Revise PAN-OS 11.2 addressed issues

This commit is contained in:
2026-04-13 14:56:21 -05:00
parent 19c7c5a6d3
commit 71f86eed34
84 changed files with 32057 additions and 236 deletions
@@ -6,4 +6,4 @@ version: 11.2.0-h1
## PAN-272809
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and CVE-2024-9474.
A fix was made to address [CVE-2024-0012](https://security.paloaltonetworks.com/CVE-2024-0012) ([PAN-SA-2024-0015](https://security.paloaltonetworks.com/PAN-SA-2024-0015)) and [CVE-2024-9474](https://security.paloaltonetworks.com/CVE-2024-9474).
+2 -2
View File
@@ -26,7 +26,7 @@ Fixed an issue with session caching where the reportd process stopped responding
## PAN-227344
Fixed an issue on Panorama where PDF Summary Reports (Monitor > PDF Reports > Manage PDF Summary) displayed no data and were blank when predefined widgets were included in the summary report.
Fixed an issue on Panorama where **PDF Summary Reports** (**Monitor > PDF Reports > Manage PDF Summary**) displayed no data and were blank when predefined widgets were included in the summary report.
## PAN-227305
@@ -90,7 +90,7 @@ Fixed an issue where the firewall CPU percentage was miscalculated, and the valu
## PAN-219768
Fixed an issue where you were unable to filter Data Filtering logs with Threat ID/NAME for custom data patterns created over Panorama.
Fixed an issue where you were unable to filter Data Filtering logs with **Threat ID/NAME** for custom data patterns created over Panorama.
## PAN-219585
@@ -6,4 +6,4 @@ version: 11.2.1-h1
## PAN-272809
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and CVE-2024-9474.
A fix was made to address [CVE-2024-0012](https://security.paloaltonetworks.com/CVE-2024-0012) ([PAN-SA-2024-0015](https://security.paloaltonetworks.com/PAN-SA-2024-0015)) and [CVE-2024-9474](https://security.paloaltonetworks.com/CVE-2024-9474).
+2 -2
View File
@@ -6,7 +6,7 @@ version: 11.2.1
## PAN-257919
Fixed an issue where, when using explicit proxy with SAML authentication, initiating SAML authentication with a non-GET request resulted in a 302 redirect response instead of the expected 200 ok response.
Fixed an issue where, when using explicit proxy with SAML authentication, initiating SAML authentication with a non-GET request resulted in a **302 redirect** response instead of the expected **200 ok** response.
## PAN-256343
@@ -46,4 +46,4 @@ Fixed an issue where, when you committed the first configuration change after bo
## PAN-164885
Fixed an issue on Panorama where Commit and Push or Push to Devices operations failed when an external dynamic list was configured to check for updates every 5 minutes due to the commit and external dynamic fetch processes overlapping.
Fixed an issue on Panorama where **Commit and Push** or **Push to Devices** operations failed when an external dynamic list was configured to check for updates every 5 minutes due to the commit and external dynamic fetch processes overlapping.
@@ -18,7 +18,7 @@ Fixed an issue on Panorama where a memory leak occurred related to the reportd p
## PAN-302927
Fixed an issue where, after upgrading Panorama, the Push to Devices option did not display selected devices, and the OK and Cancel buttons did not function as expected. Selecting OK did not close the window, and selecting Cancel returned to the main push screen with the push selected devices displaying as empty. Despite this, selecting Push or Validate Device Group Push still pushed to the previously canceled, non-displayed devices.
Fixed an issue where, after upgrading Panorama, the **Push to Devices** option did not display selected devices, and the **OK** and **Cancel** buttons did not function as expected. Selecting **OK** did not close the window, and selecting **Cancel** returned to the main push screen with the push selected devices displaying as empty. Despite this, selecting **Push** or **Validate Device Group Push** still pushed to the previously canceled, non-displayed devices.
## PAN-301801
@@ -60,7 +60,7 @@ Fixed an issue where exporting custom reports resulted in empty CSV files.
## PAN-296977
Fixed an issue where the web interface became unresponsive when attempting to view Ethernet interface details after applying a filter in NetworkInterfaces
Fixed an issue where the web interface became unresponsive when attempting to view **Ethernet** interface details after applying a filter in **Network** > **Interfaces**
## PAN-296694
@@ -80,7 +80,7 @@ Resolved multiple issues affecting IPSec tunnels using NAT Traversal (NAT-T) whe
## PAN-209516
Fixed an issue where, when creating an interface, an error occurred when you clicked OK without providing a value in the Tag field even though the field was not displayed as mandatory.
Fixed an issue where, when creating an interface, an error occurred when you clicked **OK** without providing a value in the **Tag** field even though the field was not displayed as mandatory.
## PAN-185731
@@ -58,4 +58,4 @@ Addressed a memory leak issue under sc3 and automatic commit recovery (ACR) code
## PAN-289723
Fixed an issue where the firewall web interface continuously loaded and not display any output when viewing the Route Table or FIB table (More Runtime Stats). This issue occurred when L3 configurations were added to ethernet and AE interfaces.
Fixed an issue where the firewall web interface continuously loaded and not display any output when viewing the Route Table or FIB table (**More Runtime Stats**). This issue occurred when L3 configurations were added to ethernet and AE interfaces.
@@ -38,7 +38,9 @@ Fixed an issue where devices with 5G cellular modems did not support the ATT Fir
## PAN-285181
Fixed an issue where the wifclient was not configured to utilize the GOMEMLIMIT feature.
Fixed an issue where the wifclient ran out of memory when Enhanced Application Logging was enabled and a sudden traffic increase caused a surge in EAL messages sent through WIF.
To use this fix, run the CLI command debug iot eal memory-gc native
## PAN-278688
@@ -55,7 +57,3 @@ Fixed an issue where an incorrect ASIC configuration caused silent packet drops
## PAN-269228
Fixed an issue where the all_task process stopped responding, which caused a split brain condition.
## PAN-267614
Fixed an issue where the Panorama web interface was slower than expected due to high CPU utilization on the mongodb process.
+10 -11
View File
@@ -58,7 +58,7 @@ Fixed an issue where ports went down after an HA failover.
## PAN-298684
Fixed an issue where an Application Override policy rule was not applied using an IPv4 source IP address with IPv6 enabled and Network > Zones > Pre-NAT Identification enabled.
Fixed an issue where an Application Override policy rule was not applied using an IPv4 source IP address with IPv6 enabled and **Network** > **Zones** > **Pre-NAT Identification** enabled.
## PAN-298654
@@ -92,9 +92,8 @@ Fixed an issue where, during a refresh of a large External Dynamic List (EDL), t
Fixed an issue where, after upgrading to an affected PAN-OS release, the Visible Virtual System field referenced the vsys name instead of the vsys ID, which caused inter-vsys routing to fail. This occurred when a vsys display name matched one of the vsys IDs. If you're using a multivsys environment, you must upgrade your firewalls to a fixed PAN-OS version. The best practice is to upgrade both the firewalls and Panorama to a fixed PAN-OS version.
If you don't upgrade Panorama to a fixed version, you'll encounter PAN-245064, where a commit on a multivsys firewall fails with the message "vsys name should end with a number vsys is invalid" after you "Export or push device config bundle" from 11.1.1 Panorama.
After you upgrade Panorama to a fixed version, you'll encounter PAN-214177, which causes an "Export or Push device config bundle" from Panorama to the firewall to fail. The workaround for PAN-214177 is to first push only the template configuration and then push the device group configurations.
- If you don't upgrade Panorama to a fixed version, you'll encounter PAN-245064, where a commit on a multivsys firewall fails with the message "vsys name should end with a number vsys is invalid" after you "Export or push device config bundle" from 11.1.1 Panorama.
- After you upgrade Panorama to a fixed version, you'll encounter PAN-214177, which causes an "Export or Push device config bundle" from Panorama to the firewall to fail. The workaround for PAN-214177 is to first push only the template configuration and then push the device group configurations.
## PAN-297321
@@ -150,7 +149,7 @@ Fixed an issue where, after upgrading Panorama and Log Collectors, Traffic and T
## PAN-294893
Fixed an issue where firewalls with the Send handshake messages to CTD for inspection setting enabled caused incorrect security policy rules to be matched. Specifically, traffic not identified as openai-base or openai-chatgpt applications was incorrectly matched by the ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected response page for blocked URLs was not displayed.
Fixed an issue where firewalls with the **Send handshake messages to CTD for inspection** setting enabled caused incorrect security policy rules to be matched. Specifically, traffic not identified as openai-base or openai-chatgpt applications was incorrectly matched by the ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected response page for blocked URLs was not displayed.
## PAN-294770
@@ -170,7 +169,7 @@ Fixed an issue where the firewall rebooted unexpectedly due to the useridd proce
## PAN-293985
Fixed an issue with the Panorama web interface where admin users were unable to log in and received the error message 504: Gateway Timeout.
Fixed an issue with the Panorama web interface where admin users were unable to log in and received the error message **504: Gateway Timeout**.
## PAN-293877
@@ -182,7 +181,7 @@ Fixed an issue where, when using the Hub vsys feature to redistribute Host Infor
## PAN-293848
Fixed an issue where Panorama failed to push the default value of None for the secondary NTP server address to managed firewalls, resulting in a commit validation error. This occurred even when configuring the secondary NTP server address as None in Panorama's web interface, and affected both newly deployed and long-standing production firewalls after upgrading.
Fixed an issue where Panorama failed to push the default value of **None** for the secondary NTP server address to managed firewalls, resulting in a commit validation error. This occurred even when configuring the secondary NTP server address as **None** in Panorama's web interface, and affected both newly deployed and long-standing production firewalls after upgrading.
## PAN-293511
@@ -194,7 +193,7 @@ Fixed an issue where setting the logdb-quota for the desum log type to 0 caused
## PAN-292447
Fixed an issue where Panorama did not display data in the Feature Adoption tab in Strata Cloud Manager due to the system creating and deleting a CLI user for each interval instead of reusing a permanent CLI user for telemetry.
Fixed an issue where Panorama did not display data in the **Feature Adoption** tab in Strata Cloud Manager due to the system creating and deleting a CLI user for each interval instead of reusing a permanent CLI user for telemetry.
## PAN-292393
@@ -214,7 +213,7 @@ Fixed an issue where, after configuring dual stack GlobalProtect with both IPv4
## PAN-292019
Fixed an issue on the Panorama web interface where cloud applications were not displayed under Objects > Applications after a new content upgrade and Cloud App Catalog download, and were only visible in application groups, security policy rules, and the CLI.
Fixed an issue on the Panorama web interface where cloud applications were not displayed under **Objects > Applications** after a new content upgrade and Cloud App Catalog download, and were only visible in application groups, security policy rules, and the CLI.
## PAN-291883
@@ -262,7 +261,7 @@ Fixed an issue with firewalls enabled with Security profiles where certain traff
VM-Series firewalls on Microsoft Azure environments in HA configurations only
```
Fixed an issue where, when an interface was configured with IPv6, the firewall displayed the message Unknown error during validation after the client secret expired, which caused DNS resolution to fail when resolving FQDNs and HA failovers to occur.
Fixed an issue where, when an interface was configured with IPv6, the firewall displayed the message **Unknown error** during validation after the client secret expired, which caused DNS resolution to fail when resolving FQDNs and HA failovers to occur.
## PAN-290455
@@ -286,7 +285,7 @@ Fixed an issue where firewalls configured in vwire mode modified DSCP values fro
## PAN-287693
Fixed an issue where Panorama did not use the configured proxy settings to check WildFire private cloud content and instead connected directly to the WildFire device using the management interface. This occurred even when Use Proxy Settings for Private Cloud was enabled.
Fixed an issue where Panorama did not use the configured proxy settings to check WildFire private cloud content and instead connected directly to the WildFire device using the management interface. This occurred even when **Use Proxy Settings for Private Cloud** was enabled.
## PAN-287622
+3 -1
View File
@@ -1743,7 +1743,9 @@ Fixed an issue where the firewall did not automatically recover after a machine
## PAN-285181
Fixed an issue where the wifclient was not configured to utilize the GOMEMLIMIT feature.
Fixed an issue where the wifclient ran out of memory when Enhanced Application Logging was enabled and a sudden traffic increase caused a surge in EAL messages sent through WIF.
To use this fix, run the CLI command debug iot eal memory-gc native
## PAN-285169
@@ -6,4 +6,4 @@ version: 11.2.2-h2
## PAN-272809
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and CVE-2024-9474.
A fix was made to address [CVE-2024-0012](https://security.paloaltonetworks.com/CVE-2024-0012) ([PAN-SA-2024-0015](https://security.paloaltonetworks.com/PAN-SA-2024-0015)) and [CVE-2024-9474](https://security.paloaltonetworks.com/CVE-2024-9474).
+1 -1
View File
@@ -14,7 +14,7 @@ Fixed an issue where the varrcvr process stopped responding when files were bein
## PAN-255773
Fixed an issue where errors related to applications in Content-preview caused commit failures.
Fixed an issue where errors related to applications in **Content-preview** caused commit failures.
## PAN-248508
@@ -6,7 +6,7 @@ version: 11.2.3-h3
## PAN-272809
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and CVE-2024-9474.
A fix was made to address [CVE-2024-0012](https://security.paloaltonetworks.com/CVE-2024-0012) ([PAN-SA-2024-0015](https://security.paloaltonetworks.com/PAN-SA-2024-0015)) and [CVE-2024-9474](https://security.paloaltonetworks.com/CVE-2024-9474).
## PAN-247230
@@ -18,7 +18,7 @@ Fixed an issue where the firewall did not reset the maximum latency timer for ho
## PAN-268823
Fixed an issue where Monitor > Log Display did not display all logs when you applied a filter.
Fixed an issue where **Monitor > Log Display** did not display all logs when you applied a filter.
## PAN-264549
@@ -26,4 +26,4 @@ Fixed an issue where, after modifying a policy rule on Panorama, pushes to the C
## PAN-259078
Fixed an issue where WildFire Analysis reports were not generated and the following error message was displayed: Error 500: Internal Server Error.
Fixed an issue where WildFire Analysis reports were not generated and the following error message was displayed: **Error 500: Internal Server Error**.
+15 -15
View File
@@ -22,7 +22,7 @@ Fixed an issue where dereferencing a NULL pointer that occurred when App-ID stop
## PAN-262013
Fixed an issue where Prisma Access mobile users did not receive no such name DNS responses from the firewall and were timed out.
Fixed an issue where Prisma Access mobile users did not receive **no such name** DNS responses from the firewall and were timed out.
## PAN-261991
@@ -42,7 +42,7 @@ Fixed an issue where the firewall decremented the TTL/Hop limit for BGPv6 packet
## PAN-260059
Fixed an issue where Device Telemetry Regions did not show up with the latest content due to content files not being parsed for the region list when Telemetry was turned off.
Fixed an issue where **Device Telemetry Regions** did not show up with the latest content due to content files not being parsed for the region list when Telemetry was turned off.
## PAN-259964
@@ -150,7 +150,7 @@ Fixed an issue where BGP routes from the active firewall were lost when the pass
## PAN-256666
Fixed an issue where the configd process stopped responding when Commit and Push operations were performed on multiple device groups.
Fixed an issue where the configd process stopped responding when **Commit and Push** operations were performed on multiple device groups.
## PAN-256385
@@ -170,7 +170,7 @@ Fixed an issue where the logd process repeatedly restarted due to a buffer overf
## PAN-256249
Fixed an issue on the web interface that occurred when changing the pre-shared key to a variable (Network > Network Profiles > IKE Gateways).
Fixed an issue on the web interface that occurred when changing the pre-shared key to a variable (**Network > Network Profiles > IKE Gateways**).
## PAN-256223
@@ -182,7 +182,7 @@ Fixed an issue where the management interface and front panel port interface sta
## PAN-255895
Fixed an issue where Panorama administrators with the Panorama Administrator dynamic administrator type were not able to create or modify BGP timer profiles or BGP dampening profiles.
Fixed an issue where Panorama administrators with the **Panorama Administrator** dynamic administrator type were not able to create or modify BGP timer profiles or BGP dampening profiles.
## PAN-255820
@@ -190,7 +190,7 @@ Fixed an issue where the WildFire signature generation check box in Panorama did
## PAN-255711
Fixed an issue where the firewall displayed a malformed request error when selecting a custom format and clicking OK on the configuration window due to the log type Correlation incorrectly being displayed (Device > Log Setting - Correlation > Syslog Server Profile > Custom Log Format > Correlation).
Fixed an issue where the firewall displayed a malformed request error when selecting a custom format and clicking **OK** on the configuration window due to the log type **Correlation** incorrectly being displayed (**Device > Log Setting - Correlation > Syslog Server Profile > Custom Log Format > Correlation**).
## PAN-255611
@@ -254,7 +254,7 @@ Fixed an issue where the firewall required a restart when an SD-WAN policy rule
## PAN-254411
Fixed an issue where the configd process stopped responding, which caused ERR_CONNECTION_REFUSED error messages to be displayed in admin sessions.
Fixed an issue where the configd process stopped responding, which caused **ERR_CONNECTION_REFUSED** error messages to be displayed in admin sessions.
## PAN-254373
@@ -278,7 +278,7 @@ Fixed an issue where the CLI command show running security-policy timed out when
## PAN-253819
Fixed an issue where a User Activity Report was not generated by Run Now or not emailed through the Email Schedule when the locale setting was not English.
Fixed an issue where a **User Activity Report** was not generated by **Run Now** or not emailed through the **Email Schedule** when the locale setting was not English.
## PAN-253452
@@ -350,7 +350,7 @@ Fixed an issue where network issues between the firewall and the log collector c
## PAN-250597
Fixed an issue where Global Find for a Panorama pushed shared address object displayed Others in the results.
Fixed an issue where Global Find for a Panorama pushed shared address object displayed **Others** in the results.
## PAN-250462
@@ -378,7 +378,7 @@ Fixed an issue on the firewall where the Certificate Name character limit was 31
## PAN-250127
Fixed an issue where commits failed with the error message set is not allowed when default originate was enabled with a route map that included a set action.
Fixed an issue where commits failed with the error message set is not allowed when **default originate** was enabled with a route map that included a set action.
## PAN-250024
@@ -386,7 +386,7 @@ Fixed an issue related to the reportd process where you were unable to log in to
## PAN-250021
Fixed an issue where Change Summary and Preview Changes displayed inconsistent information when changing an admin user password.
Fixed an issue where **Change Summary** and **Preview Changes** displayed inconsistent information when changing an admin user password.
## PAN-250005
@@ -422,7 +422,7 @@ Fixed an issue on Panorama where commits failed when Advanced Routing was enable
## PAN-248130
Fixed an issue where the AND operation under a Dynamic Address Group comparison did not work after upgrading the AWS plugin to 3.0.1.
Fixed an issue where the **AND** operation under a Dynamic Address Group comparison did not work after upgrading the AWS plugin to 3.0.1.
## PAN-247857
@@ -434,7 +434,7 @@ Fixed an issue on the firewall where a dataplane process restarted when updating
## PAN-247754
Fixed an issue where successful Commit and Push operations performed by SAML authenticated users were not reflected on the firewall.
Fixed an issue where successful **Commit and Push** operations performed by SAML authenticated users were not reflected on the firewall.
## PAN-247575
@@ -470,7 +470,7 @@ Fixed an issue where single TLS session packets were sent to multiple firewalls
## PAN-245892
Fixed an issue where Log Filtering (Monitor > Logs) was slower than expected.
Fixed an issue where Log Filtering (**Monitor > Logs**) was slower than expected.
## PAN-245556
@@ -486,7 +486,7 @@ Fixed an issue where the firewall TLS/SSL service profile exclusion settings wer
## PAN-243387
Fixed an issue where sessions ended with the message resources-unavailable when traffic hit a Security profile.
Fixed an issue where sessions ended with the message **resources-unavailable** when traffic hit a Security profile.
## PAN-243240
@@ -6,4 +6,4 @@ version: 11.2.4-h1
## PAN-272809
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and CVE-2024-9474.
A fix was made to address [CVE-2024-0012](https://security.paloaltonetworks.com/CVE-2024-0012) ([PAN-SA-2024-0015](https://security.paloaltonetworks.com/PAN-SA-2024-0015)) and [CVE-2024-9474](https://security.paloaltonetworks.com/CVE-2024-9474).
@@ -204,7 +204,7 @@ Fixed an issue where the firewall displayed inaccurate throughput utilization st
## PAN-259881
Fixed an issue on Panorama where traffic log details were not displayed under detailed log view.
Fixed an issue on Panorama where traffic log details were not displayed under **detailed log view**.
## PAN-258757
@@ -224,7 +224,7 @@ Fixed an issue on Panorama where configuration locks were observed during a part
## PAN-246699
Fixed an issue on Panorama where Rule Usage and Apps Seen under Security policy rules stopped incrementing.
Fixed an issue on Panorama where **Rule Usage** and **Apps Seen** under Security policy rules stopped incrementing.
## PAN-245064
@@ -232,4 +232,4 @@ Fixed an issue on Panorama where Rule Usage and Apps Seen under Security policy
Multi-vsys firewalls only
```
Fixed an issue where commits failed on the firewall after selecting Export or push device config bundle on Panorama and a force push was required.
Fixed an issue where commits failed on the firewall after selecting **Export or push device config bundle** on Panorama and a force push was required.
@@ -30,11 +30,13 @@ Fixed an issue where the logrcvr process stopped responding due to an invalid SS
## PAN-287688
Fixed an issue where the firewall failed to connect to the Palo Alto Networks update server when using a customized service route with the source interface as MGT.
Fixed an issue where the firewall failed to connect to the Palo Alto Networks update server when using a customized service route with the source interface as **MGT**.
## PAN-279901
Fixed an issue where the firewall dropped client hello packets when decryption was enabled, which prevented access to certain websites. This occurred when the client hello packet was truncated, the accumulation proxy assumed that the first packet contains at least 5 bytes, or out-of-order packets were waiting in L4 TCP.
An issue was fixed where the firewall dropped fragmented TLS ClientHello packets, which blocked access to certain websites. This occurred because the packets arrived truncated, in varying sizes and orders, and the firewall's heuristics failed to handle them correctly.
To enable this fix, run: debug dataplane set ssl-decrypt accumulate-client-hello disjoined yes
## PAN-268680
@@ -42,7 +44,7 @@ Fixed an issue where the configd process stopped responding when a configuration
## PAN-268522
Fixed an issue where the firewall failed to connect to the update server with a customized service route when the source interface was set to MGT and the source address was set as IPv4.
Fixed an issue where the firewall failed to connect to the update server with a customized service route when the source interface was set to **MGT** and the source address was set as IPv4.
## PAN-255914
@@ -82,7 +82,7 @@ Fixed an issue where content loading issues occurred on IPv6 websites due to the
## PAN-286299
Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the Network and Device tabs became read-only.
Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the **Network** and **Device** tabs became read-only.
## PAN-285285
@@ -106,7 +106,7 @@ Fixed an issue where Panorama did not update all panreplay database entries afte
## PAN-276484
Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (Device Deployment > Licenses) due to the inability to perform batch-license refreshes.
Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (**Device Deployment > Licenses**) due to the inability to perform batch-license refreshes.
## PAN-273453
@@ -62,7 +62,7 @@ Fixed an issue where, after upgrading to PAN-OS 11.1.6-h6 the Eth1/2, Eth1/3, Et
## PAN-292447
Fixed an issue where Panorama did not display data in the Feature Adoption tab in Strata Cloud Manager due to the system creating and deleting a CLI user for each interval instead of reusing a permanent CLI user for telemetry.
Fixed an issue where Panorama did not display data in the **Feature Adoption** tab in Strata Cloud Manager due to the system creating and deleting a CLI user for each interval instead of reusing a permanent CLI user for telemetry.
## PAN-291940
@@ -86,7 +86,7 @@ Fixed an issue on Panorama where API jobs failed with the error message Server e
## PAN-284279
Fixed an issue where the policy destination always defaulted to any, even when specific IP addresses and FQDNs were specified during policy import.
Fixed an issue where the policy destination always defaulted to **any**, even when specific IP addresses and FQDNs were specified during policy import.
## PAN-284067
@@ -94,7 +94,7 @@ Fixed a cumulative memory leak in the devsrvr process that occurred whenever the
## PAN-281776
Fixed an issue on the Panorama web interface where the error message PPPoEv6 Client Interface cannot be enabled with DHCPv6 client was generated when overriding aggregate interfaces even when no DHCPv6 or PPPoE was configured.
Fixed an issue on the Panorama web interface where the error message **PPPoEv6 Client Interface cannot be enabled with DHCPv6 client** was generated when overriding aggregate interfaces even when no DHCPv6 or PPPoE was configured.
## PAN-279829
@@ -4,6 +4,6 @@ product: PAN-OS
version: 11.2.4-h15
---
## PAN-000000
## BLANK-000000
A fix was made to address CVE-2026-0227.
A fix was made to address [CVE-2026-0227](https://security.paloaltonetworks.com/CVE-2026-0227).
@@ -18,4 +18,4 @@ Fixed an issue where the firewall did not reset the maximum latency timer for ho
## PAN-259078
Fixed an issue where WildFire Analysis reports were not generated and the following error message was displayed: Error 500: Internal Server Error.
Fixed an issue where WildFire Analysis reports were not generated and the following error message was displayed: **Error 500: Internal Server Error**.
@@ -14,15 +14,15 @@ Fixed an issue where upgrading Panorama and pushing configurations to the firewa
## PAN-273994
A fix was made to address CVE-2025-0111.
A fix was made to address [CVE-2025-0111](https://security.paloaltonetworks.com/CVE-2025-0111).
## PAN-273971
A fix was made to address CVE-2025-0108.
A fix was made to address [CVE-2025-0108](https://security.paloaltonetworks.com/CVE-2025-0108).
## PAN-273278
A fix was made to address CVE-2025-0109.
A fix was made to address [CVE-2025-0109](https://security.paloaltonetworks.com/CVE-2025-0109).
## PAN-273197
@@ -94,7 +94,7 @@ Fixed an issue where the firewall rebooted unexpectedly due to the all_task proc
## PAN-265742
Fixed an issue on the Panorama web interface where the OK button on the GlobalProtect gateway configuration dialog box was not clickable.
Fixed an issue on the Panorama web interface where the **OK** button on the GlobalProtect gateway configuration dialog box was not clickable.
## PAN-263987
@@ -10,7 +10,7 @@ Fixed an issue where scheduled SaaS application usage reports were generated inc
## PAN-276177
Fixed an issue where App Acceleration did not work with Oracle databases.
Fixed an issue where **App Acceleration** did not work with Oracle databases.
## PAN-274791
@@ -18,7 +18,7 @@ Fixed an issue where large IPv6 packets were reassembled incorrectly on the fire
## PAN-282206
Fixed an issue where configuring Secure Web Gateway (SWG) in no-auth mode led to latency when no decryption policy rules or No-decrypt policy rules were present.
Fixed an issue where configuring Secure Web Gateway (SWG) in **no-auth** mode led to latency when no decryption policy rules or **No-decrypt** policy rules were present.
## PAN-282022
@@ -26,7 +26,7 @@ Fixed the support limitation for the Panorama M-600 and M-700 appliances.
## PAN-280471
Fixed an issue where navigating Panorama > Monitor > Logs was slower than expected.
Fixed an issue where navigating **Panorama > Monitor > Logs** was slower than expected.
## PAN-279746
@@ -90,7 +90,7 @@ Fixed an issue on Panorama where the configd process stopped responding when fil
## PAN-271351
A fix was made to address CVE-2025-0116.
A fix was made to address [CVE-2025-0116](https://security.paloaltonetworks.com/CVE-2025-0116).
## PAN-270224
@@ -158,7 +158,7 @@ Fixed an issue where the firewall might reboot unexpectedly due to the varrcvr p
## PAN-257619
Fixed an issue on Panorama where the Task Manager took longer than expected to display managed firewall report tasks.
Fixed an issue on Panorama where the **Task Manager** took longer than expected to display managed firewall report tasks.
## PAN-257028
@@ -26,7 +26,7 @@ Fixed an issue where the firewall did not match the correct policy for SSL forwa
## PAN-268474
Fixed an issue on the firewall where the PAN-DB URL Filtering license displayed as Valid even when the firewall did not have the license, which caused traffic to drop.
Fixed an issue on the firewall where the PAN-DB URL Filtering license displayed as **Valid** even when the firewall did not have the license, which caused traffic to drop.
## PAN-261999
@@ -22,7 +22,7 @@ Fixed a race condition issue related to predict processing, which resulted in a
## PAN-287002
A fix was made to address CVE-2025-0133.
A fix was made to address [CVE-2025-0133](https://security.paloaltonetworks.com/CVE-2025-0133).
## PAN-285894
@@ -54,7 +54,7 @@ Fixed an issue where, after an upgrade, the SNMP polled values for IF-MIB::ifInE
Firewalls in HA configurations only
```
Fixed an issue where, after an upgrade, the mac receive error counter in receive incoming errors increased, which resulted in SNMP alerts.
Fixed an issue where, after an upgrade, the **mac receive error** counter in **receive incoming errors** increased, which resulted in SNMP alerts.
## PAN-283467
@@ -66,7 +66,7 @@ Fixed an issue where the firewall unexpectedly rebooted and entered maintenance
## PAN-283331
Fixed an issue where selective pushes to managed devices failed when the User ID Master Device was configured.
Fixed an issue where selective pushes to managed devices failed when the **User ID Master Device** was configured.
## PAN-282069
@@ -106,7 +106,7 @@ Fixed an issue on firewalls in HA configurations where, when using the Cloud Ide
## PAN-271273
Fixed an issue where dynamic update downloads failed when IPv6 firewalling was enabled on the firewall and both IPv4 and IPv6 were configured on the management interface.
Fixed an issue where dynamic update downloads failed when **IPv6 firewalling** was enabled on the firewall and both IPv4 and IPv6 were configured on the management interface.
## PAN-270379
@@ -138,7 +138,7 @@ Fixed an issue where large file downloads or uploads failed or remained in an in
## PAN-266900
Fixed an issue on the Panorama web interface where you were unable to click OK after selecting an install package type and file from the dropdown and selecting a firewall.
Fixed an issue on the Panorama web interface where you were unable to click **OK** after selecting an install package type and file from the dropdown and selecting a firewall.
## PAN-265745
+3 -3
View File
@@ -10,7 +10,7 @@ Fixed an issue where, after modifying a policy rule on Panorama, pushes to the C
## PAN-268823
Fixed an issue where Monitor > Log Display did not display all logs when you applied a filter.
Fixed an issue where **Monitor > Log Display** did not display all logs when you applied a filter.
## PAN-267386
@@ -82,7 +82,7 @@ Fixed an issue where the firewall reported the same value over consecutive SNMP
## PAN-259767
Fixed an issue where GlobalProtect users were unable to connect when the option Block sessions if the certificate was not issued to the authenticating device was enabled in the certificate profile.
Fixed an issue where GlobalProtect users were unable to connect when the option **Block sessions if the certificate was not issued to the authenticating device** was enabled in the certificate profile.
## PAN-259002
@@ -158,7 +158,7 @@ Fixed an issue where link flaps occurred on Panorama appliances in HA configurat
## PAN-225213
Fixed an issue where Push All Changes displayed changes that were already committed in the push scope for another device group after performing a selective commit and selective push to the first device group.
Fixed an issue where **Push All Changes** displayed changes that were already committed in the push scope for another device group after performing a selective commit and selective push to the first device group.
## PAN-222542
+27 -27
View File
@@ -98,11 +98,11 @@ Fixed an issue where the firewall was unable to generate a TSF file due to a ful
## PAN-268474
Fixed an issue on the firewall where the PAN-DB URL Filtering license displayed as Valid even when the firewall did not have the license, which caused traffic to drop.
Fixed an issue on the firewall where the PAN-DB URL Filtering license displayed as **Valid** even when the firewall did not have the license, which caused traffic to drop.
## PAN-268419
Fixed an issue where Managed Devices > Summary displayed incorrect subcolumns.
Fixed an issue where **Managed Devices > Summary** displayed incorrect subcolumns.
## PAN-268229
@@ -110,7 +110,7 @@ Fixed an issue where the firewall stopped responding during session setup for EC
## PAN-268228
Fixed an issue where Panorama administrators were unable to select Edit Selection when pushing changes to devices if they logged in using TACACS authentication.
Fixed an issue where Panorama administrators were unable to select **Edit Selection** when pushing changes to devices if they logged in using TACACS authentication.
## PAN-268127
@@ -154,7 +154,7 @@ Fixed an issue where multicast streams were unstable with ECMP and dropped every
## PAN-266900
Fixed an issue on the Panorama web interface where you were unable to click OK after selecting an install package type and file from the dropdown and selecting a firewall.
Fixed an issue on the Panorama web interface where you were unable to click **OK** after selecting an install package type and file from the dropdown and selecting a firewall.
## PAN-266704
@@ -190,7 +190,7 @@ Fixed an issue where BFD sessions took longer than expected to establish after a
## PAN-266167
Fixed an issue where the restart option for IPSec tunnels was greyed out (Network > IPSec Tunnels > IKE Info).
Fixed an issue where the **restart** option for IPSec tunnels was greyed out (**Network > IPSec Tunnels > IKE Info**).
## PAN-266003
@@ -210,11 +210,11 @@ Added debug functionality in the packet-diag log to address an issue regarding p
## PAN-265742
Fixed an issue on the Panorama web interface where the OK button on the GlobalProtect gateway configuration dialog box was not clickable.
Fixed an issue on the Panorama web interface where the **OK** button on the GlobalProtect gateway configuration dialog box was not clickable.
## PAN-265621
Fixed an issue where the restart option for IPSec tunnels was greyed out when you attempted to restart the tunnel from Network > IPSec Tunnels > IKE Info.
Fixed an issue where the **restart** option for IPSec tunnels was greyed out when you attempted to restart the tunnel from **Network > IPSec Tunnels > IKE Info**.
## PAN-265462
@@ -234,7 +234,7 @@ Fixed an issue where multiple segments of HTTP proxy connect messages were not h
## PAN-265344
Fixed an issue where Import GlobalProtect Client Package did not work after clicking OK after selecting a valid package under Device > GlobalProtect Client > Upload).
Fixed an issue where **Import GlobalProtect Client Package** did not work after clicking **OK** after selecting a valid package under **Device > GlobalProtect Client > Upload**).
## PAN-265179
@@ -270,15 +270,15 @@ Fixed an issue where OSPF adjacencies failed to come up when using a subinterfac
PA-220 firewalls only
```
Fixed an issue where Device > Setup was not displayed on the web interface.
Fixed an issue where **Device > Setup** was not displayed on the web interface.
## PAN-264678
Fixed an issue where Preview Changes did not display configuration changes in Commit and push > Push Scope.
Fixed an issue where **Preview Changes** did not display configuration changes in **Commit and push** > **Push Scope**.
## PAN-264662
Fixed an issue where HTTP POST requests were blocked for URLs that had the block-continue category configured.
Fixed an issue where HTTP POST requests were blocked for URLs that had the **block-continue** category configured.
## PAN-264289
@@ -306,7 +306,7 @@ Fixed an issue where log collectors had a low incoming log rate.
PA-440 firewalls only
```
Fixed an issue where a firewall running PAN-OS 11.1.2-h3 only displayed the Auto option for the interface duplex setting.
Fixed an issue where a firewall running PAN-OS 11.1.2-h3 only displayed the **Auto** option for the interface duplex setting.
## PAN-263843
@@ -378,7 +378,7 @@ Fixed an issue on firewalls in HA configurations where OSPF neighbors were not e
## PAN-262415
Fixed an issue where a partial configuration load failed for configuration files that contained regenerate-hostkeys.
Fixed an issue where a partial configuration load failed for configuration files that contained **regenerate-hostkeys**.
## PAN-261997
@@ -514,7 +514,7 @@ Fixed an issue where BGP Aggregate Advertise filters did not work as expected wh
## PAN-260193
Fixed an issue where GlobalProtect on macOS clients did not connect when using a client certificate and the X.509 policy was set to Use System Default.
Fixed an issue where GlobalProtect on macOS clients did not connect when using a client certificate and the X.509 policy was set to **Use System Default**.
## PAN-260149
@@ -538,7 +538,7 @@ Fixed an issue where the firewalls behind an Amazon Web Services (AWS) Gateway L
## PAN-259881
Fixed an issue on Panorama where traffic log details were not displayed under detailed log view.
Fixed an issue on Panorama where traffic log details were not displayed under **detailed log view**.
## PAN-259870
@@ -562,11 +562,11 @@ Fixed an issue on Panorama where the web interface was slower than expected or u
## PAN-259200
Fixed an issue where the firewall displayed truncated zone names in the Block IP List log when a zone name contained more than 14 characters.
Fixed an issue where the firewall displayed truncated zone names in the **Block IP List** log when a zone name contained more than 14 characters.
## PAN-259078
Fixed an issue where WildFire Analysis reports were not generated and the following error message was displayed: Error 500: Internal Server Error.
Fixed an issue where WildFire Analysis reports were not generated and the following error message was displayed: **Error 500: Internal Server Error**.
## PAN-258996
@@ -610,7 +610,7 @@ Fixed an issue on the Panorama web interface where Security policy rules loaded
## PAN-258188
Fixed an issue on Panorama Template where the virtual wire subinterface page did not display all fields and the OK button did not work.
Fixed an issue on Panorama Template where the virtual wire subinterface page did not display all fields and the **OK** button did not work.
## PAN-258149
@@ -618,7 +618,7 @@ Fixed an issue where the firewall dropped the SYN-ACK when using the TCP Fast Op
## PAN-257961
Fixed an issue on Panorama where Test Security Policy Match failed when the From or To zone fields were populated.
Fixed an issue on Panorama where **Test Security Policy Match** failed when the **From** or **To** zone fields were populated.
## PAN-257912
@@ -654,7 +654,7 @@ Fixed an issue where firewalls entered a non-functional state and displayed the
## PAN-257021
"Fixed an issue on the web interface where Match Evidence log details for Monitor > Correlated events did not populate."
"Fixed an issue on the web interface where **Match Evidence** log details for **Monitor > Correlated events** did not populate."
## PAN-256960
@@ -662,7 +662,7 @@ Fixed an issue where a custom portal login page was not displayed correctly in t
## PAN-256725
Fixed an issue on the Panorama interface where Traffic and Unified event details loaded more slowly than expected.
Fixed an issue on the Panorama interface where **Traffic** and **Unified** event details loaded more slowly than expected.
## PAN-256669
@@ -690,7 +690,7 @@ Fixed an issue where GTP sessions remained as allocated sessions on the passive
## PAN-256115
Fixed an issue where, after replacing a Panorama appliance or log collector, the secondary Panorama appliance or log collector displayed a disconnected status for the inter-log collector connection.
Fixed an issue where, after replacing a Panorama appliance or log collector, the secondary Panorama appliance or log collector displayed a **disconnected** status for the inter-log collector connection.
## PAN-255930
@@ -762,7 +762,7 @@ Fixed an issue where multiple SSHD process restarts triggered a firewall reboot
## PAN-252801
Fixed an issue where the LSVPN tunnel monitoring status displayed as No data available after re-key events.
Fixed an issue where the LSVPN tunnel monitoring status displayed as **No data available** after re-key events.
## PAN-252604
@@ -770,7 +770,7 @@ Fixed an issue where the clientless VPN did not carry authentication to other ta
## PAN-252370
Fixed an issue where services with the reserved keyword application-default were allowed.
Fixed an issue where services with the reserved keyword **application-default** were allowed.
## PAN-252300
@@ -822,7 +822,7 @@ Fixed an issue where stale BGP routes were advertised to peers even when they we
## PAN-249533
Fixed an issue where an internal error message was displayed when you selected Exclude video traffic from the tunnel (Windows and macOS only).
Fixed an issue where an internal error message was displayed when you selected **Exclude video traffic from the tunnel (Windows and macOS only)**.
## PAN-249384
@@ -878,7 +878,7 @@ Fixed an issue where the web interface stopped responding when you searched for
## PAN-242957
Fixed an issue where the Rule usage columns of overridden default policy rules on the Security policy page stopped responding.
Fixed an issue where the **Rule usage** columns of overridden default policy rules on the Security policy page stopped responding.
## PAN-242602
@@ -910,7 +910,7 @@ Fixed an issue where some commands did not have executable permissions.
## PAN-212889
Fixed an issue on Panorama where different threat names were used when querying a threat under Threat Monitor (Monitor > App Scope) and the ACC. This resulted in the ACC displaying no data after clicking a threat name in Threat Monitor and filtering it in the global filters.
Fixed an issue on Panorama where different threat names were used when querying a threat under **Threat Monitor** (**Monitor > App Scope**) and the ACC. This resulted in the ACC displaying no data after clicking a threat name in **Threat Monitor** and filtering it in the global filters.
## PAN-199141
+10 -10
View File
@@ -46,7 +46,7 @@ Fixed an issue where large IPv6 packets were reassembled incorrectly on the fire
## PAN-282206
Fixed an issue where configuring Secure Web Gateway (SWG) in no-auth mode led to latency when no decryption policy rules or No-decrypt policy rules were present.
Fixed an issue where configuring Secure Web Gateway (SWG) in **no-auth** mode led to latency when no decryption policy rules or **No-decrypt** policy rules were present.
## PAN-282069
@@ -62,7 +62,7 @@ Fixed an Issue where commits failed with the error invalid IPv6 x:x - must be gl
## PAN-280471
Fixed an issue where navigating Panorama > Monitor > Logs was slower than expected.
Fixed an issue where navigating **Panorama > Monitor > Logs** was slower than expected.
## PAN-279983
@@ -70,7 +70,7 @@ Fixed an issue where navigating Panorama > Monitor > Logs was slower than expect
PA-1400 Series firewalls only
```
Fixed an issue on the web interface where Enable Bonjour Reflector was not displayed (Network > Interfaces > Ethernet Interface).
Fixed an issue on the web interface where **Enable Bonjour Reflector** was not displayed (**Network > Interfaces > Ethernet Interface**).
## PAN-279746
@@ -122,7 +122,7 @@ Fixed an issue where unexpected failovers occurred on firewalls running PAN-OS 1
## PAN-277751
Fixed an issue where a policy-based forwarding (PBF) rule with an action of no-pbf and a service of TCP-22 did not match traffic after upgrading to PAN-OS 11.1.5-h1. As a result, traffic was matched by a lower rule with a service of any and an action of forward.
Fixed an issue where a policy-based forwarding (PBF) rule with an action of **no-pbf** and a service of TCP-22 did not match traffic after upgrading to PAN-OS 11.1.5-h1. As a result, traffic was matched by a lower rule with a service of **any** and an action of **forward**.
## PAN-277629
@@ -150,7 +150,7 @@ Fixed an issue where a session lost the PBF rule mapping after a configuration c
## PAN-276177
Fixed an issue where App Acceleration did not work with Oracle databases.
Fixed an issue where **App Acceleration** did not work with Oracle databases.
## PAN-276090
@@ -200,7 +200,7 @@ Fixed an issue where the firewall did not log the correct NAT IP address and sou
## PAN-273129
Fixed an issue on the web interface where the negate option was visible when you clicked on the rule name, but not when you viewed the target options from the rulebase attribute.
Fixed an issue on the web interface where the **negate** option was visible when you clicked on the rule name, but not when you viewed the target options from the **rulebase** attribute.
## PAN-273026
@@ -220,7 +220,7 @@ Fixed an issue where log forwarding to a UDP syslog server stopped when an unrea
## PAN-272538
Fixed an issue where the configd process stopped responding during a commit-all validation when there were uncommitted changes and share-unused-objects-with-devices was set to off.
Fixed an issue where the configd process stopped responding during a commit-all validation when there were uncommitted changes and **share-unused-objects-with-devices** was set to off.
## PAN-272171
@@ -244,7 +244,7 @@ Fixed an issue where pushing changes to a prefix list used for BGP from Panorama
## PAN-271273
Fixed an issue where dynamic update downloads failed when IPv6 firewalling was enabled on the firewall and both IPv4 and IPv6 were configured on the management interface.
Fixed an issue where dynamic update downloads failed when **IPv6 firewalling** was enabled on the firewall and both IPv4 and IPv6 were configured on the management interface.
## PAN-271181
@@ -364,7 +364,7 @@ Fixed an issue where the firewall displayed an OCSP/CRL check failure when acces
## PAN-257619
Fixed an issue on Panorama where the Task Manager took longer than expected to display managed firewall report tasks.
Fixed an issue on Panorama where the **Task Manager** took longer than expected to display managed firewall report tasks.
## PAN-255914
@@ -388,7 +388,7 @@ Fixed an issue where the Panorama web interface was slower than expected when op
Multi-vsys firewalls only
```
Fixed an issue where commits failed on the firewall after selecting Export or push device config bundle on Panorama and a force push was required.
Fixed an issue where commits failed on the firewall after selecting **Export or push device config bundle** on Panorama and a force push was required.
## PAN-233647
@@ -42,7 +42,7 @@ Fixed an issue where persistent commit failures occurred due to a missing transf
## PAN-289268
Fixed an issue where internet access through Secure Web Gateway (SWG) proxy nodes did not work when the default internet access policy rule source user was not known-user .
Fixed an issue where internet access through Secure Web Gateway (SWG) proxy nodes did not work when the default internet access policy rule source user was not **known-user**.
## PAN-288939
@@ -66,7 +66,9 @@ Fixed an issue where the popup window did not appear as expected for Clientless
## PAN-279901
Fixed an issue where the firewall dropped client hello packets when decryption was enabled, which prevented access to certain websites. This occurred when the client hello packet was truncated, the accumulation proxy assumed that the first packet contains at least 5 bytes, or out-of-order packets were waiting in L4 TCP.
An issue was fixed where the firewall dropped fragmented TLS ClientHello packets, which blocked access to certain websites. This occurred because the packets arrived truncated, in varying sizes and orders, and the firewall's heuristics failed to handle them correctly.
To enable this fix, run: debug dataplane set ssl-decrypt accumulate-client-hello disjoined yes
## PAN-279690
@@ -98,4 +100,4 @@ Fixed an issue where the all_pktproc process stopped responding when the firewal
## PAN-252706
Fixed an issue where the URL filtering response page for Continue and Override did not work with IPv6 Router Advertisement (RA) or Multicast Listener Query (MLQ) for IPv6-to-IPv6 and IPv6-to-IPv4 traffic.
Fixed an issue where the URL filtering response page for **Continue** and **Override** did not work with IPv6 Router Advertisement (RA) or Multicast Listener Query (MLQ) for IPv6-to-IPv6 and IPv6-to-IPv4 traffic.
@@ -16,9 +16,8 @@ Fixed an issue where a leak in decryption counters caused resource exhaustion, w
Fixed two issues that impacted TLSv1.2 or earlier sessions when the traffic matched a decryption policy rule with the no-decrypt action:
Connections failed when both HTTP header insertion (Objects > Security Profiles > URL Filtering > HTTP Header Insertion) and Send handshake messages to CTD for inspection (Device > Setup > Session > Decryption Settings > SSL Decryption Settings) were enabled.
New sessions failed due to software packet buffer resource depletion, which occurred when Log Successful SSL Handshake was disabled in the decryption policy rule and the decryption profile attached to the rule had both Block sessions with expired certificates and Block sessions with untrusted issuers disabled.
- Connections failed when both HTTP header insertion (**Objects > Security Profiles > URL Filtering > HTTP Header Insertion**) and **Send handshake messages to CTD for inspection** (**Device > Setup > Session > Decryption Settings > SSL Decryption Settings**) were enabled.
- New sessions failed due to software packet buffer resource depletion, which occurred when Log Successful SSL Handshake was disabled in the decryption policy rule and the decryption profile attached to the rule had both **Block sessions with expired certificates** and **Block sessions with untrusted issuers** disabled.
## PAN-306103
@@ -66,7 +65,7 @@ Addressed a memory leak issue under sc3 and automatic commit recovery (ACR) code
Subject Common Name
```
Fixed an issue where certificate data was missing in decryption logs for No decrypt policy rules and TLS1.2 traffic after upgrading, and the , Issuer Common Name, Certificate Start Date, Certificate End Date, Certificate Serial Number, and Certificate Fingerprint fields were blank in the decryption logs.
Fixed an issue where certificate data was missing in decryption logs for **No decrypt** policy rules and TLS1.2 traffic after upgrading, and the , **Issuer Common Name**, **Certificate Start Date**,**Certificate End Date**, **Certificate Serial Number**, and **Certificate Fingerprint** fields were blank in the decryption logs.
## PAN-283563
@@ -82,7 +81,7 @@ Fixed an issue where the all_task process stopped responding, which caused the f
## PAN-259853
Fixed an issue where, when the DHCP server was enabled for GlobalProtect, the commit error message was not properly displayed when Any was selected as the source interface in the service router configuration (DeviceSetupServiceService Router Configuration).
Fixed an issue where, when the DHCP server was enabled for GlobalProtect, the commit error message was not properly displayed when **Any** was selected as the source interface in the service router configuration (**Device** > **Setup** > **Service** > **Service Router Configuration**).
## PAN-258039
@@ -34,7 +34,9 @@ Fixed an issue where devices with 5G cellular modems did not support the ATT Fir
## PAN-285181
Fixed an issue where the wifclient was not configured to utilize the GOMEMLIMIT feature.
Fixed an issue where the wifclient ran out of memory when Enhanced Application Logging was enabled and a sudden traffic increase caused a surge in EAL messages sent through WIF.
To use this fix, run the CLI command debug iot eal memory-gc native
## PAN-278688
@@ -18,7 +18,7 @@ Fixed an issue where the useridd process became unresponsive, which caused User
## PAN-287688
Fixed an issue where the firewall failed to connect to the Palo Alto Networks update server when using a customized service route with the source interface as MGT.
Fixed an issue where the firewall failed to connect to the Palo Alto Networks update server when using a customized service route with the source interface as **MGT**.
## PAN-268680
@@ -26,7 +26,7 @@ Fixed an issue where the configd process stopped responding when a configuration
## PAN-268522
Fixed an issue where the firewall failed to connect to the update server with a customized service route when the source interface was set to MGT and the source address was set as IPv4.
Fixed an issue where the firewall failed to connect to the update server with a customized service route when the source interface was set to **MGT** and the source address was set as IPv4.
## PAN-241230
@@ -58,7 +58,7 @@ Fixed an issue where content loading issues occurred on IPv6 websites due to the
## PAN-286299
Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the Network and Device tabs became read-only.
Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the **Network** and **Device** tabs became read-only.
## PAN-286231
@@ -86,7 +86,7 @@ Fixed an issue where WildFire reports were not fully displayed and were not down
## PAN-276484
Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (Device Deployment > Licenses) due to the inability to perform batch-license refreshes.
Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (**Device Deployment > Licenses**) due to the inability to perform batch-license refreshes.
## PAN-259741
@@ -34,7 +34,7 @@ Fixed an issue where a dataplane crash occurred when traffic matched Inline Clou
## PAN-297775
Fixed an issue where, after upgrading, the Visible Virtual Systems field started to reference the vsys name instead of the vsys ID, which caused inter-vsys routing to fail. This occurred when a vsys display name matched one of the vsys IDs.
Fixed an issue where, after upgrading, the **Visible Virtual Systems** field started to reference the vsys name instead of the vsys ID, which caused inter-vsys routing to fail. This occurred when a vsys display name matched one of the vsys IDs.
## PAN-297240
@@ -58,7 +58,7 @@ Fixed an issue where, after upgrading Panorama and Log Collectors, Traffic and T
## PAN-294893
Fixed an issue where firewalls with the Send handshake messages to CTD for inspection setting enabled caused incorrect security policy rules to be matched. Specifically, traffic not identified as openai-base or openai-chatgpt applications was incorrectly matched by the ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected response page for blocked URLs was not displayed.
Fixed an issue where firewalls with the **Send handshake messages to CTD for inspection** setting enabled caused incorrect security policy rules to be matched. Specifically, traffic not identified as openai-base or openai-chatgpt applications was incorrectly matched by the ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected response page for blocked URLs was not displayed.
## PAN-294524
@@ -74,7 +74,7 @@ Fixed an issue where the firewall rebooted unexpectedly due to the useridd proce
## PAN-292447
Fixed an issue where Panorama did not display data in the Feature Adoption tab in Strata Cloud Manager due to the system creating and deleting a CLI user for each interval instead of reusing a permanent CLI user for telemetry.
Fixed an issue where Panorama did not display data in the **Feature Adoption** tab in Strata Cloud Manager due to the system creating and deleting a CLI user for each interval instead of reusing a permanent CLI user for telemetry.
## PAN-291940
@@ -6,7 +6,7 @@ version: 11.2.7-h8
## PAN-308727
Fixed an issue where traffic logs for Remote Networks displayed the source zone as trust instead of the remote network name.
Fixed an issue where traffic logs for **Remote Networks** displayed the source zone as **trust** instead of the remote network name.
## PAN-308468
@@ -18,7 +18,7 @@ Fixed an issue on Panorama where a memory leak occurred related to the reportd p
## PAN-302927
Fixed an issue where, after upgrading Panorama, the Push to Devices option did not display selected devices, and the OK and Cancel buttons did not function as expected. Selecting OK did not close the window, and selecting Cancel returned to the main push screen with the push selected devices displaying as empty. Despite this, selecting Push or Validate Device Group Push still pushed to the previously canceled, non-displayed devices.
Fixed an issue where, after upgrading Panorama, the **Push to Devices** option did not display selected devices, and the **OK** and **Cancel** buttons did not function as expected. Selecting **OK** did not close the window, and selecting **Cancel** returned to the main push screen with the push selected devices displaying as empty. Despite this, selecting **Push** or **Validate Device Group Push** still pushed to the previously canceled, non-displayed devices.
## PAN-301801
@@ -64,7 +64,7 @@ Fixed an issue where exporting custom reports resulted in empty CSV files.
## PAN-296977
Fixed an issue where the web interface became unresponsive when attempting to view Ethernet interface details after applying a filter in NetworkInterfaces
Fixed an issue where the web interface became unresponsive when attempting to view **Ethernet** interface details after applying a filter in **Network** > **Interfaces**
## PAN-296752
@@ -96,7 +96,7 @@ Fixed an issue where the logrcvr process stopped responding due to memory alloca
## PAN-293985
Fixed an issue with the Panorama web interface where admin users were unable to log in and received the error message 504: Gateway Timeout.
Fixed an issue with the Panorama web interface where admin users were unable to log in and received the error message **504: Gateway Timeout**.
## PAN-292770
@@ -140,7 +140,7 @@ Fixed an issue where the routed process core failed the automation run.
## PAN-209516
Fixed an issue where, when creating an interface, an error occurred when you clicked OK without providing a value in the Tag field even though the field was not displayed as mandatory.
Fixed an issue where, when creating an interface, an error occurred when you clicked **OK** without providing a value in the **Tag** field even though the field was not displayed as mandatory.
## PAN-185731
+16 -16
View File
@@ -34,7 +34,7 @@ Fixed a race condition issue related to predict processing, which resulted in a
## PAN-288930
Fixed an issue where traffic from cloud applications intermittently matched an incorrect cloud-apps policy rule when ACE (App-ID Cloud Engine) was enabled.
Fixed an issue where traffic from cloud applications intermittently matched an incorrect **cloud-apps** policy rule when ACE (App-ID Cloud Engine) was enabled.
## PAN-287818
@@ -54,7 +54,7 @@ Fixed an issue where ECMP incorrectly balanced sessions across links based on th
## PAN-286825
Fixed an issue where GlobalProtect User-ID mappings were lost after 5 minutes, which caused users to not match User-ID source-based policy rules. This occurred due to a mismatch between the GlobalProtect gateway connection settings and the device behavior and when the inactivity-logout setting was deleted and set to a different value.
Fixed an issue where GlobalProtect User-ID mappings were lost after 5 minutes, which caused users to not match User-ID source-based policy rules. This occurred due to a mismatch between the GlobalProtect gateway connection settings and the device behavior and when the **inactivity-logout** setting was deleted and set to a different value.
## PAN-285894
@@ -102,7 +102,7 @@ Fixed an issue on Panorama where the web interface performance was slower than u
Firewalls in HA configurations only
```
Fixed an issue where, after an upgrade, the mac receive error counter in receive incoming errors increased, which resulted in SNMP alerts.
Fixed an issue where, after an upgrade, the **mac receive error** counter in **receive incoming errors** increased, which resulted in SNMP alerts.
## PAN-283644
@@ -114,11 +114,11 @@ Fixed an issue where URL log ingestion decreased after an upgrade, and secondary
## PAN-283331
Fixed an issue where selective pushes to managed devices failed when the User ID Master Device was configured.
Fixed an issue where selective pushes to managed devices failed when the **User ID Master Device** was configured.
## PAN-282697
Fixed an issue where traffic was delayed significantly when it used No Authentication Explicit Proxy and matched a decryption policy rule.
Fixed an issue where traffic was delayed significantly when it used **No Authentication Explicit Proxy** and matched a decryption policy rule.
## PAN-282640
@@ -142,7 +142,7 @@ Fixed an issue where the Panorama web interface was slower than expected.
## PAN-282240
Fixed an issue where, when attempting to modify an Anti-Spyware profile via the web interface under a shared location, clicking the OK button displayed a console exception error.
Fixed an issue where, when attempting to modify an Anti-Spyware profile via the web interface under a shared location, clicking the **OK** button displayed a console exception error.
## PAN-281885
@@ -228,7 +228,7 @@ Fixed an issue where accessing a URL from the browser returned the error message
## PAN-279400
Fixed an issue where, when Restrict Certificate Extensions was enabled on decryption profiles, the basic constraints extension was overwritten incorrectly.
Fixed an issue where, when **Restrict Certificate Extensions** was enabled on decryption profiles, the basic constraints extension was overwritten incorrectly.
## PAN-279336
@@ -240,7 +240,7 @@ Fixed an issue where the configuration audit displayed inaccurate information af
## PAN-279065
Fixed an issue where the firewall sent logs with connection succeeded to the syslog server every time a connection was established, which resulted in excessive logs.
Fixed an issue where the firewall sent logs with **connection succeeded** to the syslog server every time a connection was established, which resulted in excessive logs.
## PAN-278981
@@ -280,11 +280,11 @@ Fixed an issue where the logrcvr process discarded logs due to a full queue.
## PAN-277464
Fixed an issue with intermittent access and slower than expected loading times when accessing websites. This occurred when Anti-Spyware inline cloud analysis was enabled and the SSL Command and Control action was not either allow or alert and server hello packets were out of order.
Fixed an issue with intermittent access and slower than expected loading times when accessing websites. This occurred when Anti-Spyware inline cloud analysis was enabled and the **SSL Command and Control** action was not either **allow** or **alert** and server hello packets were out of order.
## PAN-277234
Fixed an issue where a device group import resulted in a Security policy rule being created with Application set to none.
Fixed an issue where a device group import resulted in a Security policy rule being created with **Application** set to **none**.
## PAN-277147
@@ -320,7 +320,7 @@ Fixed an issue where Panorama stopped forwarding logs to a syslog server after u
## PAN-275713
Fixed an issue where the dscd process stopped responding when Endpoint Serial Number was enabled, which resulted in the **Active Directory* returning a list of serial numbers for a specific firewall from the Cloud Identity Engine.
Fixed an issue where the dscd process stopped responding when **Endpoint Serial Number** was enabled, which resulted in the **Active Directory* returning a list of serial numbers for a specific firewall from the Cloud Identity Engine.
## PAN-275133
@@ -392,7 +392,7 @@ Fixed an issue where packets were dropped initially when a SYN cookie with activ
## PAN-273597
Fixed an issue where logs in the cloud database displayed in the Not-Resolved category but not in the local database.
Fixed an issue where logs in the cloud database displayed in the **Not-Resolved** category but not in the local database.
## PAN-273453
@@ -522,7 +522,7 @@ Fixed an issue where the firewall redirected the user to the first application i
Firewalls with DPDK enabled in Azure, GCP, AWS, and KVM environments only
```
Fixed an issue where, after an upgrade to PAN-OS 11.1.4, the mac receive error counter increased without an error even though traffic was not impacted.
Fixed an issue where, after an upgrade to PAN-OS 11.1.4, the **mac receive error** counter increased without an error even though traffic was not impacted.
## PAN-268708
@@ -530,7 +530,7 @@ Fixed an issue where PDF summary and email reports displayed IPv6 addresses inst
## PAN-268614
Fixed an issue on the web interface where, when all rules were highlighted when a read-only admin user clicked the Highlight Unused Rules checkbox.
Fixed an issue on the web interface where, when all rules were highlighted when a read-only admin user clicked the **Highlight Unused Rules** checkbox.
## PAN-268489
@@ -610,7 +610,7 @@ Fixed an issue where a commit for a policy and configuration dump overlapped, wh
## PAN-261074
Fixed an issue where the firewall delayed video file transfers over SMB when Exclude Video Traffic from the Tunnel feature was enabled and no applications were added to the list.
Fixed an issue where the firewall delayed video file transfers over SMB when **Exclude Video Traffic** from the Tunnel feature was enabled and no applications were added to the list.
## PAN-260229
@@ -670,7 +670,7 @@ Fixed an issue on Panorama where a core file was generated by /usr/local/bin/log
## PAN-254524
Fixed an issue on Panorama where, when the Commit and Push button was clicked during a selective Commit and Push operation, the window stopped responding, which caused the operation to be delayed.
Fixed an issue on Panorama where, when the **Commit and Push** button was clicked during a selective **Commit and Push** operation, the window stopped responding, which caused the operation to be delayed.
## PAN-253127
+80 -82
View File
@@ -18,7 +18,7 @@ Fixed an issue where the logrcvr process stopped responding due to memory alloca
## PAN-294488
Fixed an issue where certificate data was missing in decryption logs for No decrypt policy rules and TLS1.2 traffic after upgrading, and the Subject Common Name, Issuer Common Name, Certificate Start Date, Certificate End Date, Certificate Serial Number, and Certificate Fingerprint fields were blank in the decryption logs.
Fixed an issue where certificate data was missing in decryption logs for **No decrypt** policy rules and TLS1.2 traffic after upgrading, and the **Subject Common Name**, **Issuer Common Name**, **Certificate Start Date**, **Certificate End Date**, **Certificate Serial Number**, and **Certificate Fingerprint** fields were blank in the decryption logs.
## PAN-294436
@@ -46,7 +46,7 @@ Fixed an issue where, after upgrading the firewall having an IKE gateway that us
Panorama virtual appliances in FIPS mode only
```
Fixed an issue where plugin installs failed with the error invalid image after manually uploading the plugin package from the Customer Support Portal (CSP).
Fixed an issue where plugin installs failed with the error **invalid image** after manually uploading the plugin package from the Customer Support Portal (CSP).
## PAN-292503
@@ -142,7 +142,7 @@ Fixed an issue where SNMP walks returned a value of 0 for the CPS (Connections P
Panorama virtual appliances only
```
Fixed an issue on the web interface where you were unable to export the Threat Map.
Fixed an issue on the web interface where you were unable to export the **Threat Map**.
## PAN-290900
@@ -150,11 +150,11 @@ Fixed an issue where Panorama in FIPS-CC mode failed to push IKEv2 Post-Quantum
## PAN-290702
Fixed an issue where Log Quotas incorrectly displayed a value that was higher than possible.
Fixed an issue where **Log Quotas** incorrectly displayed a value that was higher than possible.
## PAN-290694
Fixed an issue on the Panorama web interface where you were unable to push shared objects to devices if an HA failover occurred during a configuration push.
Fixed an issue on the Panorama web interface where you were unable to **push** shared objects to devices if an HA failover occurred during a configuration push.
## PAN-290691
@@ -166,15 +166,15 @@ Fixed an issue where, when multiple scheduled vulnerability reports were were se
## PAN-290241
Fixed an issue where the useridd process became unresponsive, which caused User ID CLI commands to time out.
Fixed an issue where the **useridd** process became unresponsive, which caused User ID CLI commands to time out.
## PAN-290191
Fixed an issue where BGP learned routes were not advertised when Legacy Routing was used and an export policy rule was configured to match the next hop of the learned route.
Fixed an issue where BGP learned routes were not advertised when **Legacy Routing** was used and an export policy rule was configured to match the next hop of the learned route.
## PAN-290157
Fixed an issue on Panorama where the configd process stopped responding when filtering in the Config Audit window, which caused Panorama to restart unexpectedly.
Fixed an issue on Panorama where the configd process stopped responding when filtering in the **Config Audit** window, which caused Panorama to restart unexpectedly.
## PAN-290088
@@ -226,7 +226,7 @@ Fixed an issue related to external URL lists where pushing configuration changes
## PAN-289573
Fixed an issue on Panorama where the web interface became unresponsive when attempting to edit the Allow traffic to specified FQDN when Enforce GlobalProtect Connection for Network Access setting in a GlobalProtect portal configuration after adding 40 or more FQDN entries.
Fixed an issue on Panorama where the web interface became unresponsive when attempting to edit the **Allow traffic to specified FQDN when Enforce GlobalProtect Connection for Network Access** setting in a GlobalProtect portal configuration after adding 40 or more FQDN entries.
## PAN-289532
@@ -266,7 +266,7 @@ Fixed an issue on the Panorama web interface where a template name or device gro
## PAN-289268
Fixed an issue where internet access through Secure Web Gateway (SWG) proxy nodes did not work when the default internet access policy rule source user was not known-user.
Fixed an issue where internet access through Secure Web Gateway (SWG) proxy nodes did not work when the default internet access policy rule source user was not **known-user**.
## PAN-289239
@@ -370,7 +370,7 @@ Fixed an issue where the maximum registered IP address for was incorrectly set t
## PAN-287842
Fixed an issue where the comm process stopped responding due to missing heartbeats, which resulted in a system alert and HA communication loss on slot1.
Fixed an issue where the **comm** process stopped responding due to missing heartbeats, which resulted in a system alert and HA communication loss on slot1.
## PAN-287838
@@ -386,11 +386,11 @@ Fixed an issue where SAML authentication failed, which caused the GlobalProtect
## PAN-287734
Fixed an issue where the error message Scan ERR: Internal Err 1002 was generated unexpectedly when WIF shared memory use was high.
Fixed an issue where the error message **Scan ERR: Internal Err 1002** was generated unexpectedly when WIF shared memory use was high.
## PAN-287688
Fixed an issue where the firewall failed to connect to the Palo Alto Networks update server when using a customized service route with the source interface as MGT.
Fixed an issue where the firewall failed to connect to the Palo Alto Networks update server when using a customized service route with the source interface as **MGT**.
## PAN-287621
@@ -474,7 +474,7 @@ Fixed an issue where the device-group-tags CLI command used an unnecessary confi
VM-Series firewalls only AWS environments only
```
Fixed an issue where the firewall did not send ICMP unreachable - Fragmentation Needed message when it received packets larger than the MTU.
Fixed an issue where the firewall did not send **ICMP unreachable - Fragmentation Needed** message when it received packets larger than the MTU.
## PAN-286818
@@ -486,7 +486,7 @@ Fixed an issue where closing an SSH session to a Panorama using Ctrl+D did not g
Panorama virtual appliances in HA configurations on Microsoft Azure environments only
```
Fixed an issue where plugin versions displayed when hovering over the Green Match icon were inconsistent even though the web interface reported the versions as matching.
Fixed an issue where plugin versions displayed when hovering over the **Green Match** icon were inconsistent even though the web interface reported the versions as matching.
## PAN-286734
@@ -502,7 +502,7 @@ Added uplink counters to enhance debug capability for traffic drops.
Panorama appliances only
```
Fixed an issue where the Require SSL/TLS secured connection in the LDAP profile within the template stack did not take effect after overriding the configuration. This occurred even when the setting was enabled multiple times.
Fixed an issue where the **Require SSL/TLS secured connection** in the LDAP profile within the template stack did not take effect after overriding the configuration. This occurred even when the setting was enabled multiple times.
## PAN-286669
@@ -526,7 +526,7 @@ Fixed an issue on Panorama where logs were not forwarded to syslog servers due t
## PAN-286475
Fixed an issue where the option to sort sequence numbers was missing from Filters prefix list in the advanced routing filters.
Fixed an issue where the option to sort sequence numbers was missing from **Filters prefix list** in the advanced routing filters.
## PAN-286443
@@ -538,7 +538,7 @@ Fixed an issue where, when getting transceiver information from ESCC for SFP 25G
## PAN-286299
Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the Network and Device tab became read-only.
Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the **Network** and **Device** tab became read-only.
## PAN-286231
@@ -562,7 +562,7 @@ Fixed an issue where the XML API returned an error when attempting to view debug
## PAN-285834
Fixed an issue on Panorama where Policy recommendation displayed Unable to read data for certain profiles due to a large response size.
Fixed an issue on Panorama where **Policy recommendation** displayed **Unable to read data** for certain profiles due to a large response size.
## PAN-285818
@@ -606,7 +606,7 @@ Fixed an issue where commits remained at 98% completion when static route config
## PAN-284907
Fixed an issue where the Panorama web interface displayed No Data when viewing configuration logs to see changes before and after a configuration change.
Fixed an issue where the Panorama web interface displayed **No Data** when viewing configuration logs to see changes before and after a configuration change.
## PAN-284878
@@ -638,7 +638,7 @@ Fixed an issue where, when a firewall had more than 4,400 logical interfaces, co
## PAN-284441
Fixed an issue where, after upgrading the firewall, GlobalProtect connections failed with the error message Network Connection is unreachable.
Fixed an issue where, after upgrading the firewall, GlobalProtect connections failed with the error message **Network Connection is unreachable**.
## PAN-284380
@@ -702,7 +702,7 @@ Fixed an issue where HTTP/2 child streams were blocked by strict-ip-check zone p
## PAN-283613
Fixed an issue on the web interface where the IP Tag Quota(%) value displayed as 2 even when changed.
Fixed an issue on the web interface where the **IP Tag** **Quota(%)** value displayed as 2 even when changed.
## PAN-283575
@@ -726,7 +726,7 @@ Fixed an issue where the SAML single log out (SLO) URL was not correctly display
## PAN-283333
Fixed an issue where threat logs displayed logs from the N/A threat category when a random string was used for the category-of-threatid filter in threat logs.
Fixed an issue where threat logs displayed logs from the **N/A** threat category when a random string was used for the **category-of-threatid** filter in threat logs.
## PAN-283316
@@ -738,7 +738,7 @@ Fixed an issue where the OSPFv3 area nssa default-information-originate CLI comm
## PAN-283206
Fixed an issue where configuring an HTTP profile to send Webhook alerts to Microsoft Teams failed with a 400 Bad request error when clicking Send Test Log.
Fixed an issue where configuring an HTTP profile to send Webhook alerts to Microsoft Teams failed with a 400 Bad request error when clicking **Send Test Log**.
## PAN-283168
@@ -774,7 +774,7 @@ Fixed an issue where firewalls in air-gapped environments attempted to connect t
## PAN-282454
Fixed an issue where, when you added the Virtual System Name column under Unified Logs, the column did not remain visible in the table if you closed and re-opened the tab.
Fixed an issue where, when you added the **Virtual System Name** column under **Unified Logs**, the column did not remain visible in the table if you closed and re-opened the tab.
## PAN-282277
@@ -786,7 +786,7 @@ Fixed an issue where firewalls became unstable and stopped responding, which res
## PAN-281776
Fixed an issue on the Panorama web interface where the error message PPPoEv6 Client Interface cannot be enabled with DHCPv6 client was generated when overriding aggregate interfaces even when no DHCPv6 or PPPoE was configured.
Fixed an issue on the Panorama web interface where the error message **PPPoEv6 Client Interface cannot be enabled with DHCPv6 client** was generated when overriding aggregate interfaces even when no DHCPv6 or PPPoE was configured.
## PAN-281596
@@ -810,11 +810,11 @@ Fixed an issue on Panorama managed firewalls where, when the service route confi
## PAN-281096
Fixed an issue on HA clusters where, when link and path monitoring was configured and the failover condition was set to all, disconnecting and reconnecting monitored ethernet ports caused the firewall to switch to a nonfunctional role, which resulted in all interfaces except the HA interface going down.
Fixed an issue on HA clusters where, when link and path monitoring was configured and the failover condition was set to **all**, disconnecting and reconnecting monitored ethernet ports caused the firewall to switch to a nonfunctional role, which resulted in all interfaces except the HA interface going down.
## PAN-281017
Fixed an issue where shared objects were displayed in the Push Scope after pushing the configuration from Panorama to managed firewalls.
Fixed an issue where shared objects were displayed in the **Push Scope** after pushing the configuration from Panorama to managed firewalls.
## PAN-280910
@@ -846,7 +846,7 @@ Fixed an issue in the URL filtering logs where the columns and the displayed con
## PAN-280013
Fixed an issue where User-ID custom reports were unable to exclude IP address 0.0.0.0 when using the filter ip notin 0.0.0.0.
Fixed an issue where User-ID custom reports were unable to exclude IP address 0.0.0.0 when using the filter **ip notin 0.0.0.0**.
## PAN-279829
@@ -870,7 +870,7 @@ Fixed an issue where threat names were displayed differently on the web interfac
## PAN-279584
Fixed an issue where, during software deployment from Panorama to multiple firewalls, some firewalls did not automatically reboot after the upgrade, even when Reboot device after install was selected. This was due to the Panorama timing out before the software deployment completed on the affected firewalls, which prevented the reboot request from being sent.
Fixed an issue where, during software deployment from Panorama to multiple firewalls, some firewalls did not automatically reboot after the upgrade, even when **Reboot device after install** was selected. This was due to the Panorama timing out before the software deployment completed on the affected firewalls, which prevented the reboot request from being sent.
## PAN-279415
@@ -886,7 +886,7 @@ Fixed an issue where changes made to the management interface permitted IP addre
## PAN-279195
Fixed an issue on Panorama where Device Health displayed the device memory as 0%.
Fixed an issue on Panorama where **Device Health** displayed the device memory as 0%.
## PAN-278836
@@ -902,7 +902,7 @@ Fixed an issue where the configd process restarted during a configuration push f
## PAN-278507
Fixed an issue where the OCSP Signing purpose was not included in the Extended Key Usage field when a certificate was generated on the firewall with the OCSP responder called in the certificate. This caused the GlobalProtect connection to fail with the error Missing OCSP signing purpose in the ExtendedKeyUsage.
Fixed an issue where the OCSP Signing purpose was not included in the **Extended Key Usage** field when a certificate was generated on the firewall with the OCSP responder called in the certificate. This caused the GlobalProtect connection to fail with the error **Missing OCSP signing purpose in the ExtendedKeyUsage**.
## PAN-278364
@@ -926,7 +926,7 @@ Fixed an issue where the number of registered IP Tags on Panorama did not match
VM-Series firewalls in AWS environments only
```
Fixed an issue where HA failover mode incorrectly changed from interface move to secondary IP move after a reboot.
Fixed an issue where HA failover mode incorrectly changed from **interface move** to **secondary IP move** after a reboot.
## PAN-277759
@@ -938,7 +938,7 @@ Fixed an issue that caused the request system private-data-reset CLI command to
## PAN-277682
Fixed an issue where moving an address object from a device group to shared and renaming it did not reflect in the address group, which caused commits to fail.
Fixed an issue where moving an address object from a device group to **shared** and renaming it did not reflect in the address group, which caused commits to fail.
## PAN-277617
@@ -978,7 +978,7 @@ Fixed an issue on Panorama where the logd process stopped responding unexpectedl
## PAN-276795
Fixed an issue where the GlobalProtect client displayed an error message when you clicked Check Now and Preferred Releases and Base Releases were unchecked (Device > Software).
Fixed an issue where the GlobalProtect client displayed an error message when you clicked **Check Now** and **Preferred Releases** and **Base Releases** were unchecked (**Device > Software**).
## PAN-276694
@@ -1002,11 +1002,11 @@ Fixed an issue where Panorama stopped responding when running reports.
## PAN-276484
Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (Device Deployment > Licenses) due to the inability to perform batch-license refreshes.
Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (**Device Deployment > Licenses**) due to the inability to perform batch-license refreshes.
## PAN-276412
Fixed an issue where you were unable to download XML files from Panorama > Summary > Backups.
Fixed an issue where you were unable to download XML files from **Panorama > Summary > Backups**.
## PAN-276352
@@ -1014,15 +1014,15 @@ Fixed an issue where multicast flows were dropped due to a missing sysd variable
## PAN-276321
Fixed an issue where User-ID mappings were not correctly redistributed from Panorama to firewalls, causing some users to be identified as unknown, which prevented access to resources based on AD group membership.
Fixed an issue where User-ID mappings were not correctly redistributed from Panorama to firewalls, causing some users to be identified as **unknown**, which prevented access to resources based on AD group membership.
## PAN-276144
Fixed an issue on the web interface where the Response Page action column was not accessible.
Fixed an issue on the web interface where the **Response Page** **action** column was not accessible.
## PAN-276033
Fixed an issue on Panorama managed firewalls where SAML identity provider and Clientless Apps objects did not have override or revert options.
Fixed an issue on Panorama managed firewalls where **SAML identity provider** and **Clientless Apps** objects did not have override or revert options.
## PAN-276000
@@ -1038,7 +1038,7 @@ Fixed an issue where the Log Collector service did not start on a new Log Collec
## PAN-275601
Fixed an issue where, when Panorama was not internet connected and you attempted to upload images to managed firewalls using the Validate option, the upload failed with the error Failed to create multi-upload job. No valid software deploy targets found.
Fixed an issue where, when Panorama was not internet connected and you attempted to upload images to managed firewalls using the **Validate** option, the upload failed with the error **Failed to create multi-upload job. No valid software deploy targets found**.
## PAN-275451
@@ -1066,7 +1066,7 @@ Fixed an issue where you were unable to to adjust the frequency of the Advanced
## PAN-274907
Fixed an issue on Panorama where Config Audit Commit Date displayed the timestamp of the configuration edit instead of the commit time.
Fixed an issue on Panorama where **Config Audit Commit Date** displayed the timestamp of the configuration edit instead of the commit time.
## PAN-274650
@@ -1106,11 +1106,11 @@ Fixed an issue on Panorama where the request batch license info CLI command disp
## PAN-274038
Fixed an issue where you were unable to use the s_encrypted field in custom reports for the Panorama threat log database.
Fixed an issue where you were unable to use the **s_encrypted** field in custom reports for the Panorama threat log database.
## PAN-273991
Fixed an issue where the transmit power for a cable that was used on port 44 displayed as N/A.
Fixed an issue where the transmit power for a cable that was used on port 44 displayed as **N/A**.
## PAN-273969
@@ -1134,7 +1134,7 @@ Fixed an issue where firewalls configured with a VPN tunnel stopped responding w
## PAN-273010
Fixed an issue where the configuration version did not increment in the Audit Comment Archive after making changes to the Security policy rule with an audit comment and performing a commit. As a result, all subsequent changes were grouped under the same configuration version, which prevented the comparison of changes in the Rule Changes field of the Security policy rule.
Fixed an issue where the configuration version did not increment in the Audit Comment Archive after making changes to the Security policy rule with an audit comment and performing a commit. As a result, all subsequent changes were grouped under the same configuration version, which prevented the comparison of changes in the **Rule Changes** field of the Security policy rule.
## PAN-273008
@@ -1154,15 +1154,15 @@ Fixed an issue where you were unable to export the GlobalProtect client software
## PAN-272790
Fixed an issue on the Panorama web interface where administrators were unable to export GlobalProtect client images and received an scp export failed error. This was due to the system attempting to retrieve the file from an incorrect directory.
Fixed an issue on the Panorama web interface where administrators were unable to export GlobalProtect client images and received an **scp export failed** error. This was due to the system attempting to retrieve the file from an incorrect directory.
## PAN-272743
Fixed an issue where non-captive portal traffic was not visible under Traffic Logs when the traffic was denied by an authentication rule and the session was discarded.
Fixed an issue where non-captive portal traffic was not visible under **Traffic Logs** when the traffic was denied by an authentication rule and the session was discarded.
## PAN-272726
Fixed an issue on the web interface where the URL Filtering change category feature did not work.
Fixed an issue on the web interface where the **URL Filtering** change category feature did not work.
## PAN-272505
@@ -1170,7 +1170,7 @@ Fixed an issue where GlobalProtect cookie authentication failed with the error U
## PAN-272469
Fixed an issue where the DNS exception displayed 0 instead of no result in the anti-spyware profile when no threat ID was available for a DNS Security category.
Fixed an issue where the DNS exception displayed **0** instead of **no result** in the anti-spyware profile when no threat ID was available for a DNS Security category.
## PAN-272408
@@ -1222,7 +1222,7 @@ A CLI counter was added to indicate a full suppression queue.
## PAN-271412
Fixed an issue where the character ( + ) in the authentication message prompt displayed incorrectly as #43; on the GlobalProtect client after upgrading to a PAN-OS 10.2 release.
Fixed an issue where the character ( + ) in the authentication message prompt displayed incorrectly as **#43;** on the GlobalProtect client after upgrading to a PAN-OS 10.2 release.
## PAN-271301
@@ -1242,7 +1242,7 @@ Fixed an issue where the firewall displayed an incorrect maximum translated IP c
## PAN-271061
Fixed an issue on the web interface where you were unable to add Threat IDs to Signature Exceptions.
Fixed an issue on the web interface where you were unable to add Threat IDs to **Signature Exceptions**.
## PAN-270747
@@ -1266,11 +1266,11 @@ Fixed an issue threat reports were empty when generated from Panorama, but displ
## PAN-269843
Fixed an issue where the firewall dropped non-SYN TCP packets even when the Reject non-SYN TCP option was set to No when a session rematch was triggered.
Fixed an issue where the firewall dropped non-SYN TCP packets even when the **Reject non-SYN TCP** option was set to **No** when a session rematch was triggered.
## PAN-269716
Fixed an issue where half-closed TCP sessions did not refresh the session timeout when continuously receiving data after setting the cfg.session.tcp-no-refresh-fin-rst option toTrue.
Fixed an issue where half-closed TCP sessions did not refresh the session timeout when continuously receiving data after setting the cfg.session.tcp-no-refresh-fin-rst option to True.
## PAN-269659
@@ -1310,7 +1310,7 @@ Fixed an issue where the aggressive clean-up threshold for disk space was set to
## PAN-269176
Fixed an issue where the domain-edl column was empty in the threat log even when a threat was detected as a DNS alert.
Fixed an issue where the **domain-edl** column was empty in the threat log even when a threat was detected as a DNS alert.
## PAN-269155
@@ -1342,7 +1342,7 @@ Fixed an issue where the configd process stopped responding when a configuration
## PAN-268606
Fixed an issue where GlobalProtect users with client certificates received an authentication failure message without entering a password and clicking connect or login.
Fixed an issue where GlobalProtect users with client certificates received an authentication failure message without entering a password and clicking **connect** or **login**.
## PAN-268597
@@ -1354,7 +1354,7 @@ Fixed an issue where the web interface was slower than expected when logging in
## PAN-268522
Fixed an issue where the firewall failed to connect to the update server with a customized service route when the source interface was set to MGT and the source address was set as IPv4.
Fixed an issue where the firewall failed to connect to the update server with a customized service route when the source interface was set to **MGT** and the source address was set as IPv4.
## PAN-268426
@@ -1376,11 +1376,9 @@ Fixed an issue where importing a device configuration into Panorama failed with
To use this fix:
Enable the configuration. Commit failures may occur if the device is not able to support the number of objects.
Export and push the device group only.
Push the template.
1. Enable the configuration. Commit failures may occur if the device is not able to support the number of objects.
2. Export and push the device group only.
3. Push the template.
Note: This fix is supported on PAN-OS 10.2 and later releases.
@@ -1390,7 +1388,7 @@ Fixed an issue where commits failed with a validation error when you changed the
## PAN-267912
Fixed an issue on the Panorama web interface where Application and Category was not able to be selected under Test Policy Match.
Fixed an issue on the Panorama web interface where **Application** and **Category** was not able to be selected under **Test Policy Match**.
## PAN-267830
@@ -1406,7 +1404,7 @@ Fixed an issue where the Panorama web interface was slower than expected due to
Firewalls in HA configuration only
```
Fixed an issue where the Network pre-negotiation enabled page did not display on the firewall dashboard.
Fixed an issue where the **Network pre-negotiation enabled** page did not display on the firewall dashboard.
## PAN-267381
@@ -1426,7 +1424,7 @@ Fixed an issue where the all_task process stopped responding, which caused the f
VM-Series firewalls only
```
Fixed an issue where BGP route refreshes occurred when a commit was performed if AS Set was enabled for BGP aggregate routes.
Fixed an issue where BGP route refreshes occurred when a commit was performed if **AS Set** was enabled for BGP aggregate routes.
## PAN-267045
@@ -1438,7 +1436,7 @@ Fixed an issue where the firewall generated AAAA DNS queries when IPv6 firewalli
## PAN-266905
Fixed an issue where sessions ended with the message decrypt error in the logs for traffic that matched a no-decrypt policy.
Fixed an issue where sessions ended with the message decrypt error in the logs for traffic that matched a **no-decrypt** policy.
## PAN-266698
@@ -1506,7 +1504,7 @@ Fixed an issue where the routed process core failed the automation run.
## PAN-264040
Fixed an issue where AAAA DNS queries went out even when IPv6 firewalling was disabled.
Fixed an issue where AAAA DNS queries went out even when **IPv6 firewalling** was disabled.
## PAN-263699
@@ -1558,7 +1556,7 @@ Fixed an issue where Voice over WiFi (VoWiFi) stopped working after switching fr
## PAN-261936
Fixed an issue where WildFire submission logs were not displayed when filtered by Sender Address.
Fixed an issue where WildFire submission logs were not displayed when filtered by **Sender Address**.
## PAN-261602
@@ -1566,7 +1564,7 @@ Fixed an issue where GlobalProtect Decryption logs were not forwarded to Panoram
## PAN-260879
Fixed an issue where the Panorama port 28270 did not adhere to the restricted TLS version and ciphers set in the Secure Communication Settings.
Fixed an issue where the Panorama port 28270 did not adhere to the restricted TLS version and ciphers set in the **Secure Communication Settings**.
## PAN-260790
@@ -1582,7 +1580,7 @@ Fixed an issue where daily email reports generated from the custom report did no
## PAN-260581
Fixed an issue where Panorama template changes to the zone and virtual router were not pushed to managed firewalls when the template stack default virtual system was set to None.
Fixed an issue where Panorama template changes to the zone and virtual router were not pushed to managed firewalls when the template stack default virtual system was set to **None**.
## PAN-260540
@@ -1606,7 +1604,7 @@ Fixed an issue where the firewall dropped GRE keepalive packets that were encaps
## PAN-259343
Fixed an issue on the Panorama web interface where the Configuration tab did not accurately display changes made to URL filtering profiles.
Fixed an issue on the Panorama web interface where the **Configuration** tab did not accurately display changes made to URL filtering profiles.
## PAN-259284
@@ -1638,7 +1636,7 @@ Fixed an issue where the firewall dataplane stopped responding, which caused BGP
## PAN-257616
Fixed an issue where selective push operations from Panorama to managed firewalls failed with the error message Failed to generate selective push configuration. Schema validation failed. Please try a full push.
Fixed an issue where selective push operations from Panorama to managed firewalls failed with the error message **Failed to generate selective push configuration. Schema validation failed. Please try a full push**.
## PAN-257362
@@ -1654,11 +1652,11 @@ Fixed an issue where the mp-monitor logs did not print disk SMART data.
## PAN-257074
Fixed an issue on the Panorama web interface where the template sync status showed Out-of-Sync for managed devices after a combined commit-all operation. This occurred due to Panorama sending the default MD5 sum of the template to the firewall instead of the correct MD5 sum.
Fixed an issue on the Panorama web interface where the template sync status showed **Out-of-Sync** for managed devices after a combined commit-all operation. This occurred due to Panorama sending the default MD5 sum of the template to the firewall instead of the correct MD5 sum.
## PAN-256560
Fixed an issue where exporting a Custom Report to CSV format did not display the full report if it contained non-ASCII characters.
Fixed an issue where exporting a **Custom Report** to CSV format did not display the full report if it contained non-ASCII characters.
## PAN-256552
@@ -1746,7 +1744,7 @@ Fixed an issue where the class of service (CoS) priority bit was not modified, c
## PAN-252706
Fixed an issue where the URL filtering response page for Continue and Override did not work with IPv6 Router Advertisement (RA) or Multicast Listener Query (MLQ) for IPv6-to-IPv6 and IPv6-to-IPv4 traffic.
Fixed an issue where the URL filtering response page for **Continue** and **Override** did not work with IPv6 Router Advertisement (RA) or Multicast Listener Query (MLQ) for IPv6-to-IPv6 and IPv6-to-IPv4 traffic.
## PAN-252699
@@ -1786,17 +1784,17 @@ Fixed an issue on the Panorama web interface where you were unable to add static
## PAN-242777
Fixed and issue where users previously reported limitations due to session count caps when utilizing Web Proxy features on PA-5400 Series Firewalls. To address these performance complaints and support higher traffic volumes, we have increased the maximum session capacity on specific PA-5400F series platforms, leveraging available system memory. This update ensures greater capacity and stability for high-volume environments.
Fixed and issue where users previously reported limitations due to session count caps when utilizing **Web Proxy** features on PA-5400 Series Firewalls. To address these performance complaints and support higher traffic volumes, we have increased the maximum session capacity on specific **PA-5400F** series platforms, leveraging available system memory. This update ensures greater capacity and stability for high-volume environments.
The supported session limits are:
| Platform | Max Sessions |
| --- | --- |
| PA-5410 | 95K |
| PA-5420 | 95K |
| PA-5430 | 95K |
| PA-5440 | 225K |
| PA-5445 | 250K |
| -------- | ------------ |
| PA-5410 | 95K |
| PA-5420 | 95K |
| PA-5430 | 95K |
| PA-5440 | 225K |
| PA-5445 | 250K |
## PAN-241953
@@ -1812,7 +1810,7 @@ Fixed an issue where the SNMP get request status value for Panorama connections
## PAN-238208
Fixed an issue where the firewall API returned inconsistent responses to a failed call using a valid API key. With this fix, the firewall returns the error Session is invalid if the session is not available for the cookie.
Fixed an issue where the firewall API returned inconsistent responses to a failed call using a valid API key. With this fix, the firewall returns the error **Session is invalid** if the session is not available for the cookie.
## PAN-234993