Revise PAN-OS 11.2 addressed issues

This commit is contained in:
2026-04-13 14:56:21 -05:00
parent 19c7c5a6d3
commit 71f86eed34
84 changed files with 32057 additions and 236 deletions
+350
View File
@@ -0,0 +1,350 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 50%" />
<col style="width: 50%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">Issue ID</th>
<th class="entry">Description</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-276130</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when a new IKEv2 was created on Panorama on a
PAN-OS 11.2 release using the default IKE version (IKEv2) and IPSec
crypto profiles with no specific changes to the crypto profile
parameters, and the configuration was pushed to a firewall on PAN-OS
11.2.0 to PAN-OS 11.2.4, the firewall interpreted the IKEv2 gateway as
IKEv1.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-274029</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where upgrading Panorama and pushing configurations to
the firewall caused an IKE version mismatch, which resulted in IPSec
tunnel failure with the peer device.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273994</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-0111"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-0111</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273971</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-0108"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-0108</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273278</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-0109"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-0109</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273197</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the endpoint ID was not populated in logs when
the least significant word of the Geneve header was 0.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273165</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where HTTP/2 sessions failed on the firewall when
Dynamic Memory Management was enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273085</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where you were unable to edit or
create policy rules.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273019</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an intermittent issue where SSL decryption failed.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-272021</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">M-300 Appliances only</tt>) Fixed an issue where a
split brain condition was not triggered during an inter-Log Collector
disconnect between DLC firewalls in an Elasticsearch cluster, which
resulted in missing logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-271926</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TLS 1.3 decryption failed with a bad record MAC
error when the firewall was configured to decrypt and inspect TLS
traffic.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271828</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after an accumulation proxy changed to
no-decrypt or no proxy, only the Client Hello was sent to Content
Threat Detection.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270549</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where some TLS connections were not handled correctly,
which led to instability in the dataplane.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270248</b></div>
</td>
<td class="entry relcol">
Fixed an issue where the firewall failed to forward logs to a SNMP trap
server if the SNMP manager IP address was unable to be resolved.
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268815</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall entered a non-functional state due
to duplicate entries in the shared memory.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268727</b></div>
</td>
<td class="entry relcol">
Fixed an issue where traffic was dropped when the accumulation proxy was
enabled and header insertion modified packets.
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268229</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding during session
setup for ECMP hit-count updates.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268215</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Panorama appliances in HA configurations only</tt>)
Fixed an issue where, when Elasticsearch was forming a cluster and the
port was disabled or disconnected and then reconnected, Elasticsearch
did not reform the cluster
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267781</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not display the Source Dynamic
Address Group.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267671</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted unexpectedly due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process restarting and repeated OOM conditions occurring on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>pan_task</a
>
process.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-265742</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the Panorama web interface where the
<span class="ph uicontrol">OK</span> button on the GlobalProtect
gateway configuration dialog box was not clickable.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-263987</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where, when a NAT transversal IPSec
tunnel was terminated, and the NAT rule that was applied to the NAT-T
IPSec tunnel was on the same firewall, traffic flowing through the
tunnel was not correctly translated.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-252036</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when the GlobalProtect portal was not
configured, accessing the GlobalProtect gateway still loaded a portal
malformed page.
</div>
</td>
</tr>
</tbody>
</table>