Revise PAN-OS 11.2 addressed issues

This commit is contained in:
2026-04-13 14:56:21 -05:00
parent 19c7c5a6d3
commit 71f86eed34
84 changed files with 32057 additions and 236 deletions
+544
View File
@@ -0,0 +1,544 @@
<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-270802</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after modifying a policy rule on Panorama,
pushes to the Cloud NGFW failed with the error
<span class="ph systemoutput">saas-user-list unexpected here</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-268823</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">Monitor &gt; Log Display</span> did not
display all logs when you applied a filter.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-267386</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where VPC IDs and Security keys were not mapped to the
correct interfaces for Google IPS.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-266769</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect gateway did not handle IP
address changes of the inner gateway when the NGPA new protocol was
enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-266581</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a failed SSL connection to a syslog server
resulted in a
<span class="ph systemoutput">/tmp/srvr.crt.xxxxxx</span> file not
being removed, which caused index node (inode) exhaustion.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-266114</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when a new set of URL logs came in, the content
of the earlier URL and traffic logs were lost.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-265785</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted due to a
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>sysd</a
>
variable being modified before it was created.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-264249</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where SNMP queries timed out when using
SNMP.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-264246</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Authentication Portal did not work properly
with session cookies when the request to the portal contained the
header <span class="ph systemoutput">Sec-Fetch-Site=cross-site</span>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263680</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Prisma Access gateways consistently stopped
responding with process restarts.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263559</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the dataplane stopped responding and the firewall
unexpectedly rebooted due to multiple process restarts.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-263287</b></div>
</td>
<td class="entry relcol">
<div class="p">
The PAN-COMMON-MIB.my file was updated to support new object
identifiers (OID) to poll interface use via SNMP with table
identifiers.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262340</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where FQDN resolution failed for address objects, and
all FQDN traffic was denied by the interzone-default policy rule.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-262254</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall experienced an OOM condition and the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>useridd</a
>
process stopped responding, which caused the firewall to drop
interfaces from their respective aggregate groups.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-261489</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an out-of-memory (OOM) condition caused a
firewall outage.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260662</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where large file downloads were slower than expected
when private IP address visibility was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260512</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where accessing the IP address of the device address
group objects from the user interface caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process to stop responding.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-260316</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task</a
>
process stopped responding and the firewall rebooted.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259910</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall reported the same value over
consecutive SNMP polls when asynchronous mode was enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259767</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect users were unable to connect when
the option
<span class="ph uicontrol"
>Block sessions if the certificate was not issued to the
authenticating device</span
>
was enabled in the certificate profile.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-259002</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where frequent external dynamic list updates caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process to restart.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257736</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
traffic to benign applications was was impacted by holding TCP
sequential segments for MLC inspection and not releasing the full
chain after a benign verdict was received.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257601</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5450 firewalls only</tt>) Fixed an issue where
Networking Cards (NC) experienced an internal link fault which caused
path monitoring failure on the Dataplane Processing Card (DPC).
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-257327</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5440 firewalls only</tt>) Fixed an issue where a
failover event occurred unexpectedly on the firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-256077</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the GlobalProtect client would disconnect
consistently due to keep-alive timeouts when using an SSL-only tunnel.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-254704</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>LSVPN Portal firewalls in active/passive HA configurations only</tt
>) Fixed an issue where the satellite cookie key did not sync between
LSVPN portal HA firewalls, which resulted in re-authentication of
satellites with the portal during the event of HA failover.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-251973</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not detect evasions due to TCP
checksum offloading not being enabled.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250394</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a large amount of group data caused serialization
errors and prevented synchronization.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-250371</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process stopped responding, which caused commits to fail with the
error message
<span class="ph systemoutput"
>Management server failed to send phase 1 to client logrcvr</span
>.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-240990</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph systemoutput">l3svc.py</span> displayed incorrect
logs.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-239952</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/passive HA configurations only</tt
>) Fixed an issue where HA sync messages from the active firewall took
longer than expected to reach the passive firewall.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-230893</b></div>
</td>
<td class="entry relcol">
<div class="p">
Added a CLI command to address an issue where system lock files
blocked authentication.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-230825</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where link flaps occurred on Panorama appliances in HA
configurations.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-225213</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">Push All Changes</span> displayed changes
that were already committed in the push scope for another device group
after performing a selective commit and selective push to the first
device group.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-222542</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7000 Series firewalls only</tt>) Fixed an issue
where Log Forward Cards (LFC) were incorrectly identified as
distribution policies, which caused packet loss due to traffic, BFD,
and other control packets being forwarded to the LFC.
</div>
</td>
</tr>
<tr class="row rowsep">
<td class="entry">
<div class="p"><b class="ph b">PAN-214773</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where RTP packets traversing inter-vsys were dropped on
the outgoing vsys.
</div>
</td>
</tr>
</tbody>
</table>