFire submission logs incorrectly reported allowed malicious samples even when they were blocked by threat prevention profiles.
## PAN-266427
Fixed an issue on the firewall where, when a high number of SD-WAN branch sites or interfaces were not connected, SD-WAN processes and tund processes stopped responding due to a high probing rate.
## PAN-266116
Fixed an issue where URLs did not work due to certificate revocation list (CRL) requests failing.
## PAN-265900
Fixed an issue where the firewall stopped responding due to a tund process or SD-WAN process restart.
## PAN-265791
Fixed an issue where the all_task process stopped responding, which caused the dataplane to go down.
## PAN-264982
```caveat
VM-Series firewalls on Kernel-based Virtual Machine (KVM) only
```
Fixed an issue where the firewall entered maintenance mode after an auto-commit when sending an ARP packet through the loopback interface using an IPv6 address.
## PAN-264708
Fixed an issue where a selective push was blocked when a configuration load was done.
## PAN-262729
```caveat
Panorama appliances only
```
Fixed an issue where the configd process experienced continuous high CPU utilization and repeatedly restarted.
## PAN-262373
Fixed an issue where the error message Failed to reload config files displayed in the system logs even when device telemetry was not enabled.
## PAN-262372
Fixed an issue where the firewall generated the error message Successfully generating a new set of config files in the system logs even when device telemetry was not enabled.
## PAN-262063
Fixed an issue where the firewall did not display the converted configurations before a commit and reboot, and the commit failed when attempting to migrate from MS to FRR mode.
## PAN-261597
Fixed an issue where the all_pktproc process stopped responding, which caused the firewall to become unavailable.
## PAN-261312
Fixed an issue where a commit for a policy and configuration dump overlapped, which resulted in a null pointer exception.
## PAN-261074
Fixed an issue where the firewall delayed video file transfers over SMB when Exclude Video Traffic from the Tunnel feature was enabled and no applications were added to the list.
## PAN-260229
Fixed an issue where HA path monitoring using VWire did not work as expected after a reboot.
## PAN-259727
```caveat
Panorama appliances in HA configurations only
```
Fixed an issue where Panorama became unresponsive and displayed a 504 gateway timeout error when accessing the web interface or the CLI.
## PAN-259610
Fixed an issue where Wildfire content installation failed for WF-500B clusters when deployed from Panorama using the deployment schedule.
## PAN-258743
Fixed an issue where, when you attempted to select a redistribution profile when creating a BGP Redistribute policy rule, the firewall displayed an empty dropdown.
## PAN-258166
```caveat
PA-220 firewalls only
```
Fixed an issue where the root partition frequently reached 100%.
## PAN-258162
```caveat
Panorama appliances on AWS environments only
```
( Fixed an issue where IP addresses were not retrieved in Dynamic Address Groups when multiple AND operators were configured.
## PAN-257183
Fixed an issue where the firewall dropped DNS traffic when using DNS Security.
## PAN-256904
Fixed an issue where the firewall inconsistently blocked URLs due to intermittent URL category misidentification.
## PAN-256867
Fixed an issue where the logrcvr process stopped responding while processing session logs for forwarding to the LFC.
## PAN-255759
Fixed an issue where the firewall was unable to match HIP data with the correct anti-malware object for Windows Defender.
## PAN-254904
Fixed an issue on Panorama where a core file was generated by /usr/local/bin/logd during a restart.
## PAN-254524
Fixed an issue on Panorama where, when the Commit and Push button was clicked during a selective Commit and Push operation, the window stopped responding, which caused the operation to be delayed.
## PAN-253127
Fixed an issue where, after upgrading to PAN-OS 11.0.2-h3, the hardware pool DFLT became highly utilized, and the packet buffer gradually increased.
## PAN-251715
Fixed an issue where the firewall closed the SSL connection to the user ID agent.
## PAN-243235
Fixed an issue where Panorama stopped responding and rebooted repeatedly after an upgrade.
## PAN-193285
Fixed an issue where the policy optimizer feature did not add entries back to the mongodb database after removing them during an upgrade or downgrade.
File diff suppressed because it is too large Load Diff
@@ -0,0 +1,71 @@
---
type: Addressed
product: PAN-OS
version: 11.2.9
---
## PAN-297972
Fixed an issue where a dataplane crash occurred when traffic matched Inline Cloud Analysis prefiltering signatures, even when Inline Cloud Analysis features were not enabled.
## PAN-297458
Fixed an issue where the all_task_1 process crashed on the firewall when the wif service wasn't available because the wif detection ID was not in the current service table.
## PAN-297261
Fixed an issue where the proxy-protocol debug level was set to verbose on Prisma Access instances, even when it was not explicitly configured, which caused excessive logging by the pan_task process.
## PAN-296519
Fixed an issue where a stream receiving a reconnect signal with an associated error in Wifclient caused the entire pool to close, which resulted in a complete disconnection.
## PAN-296478
Fixed an issue where, after upgrading to PAN-OS 10.2.13-h10, GlobalProtect Clientless VPN on PA-3250 firewalls failed to execute JavaScript links, resulting in an authorization error. This occurred because the firewall was incorrectly injecting text into URLs when JavaScript buttons or dropdown menus were clicked within the Clientless VPN portal.
## PAN-296283
Fixed an issue where, on hardware platforms with the SaaS inline license, Additional Header Logging (AHL) hash table creation proceeded even when the feature was disabled through the CLI, potentially leading to crashes.
## PAN-295944
Fixed an issue where static routes remained active in the FIB and RIB even when the associated physical port interface was down, which resulted in traffic being incorrectly routed through a non-operational interface.
## PAN-295812
Fixed an issue where the throughput data on the Switch Card Module (SCM) was not accurately reported. This issue affected Standard SC USABN and USABN-2 when using Direct-IO deployment.
## PAN-295342
Fixed an issue where the pan_comm process stopped responding due to insufficient time allocated to read file descriptors when processing long messages.
## PAN-292539
```caveat
CN-Series firewalls only
```
Fixed an issue where the firewall generated incomplete or corrupted tech support files (TSF) due to high disk usage on the management plane.
## PAN-291940
Fixed an issue where the firewall established multiple TCP connections to a syslog server, which caused logs to be dropped. This occurred because the firewall established a new TCP session for each transfer and the sessions were not closed, which resulted in a continuous increase in connections over time.
## PAN-289249
Fixed an issue where a memory leak occurred on the reportd process when a WildFire update was initiated while device telemetry data collection was in progress. This resulted in an OOM condition.
## PAN-281721
Fixed an issue where the firewall generated high-severity system alerts indicating that the configuration size exceeded the maximum recommended size, even when the configuration size was within the expected limits.
## PAN-277178
Fixed an issue on Panorama where you were unable to delete a shared object due to the rulebase incorrectly referencing the shared object instead of the device group-specific object when the name was used.
To use this fix, delete the original shared object after cloning it to a device group with the same name.
## PAN-272245
Fixed an issue where the dnsproxy process crashed due to memory corruption caused by a race condition when allow list downloading was impacted by config change.