diff --git a/reference/PAN-OS/known/11.1.0.html b/reference/PAN-OS/known/11.1.0.html new file mode 100644 index 0000000..2f496b9 --- /dev/null +++ b/reference/PAN-OS/known/11.1.0.html @@ -0,0 +1,1648 @@ +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-304756
+
+ This issue is now resolved. See
+ PAN-OS 11.1.13-h1 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push might
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-298505
+
+ This issue is now resolved. See
+ PAN-OS 11.1.6-h20 Addressed Issues,
+ PAN-OS 11.1.10-h7 Addressed Issues, and
+ PAN-OS 11.1.12 Addressed Issues
+
+ |
+
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual
+ system IDs (vsys ID) changes causing auto-commit failures with
+ validation errors. This occurs when the multi-vsys firewall has
+ virtual systems managed by Panorama, and the vsys ID sequence breaks
+ when unused virtual systems are deleted and the changes are pushed to
+ the firewall.
+
+ |
+
|
+ PAN-294179
+
+ This issue is now resolved. See PAN-OS 11.1.6-h17 Addressed Issues.
+
+ |
+ + On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. + | +
|
+ PAN-291288
+ |
+ + An active firewall might unexpectedly reboot due to a + pan_task crash caused by a page + allocation failure. This issue is observed after a period of runtime + with traffic and telemetry collection. + | +
|
+ PAN-290088
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-289383
+ |
+
+
+ (PA-800 series firewalls only) Upgrading
+ firewalls to PAN-OS 11.0 or later causes SFP ports to go
+ non-operational when the firewall uses forced port mode and the
+ connected peer device operates without auto-negotiation.
+
+
+ Workaround: Enable auto-negotiation on the
+ connected peer firewall.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See
+ PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ Routed process may stop responding after changing MTU or any link
+ parameters when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-286231
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-285894
+ |
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may
+ occur, which could result in firewall reboots.
+
+
+ Workaround: Disable the Preserve Pre-NAT feature
+ using the
+ set deviceconfig setting preserve-prenat-feature no
+ CLI command.
+
+ |
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-281885
+ |
+
+
+ When exporting and importing the CSV file, the hash values of
+ pre-shared key (PSK) variables set at template and template stack
+ levels inconsistently change, resulting in both variables displaying
+ the same hash value.
+
+ |
+
|
+ PAN-280532
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues.
+
+ |
+
+
+ When you use a single syslog server over TCP for log forwarding, and
+ the connectivity to the syslog server breaks, syslog forwarding does
+ not resume even after the connectivity to the server restores.
+
+
+ Workaround: Performing one of the following tasks:
+
+
|
+
|
+ PAN-280471
+ |
+
+
+ When applying filters or searching for logs in the
+
+ section, you might experience slow performance.
+
+ |
+
|
+ PAN-277417
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues.
+
+ |
+
+
+ Memory leak issues can occur during the parsing of server certificates
+ used for SSL Inbound Inspection, preventing the firewall from
+ completing inspection.
+
+ |
+
|
+ PAN-277034
+
+ This issue is now resolved. See PAN-OS 11.1.10-h5 Addressed Issuesand
+ PAN-OS 11.1.6-h19 Addressed Issues
+
+ |
+ + WildFire reports might not fully display or be downloadable because some + static resources fail to load. + | +
|
+ PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues
+
+ |
+
+
+ When Panorama is not internet-connected and you try to upload images
+ to the managed firewalls by using the
+ Validate option, the upload fails
+ with the following error:
+ Failed to create multi-upload job. No valid software deploy targets
+ found.
+
+ |
+
|
+ PAN-273300
+
+ This issue is now resolved. See PAN-OS 11.1.6-h1 Addressed Issues
+
+ |
+
+
+ When upgrading Panorama from PAN-OS 10.2 or PAN-OS 11.0 to PAN-OS 11.1
+ or a later release, Panorama fails to upgrade if it is operating
+ within a Collector Group. The following error appears:Error: Traceback (most recent call last):File
+ "/opt/panrepo/releases/<PANOS release version>/validate"...
+ (min ([dts['min'] for dts in 10g_type_intv_dir.values() if
+ dts|'min']])-strftime ('%Y-%m-%d'),
+
+ |
+
|
+ PAN-262556
+ |
+
+
+ The ElasticSearch cluster health status might continue to remain
+ yellow for an extended period after upgrading to PAN-OS 11.1.0.
+
+ |
+
|
+ PAN-262287
+ |
+
+
+ Dereferencing a NULL pointer that occurs might cause
+ pan_task
+ processes to crash.
+
+ |
+
|
+ PAN-262263
+ |
+
+
+ (PA-1400, PA-3400, and PA-5400 Series firewalls) The links on the firewall's RJ-45 ports may go up and down
+ additional times during a reboot, causing unexpected downtime.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-257615
+
+ This issue is now resolved. See PAN-OS 11.1.2-h9 Addressed Issues.
+
+ |
+
+
+ The Panorama web interface intermittently displays logs or fails to
+ display logs completely.
+
+ |
+
|
+ PAN-259769
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues.
+
+ |
+
+
+ GlobalProtect portal is not accessible via a web browser and the app
+ displays the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-250062
+
+ This issue is now resolved. See PAN-OS 11.1.4-h4 Addressed Issues.
+
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-243951
+
+ This issue is now resolved. See PAN-OS 11.1.2-h3 Addressed Issues
+
+ |
+
+
+ On the Panorama management sever in an active/passive High
+ Availability (HA) configuration, managed devices () display as out-of-sync on the
+ passive HA peer when configuration changes are made to the SD-WAN
+ () configuration on the active HA peer.
+
+
+ Workaround: Manually synchronize the Panorama HA
+ peers.
+
+
|
+
|
+ PAN-242910
+ |
+
+
+ On the Panorama management server, Panorama administrators () that are assigned a custom Panorama admin role () with Push All Changes enabled are
+ unable to push configuration changes to managed firewalls when
+ Managed Devices and
+ Push For Other Admins are disabled.
+
+ |
+
|
+ PAN-242561
+ |
+
+
+ GlobalProtect tunnel might disconnect shortly after being established
+ when SSL is used as a transport protocol.
+
+
+ Workaround: Disable Internet Protocol version 6
+ (TCP/IPv6) on the PANGP Virtual Network Adapter.
+
+ |
+
|
+ PAN-241041
+
+ This issue is now resolved. See PAN-OS 11.1.3 Addressed Issues
+
+ |
+
+
+ On the Panorama management server exporting template or template stack
+ variables () in CSV format results in an empty CSV file.
+
+ |
+
|
+ PAN-237106
+
+ This issue is now resolved. See PAN-OS 11.1.8 Addressed Issues
+
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-234408
+ |
+
+
+ Enterprise DLP cannot detect and block non-file based traffic for
+ ChatGPT from traffic forwarded to the DLP cloud service from an NGFW.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-229081
+ |
+
+
+ (PA-7500 firewalls only) The CLI commands
+ show logging-status and
+ show logging-status verbose yes do
+ not display aggregate log forwarding statistics on the Management
+ Plane.
+
+ |
+
|
+ PAN-228491
+ |
+
+
+ On the AWS environment, the session failover takes up to 4 minutes.
+
+ |
+
|
+ PAN-225337
+ |
+
+
+ On the Panorama management server, the configuration push to a
+ multi-vsys firewall fails if you:
+
+
+ Workaround: Select
+
+ and edit the Panorama Settings to enable one of the following:
+
+
+ Alternatively, you can remove the duplicate address objects from the
+ device group configuration to allow only the
+ Shared objects in your
+ configuration.
+
+ |
+
|
+ PAN-224502
+ |
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0
+ might take longer than expected.
+
+ |
+
|
+ PAN-222805
+ |
+
+
+ (PA-7500 firewall only) The CLI command
+ show running resource-monitor ingress-backlogs
+ does not display the correct usage values.
+
+ |
+
|
+ PAN-220577
+ |
+
+
+ With firewalls in AWS environment that are licensed with VM capacity
+ and secure web proxy licenses, it is observed that the enablement of
+ the web-proxy config fails.
+
+
+ Workaround: Reboot the firewall after the web
+ proxy license is applied.
+
+ |
+
|
+ PAN-220180
+ |
+
+
+ Configured botnet reports () are not generated.
+
+ |
+
|
+ PAN-217307
+
+ This issue is now resolved. See PAN-OS 11.1.3 Addressed Issues.
+
+ |
+
+
+ The following Security policy rule () filters return no results:
+
+
+ log-start eq no
+
+ log-end eq no
+ log-end eq yes
+ |
+
|
+ PAN-208794
+ |
+
+
+ In firewalls with transparent proxy, it is observed that a reboot is
+ necessary to view the transit sessions.
+
+
+ Workaround: Edit the virtual router settings with
+ any minor change and commit again. Any changes to the
+ network/interfaces or network/virtual routers usually fixes this
+ issue.
+
+
+ Alternatively, you may try rebooting the firewall. This issue
+ disappears following reboot after the
+ swg is setup and configured.
+
+ |
+
|
+ PAN-207733
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if
+ the DHCPv6 server goes down, after the lease time expires, the DHCPv6
+ client should enter SOLICIT state on both the Active and Passive
+ firewalls. Instead, the client is stuck in BOUND state with an IPv6
+ address having lease time 0 on the Passive firewall.
+
+ |
+
|
+ PAN-207611
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the
+ Passive firewall sometimes crashes.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-207040
+ |
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade
+ from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
+ commits fail and SD-WAN devices on Panorama have no Virtual Router
+ name.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-194978
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , hovering the mouse over a power over Ethernet (PoE)
+ Link State icon does not display
+ link speed and link duplex details.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-184708
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
|
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-164885
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues
+
+ |
+
+
+ On the Panorama management server, pushes to managed firewalls (
+ or Commit and Push) may fail when an
+ EDL () is configured to
+ Check for updates every 5 minutes
+ due to the commit and EDL fetch processes overlapping. This is more
+ likely to occur when multiple EDLs are configured to check for updates
+ every 5 minutes.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-304756
+
+ This issue is now resolved. See
+ PAN-OS 11.1.13-h1 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push might
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-298505
+
+ This issue is now resolved. See
+ PAN-OS 11.1.6-h20 Addressed Issues,
+ PAN-OS 11.1.10-h7 Addressed Issues, and
+ PAN-OS 11.1.12 Addressed Issues
+
+ |
+
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual
+ system IDs (vsys ID) changes causing auto-commit failures with
+ validation errors. This occurs when the multi-vsys firewall has
+ virtual systems managed by Panorama, and the vsys ID sequence breaks
+ when unused virtual systems are deleted and the changes are pushed to
+ the firewall.
+
+ |
+
|
+ PAN-294179
+ This issue is now resolved. See PAN-OS 11.1.6-h17 Addressed Issues.
+ |
+ + On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. + | +
|
+ PAN-291288
+ |
+ + An active firewall might unexpectedly reboot due to a + pan_task crash caused by a page + allocation failure. This issue is observed after a period of runtime + with traffic and telemetry collection. + | +
|
+ PAN-290088
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-289383
+ |
+
+
+ (PA-800 series firewalls only) Upgrading
+ firewalls to PAN-OS 11.0 or later causes SFP ports to go
+ non-operational when the firewall uses forced port mode and the
+ connected peer device operates without auto-negotiation.
+
+
+ Workaround: Enable auto-negotiation on the
+ connected peer firewall.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See
+ PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ Routed process may stop responding after changing MTU or any link
+ parameters when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-286231
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-285894
+ |
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may
+ occur, which could result in firewall reboots.
+
+
+ Workaround: Disable the Preserve Pre-NAT feature
+ using the
+ set deviceconfig setting preserve-prenat-feature no
+ CLI command.
+
+ |
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-281885
+ |
+
+
+ When exporting and importing the CSV file, the hash values of
+ pre-shared key (PSK) variables set at template and template stack
+ levels inconsistently change, resulting in both variables displaying
+ the same hash value.
+
+ |
+
|
+ PAN-280532
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues.
+
+ |
+
+
+ When you use a single syslog server over TCP for log forwarding, and
+ the connectivity to the syslog server breaks, syslog forwarding does
+ not resume even after the connectivity to the server restores.
+
+
+ Workaround: Performing one of the following tasks:
+
+
|
+
|
+ PAN-280471
+ |
+
+
+ When applying filters or searching for logs in the
+ section, you might experience slow performance.
+
+ |
+
|
+ PAN-279415
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ Service routes configured for a data plane interface might incorrectly
+ route traffic through the management plane interface instead. This
+ issue impacts Syslog and CRL status traffic when the service route
+ lacks a specific destination custom service route.
+
+ |
+
|
+ PAN-278296
+ |
+
+
+ The system MAC address of the aggregate interface is the same on both
+ the active and the passive devices, causing some packets to be sent
+ incorrectly to the passive device. This is causing the AE interface on
+ the active firewall to not come up.
+
+ |
+
|
+ PAN-277417
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues.
+
+ |
+
+
+ Memory leak issues can occur during the parsing of server certificates
+ used for SSL Inbound Inspection, preventing the firewall from
+ completing inspection.
+
+ |
+
|
+ PAN-277034
+
+ This issue is now resolved. See PAN-OS 11.1.10-h5 Addressed Issuesand
+ PAN-OS 11.1.6-h19 Addressed Issues
+
+ |
+ + WildFire reports might not fully display or be downloadable because some + static resources fail to load. + | +
|
+ PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues
+
+ |
+
+
+ When Panorama is not internet-connected and you try to upload images
+ to the managed firewalls by using the
+ Validate option, the upload fails
+ with the following error:
+ Failed to create multi-upload job. No valid software deploy targets
+ found.
+
+ |
+
|
+ PAN-273300
+
+ This issue is now resolved. See PAN-OS 11.1.6-h1 Addressed Issues
+
+ |
+
+
+ When upgrading Panorama from PAN-OS 10.2 or PAN-OS 11.0 to PAN-OS 11.1
+ or a later release, Panorama fails to upgrade if it is operating
+ within a Collector Group. The following error appears:Error: Traceback (most recent call last):File
+ "/opt/panrepo/releases/<PANOS release version>/validate"...
+ (min ([dts['min'] for dts in 10g_type_intv_dir.values() if
+ dts|'min']])-strftime ('%Y-%m-%d'),
+
+ |
+
|
+ PAN-263987
+
+ This issue is now resolved. See PAN-OS 11.1.4-h4 Addressed Issues.
+
+ |
+
+
+ When a NAT traversal (NAT-T or UDP encapsulation) IPSec tunnel is
+ terminated on a Palo Alto Networks firewall and the NAT rule applied
+ to the NAT-T IPSec tunnel is also on the same firewall, then the data
+ traffic flowing through the NAT-T IPSec tunnel can't be NATed
+ correctly.
+
+ |
+
|
+ PAN-262556
+ |
+
+
+ The ElasticSearch cluster health status might continue to remain
+ yellow for an extended period after upgrading to PAN-OS 11.1.1.
+
+ |
+
|
+ PAN-262287
+ |
+
+
+ Dereferencing a NULL pointer that occurs might cause
+ pan_task
+ processes to crash.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-259769
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues.
+
+ |
+
+
+ GlobalProtect portal is not accessible via a web browser and the app
+ displays the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-257615
+
+ This issue is now resolved. See PAN-OS 11.1.2-h9 Addressed Issues.
+
+ |
+
+
+ The Panorama web interface intermittently displays logs or fails to
+ display logs completely.
+
+ |
+
|
+ PAN-250062
+
+ This issue is now resolved. See PAN-OS 11.1.4-h4 Addressed Issues.
+
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-243951
+
+ This issue is now resolved. See PAN-OS 11.1.2-h3 Addressed Issues
+
+ |
+
+
+ On the Panorama management sever in an active/passive High
+ Availability (HA) configuration, managed devices () display as out-of-sync on the
+ passive HA peer when configuration changes are made to the SD-WAN
+ () configuration on the active HA peer.
+
+
+ Workaround: Manually synchronize the Panorama HA
+ peers.
+
+
|
+
|
+ PAN-242910
+ |
+
+
+ On the Panorama management server, Panorama administrators () that are assigned a custom Panorama admin role () with Push All Changes enabled are
+ unable to push configuration changes to managed firewalls when
+ Managed Devices and
+ Push For Other Admins are disabled.
+
+ |
+
|
+ PAN-242837
+ |
+
+
+ Default login credentials and SSH fail after enabling FIPS-CC Mode on
+ a firewall or Panorama after converting through the Maintenance
+ Recovery Tool (MRT). The firewall or Panorama becomes stuck and
+ requires a factory reset to recover.
+
+ |
+
|
+ PAN-242561
+ |
+
+
+ GlobalProtect tunnel might disconnect shortly after being established
+ when SSL is used as a transport protocol.
+
+
+ Workaround: Disable Internet Protocol version 6
+ (TCP/IPv6) on the PANGP Virtual Network Adapter.
+
+ |
+
|
+ PAN-237106
+
+ This issue is now resolved. See PAN-OS 11.1.8 Addressed Issues
+
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-238769
+ |
+
+
+ FIPS-CC VM only. Upgrading to 10.1.10-h2 or 10.1.11 will change all
+ locally created security Policy actions to Deny. Re-load the back-up
+ config taken before upgrading or the last version to get the previous
+ config back. Also, Unable to login to FIPSCC Mode devices with default
+ credentials after converting the mode for 10.1.12 release , 10.2.7
+ release , 11.1.0 , 11.1.1, 11.0.3 versions.
+
+ |
+
|
+ PAN-241041
+
+ This issue is now resolved. See PAN-OS 11.1.3 Addressed Issues
+
+ |
+
+
+ On the Panorama management server exporting template or template stack
+ variables () in CSV format results in an empty CSV file.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-225337
+
+ This issue is now resolved. See PAN-OS 11.1.2 Addressed Issues
+
+ |
+
+
+ On the Panorama management server, the configuration push to a
+ multi-vsys firewall fails if you:
+
+
+ Workaround: Select
+
+ and edit the Panorama Settings to enable one of the following:
+
+
+ Alternatively, you can remove the duplicate address objects from the
+ device group configuration to allow only the
+ Shared objects in your
+ configuration.
+
+ |
+
|
+ PAN-224502
+ |
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0
+ might take longer than expected.
+
+ |
+
|
+ PAN-220180
+ |
+
+
+ Configured botnet reports () are not generated.
+
+ |
+
|
+ PAN-217307
+
+ This issue is now resolved. See PAN-OS 11.1.3 Addressed Issues.
+
+ |
+
+
+ The following Security policy rule () filters return no results:
+
+
+ log-start eq no
+
+ log-end eq no
+ log-end eq yes
+ |
+
|
+ PAN-207733
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if
+ the DHCPv6 server goes down, after the lease time expires, the DHCPv6
+ client should enter SOLICIT state on both the Active and Passive
+ firewalls. Instead, the client is stuck in BOUND state with an IPv6
+ address having lease time 0 on the Passive firewall.
+
+ |
+
|
+ PAN-207611
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the
+ Passive firewall sometimes crashes.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-207040
+ |
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade
+ from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
+ commits fail and SD-WAN devices on Panorama have no Virtual Router
+ name.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-194978
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , hovering the mouse over a power over Ethernet (PoE)
+ Link State icon does not display
+ link speed and link duplex details.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-184708
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
|
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-164885
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues
+
+ |
+
+
+ On the Panorama management server, pushes to managed firewalls (
+ or Commit and Push) may fail when an
+ EDL () is configured to
+ Check for updates every 5 minutes
+ due to the commit and EDL fetch processes overlapping. This is more
+ likely to occur when multiple EDLs are configured to check for updates
+ every 5 minutes.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-308564
+ |
+
+
+ Packets are dropped on SD-WAN interfaces if they require fragmentation
+ for an interface but have the
+ Don't Fragment (DF) bit set. This
+ results in unexpected packet drops. This affects client to server
+ sessions when using SD-WAN for NGFW.
+
+
+ Workaround: Allow fragmenting packets with DF bit
+ set (debug dataplane set ip4-ignore-df yes).
+
+ |
+
|
+
+ PAN-307795 This issue affects PAN-OS 11.1.10-h7 through 11.1.10-h11.
+
+
+ This issue is now resolved. See
+ PAN-OS 11.1.10-h12 Addressed Issues.
+
+ |
+
+
+ On a standalone Panorama, the system incorrectly generates system logs
+ indicating a lost connection to its peer even when High Availability
+ is not configured. You can safely ignore these logs, as they do not
+ affect operations.
+
+ |
+
|
+ PAN-306502
+
+ This issue is now resolved. See
+ PAN-OS 11.1.10-h10 Addressed Issues.
+
+ |
+
+
+ TLS sessions using version 1.2 or earlier may fail when session
+ traffic matches a decryption policy rule with the no-decrypt action
+ under either of the following conditions:
+
+
+
+
+
+
+
+ If both of these conditions are met, the session is guaranteed to
+ fail.
+
+
+ Workaround: Perform one of the following tasks:
+
+
|
+
|
+ PAN-305301
+
+ This issue is now resolved. See
+ PAN-OS 11.1.10-h12 Addressed Issues.
+
+ |
+
+
+ The timing of GlobalProtect lifetime expiry or inactivity logout
+ notifications used for GlobalProtect SSL tunnels may cause the
+ pan_task
+ process to stop responding and the dataplane to restart.
+
+
+ Workaround: Select
+ Network > GlobalProtect > Gateways > <gateway-config> > Agent > <agent-config> > Connection Settings
+ and change the value of both
+ Notify Before Lifetime Expires (min)
+ and
+ Notify Before Inactivity Logout (min)
+ to 0.
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See
+ PAN-OS 11.1.13-h1 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push might
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-304576
+ |
+
+
+ Traffic interruption may occur when inspection of HTTP/2 traffic is
+ enabled.
+
+
+ Workaround: Disable HTTP/2 server push using the
+ set deviceconfig setting http2 server-push no
+ CLI command.
+
+ |
+
|
+ PAN-303959
+ |
+
+
+ Traffic that is incorrectly identified as unknown-tcp/unknown-udp
+ eventually drops due to an App-ID resource limitation issue.
+
+ |
+
|
+ PAN-303051
+ This issue is now resolved. See
+ PAN-OS 11.1.13 Addressed Issues
+ |
+
+
+ The reportd process experiences a
+ memory leak because it retains memory that was temporarily used for
+ report generation. Once a task is complete, the process fails to
+ release this memory for reuse, leading to continuous accumulation and
+ eventual memory exhaustion on the Panorama device.
+
+ |
+
|
+ PAN-298505
+
+ This issue is now resolved. See PAN-OS 11.1.10-h7 Addressed Issuesand
+ PAN-OS 11.1.12 Addressed Issues
+
+ |
+
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual
+ system IDs (vsys ID) changes causing auto-commit failures with
+ validation errors. This occurs when the multi-vsys firewall has
+ virtual systems managed by Panorama, and the vsys ID sequence breaks
+ when unused virtual systems are deleted and the changes are pushed to
+ the firewall.
+
+ |
+
|
+ PAN-297295
+
+ This issue is now resolved. See PAN-OS 11.1.13 Addressed Issues
+
+ |
+
+ (VM-Series firewalls on Microsoft Azure environments only)
+
+ After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent process restarts multiple
+ times and exhausts its restart limit, resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-296977
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ When you apply a filter in
+ Network > Interfaces and then try
+ to view Ethernet interface details
+ using the web interface, the web interface becomes unresponsive.
+
+ |
+
|
+ PAN-294179
+
+ This issue is now resolved. See PAN-OS 11.1.10-h4 Addressed Issues.
+
+ |
+ + On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. + | +
|
+ PAN-293673
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+ + When the firewall generates a high volume of logs and attempts to export + these logs to an FTP server, it may consume excessive memory leading to + all PAN-OS processes crashing. + | +
|
+ PAN-292202
+ |
+
+
+ The system logs repeatedly displayed the alert `Clearing snmpd.log due
+ to log overflow` due to the SNMP counters rolling over. This is a
+ benign message and does not impact device functionality.
+
+ |
+
|
+ PAN-289432
+ |
+
+
+ Generating a certificate with the
+ block-private-key yes command on
+ Panorama fails with the error:
+
+
+ Could not get parameters for double encryption.
+ This occurred when the certificate was signed by an external
+ Certificate Authority (CA).
+
+ |
+
|
+ PAN-290996
+
+ This issue is now resolved. See PAN-OS 11.1.10-h1 Addressed Issues
+ and
+ PAN-OS 11.1.11 Addressed Issues.
+
+ |
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS)
+ counters incorrectly return a value of 0 for each virtual system
+ (VSYS), despite the firewall actively processing connections.
+
+ |
+
|
+ PAN-290235
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues.
+
+ |
+
+
+ The
+ dscd
+ process crashes continuously on MIPS platforms (for example, PA-850
+ firewalls) due to a runtime error related to an invalid memory address
+ or nil pointer dereference. This occurs when the golang library
+ upgrade in CIE is not compatible with the MIPS platform.
+
+ |
+
|
+ PAN-290088
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-289383
+ |
+
+
+ (PA-800 series firewalls only) Upgrading
+ firewalls to PAN-OS 11.0 or later causes SFP ports to go
+ non-operational when the firewall uses forced port mode and the
+ connected peer device operates without auto-negotiation.
+
+
+ Workaround: Enable auto-negotiation on the
+ connected peer firewall.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See
+ PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ Routed process may stop responding after changing MTU or any link
+ parameters when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-287056
+
+ This issue is now resolved. See PAN-OS 11.1.10-h1 Addressed Issues
+ and
+ PAN-OS 11.1.11 Addressed Issues.
+
+ |
+
+
+ A BGP export policy rule that matches on a next hop fails to block the
+ advertisement of static routes, and the firewall incorrectly matches
+ the egress interface IP address instead of the original next-hop IP
+ address of the static route, which causes the deny rule to fail.
+
+ |
+
|
+ PAN-286848
+ |
+
+
+ ECMP incorrectly balances sessions across links based on the
+ configured metric, which leads to an imbalance in traffic distribution
+ and results in traffic assignment shifting disproportionately to
+ routes with lower metrics.
+
+ |
+
|
+ PAN-286496
+ |
+
+
+ (NGFW Clusters) URL-continue and override
+ continue selections will function like a general URL-block action.
+
+ |
+
|
+ PAN-286306
+
+ This issue is now resolved. See PAN-OS 11.1.10-h1 Addressed Issues
+ and
+ PAN-OS 11.1.11 Addressed Issues.
+
+ |
+
+
+ When getting transceiver information from ESCC for SFP 25G modules,
+ the transceiver code incorrectly displays
+ Unknown instead of
+ 25GBase-SR.
+
+ |
+
|
+ PAN-286231
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-285894
+ |
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may
+ occur, which could result in firewall reboots.
+
+
+ Workaround: Disable the Preserve Pre-NAT feature
+ using the
+ set deviceconfig setting preserve-prenat-feature no
+ CLI command.
+
+ |
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-282854
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ The Elasticsearch cluster fails to start after deploying dedicated log
+ collectors in a multi-collector environment.
+
+ Workaround: Restart all the involved log collectors.
+ |
+
|
+ PAN-279901
+ |
+
+
+ When decryption is enabled, segmented Client Hello packets can cause
+ website access issues and memory leaks under the following conditions:
+
+
+ To enable this fix, run the CLI command
+ bug dataplane set ssl-decrypt accumulate-client-hello disjoined
+ yes
+
+ |
+
|
+ PAN-279415
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ Service routes configured for a data plane interface might incorrectly
+ route traffic through the management plane interface instead. This
+ issue impacts Syslog and CRL status traffic when the service route
+ lacks a specific destination custom service route.
+
+ |
+
|
+ PAN-277034
+
+ This issue is now resolved. See PAN-OS 11.1.10-h5 Addressed Issues
+
+ |
+ + WildFire reports might not fully display or be downloadable because some + static resources fail to load. + | +
|
+ PAN-276920
+ |
+
+
+ URL filtering response pages may load slowly or fail to display when
+ users request websites that are blocked in the URL Filtering profile
+ (site access for the corresponding URL category is
+ block,
+ continue, or
+ override) attached to the matching
+ Security policy rule. This occurs on an intermittent basis.
+
+ |
+
|
+ PAN-275047
+ |
+
+
+ (VM-Series firewalls only) After an upgrade,
+ the firewall is unable to send logs to the Strata Logging Service
+ (SLS) when using a specific proxy server, and the SSL connection
+ status displays as failed when attempting to forward logs through the
+ web proxy.
+
+ |
+
|
+ PAN-262556
+ |
+
+
+ The ElasticSearch cluster health status might continue to remain
+ yellow for an extended period after upgrading to PAN-OS 11.1
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-254240
+ |
+
+
+ In the event of an HSCI flap on an NGFW cluster node, traffic
+ reconvergence takes three to four seconds.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
|
+ PAN-251551
+ |
+
+
+ When an NGFW cluster agent crashes and doesn't recover, leader
+ election will take approximately 45 seconds to begin and traffic
+ failover will occur during that time.
+
+ |
+
|
+ PAN-250903
+ |
+
+
+ In a congestion scenario on an HSCI port of an NGFW cluster node, the
+ QoS priorities of cross node traffic streams might be reversed if
+ you're using the default QoS profile with class1 to class8 set as high
+ to low.
+
+ |
+
|
+ PAN-247974
+ |
+
+
+ LACP flap is expected during a device failover in an NGFW cluster due
+ to an L2 ctrld restart on the new leader node.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-224502
+ |
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0
+ might take longer than expected.
+
+ |
+
|
+ PAN-220180
+ |
+
+
+ Configured botnet reports () are not generated.
+
+ |
+
|
+ PAN-207733
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if
+ the DHCPv6 server goes down, after the lease time expires, the DHCPv6
+ client should enter SOLICIT state on both the Active and Passive
+ firewalls. Instead, the client is stuck in BOUND state with an IPv6
+ address having lease time 0 on the Passive firewall.
+
+ |
+
|
+ PAN-207611
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the
+ Passive firewall sometimes crashes.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-207040
+ |
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade
+ from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
+ commits fail and SD-WAN devices on Panorama have no Virtual Router
+ name.
+
+ |
+
|
+ PAN-206913
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls,
+ releasing the IPv6 address from the client (using Release in the UI or
+ using the
+ request dhcp client ipv6 release all
+ CLI command) releases the IPv6 address from the Active firewall, but
+ not the Passive firewall.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-194978
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , hovering the mouse over a power over Ethernet (PoE)
+ Link State icon does not display
+ link speed and link duplex details.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-184708
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
|
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-308564
+ |
+
+
+ Packets are dropped on SD-WAN interfaces if they require fragmentation
+ for an interface but have the
+ Don't Fragment (DF) bit set. This
+ results in unexpected packet drops. This affects client to server
+ sessions when using SD-WAN for NGFW.
+
+
+ Workaround: Allow fragmenting packets with DF bit
+ set (debug dataplane set ip4-ignore-df yes).
+
+ |
+
|
+ PAN-307795
+
+ This issue is now resolved. See
+ PAN-OS 11.1.13-h1 Addressed Issues.
+
+ |
+
+
+ On a standalone Panorama, the system incorrectly generates system logs
+ indicating a lost connection to its peer even when High Availability
+ is not configured. You can safely ignore these logs, as they do not
+ affect operations.
+
+ |
+
|
+ PAN-306502
+
+ This issue is now resolved. See
+ PAN-OS 11.1.13 Addressed Issues.
+
+ |
+
+
+ TLS sessions using version 1.2 or earlier may fail when session
+ traffic matches a decryption policy rule with the no-decrypt action
+ under either of the following conditions:
+
+
+
+
+
+
+
+ If both of these conditions are met, the session is guaranteed to
+ fail.
+
+
+ Workaround: Perform one of the following tasks:
+
+
|
+
|
+ PAN-305301
+
+ This issue is now resolved. See
+ PAN-OS 11.1.13-h1 Addressed Issues.
+
+ |
+
+
+ The timing of GlobalProtect lifetime expiry or inactivity logout
+ notifications used for GlobalProtect SSL tunnels may cause the
+ pan_task
+ process to stop responding and the dataplane to restart.
+
+
+ Workaround: Select
+ Network > GlobalProtect > Gateways > <gateway-config> > Agent > <agent-config> > Connection Settings
+ and change the value of both
+ Notify Before Lifetime Expires (min)
+ and
+ Notify Before Inactivity Logout (min)
+ to 0.
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See
+ PAN-OS 11.1.13-h1 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push might
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-304576
+ |
+
+
+ Traffic interruption may occur when inspection of HTTP/2 traffic is
+ enabled.
+
+
+ Workaround: Disable HTTP/2 server push using the
+ set deviceconfig setting http2 server-push no
+ CLI command.
+
+ |
+
|
+ PAN-303959
+ |
+
+
+ Traffic that is incorrectly identified as unknown-tcp/unknown-udp
+ eventually drops due to an App-ID resource limitation issue.
+
+ |
+
|
+ PAN-303051
+
+ This issue is now resolved. See
+ PAN-OS 11.1.13 Addressed Issues.
+
+ |
+
+
+ The reportd process experiences a
+ memory leak because it retains memory that was temporarily used for
+ report generation. Once a task is complete, the process fails to
+ release this memory for reuse, leading to continuous accumulation and
+ eventual memory exhaustion on the Panorama device.
+
+ |
+
|
+ PAN-298505
+
+ This issue is now resolved. See
+ PAN-OS 11.1.12 Addressed Issues
+
+ |
+
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual
+ system IDs (vsys ID) changes causing auto-commit failures with
+ validation errors. This occurs when the multi-vsys firewall has
+ virtual systems managed by Panorama, and the vsys ID sequence breaks
+ when unused virtual systems are deleted and the changes are pushed to
+ the firewall.
+
+ |
+
|
+ PAN-297295
+
+ This issue is now resolved. See PAN-OS 11.1.13 Addressed Issues
+
+ |
+
+ (VM-Series firewalls on Microsoft Azure environments only)
+
+ After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent process restarts multiple
+ times and exhausts its restart limit, resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-292202
+ |
+
+
+ The system logs repeatedly displayed the alert
+ Clearing snmpd.log due to log overflow
+ due to the SNMP counters rolling over. This is a benign message and
+ does not impact device functionality.
+
+ |
+
|
+ PAN-289432
+ |
+
+
+ Generating a certificate with the
+ block-private-key yes command on
+ Panorama fails with the error:
+
+
+ Could not get parameters for double encryption.
+ This occurred when the certificate was signed by an external
+ Certificate Authority (CA).
+
+ |
+
|
+ PAN-289383
+ |
+
+
+ (PA-800 series firewalls only) Upgrading
+ firewalls to PAN-OS 11.0 or later causes SFP ports to go
+ non-operational when the firewall uses forced port mode and the
+ connected peer device operates without auto-negotiation.
+
+
+ Workaround: Enable auto-negotiation on the
+ connected peer firewall.
+
+ |
+
|
+ PAN-286848
+ |
+
+
+ ECMP incorrectly balances sessions across links based on the
+ configured metric, which leads to an imbalance in traffic distribution
+ and results in traffic assignment shifting disproportionately to
+ routes with lower metrics.
+
+ |
+
|
+ PAN-286496
+ |
+
+
+ (NGFW Clusters) URL-continue and override
+ continue selections will function like a general URL-block action.
+
+ |
+
|
+ PAN-285894
+ |
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may
+ occur, which could result in firewall reboots.
+
+
+ Workaround: Disable the Preserve Pre-NAT feature
+ using the
+ set deviceconfig setting preserve-prenat-feature no
+ CLI command.
+
+ |
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-276920
+ |
+
+
+ URL filtering response pages may load slowly or fail to display when
+ users request websites that are blocked in the URL Filtering profile
+ (site access for the corresponding URL category is
+ block,
+ continue, or
+ override) attached to the matching
+ Security policy rule. This occurs on an intermittent basis.
+
+ |
+
|
+ PAN-275047
+ |
+
+
+ (VM-Series firewalls only) After an upgrade,
+ the firewall is unable to send logs to the Strata Logging Service
+ (SLS) when using a specific proxy server, and the SSL connection
+ status displays as failed when attempting to forward logs through the
+ web proxy.
+
+ |
+
|
+ PAN-262556
+ |
+
+
+ The ElasticSearch cluster health status might continue to remain
+ yellow for an extended period after upgrading to PAN-OS 11.1
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-254240
+ |
+
+
+ In the event of an HSCI flap on an NGFW cluster node, traffic
+ reconvergence takes three to four seconds.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
|
+ PAN-251551
+ |
+
+
+ When an NGFW cluster agent crashes and doesn't recover, leader
+ election will take approximately 45 seconds to begin and traffic
+ failover will occur during that time.
+
+ |
+
|
+ PAN-250903
+ |
+
+
+ In a congestion scenario on an HSCI port of an NGFW cluster node, the
+ QoS priorities of cross node traffic streams might be reversed if
+ you're using the default QoS profile with class1 to class8 set as high
+ to low.
+
+ |
+
|
+ PAN-247974
+ |
+
+
+ LACP flap is expected during a device failover in an NGFW cluster due
+ to an L2 ctrld restart on the new leader node.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-224502
+ |
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0
+ might take longer than expected.
+
+ |
+
|
+ PAN-220180
+ |
+
+
+ Configured botnet reports () are not generated.
+
+ |
+
|
+ PAN-207733
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if
+ the DHCPv6 server goes down, after the lease time expires, the DHCPv6
+ client should enter SOLICIT state on both the Active and Passive
+ firewalls. Instead, the client is stuck in BOUND state with an IPv6
+ address having lease time 0 on the Passive firewall.
+
+ |
+
|
+ PAN-207611
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the
+ Passive firewall sometimes crashes.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-207040
+ |
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade
+ from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
+ commits fail and SD-WAN devices on Panorama have no Virtual Router
+ name.
+
+ |
+
|
+ PAN-206913
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls,
+ releasing the IPv6 address from the client (using Release in the UI or
+ using the
+ request dhcp client ipv6 release all
+ CLI command) releases the IPv6 address from the Active firewall, but
+ not the Passive firewall.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-194978
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , hovering the mouse over a power over Ethernet (PoE)
+ Link State icon does not display
+ link speed and link duplex details.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-184708
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
|
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-308564
+ |
+
+
+ Packets are dropped on SD-WAN interfaces if they require fragmentation
+ for an interface but have the
+ Don't Fragment (DF) bit set. This
+ results in unexpected packet drops. This affects client to server
+ sessions when using SD-WAN for NGFW.
+
+
+ Workaround: Allow fragmenting packets with DF bit
+ set (debug dataplane set ip4-ignore-df yes).
+
+ |
+
|
+ PAN-307795
+
+ This issue is now resolved. See
+ PAN-OS 11.1.13-h1 Addressed Issues.
+
+ |
+
+
+ On a standalone Panorama, the system incorrectly generates system logs
+ indicating a lost connection to its peer even when High Availability
+ is not configured. You can safely ignore these logs, as they do not
+ affect operations.
+
+ |
+
|
+ PAN-306502
+
+ This issue is now resolved. See
+ PAN-OS 11.1.13 Addressed Issues.
+
+ |
+
+
+ TLS sessions using version 1.2 or earlier may fail when session
+ traffic matches a decryption policy rule with the no-decrypt action
+ under either of the following conditions:
+
+
+
+
+
+
+
+ If both of these conditions are met, the session is guaranteed to
+ fail.
+
+
+ Workaround: Perform one of the following tasks:
+
+
|
+
|
+ PAN-305301
+
+ This issue is now resolved. See
+ PAN-OS 11.1.13-h1 Addressed Issues.
+
+ |
+
+
+ The timing of GlobalProtect lifetime expiry or inactivity logout
+ notifications used for GlobalProtect SSL tunnels may cause the
+ pan_task
+ process to stop responding and the dataplane to restart.
+
+
+ Workaround: Select
+ Network > GlobalProtect > Gateways > <gateway-config> > Agent > <agent-config> > Connection Settings
+ and change the value of both
+ Notify Before Lifetime Expires (min)
+ and
+ Notify Before Inactivity Logout (min)
+ to 0.
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See
+ PAN-OS 11.1.13-h1 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push might
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-304576
+ |
+
+
+ Traffic interruption may occur when inspection of HTTP/2 traffic is
+ enabled.
+
+
+ Workaround: Disable HTTP/2 server push using the
+ set deviceconfig setting http2 server-push no
+ CLI command.
+
+ |
+
|
+ PAN-303959
+ |
+
+
+ Traffic that is incorrectly identified as unknown-tcp/unknown-udp
+ eventually drops due to an App-ID resource limitation issue.
+
+ |
+
|
+ PAN-303051
+ This issue is now resolved. See
+ PAN-OS 11.1.13 Addressed Issues
+ |
+
+
+ The reportd process experiences a
+ memory leak because it retains memory that was temporarily used for
+ report generation. Once a task is complete, the process fails to
+ release this memory for reuse, leading to continuous accumulation and
+ eventual memory exhaustion on the Panorama device.
+
+ |
+
|
+ PAN-297295
+
+ This issue is now resolved. See PAN-OS 11.1.13 Addressed Issues
+
+ |
+
+ (VM-Series firewalls on Microsoft Azure environments only)
+
+ After upgrading to an affected release, the firewall restarts
+ continuously because the
+ brdagent process restarts multiple
+ times and exhausts its restart limit, resulting in a segfault error.
+ This issue occurs when a high burst of traffic is sent to the Azure
+ PA-VM (Palo Alto Networks Virtual Machine), and impacts production
+ environments due to the regular reboots.
+
+
+ Workaround: Migrate the VM instance to Dv5
+ instance type. On these instance types, SYN packets are not routed to
+ the synthetic path, avoiding this condition. Suggested direct resizing
+ paths are:
+
+
+
+
+
+
+
+ Azure VMs with ephemeral storage can only be resized to another
+ type with ephemeral storage.
+
+ |
+
|
+ PAN-292202
+ |
+
+
+ The system logs repeatedly displayed the alert
+ Clearing snmpd.log due to log overflow
+ due to the SNMP counters rolling over. This is a benign message and
+ does not impact device functionality.
+
+ |
+
|
+ PAN-289432
+ |
+
+
+ Generating a certificate with the
+ block-private-key yes command on
+ Panorama fails with the error:
+
+
+ Could not get parameters for double encryption.
+ This occurred when the certificate was signed by an external
+ Certificate Authority (CA).
+
+ |
+
|
+ PAN-289383
+ |
+
+
+ (PA-800 series firewalls only) Upgrading
+ firewalls to PAN-OS 11.0 or later causes SFP ports to go
+ non-operational when the firewall uses forced port mode and the
+ connected peer device operates without auto-negotiation.
+
+
+ Workaround: Enable auto-negotiation on the
+ connected peer firewall.
+
+ |
+
|
+ PAN-286848
+ |
+
+
+ ECMP incorrectly balances sessions across links based on the
+ configured metric, which leads to an imbalance in traffic distribution
+ and results in traffic assignment shifting disproportionately to
+ routes with lower metrics.
+
+ |
+
|
+ PAN-286496
+ |
+
+
+ (NGFW Clusters) URL-continue and override
+ continue selections will function like a general URL-block action.
+
+ |
+
|
+ PAN-285894
+ |
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may
+ occur, which could result in firewall reboots.
+
+
+ Workaround: Disable the Preserve Pre-NAT feature
+ using the
+ set deviceconfig setting preserve-prenat-feature no
+ CLI command.
+
+ |
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-279415
+ |
+
+
+ Service routes configured for a data plane interface might incorrectly
+ route traffic through the management plane interface instead. This
+ issue impacts Syslog and CRL status traffic when the service route
+ lacks a specific destination custom service route.
+
+ |
+
|
+ PAN-276920
+ |
+
+
+ URL filtering response pages may load slowly or fail to display when
+ users request websites that are blocked in the URL Filtering profile
+ (site access for the corresponding URL category is
+ block,
+ continue, or
+ override) attached to the matching
+ Security policy rule. This occurs on an intermittent basis.
+
+ |
+
|
+ PAN-275047
+ |
+
+
+ (VM-Series firewalls only) After an upgrade,
+ the firewall is unable to send logs to the Strata Logging Service
+ (SLS) when using a specific proxy server, and the SSL connection
+ status displays as failed when attempting to forward logs through the
+ web proxy.
+
+ |
+
|
+ PAN-262556
+ |
+
+
+ The ElasticSearch cluster health status might continue to remain
+ yellow for an extended period after upgrading to PAN-OS 11.1
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-254240
+ |
+
+
+ In the event of an HSCI flap on an NGFW cluster node, traffic
+ reconvergence takes three to four seconds.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
|
+ PAN-251551
+ |
+
+
+ When an NGFW cluster agent crashes and doesn't recover, leader
+ election will take approximately 45 seconds to begin and traffic
+ failover will occur during that time.
+
+ |
+
|
+ PAN-250903
+ |
+
+
+ In a congestion scenario on an HSCI port of an NGFW cluster node, the
+ QoS priorities of cross node traffic streams might be reversed if
+ you're using the default QoS profile with class1 to class8 set as high
+ to low.
+
+ |
+
|
+ PAN-247974
+ |
+
+
+ LACP flap is expected during a device failover in an NGFW cluster due
+ to an L2 ctrld restart on the new leader node.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-224502
+ |
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0
+ might take longer than expected.
+
+ |
+
|
+ PAN-220180
+ |
+
+
+ Configured botnet reports () are not generated.
+
+ |
+
|
+ PAN-207733
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if
+ the DHCPv6 server goes down, after the lease time expires, the DHCPv6
+ client should enter SOLICIT state on both the Active and Passive
+ firewalls. Instead, the client is stuck in BOUND state with an IPv6
+ address having lease time 0 on the Passive firewall.
+
+ |
+
|
+ PAN-207611
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the
+ Passive firewall sometimes crashes.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-207040
+ |
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade
+ from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
+ commits fail and SD-WAN devices on Panorama have no Virtual Router
+ name.
+
+ |
+
|
+ PAN-206913
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls,
+ releasing the IPv6 address from the client (using Release in the UI or
+ using the
+ request dhcp client ipv6 release all
+ CLI command) releases the IPv6 address from the Active firewall, but
+ not the Passive firewall.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-194978
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , hovering the mouse over a power over Ethernet (PoE)
+ Link State icon does not display
+ link speed and link duplex details.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-184708
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
|
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-308564
+ |
+
+
+ Packets are dropped on SD-WAN interfaces if they require fragmentation
+ for an interface but have the
+ Don't Fragment (DF) bit set. This
+ results in unexpected packet drops. This affects client to server
+ sessions when using SD-WAN for NGFW.
+
+
+ Workaround: Allow fragmenting packets with DF bit
+ set (debug dataplane set ip4-ignore-df yes).
+
+ |
+
|
+ PAN-307795
+
+ This issue is now resolved. See
+ PAN-OS 11.1.13-h1 Addressed Issues.
+
+ |
+
+
+ On a standalone Panorama, the system incorrectly generates system logs
+ indicating a lost connection to its peer even when High Availability
+ is not configured. You can safely ignore these logs, as they do not
+ affect operations.
+
+ |
+
|
+ PAN-305301
+
+ This issue is now resolved. See
+ PAN-OS 11.1.13-h1 Addressed Issues.
+
+ |
+
+
+ The timing of GlobalProtect lifetime expiry or inactivity logout
+ notifications used for GlobalProtect SSL tunnels may cause the
+ pan_task
+ process to stop responding and the dataplane to restart.
+
+
+ Workaround: Select
+ Network > GlobalProtect > Gateways > <gateway-config> > Agent > <agent-config> > Connection Settings
+ and change the value of both
+ Notify Before Lifetime Expires (min)
+ and
+ Notify Before Inactivity Logout (min)
+ to 0.
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See
+ PAN-OS 11.1.13-h1 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push might
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-304576
+ |
+
+
+ Traffic interruption may occur when inspection of HTTP/2 traffic is
+ enabled.
+
+
+ Workaround: Disable HTTP/2 server push using the
+ set deviceconfig setting http2 server-push no
+ CLI command.
+
+ |
+
|
+ PAN-303959
+ |
+
+
+ Traffic that is incorrectly identified as unknown-tcp/unknown-udp
+ eventually drops due to an App-ID resource limitation issue.
+
+ |
+
|
+ PAN-292202
+ |
+
+
+ The system logs repeatedly displayed the alert
+ Clearing snmpd.log due to log overflow
+ due to the SNMP counters rolling over. This is a benign message and
+ does not impact device functionality.
+
+ |
+
|
+ PAN-289432
+ |
+
+
+ Generating a certificate with the
+ block-private-key yes command on
+ Panorama fails with the error:
+
+
+ Could not get parameters for double encryption.
+ This occurred when the certificate was signed by an external
+ Certificate Authority (CA).
+
+ |
+
|
+ PAN-289383
+ |
+
+
+ (PA-800 series firewalls only) Upgrading
+ firewalls to PAN-OS 11.0 or later causes SFP ports to go
+ non-operational when the firewall uses forced port mode and the
+ connected peer device operates without auto-negotiation.
+
+
+ Workaround: Enable auto-negotiation on the
+ connected peer firewall.
+
+ |
+
|
+ PAN-286848
+ |
+
+
+ ECMP incorrectly balances sessions across links based on the
+ configured metric, which leads to an imbalance in traffic distribution
+ and results in traffic assignment shifting disproportionately to
+ routes with lower metrics.
+
+ |
+
|
+ PAN-286496
+ |
+
+
+ (NGFW Clusters) URL-continue and override
+ continue selections will function like a general URL-block action.
+
+ |
+
|
+ PAN-285894
+ |
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may
+ occur, which could result in firewall reboots.
+
+
+ Workaround: Disable the Preserve Pre-NAT feature
+ using the
+ set deviceconfig setting preserve-prenat-feature no
+ CLI command.
+
+ |
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-279415
+ |
+
+
+ Service routes configured for a data plane interface might incorrectly
+ route traffic through the management plane interface instead. This
+ issue impacts Syslog and CRL status traffic when the service route
+ lacks a specific destination custom service route.
+
+ |
+
|
+ PAN-276920
+ |
+
+
+ URL filtering response pages may load slowly or fail to display when
+ users request websites that are blocked in the URL Filtering profile
+ (site access for the corresponding URL category is
+ block,
+ continue, or
+ override) attached to the matching
+ Security policy rule. This occurs on an intermittent basis.
+
+ |
+
|
+ PAN-275047
+ |
+
+
+ (VM-Series firewalls only) After an upgrade,
+ the firewall is unable to send logs to the Strata Logging Service
+ (SLS) when using a specific proxy server, and the SSL connection
+ status displays as failed when attempting to forward logs through the
+ web proxy.
+
+ |
+
|
+ PAN-273158
+ |
+
+
+ (PA-7000 Series firewalls only) Due to an
+ incorrect configuration on the ASIC, receiving a mix of jumbo and
+ non-jumbo packets may cause silent packet drops or application
+ slowness.
+
+ |
+
|
+ PAN-262556
+ |
+
+
+ The ElasticSearch cluster health status might continue to remain
+ yellow for an extended period after upgrading to PAN-OS 11.1
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-254240
+ |
+
+
+ In the event of an HSCI flap on an NGFW cluster node, traffic
+ reconvergence takes three to four seconds.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
|
+ PAN-251551
+ |
+
+
+ When an NGFW cluster agent crashes and doesn't recover, leader
+ election will take approximately 45 seconds to begin and traffic
+ failover will occur during that time.
+
+ |
+
|
+ PAN-250903
+ |
+
+
+ In a congestion scenario on an HSCI port of an NGFW cluster node, the
+ QoS priorities of cross node traffic streams might be reversed if
+ you're using the default QoS profile with class1 to class8 set as high
+ to low.
+
+ |
+
|
+ PAN-247974
+ |
+
+
+ LACP flap is expected during a device failover in an NGFW cluster due
+ to an L2 ctrld restart on the new leader node.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-224502
+ |
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0
+ might take longer than expected.
+
+ |
+
|
+ PAN-220180
+ |
+
+
+ Configured botnet reports () are not generated.
+
+ |
+
|
+ PAN-207733
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if
+ the DHCPv6 server goes down, after the lease time expires, the DHCPv6
+ client should enter SOLICIT state on both the Active and Passive
+ firewalls. Instead, the client is stuck in BOUND state with an IPv6
+ address having lease time 0 on the Passive firewall.
+
+ |
+
|
+ PAN-207611
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the
+ Passive firewall sometimes crashes.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-207040
+ |
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade
+ from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
+ commits fail and SD-WAN devices on Panorama have no Virtual Router
+ name.
+
+ |
+
|
+ PAN-206913
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls,
+ releasing the IPv6 address from the client (using Release in the UI or
+ using the
+ request dhcp client ipv6 release all
+ CLI command) releases the IPv6 address from the Active firewall, but
+ not the Passive firewall.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-194978
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , hovering the mouse over a power over Ethernet (PoE)
+ Link State icon does not display
+ link speed and link duplex details.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-184708
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
|
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-304756
+
+ This issue is now resolved. See
+ PAN-OS 11.1.13-h1 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push might
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-298505
+
+ This issue is now resolved. See
+ PAN-OS 11.1.6-h20 Addressed Issues,
+ PAN-OS 11.1.10-h7 Addressed Issues, and
+ PAN-OS 11.1.12 Addressed Issues
+
+ |
+
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual
+ system IDs (vsys ID) changes causing auto-commit failures with
+ validation errors. This occurs when the multi-vsys firewall has
+ virtual systems managed by Panorama, and the vsys ID sequence breaks
+ when unused virtual systems are deleted and the changes are pushed to
+ the firewall.
+
+ |
+
|
+ PAN-294179
+ This issue is now resolved. See PAN-OS 11.1.6-h17 Addressed Issues.
+ |
+ + On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. + | +
|
+ PAN-291288
+ |
+ + An active firewall might unexpectedly reboot due to a + pan_task crash caused by a page + allocation failure. This issue is observed after a period of runtime + with traffic and telemetry collection. + | +
|
+ PAN-290088
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-289383
+ |
+
+
+ (PA-800 series firewalls only) Upgrading
+ firewalls to PAN-OS 11.0 or later causes SFP ports to go
+ non-operational when the firewall uses forced port mode and the
+ connected peer device operates without auto-negotiation.
+
+
+ Workaround: Enable auto-negotiation on the
+ connected peer firewall.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See
+ PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ Routed process may stop responding after changing MTU or any link
+ parameters when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-287871
+
+ This issue affects PAN-OS 11.1.2-h9
+
+ |
+
+
+ When SSL Inbound Inspection is enabled and the firewall receives
+ fragmented Client Hello packets that include the TCP timestamp option,
+ the Client Hello message is forwarded to the destination server
+ without the timestamp option.
+
+ |
+
|
+ PAN-286231
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-285894
+ |
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may
+ occur, which could result in firewall reboots.
+
+
+ Workaround: Disable the Preserve Pre-NAT feature
+ using the
+ set deviceconfig setting preserve-prenat-feature no
+ CLI command.
+
+ |
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-281885
+ |
+
+
+ When exporting and importing the CSV file, the hash values of
+ pre-shared key (PSK) variables set at template and template stack
+ levels inconsistently change, resulting in both variables displaying
+ the same hash value.
+
+ |
+
|
+ PAN-280532
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues.
+
+ |
+
+
+ When you use a single syslog server over TCP for log forwarding, and
+ the connectivity to the syslog server breaks, syslog forwarding does
+ not resume even after the connectivity to the server restores.
+
+
+ Workaround: Performing one of the following tasks:
+
+
|
+
|
+ PAN-280471
+ |
+
+
+ When applying filters or searching for logs in the
+ section, you might experience slow performance.
+
+ |
+
|
+ PAN-279415
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ Service routes configured for a data plane interface might incorrectly
+ route traffic through the management plane interface instead. This
+ issue impacts Syslog and CRL status traffic when the service route
+ lacks a specific destination custom service route.
+
+ |
+
|
+ PAN-278296
+ |
+
+
+ The system MAC address of the aggregate interface is the same on both
+ the active and the passive devices, causing some packets to be sent
+ incorrectly to the passive device. This is causing the AE interface on
+ the active firewall to not come up.
+
+ |
+
|
+ PAN-277417
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues.
+
+ |
+
+
+ Memory leak issues can occur during the parsing of server certificates
+ used for SSL Inbound Inspection, preventing the firewall from
+ completing inspection.
+
+ |
+
|
+ PAN-277034
+
+ This issue is now resolved. See PAN-OS 11.1.10-h5 Addressed Issuesand
+ PAN-OS 11.1.6-h19 Addressed Issues
+
+ |
+ + WildFire reports might not fully display or be downloadable because some + static resources fail to load. + | +
|
+ PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues
+
+ |
+
+
+ When Panorama is not internet-connected and you try to upload images
+ to the managed firewalls by using the
+ Validate option, the upload fails
+ with the following error:
+ Failed to create multi-upload job. No valid software deploy targets
+ found.
+
+ |
+
|
+ PAN-273300
+
+ This issue is now resolved. See PAN-OS 11.1.6-h1 Addressed Issues
+
+ |
+
+
+ When upgrading Panorama from PAN-OS 10.2 or PAN-OS 11.0 to PAN-OS 11.1
+ or a later release, Panorama fails to upgrade if it is operating
+ within a Collector Group. The following error appears:Error: Traceback (most recent call last):File
+ "/opt/panrepo/releases/<PANOS release version>/validate"...
+ (min ([dts['min'] for dts in 10g_type_intv_dir.values() if
+ dts|'min']])-strftime ('%Y-%m-%d'),
+
+ |
+
|
+ PAN-263987
+
+ This issue is now resolved. See PAN-OS 11.1.4-h4 Addressed Issues.
+
+ |
+
+
+ When a NAT traversal (NAT-T or UDP encapsulation) IPSec tunnel is
+ terminated on a Palo Alto Networks firewall and the NAT rule applied
+ to the NAT-T IPSec tunnel is also on the same firewall, then the data
+ traffic flowing through the NAT-T IPSec tunnel can't be NATed
+ correctly.
+
+ |
+
|
+ PAN-263208
+
+ This issue is now resolved. See PAN-OS 11.1.2-h16 Addressed Issues.
+
+ |
+
+
+ (PA-5440 and PA-5445 firewalls only) High
+ system load can cause the firewall to generate interrupts and trigger
+ dataplane crashes.
+
+ |
+
|
+ PAN-262556
+ |
+
+
+ The ElasticSearch cluster health status might continue to remain
+ yellow for an extended period after upgrading to PAN-OS 11.1.2.
+
+ |
+
|
+ PAN-262287
+ |
+
+
+ Dereferencing a NULL pointer that occurs might cause
+ pan_task
+ processes to crash.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-259769
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues.
+
+ |
+
+
+ GlobalProtect portal is not accessible via a web browser and the app
+ displays the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-257615
+
+ This issue is now resolved. See PAN-OS 11.1.2-h9 Addressed Issues.
+
+ |
+
+
+ The Panorama web interface intermittently displays logs or fails to
+ display logs completely.
+
+ |
+
|
+ PAN-255538
+ |
+
+
+ On the PA-455 firewall, the LEDs indicating the link status of Ports 3
+ and 4 are swapped.
+
+ |
+
|
+ PAN-252085
+ |
+
+
+ The PA-450R, PA-450R-5G, and PA-455 firewalls can experience an
+ interruption of traffic when switching the combo port connection from
+ fiber to copper.
+
+
+ Workaround: With the copper port connected,
+ initiate a soft reboot of the firewall using the CLI command
+ request restart system. After the
+ reboot, the copper port will be able to process traffic.
+
+ |
+
|
+ PAN-250062
+
+ This issue is now resolved. See PAN-OS 11.1.4-h4 Addressed Issues.
+
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-243951
+
+ This issue is now resolved. See PAN-OS 11.1.2-h3 Addressed Issues
+
+ |
+
+
+ On the Panorama management sever in an active/passive High
+ Availability (HA) configuration, managed devices () display as out-of-sync on the
+ passive HA peer when configuration changes are made to the SD-WAN
+ () configuration on the active HA peer.
+
+
+ Workaround: Manually synchronize the Panorama HA
+ peers.
+
+
|
+
|
+ PAN-241041
+
+ This issue is now resolved. See PAN-OS 11.1.3 Addressed Issues
+
+ |
+
+
+ On the Panorama management server exporting template or template stack
+ variables () in CSV format results in an empty CSV file.
+
+ |
+
|
+ PAN-237106
+
+ This issue is now resolved. See PAN-OS 11.1.8 Addressed Issues
+
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-224502
+ |
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0
+ might take longer than expected.
+
+ |
+
|
+ PAN-220180
+ |
+
+
+ Configured botnet reports () are not generated.
+
+ |
+
|
+ PAN-217307
+
+ This issue is now resolved. See PAN-OS 11.1.3 Addressed Issues.
+
+ |
+
+
+ The following Security policy rule () filters return no results:
+
+
+ log-start eq no
+
+ log-end eq no
+ log-end eq yes
+ |
+
|
+ PAN-207733
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if
+ the DHCPv6 server goes down, after the lease time expires, the DHCPv6
+ client should enter SOLICIT state on both the Active and Passive
+ firewalls. Instead, the client is stuck in BOUND state with an IPv6
+ address having lease time 0 on the Passive firewall.
+
+ |
+
|
+ PAN-207611
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the
+ Passive firewall sometimes crashes.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-207040
+ |
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade
+ from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
+ commits fail and SD-WAN devices on Panorama have no Virtual Router
+ name.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-194978
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , hovering the mouse over a power over Ethernet (PoE)
+ Link State icon does not display
+ link speed and link duplex details.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-184708
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
|
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-164885
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues
+
+ |
+
+
+ On the Panorama management server, pushes to managed firewalls (
+ or Commit and Push) may fail when an
+ EDL () is configured to
+ Check for updates every 5 minutes
+ due to the commit and EDL fetch processes overlapping. This is more
+ likely to occur when multiple EDLs are configured to check for updates
+ every 5 minutes.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-304756
+
+ This issue is now resolved. See
+ PAN-OS 11.1.13-h1 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push might
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-298505
+
+ This issue is now resolved. See
+ PAN-OS 11.1.6-h20 Addressed Issues,
+ PAN-OS 11.1.10-h7 Addressed Issues, and
+ PAN-OS 11.1.12 Addressed Issues
+
+ |
+
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual
+ system IDs (vsys ID) changes causing auto-commit failures with
+ validation errors. This occurs when the multi-vsys firewall has
+ virtual systems managed by Panorama, and the vsys ID sequence breaks
+ when unused virtual systems are deleted and the changes are pushed to
+ the firewall.
+
+ |
+
|
+ PAN-294179
+ This issue is now resolved. See PAN-OS 11.1.6-h17 Addressed Issues.
+ |
+ + On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. + | +
|
+ PAN-291288
+ |
+ + An active firewall might unexpectedly reboot due to a + pan_task crash caused by a page + allocation failure. This issue is observed after a period of runtime + with traffic and telemetry collection. + | +
|
+ PAN-290088
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-289383
+ |
+
+
+ (PA-800 series firewalls only) Upgrading
+ firewalls to PAN-OS 11.0 or later causes SFP ports to go
+ non-operational when the firewall uses forced port mode and the
+ connected peer device operates without auto-negotiation.
+
+
+ Workaround: Enable auto-negotiation on the
+ connected peer firewall.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See
+ PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ Routed process may stop responding after changing MTU or any link
+ parameters when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-287871
+
+ This issue affects PAN-OS 11.1.3-h2
+
+ |
+
+
+ When SSL Inbound Inspection is enabled and the firewall receives
+ fragmented Client Hello packets that include the TCP timestamp option,
+ the Client Hello message is forwarded to the destination server
+ without the timestamp option.
+
+ |
+
|
+ PAN-286231
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-285894
+ |
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may
+ occur, which could result in firewall reboots.
+
+
+ Workaround: Disable the Preserve Pre-NAT feature
+ using the
+ set deviceconfig setting preserve-prenat-feature no
+ CLI command.
+
+ |
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-281885
+ |
+
+
+ When exporting and importing the CSV file, the hash values of
+ pre-shared key (PSK) variables set at template and template stack
+ levels inconsistently change, resulting in both variables displaying
+ the same hash value.
+
+ |
+
|
+ PAN-280532
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues.
+
+ |
+
+
+ When you use a single syslog server over TCP for log forwarding, and
+ the connectivity to the syslog server breaks, syslog forwarding does
+ not resume even after the connectivity to the server restores.
+
+
+ Workaround: Performing one of the following tasks:
+
+
|
+
|
+ PAN-280471
+ |
+
+
+ When applying filters or searching for logs in the
+ section, you might experience slow performance.
+
+ |
+
|
+ PAN-279621
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues.
+
+ |
+
+
+ Early aging and removal of firewall session while they are still
+ active can lead to intermittent instabilities and crashes for proxy
+ traffic, the Content and Threat detection engine, and any data-path
+ processing.
+
+ |
+
|
+ PAN-279415
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ Service routes configured for a data plane interface might incorrectly
+ route traffic through the management plane interface instead. This
+ issue impacts Syslog and CRL status traffic when the service route
+ lacks a specific destination custom service route.
+
+ |
+
|
+ PAN-278296
+ |
+
+
+ The system MAC address of the aggregate interface is the same on both
+ the active and the passive devices, causing some packets to be sent
+ incorrectly to the passive device. This is causing the AE interface on
+ the active firewall to not come up.
+
+ |
+
|
+ PAN-277417
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues.
+
+ |
+
+
+ Memory leak issues can occur during the parsing of server certificates
+ used for SSL Inbound Inspection, preventing the firewall from
+ completing inspection.
+
+ |
+
|
+ PAN-277034
+
+ This issue is now resolved. See PAN-OS 11.1.10-h5 Addressed Issuesand
+ PAN-OS 11.1.6-h19 Addressed Issues
+
+ |
+ + WildFire reports might not fully display or be downloadable because some + static resources fail to load. + | +
|
+ PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues
+
+ |
+
+
+ When Panorama is not internet-connected and you try to upload images
+ to the managed firewalls by using the
+ Validate option, the upload fails
+ with the following error:
+ Failed to create multi-upload job. No valid software deploy targets
+ found.
+
+ |
+
|
+ PAN-273300
+
+ This issue is now resolved. See PAN-OS 11.1.6-h1 Addressed Issues
+
+ |
+
+
+ When upgrading Panorama from PAN-OS 10.2 or PAN-OS 11.0 to PAN-OS 11.1
+ or a later release, Panorama fails to upgrade if it is operating
+ within a Collector Group. The following error appears:Error: Traceback (most recent call last):File
+ "/opt/panrepo/releases/<PANOS release version>/validate"...
+ (min ([dts['min'] for dts in 10g_type_intv_dir.values() if
+ dts|'min']])-strftime ('%Y-%m-%d'),
+
+ |
+
|
+ PAN-265336
+ (PAN-OS 11.1.3-h6 only)
+ |
+
+
+ Copper ports flap when generating a technical support file, executing
+ telemetry, or retrieving port status using a Management Data
+ Input/Output (MDIO) read.
+
+ |
+
|
+ PAN-263987
+
+ This issue is now resolved. See PAN-OS 11.1.4-h4 Addressed Issues.
+
+ |
+
+
+ When a NAT traversal (NAT-T or UDP encapsulation) IPSec tunnel is
+ terminated on a Palo Alto Networks firewall and the NAT rule applied
+ to the NAT-T IPSec tunnel is also on the same firewall, then the data
+ traffic flowing through the NAT-T IPSec tunnel can't be NATed
+ correctly.
+
+ |
+
|
+ PAN-263940
+ |
+
+
+ On a PA-7500 Series firewall node in an NGFW cluster, if the data
+ processing card is in slot 6, packet drops are expected.
+
+ |
+
|
+ PAN-262287
+ |
+
+
+ Dereferencing a NULL pointer that occurs might cause
+ pan_task
+ processes to crash.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-259769
+
+ This issue is now resolved. See PAN-OS 11.1.3-h6 Addressed Issues
+
+ |
+
+
+ GlobalProtect portal is not accessible via a web browser and the app
+ displays the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-259733
+
+ This issue is now resolved. See PAN-OS 11.1.3-h2 Addressed Issues.
+
+ |
+
+
+ Custom reports created in PAN-OS are not deleted as expected,
+ resulting in high memory use by the
+ reportd
+ process. This can lead to issues, such as out-of-memory conditions,
+ content installation failures, and unexpected firewall reboots.
+
+ |
+
|
+ PAN-257615
+
+ This issue is now resolved. See
+ PAN-OS 11.1.3-h4 Addressed Issues.
+
+ |
+
+
+ The Panorama web interface intermittently displays logs or fails to
+ display logs completely.
+
+ |
+
|
+ PAN-255868
+
+ This issue is now resolved. See PAN-OS 11.1.3-h1 Addressed Issues.
+
+ |
+
+
+ (PA-3400 Series firewalls only) After enabling
+ kernel data collection during a silent reboot, the firewall fails and
+ reboots to maintenance mode.
+
+
+ Workaround: To recover the firewall, initiate a
+ reboot from maintenance mode.
+
+ |
+
|
+ PAN-255579
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues.
+
+ |
+
+
+ Demo Mode and Log Forwarding: PA-7500 Series firewalls and Panorama
+ display data plane logs after a delay.
+
+ |
+
|
+ PAN-255285
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues.
+
+ |
+
+
+ If only the HCSI-A link is connected on NGFW cluster nodes (the HSCI-B
+ link is not connected) and the management interfaces goes down, the
+ situation will result in a split brain.
+
+ |
+
|
+ PAN-255116
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues
+
+ |
+
+
+ When QoS is applied, traffic on an NGFW cluster node going from an
+ MC-LAG interface to a destination stops when a member of the MC-LAG
+ goes down.
+
+ |
+
|
+ PAN-254927
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues
+
+ |
+
+
+ Certain types of data packets sent to threat inspection processing on
+ the Networking cards of PA-7500 Series firewalls cause a pan_task
+ crash.
+
+ |
+
|
+ PAN-254827
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues
+
+ |
+
+
+ When you change an IP address on a management interface on any of the
+ NGFW cluster nodes, there's no workflow in cluster-config to detect
+ this change, so the subsequent commit-all will not push the updated
+ management IP address.
+
+
+ Workaround: You must manually make an unrelated
+ change to cluster-config in order for Panorama to detect this change;
+ the subsequent commit-all will push the cluster-config with the
+ updated management IP address to cluster-manager.
+
+ |
+
|
+ PAN-254351
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues
+
+ |
+
+
+ An NGFW cluster node could get stuck in suspended state in some cases
+ when you use GRE tunnel termination with keepalive enabled on both
+ ends.
+
+ |
+
|
+ PAN-254240
+ |
+
+
+ In the event of an HSCI flap on an NGFW cluster node, traffic
+ reconvergence takes three to four seconds.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
|
+ PAN-253466
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues
+
+ |
+
+
+ In the event of a cluster manager restart on the leader node of an
+ NGFW cluster, traffic stops because the state machine transitions to
+ unknown and the leader is not changing.
+
+ |
+
|
+ PAN-253466
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues
+
+ |
+
+
+ On an NGFW cluster node, an expected packet buffer leak occurs with
+ FTP/SIP traffic over an extended period of time.
+
+ |
+
|
+ PAN-252358
+ |
+
+
+ (PA-7500 Series firewalls only) In the event of
+ a corosync restart, an NGFW cluster node goes to failed state.
+
+ |
+
|
+ PAN-251639
+
+ This issue is now resolved. See PAN-OS 11.1.4 Addressed Issues.
+
+ |
+
+
+ When a Wildfire Analysis security profile is enabled, an out of memory
+ condition might occur due to a memory leak in the
+ varrcvr process.
+
+ |
+
|
+ PAN-251551
+ |
+
+
+ (PA-7500 Series firewalls only) When an NGFW
+ cluster agent crashes and doesn't recover, leader election will take
+ approximately 45 seconds to begin and traffic failover will occur
+ during that time.
+
+ |
+
|
+ PAN-251501
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues
+
+ |
+
+
+ Upon a reboot, an NGFW cluster node will occasionally fail to rejoin a
+ cluster due to a timing issue.
+
+ |
+
|
+ PAN-250903
+ |
+
+
+ (PA-7500 Series firewalls only) In a congestion
+ scenario on an HSCI port of an NGFW cluster node, the QoS priorities
+ of cross node traffic streams might be reversed if you're using the
+ default QoS profile with class1 to class8 set as high to low.
+
+ |
+
|
+ PAN-250062
+
+ This issue is now resolved. See PAN-OS 11.1.4-h4 Addressed Issues.
+
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-250043
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues
+
+ |
+
+
+ On an NGFW cluster node, if you configure a QoS interface with an
+ Egress Max (Mbps) that exceeds 68000, the operation will fail with a
+ message indicating "...is not a valid reference.…" The QoS Max
+ bandwidth on any interface cannot be configured to be more than 68000.
+
+ |
+
|
+ PAN-249727
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues
+
+ |
+
+
+ On an NGFW cluster node, the Custom/Pre-defined URL category is not
+ part of the session flow data and a promoted session after failover
+ does not include it.
+
+ |
+
|
+ PAN-248762
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues
+
+ |
+
+
+ A firewall using the Advanced Routing Engine configured with OSPF
+ crashes when connecting to the neighbor while exchanging route maps.
+
+ |
+
|
+ PAN-247974
+ |
+
+
+ (PA-7500 Series firewalls only) LACP flap is
+ expected during a device failover in an NGFW cluster due to an L2
+ ctrld restart on the new leader node.
+
+ |
+
|
+ PAN-240529
+
+ This issue is now resolved. See
+ PAN-OS 11.1.7 Addressed Issues
+
+ |
+
+
+ (PA-7500 Series firewalls only) Cloud
+ application information is missing from traffic logs on NGFW cluster
+ nodes.
+
+ |
+
|
+ PAN-237106
+
+ This issue is now resolved. See PAN-OS 11.1.8 Addressed Issues
+
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-227978
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues
+
+ |
+
+
+ The UI widget does not accurately list the status of the port when
+ NGFW clustering is enabled.
+
+ |
+
|
+ PAN-224502
+ |
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0
+ might take longer than expected.
+
+ |
+
|
+ PAN-220180
+ |
+
+
+ Configured botnet reports () are not generated.
+
+ |
+
|
+ PAN-207733
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if
+ the DHCPv6 server goes down, after the lease time expires, the DHCPv6
+ client should enter SOLICIT state on both the Active and Passive
+ firewalls. Instead, the client is stuck in BOUND state with an IPv6
+ address having lease time 0 on the Passive firewall.
+
+ |
+
|
+ PAN-207611
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the
+ Passive firewall sometimes crashes.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-207040
+ |
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade
+ from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
+ commits fail and SD-WAN devices on Panorama have no Virtual Router
+ name.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-194978
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , hovering the mouse over a power over Ethernet (PoE)
+ Link State icon does not display
+ link speed and link duplex details.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-184708
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
|
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-164885
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues
+
+ |
+
+
+ On the Panorama management server, pushes to managed firewalls (
+ or Commit and Push) may fail when an
+ EDL () is configured to
+ Check for updates every 5 minutes
+ due to the commit and EDL fetch processes overlapping. This is more
+ likely to occur when multiple EDLs are configured to check for updates
+ every 5 minutes.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-304756
+
+ This issue is now resolved. See
+ PAN-OS 11.1.13-h1 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push might
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-298505
+
+ This issue is now resolved. See
+ PAN-OS 11.1.6-h20 Addressed Issues,
+ PAN-OS 11.1.10-h7 Addressed Issues, and
+ PAN-OS 11.1.12 Addressed Issues
+
+ |
+
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual
+ system IDs (vsys ID) changes causing auto-commit failures with
+ validation errors. This occurs when the multi-vsys firewall has
+ virtual systems managed by Panorama, and the vsys ID sequence breaks
+ when unused virtual systems are deleted and the changes are pushed to
+ the firewall.
+
+ |
+
|
+ PAN-294179
+
+ This issue is now resolved. See PAN-OS 11.1.6-h17 Addressed Issues.
+
+ |
+ + On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. + | +
|
+ PAN-293673
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+ + When the firewall generates a high volume of logs and attempts to export + these logs to an FTP server, it may consume excessive memory leading to + all PAN-OS processes crashing. + | +
|
+ PAN-291288
+ |
+ + An active firewall might unexpectedly reboot due to a + pan_task crash caused by a page + allocation failure. This issue is observed after a period of runtime + with traffic and telemetry collection. + | +
|
+ PAN-290088
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-289383
+ |
+
+
+ (PA-800 series firewalls only) Upgrading
+ firewalls to PAN-OS 11.0 or later causes SFP ports to go
+ non-operational when the firewall uses forced port mode and the
+ connected peer device operates without auto-negotiation.
+
+
+ Workaround: Enable auto-negotiation on the
+ connected peer firewall.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See
+ PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ Routed process may stop responding after changing MTU or any link
+ parameters when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-287871
+
+ This issue affects PAN-OS 11.1.4-h4
+
+ |
+
+
+ When SSL Inbound Inspection is enabled and the firewall receives
+ fragmented Client Hello packets that include the TCP timestamp option,
+ the Client Hello message is forwarded to the destination server
+ without the timestamp option.
+
+ |
+
|
+ PAN-286255
+
+ This issue affects PAN-OS 11.1.4-h15
+
+ |
+
+
+ When a firewall receives an unexpected termination request for certain
+ SSL sessions , NGFW dataplane might experience a slow buffer resource
+ leak.
+
+
+ Workaround: Disable accumulation proxy on the
+ NGFW.
+
+ |
+
|
+ PAN-286255
+
+ This issue affects PAN-OS 11.1.7-h2
+
+
+ This issue is now resolved. See PAN-OS 11.1.6-h7 Addressed Issues.
+
+ |
+
+
+ When a firewall receives an unexpected termination request for certain
+ SSL sessions , NGFW dataplane might experience a slow buffer resource
+ leak.
+
+
+ Workaround: Disable accumulation proxy on the
+ NGFW.
+
+ |
+
|
+ PAN-286231
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-285894
+ |
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may
+ occur, which could result in firewall reboots.
+
+
+ Workaround: Disable the Preserve Pre-NAT feature
+ using the
+ set deviceconfig setting preserve-prenat-feature no
+ CLI command.
+
+ |
+
|
+ PAN-285587
+
+ This issue affects PAN-OS 11.1.4-h13.
+
+ |
+
+
+ Bootstrapping the VM-Series firewall on OpenStack with user-data does
+ not function correctly. When you run the command show
+ system bootstrap status shows, the
+ output shows the message
+ No Install media detected.
+
+ |
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-281885
+ |
+
+
+ When exporting and importing the CSV file, the hash values of
+ pre-shared key (PSK) variables set at template and template stack
+ levels inconsistently change, resulting in both variables displaying
+ the same hash value.
+
+ |
+
|
+ PAN-280532
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues.
+
+ |
+
+
+ When you use a single syslog server over TCP for log forwarding, and
+ the connectivity to the syslog server breaks, syslog forwarding does
+ not resume even after the connectivity to the server restores.
+
+
+ Workaround: Performing one of the following tasks:
+
+
|
+
|
+ PAN-280471
+ |
+
+
+ When applying filters or searching for logs in the
+ section, you might experience slow performance.
+
+ |
+
|
+ PAN-279746
+
+ This issue affects PAN-OS 11.1.4-h4 and PAN-OS 11.1.4-h7.
+
+
+ This issue is now resolved. See
+ PAN-OS 11.1.4-h15 Addressed Issues.
+
+ |
+
+
+ An SSL/TLS Client Hello may not be transmitted out of the firewall if
+ the Client Hello arrives in multiple TCP segments and the traffic is
+ not subject to SSL decryption (for example, SMTP over SSL).
+
+ |
+
|
+ PAN-279621
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues.
+
+ |
+
+
+ Early aging and removal of firewall session while they are still
+ active can lead to intermittent instabilities and crashes for proxy
+ traffic, the Content and Threat detection engine, and any data-path
+ processing.
+
+ |
+
|
+ PAN-279415
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ Service routes configured for a data plane interface might incorrectly
+ route traffic through the management plane interface instead. This
+ issue impacts Syslog and CRL status traffic when the service route
+ lacks a specific destination custom service route.
+
+ |
+
|
+ PAN-278296
+ |
+
+
+ The system MAC address of the aggregate interface is the same on both
+ the active and the passive devices, causing some packets to be sent
+ incorrectly to the passive device. This is causing the AE interface on
+ the active firewall to not come up.
+
+ |
+
|
+ PAN-277417
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues.
+
+ |
+
+
+ Memory leak issues can occur during the parsing of server certificates
+ used for SSL Inbound Inspection, preventing the firewall from
+ completing inspection.
+
+ |
+
|
+ PAN-277034
+
+ This issue is now resolved. See PAN-OS 11.1.10-h5 Addressed Issuesand
+ PAN-OS 11.1.6-h19 Addressed Issues
+
+ |
+ + WildFire reports might not fully display or be downloadable because some + static resources fail to load. + | +
|
+ PAN-275905
+ This issue affects PAN-OS 11.1.4-h4 and PAN-OS 11.1.4-h7.
+ |
+
+
+ A high volume of incoming logs to a Collector Group can significantly
+ increase CPU usage on the Elasticsearch and Management Server,
+ potentially causing process instability or crashes.
+
+ |
+
|
+ PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues
+
+ |
+
+
+ When Panorama is not internet-connected and you try to upload images
+ to the managed firewalls by using the
+ Validate option, the upload fails
+ with the following error:
+ Failed to create multi-upload job. No valid software deploy targets
+ found.
+
+ |
+
|
+ PAN-274791
+
+ This issue affects PAN-OS 11.1.4-h4 and PAN-OS 11.1.4-h7.
+
+
+ This issue is now resolved. See
+ PAN-OS 11.1.6-h3 Addressed Issues.
+
+ |
+
+
+ The firewall might reboot when traffic matches with certain Advanced
+ features (such as Advanced Threat Prevention and Advanced URL
+ Filtering with properly configured URL
+ Filtering/Anti-Spyware/Vulnerability security profiles) and Shared
+ Pool Type 32 becomes depleted.
+
+ |
+
|
+ PAN-273300
+
+ This issue is now resolved. See PAN-OS 11.1.6-h1 Addressed Issues
+
+ |
+
+
+ When upgrading Panorama from PAN-OS 10.2 or PAN-OS 11.0 to PAN-OS 11.1
+ or a later release, Panorama fails to upgrade if it is operating
+ within a Collector Group. The following error appears:Error: Traceback (most recent call last):File
+ "/opt/panrepo/releases/<PANOS release version>/validate"...
+ (min ([dts['min'] for dts in 10g_type_intv_dir.values() if
+ dts|'min']])-strftime ('%Y-%m-%d'),
+
+ |
+
|
+ PAN-272085
+
+ (This issue affects PAN-OS 11.1.4-h4 and PAN-OS 11.1.4-h7.)
+
+ |
+
+
+ When DoH is enabled for DNS Security, multiple DoH transactions in a
+ single HTTP/1 connection might unexpectedly cause the firewall to
+ crash and reboot.
+
+
+ Workaround: Manually disable DoH support for DNS
+ Security using the
+ set deviceconfig setting dns-over-https enable no
+ CLI command. Alternatively, you can remove the DNS Security
+ configuration used to handle DoH traffic.
+
+ |
+
|
+ PAN-270549
+
+ This issue affects PAN-OS 11.1.4-h4 and PAN-OS 11.1.4-h7.
+
+
+ This issue is now resolved. See
+ PAN-OS 11.1.6-h1 Addressed Issues.
+
+ |
+
+
+ Some TLS connections are not handled correctly leading to an
+ instability in the dataplane of PAN-OS.
+
+ |
+
|
+ PAN-270224
+
+ This issue affects PAN-OS 11.1.4-h4 and PAN-OS 11.1.4-h7.
+
+
+ This issue is now resolved. See PAN-OS 11.1.4-h9 Addressed Issues.
+
+ |
+
+
+ When querying for logs in the
+ Monitor tab in Panorama, some
+ forwarded logs might be missing from the results.
+
+ |
+
|
+ PAN-269106
+
+ This issue affects PAN-OS 11.1.4-h4 and PAN-OS 11.1.4-h7.
+
+
+ This issue is now resolved. See PAN-OS 11.1.6-h1 Addressed Issues.
+
+ |
+
+
+ When using a cloud-based ML detection engine (MICA), the
+ wifclient might crash during
+ server cert verification for MICA gRPC connections and cause the
+ dataplane to restart. On certain platforms, this might cause the
+ firewall to reboot.
+
+
+ Workaround: Disable CRL using the following CLI
+ command:debug iot eal key-value PAN_ICD_SERVER_CERT_USE_CRL=False
+
+ |
+
|
+ PAN-267671
+
+ This issue is now resolved. See PAN-OS 11.1.4-h13 Addressed Issues.
+
+ |
+
+
+ Exporting reports in PDF or CSV format and processing hourly scheduled
+ report results can potentially trigger memory leaks. As a result, this
+ can lead to process crashes and firewall reboots.
+
+ |
+
|
+ PAN-268815
+
+ This issue affects PAN-OS 11.1.4-h4 and PAN-OS 11.1.4-h7.
+
+
+ This issue is now resolved. See PAN-OS 11.1.6-h1 Addressed Issues.
+
+ |
+
+
+ When using IoT Security, the
+ wifclient might exit multiple
+ times causing the firewall to reboot.
+
+
+ Workaround: Uninstall the IoT Security license and
+ disable
+ Enable enhanced application logging
+ ().
+
+ |
+
|
+ PAN-263226
+
+ This issue is now resolved. See PAN-OS 11.1.4-h4 Addressed Issues.
+
+ |
+
+
+ When SSL decryption is enabled and Client Hello messages span multiple
+ TCP segments, elements from the proxy_l2info memory pool may not be
+ freed properly. Memory leaks in this pool cause some SSL decryption
+ sessions to fail.
+
+
+ Workaround: Disable Client Hello accumulation
+ using the
+ debug dataplane set ssl-decrypt accumulate-client-hello disable
+ yes
+ CLI command.
+
+ |
+
|
+ PAN-263987
+
+ This issue is now resolved. See PAN-OS 11.1.4-h4 Addressed Issues.
+
+ |
+
+
+ When a NAT traversal (NAT-T or UDP encapsulation) IPSec tunnel is
+ terminated on a Palo Alto Networks firewall and the NAT rule applied
+ to the NAT-T IPSec tunnel is also on the same firewall, then the data
+ traffic flowing through the NAT-T IPSec tunnel can't be NATed
+ correctly.
+
+ |
+
|
+ PAN-263940
+ |
+
+
+ On a PA-7500 Series firewall node in an NGFW cluster, if the data
+ processing card is in slot 6, packet drops are expected.
+
+ |
+
|
+ PAN-263208
+
+ This issue is now resolved. See PAN-OS 11.1.4-h9 Addressed Issues.
+
+ |
+
+
+ (PA-5440 and PA-5445 firewalls only) High
+ system load can cause the firewall to generate interrupts and trigger
+ dataplane crashes.
+
+ |
+
|
+ PAN-262556
+ |
+
+
+ The ElasticSearch cluster health status might continue to remain
+ yellow for an extended period after upgrading to PAN-OS 11.1.
+
+ |
+
|
+ PAN-262287
+ |
+
+
+ Dereferencing a NULL pointer that occurs might cause
+ pan_task
+ processes to crash.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-260512
+
+ This issue affects PAN-OS 11.1.4-h4 and PAN-OS 11.1.4-h7.
+
+
+ This issue is now resolved. See PAN-OS 11.1.4-h9 Addressed Issues.
+
+ |
+
+
+ When accessing the IP addresses of Dynamic address group objects from
+ the Panorama user interface in a configuration with numerous Device
+ Groups, the configd process might stop
+ responding.
+
+ |
+
|
+ PAN-259769
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues.
+
+ |
+
+
+ GlobalProtect portal is not accessible via a web browser and the app
+ displays the error
+ ERR_EMPTY_RESPONSE.
+
+ |
+
|
+ PAN-259733
+
+ This issue is now resolved. See
+ PAN-OS 11.1.4-h1 Addressed Issues
+
+ .
+ |
+
+
+ Custom reports created in PAN-OS are not deleted as expected,
+ resulting in high memory use by the
+ reportd
+ process. This can lead to issues, such as out-of-memory conditions,
+ content installation failures, and unexpected firewall reboots.
+
+ |
+
|
+ PAN-258570
+
+ This issue affects PAN-OS 11.1.4-h4 and PAN-OS 11.1.4-h7.
+
+
+ This issue is now resolved. See
+ PAN-OS 11.1.6-h3 Addressed Issues.
+
+ |
+
+
+ The
+ varrcvr
+ process might progressively use more memory resulting in unexpected
+ reboots when WildFire file forwarding is handling PE files.
+
+ |
+
|
+ PAN-257957
+
+ This issue affects 11.1.4-h1.
+
+
+ This issue is now resolved. See PAN-OS 11.1.4-h4 Addressed Issues.
+
+ |
+
+
+ If you enable FIPS-CC mode and use the PAP or CHAP authentication
+ methods for your RADIUS server, the authd process may restart
+ unexpectedly. To avoid this issue, use one of the following
+ workarounds:
+
+
|
+
|
+ PAN-257615
+
+ This issue is now resolved. See PAN-OS 11.1.4-h1 Addressed Issues.
+
+ |
+
+
+ The Panorama web interface intermittently displays logs or fails to
+ display logs completely.
+
+ |
+
|
+ PAN-255579
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues.
+
+ |
+
+
+ Demo Mode and Log Forwarding: PA-7500 Series firewalls and Panorama
+ display data plane logs after a delay.
+
+ |
+
|
+ PAN-255285
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues.
+
+ |
+
+
+ If only the HCSI-A link is connected on NGFW cluster nodes (the HSCI-B
+ link is not connected) and the management interfaces goes down, the
+ situation will result in a split brain.
+
+ |
+
|
+ PAN-255116
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues
+
+ |
+
+
+ When QoS is applied, traffic on an NGFW cluster node going from an
+ MC-LAG interface to a destination stops when a member of the MC-LAG
+ goes down.
+
+ |
+
|
+ PAN-254927
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues
+
+ |
+
+
+ Certain types of data packets sent to threat inspection processing on
+ the Networking cards of PA-7500 Series firewalls cause a pan_task
+ crash.
+
+ |
+
|
+ PAN-254827
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues
+
+ |
+
+
+ When you change an IP address on a management interface on any of the
+ NGFW cluster nodes, there's no workflow in cluster-config to detect
+ this change, so the subsequent commit-all will not push the updated
+ management IP address.
+
+
+ Workaround: You must manually make an unrelated
+ change to cluster-config in order for Panorama to detect this change;
+ the subsequent commit-all will push the cluster-config with the
+ updated management IP address to cluster-manager.
+
+ |
+
|
+ PAN-254351
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues
+
+ |
+
+
+ An NGFW cluster node could get stuck in suspended state in some cases
+ when you use GRE tunnel termination with keepalive enabled on both
+ ends.
+
+ |
+
|
+ PAN-254240
+ |
+
+
+ In the event of an HSCI flap on an NGFW cluster node, traffic
+ reconvergence takes three to four seconds.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
|
+ PAN-253557
+ |
+
+
+ In the event of a cluster manager restart on the leader node of an
+ NGFW cluster, traffic stops because the state machine transitions to
+ unknown and the leader is not changing.
+
+ |
+
|
+ PAN-253466
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues
+
+ |
+
+
+ On an NGFW cluster node, an expected packet buffer leak occurs with
+ FTP/SIP traffic over an extended period of time.
+
+ |
+
|
+ PAN-252358
+ |
+
+
+ (PA-7500 Series firewalls only) In the event of
+ a corosync restart, an NGFW cluster node goes to failed state.
+
+ |
+
|
+ PAN-251551
+ |
+
+
+ (PA-7500 Series firewalls only) When an NGFW
+ cluster agent crashes and doesn't recover, leader election will take
+ approximately 45 seconds to begin and traffic failover will occur
+ during that time.
+
+ |
+
|
+ PAN-251501
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues
+
+ |
+
+
+ Upon a reboot, an NGFW cluster node will occasionally fail to rejoin a
+ cluster due to a timing issue.
+
+ |
+
|
+ PAN-250903
+ |
+
+
+ (PA-7500 Series firewalls only) In a congestion
+ scenario on an HSCI port of an NGFW cluster node, the QoS priorities
+ of cross node traffic streams might be reversed if you're using the
+ default QoS profile with class1 to class8 set as high to low.
+
+ |
+
|
+ PAN-250062
+
+ This issue is now resolved. See PAN-OS 11.1.4-h4 Addressed Issues.
+
+ |
+
+
+ Device telemetry might fail at configured intervals due to bundle
+ generation issues.
+
+ |
+
|
+ PAN-250043
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues
+
+ |
+
+
+ On an NGFW cluster node, if you configure a QoS interface with an
+ Egress Max (Mbps) that exceeds 68000, the operation will fail with a
+ message indicating "...is not a valid reference.…" The QoS Max
+ bandwidth on any interface cannot be configured to be more than 68000.
+
+ |
+
|
+ PAN-249727
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues
+
+ |
+
+
+ On an NGFW cluster node, the Custom/Pre-defined URL category is not
+ part of the session flow data and a promoted session after failover
+ does not include it.
+
+ |
+
|
+ PAN-248762
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues
+
+ |
+
+
+ A firewall using the Advanced Routing Engine configured with OSPF
+ crashes when connecting to the neighbor while exchanging route maps.
+
+ |
+
|
+ PAN-247974
+ |
+
+
+ (PA-7500 Series firewalls only) LACP flap is
+ expected during a device failover in an NGFW cluster due to an L2
+ ctrld restart on the new leader node.
+
+ |
+
|
+ PAN-240529
+
+ This issue is now resolved. See
+ PAN-OS 11.1.7 Addressed Issues
+
+ |
+
+
+ (PA-7500 Series firewalls only) Cloud
+ application information is missing from traffic logs on NGFW cluster
+ nodes.
+
+ |
+
|
+ PAN-237106
+
+ This issue is now resolved. See PAN-OS 11.1.8 Addressed Issues
+
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-227978
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues
+
+ |
+
+
+ The UI widget does not accurately list the status of the port when
+ NGFW clustering is enabled.
+
+ |
+
|
+ PAN-224502
+ |
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0
+ might take longer than expected.
+
+ |
+
|
+ PAN-220180
+ |
+
+
+ Configured botnet reports () are not generated.
+
+ |
+
|
+ PAN-207733
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if
+ the DHCPv6 server goes down, after the lease time expires, the DHCPv6
+ client should enter SOLICIT state on both the Active and Passive
+ firewalls. Instead, the client is stuck in BOUND state with an IPv6
+ address having lease time 0 on the Passive firewall.
+
+ |
+
|
+ PAN-207611
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the
+ Passive firewall sometimes crashes.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-207040
+ |
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade
+ from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
+ commits fail and SD-WAN devices on Panorama have no Virtual Router
+ name.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-194978
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , hovering the mouse over a power over Ethernet (PoE)
+ Link State icon does not display
+ link speed and link duplex details.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-184708
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
|
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-164885
+
+ This issue is now resolved. See PAN-OS 11.1.5 Addressed Issues
+
+ |
+
+
+ On the Panorama management server, pushes to managed firewalls (
+ or Commit and Push) may fail when an
+ EDL () is configured to
+ Check for updates every 5 minutes
+ due to the commit and EDL fetch processes overlapping. This is more
+ likely to occur when multiple EDLs are configured to check for updates
+ every 5 minutes.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-304756
+
+ This issue is now resolved. See
+ PAN-OS 11.1.13-h1 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push might
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-298505
+
+ This issue is now resolved. See
+ PAN-OS 11.1.6-h20 Addressed Issues,
+ PAN-OS 11.1.10-h7 Addressed Issues, and
+ PAN-OS 11.1.12 Addressed Issues
+
+ |
+
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual
+ system IDs (vsys ID) changes causing auto-commit failures with
+ validation errors. This occurs when the multi-vsys firewall has
+ virtual systems managed by Panorama, and the vsys ID sequence breaks
+ when unused virtual systems are deleted and the changes are pushed to
+ the firewall.
+
+ |
+
|
+ PAN-294179
+ This issue is now resolved. See PAN-OS 11.1.6-h17 Addressed Issues.
+ |
+ + On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. + | +
|
+ PAN-293673
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+ + When the firewall generates a high volume of logs and attempts to export + these logs to an FTP server, it may consume excessive memory leading to + all PAN-OS processes crashing. + | +
|
+ PAN-292202
+
+ This issue is now resolved. See
+
+ |
+
+
+ The system logs repeatedly displayed the alert `Clearing snmpd.log due
+ to log overflow` due to the SNMP counters rolling over. This is a
+ benign message and does not impact device functionality.
+
+ |
+
|
+ PAN-291288
+ |
+ + An active firewall might unexpectedly reboot due to a + pan_task crash caused by a page + allocation failure. This issue is observed after a period of runtime + with traffic and telemetry collection. + | +
|
+ PAN-290088
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-289383
+ |
+
+
+ (PA-800 series firewalls only) Upgrading
+ firewalls to PAN-OS 11.0 or later causes SFP ports to go
+ non-operational when the firewall uses forced port mode and the
+ connected peer device operates without auto-negotiation.
+
+
+ Workaround: Enable auto-negotiation on the
+ connected peer firewall.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See
+ PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ Routed process may stop responding after changing MTU or any link
+ parameters when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-287871
+ |
+
+
+ When SSL Inbound Inspection is enabled and the firewall receives
+ fragmented Client Hello packets that include the TCP timestamp option,
+ the Client Hello message is forwarded to the destination server
+ without the timestamp option.
+
+ |
+
|
+ PAN-287056
+
+ This issue is now resolved. See PAN-OS 11.1.6-h14 Addressed Issues
+
+ |
+
+
+ A BGP export policy rule that matches on a next hop fails to block the
+ advertisement of static routes, and the firewall incorrectly matches
+ the egress interface IP address instead of the original next-hop IP
+ address of the static route, which causes the deny rule to fail.
+
+ |
+
|
+ PAN-286496
+ |
+
+
+ (NGFW Clusters) URL-continue and override
+ continue selections will function like a general URL-block action.
+
+ |
+
|
+ PAN-286255
+
+ This issue is now resolved. See PAN-OS 11.1.6-h7 Addressed Issues.
+
+ |
+
+
+ When a firewall receives an unexpected termination request for certain
+ SSL sessions, NGFW dataplane might experience a slow buffer resource
+ leak.
+
+
+ Workaround: Disable accumulation proxy on the
+ NGFW.
+
+ |
+
|
+ PAN-286231
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-285894
+ |
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may
+ occur, which could result in firewall reboots.
+
+
+ Workaround: Disable the Preserve Pre-NAT feature
+ using the
+ set deviceconfig setting preserve-prenat-feature no
+ CLI command.
+
+ |
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-281885
+ |
+
+
+ When exporting and importing the CSV file, the hash values of
+ pre-shared key (PSK) variables set at template and template stack
+ levels inconsistently change, resulting in both variables displaying
+ the same hash value.
+
+ |
+
|
+ PAN-280532
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues.
+
+ |
+
+
+ When you use a single syslog server over TCP for log forwarding, and
+ the connectivity to the syslog server breaks, syslog forwarding does
+ not resume even after the connectivity to the server restores.
+
+
+ Workaround: Performing one of the following tasks:
+
+
|
+
|
+ PAN-280471
+ |
+
+
+ When applying filters or searching for logs in the
+ section, you might experience slow performance.
+
+ |
+
|
+ PAN-279746
+ |
+
+
+ An SSL/TLS Client Hello may not be transmitted out of the firewall if
+ the Client Hello arrives in multiple TCP segments and the traffic is
+ not subject to SSL decryption (for example, SMTP over SSL).
+
+ |
+
|
+ PAN-279621
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues.
+
+ |
+
+
+ Early aging and removal of firewall session while they are still
+ active can lead to intermittent instabilities and crashes for proxy
+ traffic, the Content and Threat detection engine, and any data-path
+ processing.
+
+ |
+
|
+ PAN-279415
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ Service routes configured for a data plane interface might incorrectly
+ route traffic through the management plane interface instead. This
+ issue impacts Syslog and CRL status traffic when the service route
+ lacks a specific destination custom service route.
+
+ |
+
|
+ PAN-278296
+ |
+
+
+ The system MAC address of the aggregate interface is the same on both
+ the active and the passive devices, causing some packets to be sent
+ incorrectly to the passive device. This is causing the AE interface on
+ the active firewall to not come up.
+
+ |
+
|
+ PAN-277417
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues.
+
+ |
+
+
+ Memory leak issues can occur during the parsing of server certificates
+ used for SSL Inbound Inspection, preventing the firewall from
+ completing inspection.
+
+ |
+
|
+ PAN-277034
+
+ This issue is now resolved. See PAN-OS 11.1.10-h5 Addressed Issuesand
+ PAN-OS 11.1.6-h19 Addressed Issues
+
+ |
+ + WildFire reports might not fully display or be downloadable because some + static resources fail to load. + | +
|
+ PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues
+
+ |
+
+
+ When Panorama is not internet-connected and you try to upload images
+ to the managed firewalls by using the
+ Validate option, the upload fails
+ with the following error:
+ Failed to create multi-upload job. No valid software deploy targets
+ found.
+
+ |
+
|
+ PAN-273300
+
+ This issue is now resolved. See PAN-OS 11.1.6-h1 Addressed Issues
+
+ |
+
+
+ When upgrading Panorama from PAN-OS 10.2 or PAN-OS 11.0 to PAN-OS 11.1
+ or a later release, Panorama fails to upgrade if it is operating
+ within a Collector Group. The following error appears:Error: Traceback (most recent call last):File
+ "/opt/panrepo/releases/<PANOS release version>/validate"...
+ (min ([dts['min'] for dts in 10g_type_intv_dir.values() if
+ dts|'min']])-strftime ('%Y-%m-%d'),
+
+ |
+
|
+ PAN-269193
+
+ This issue is now resolved. See PAN-OS 11.1.8 Addressed Issues.
+
+ |
+
+
+ When multiple application are configured for GlobalProtect Clientless
+ VPN, users are directed to the first application instead of the portal
+ page with a list of application.
+
+ |
+
|
+ PAN-262556
+ |
+
+
+ The ElasticSearch cluster health status might continue to remain
+ yellow for an extended period after upgrading to PAN-OS 11.1
+
+ |
+
|
+ PAN-261429
+
+ This issue is now resolved. See PAN-OS 11.1.6-h10 Addressed Issues
+ and
+ PAN-OS 11.1.8 Addressed Issues.
+
+ |
+
+
+ The command
+ show auth radius-require-msg-authentic
+ might return no output.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-254240
+ |
+
+
+ In the event of an HSCI flap on an NGFW cluster node, traffic
+ reconvergence takes three to four seconds.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
|
+ PAN-252358
+ |
+
+
+ (PA-7500 Series firewalls only) In the event of
+ a corosync restart, an NGFW cluster node goes to failed state.
+
+ |
+
|
+ PAN-251551
+ |
+
+
+ (PA-7500 Series firewalls only) When an NGFW
+ cluster agent crashes and doesn't recover, leader election will take
+ approximately 45 seconds to begin and traffic failover will occur
+ during that time.
+
+ |
+
|
+ PAN-250903
+ |
+
+
+ (PA-7500 Series firewalls only) In a congestion
+ scenario on an HSCI port of an NGFW cluster node, the QoS priorities
+ of cross node traffic streams might be reversed if you're using the
+ default QoS profile with class1 to class8 set as high to low.
+
+ |
+
|
+ PAN-247974
+ |
+
+
+ (PA-7500 Series firewalls only) LACP flap is
+ expected during a device failover in an NGFW cluster due to an L2
+ ctrld restart on the new leader node.
+
+ |
+
|
+ PAN-240529
+
+ This issue is now resolved. See
+ PAN-OS 11.1.7 Addressed Issues
+
+ |
+
+
+ (PA-7500 Series firewalls only) Cloud
+ application information is missing from traffic logs on NGFW cluster
+ nodes.
+
+ |
+
|
+ PAN-237106
+
+ This issue is now resolved. See PAN-OS 11.1.8 Addressed Issues
+
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-224502
+ |
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0
+ might take longer than expected.
+
+ |
+
|
+ PAN-220180
+ |
+
+
+ Configured botnet reports () are not generated.
+
+ |
+
|
+ PAN-207733
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if
+ the DHCPv6 server goes down, after the lease time expires, the DHCPv6
+ client should enter SOLICIT state on both the Active and Passive
+ firewalls. Instead, the client is stuck in BOUND state with an IPv6
+ address having lease time 0 on the Passive firewall.
+
+ |
+
|
+ PAN-207611
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the
+ Passive firewall sometimes crashes.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-207040
+ |
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade
+ from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
+ commits fail and SD-WAN devices on Panorama have no Virtual Router
+ name.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-194978
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , hovering the mouse over a power over Ethernet (PoE)
+ Link State icon does not display
+ link speed and link duplex details.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-184708
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
|
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-308564
+ |
+
+
+ Packets are dropped on SD-WAN interfaces if they require fragmentation
+ for an interface but have the
+ Don't Fragment (DF) bit set. This
+ results in unexpected packet drops. This affects client to server
+ sessions when using SD-WAN for NGFW.
+
+
+ Workaround: Allow fragmenting packets with DF bit
+ set (debug dataplane set ip4-ignore-df yes).
+
+ |
+
|
+
+ PAN-307795 This issue affects PAN-OS 11.1.6-h21 through 11.1.6-h24
+
+
+
+ This issue is now resolved. See PAN-OS 11.1.10-h12 Addressed Issues.
+
+ |
+
+
+ On a standalone Panorama, the system incorrectly generates system logs
+ indicating a lost connection to its peer even when High Availability
+ is not configured. You can safely ignore these logs, as they do not
+ affect operations.
+
+ |
+
|
+ PAN-306502
+
+ This issue is now resolved. See PAN-OS 11.1.6-h23 Addressed Issues.
+
+ |
+
+
+ TLS sessions using version 1.2 or earlier may fail when session
+ traffic matches a decryption policy rule with the no-decrypt action
+ under either of the following conditions:
+
+
+
+
+
+
+
+ If both of these conditions are met, the session is guaranteed to
+ fail.
+
+
+ Workaround: Perform one of the following tasks:
+
+
|
+
|
+ PAN-305301
+
+ This issue is now resolved. See PAN-OS 11.1.10-h12 Addressed Issues.
+
+ |
+
+
+ The timing of GlobalProtect lifetime expiry or inactivity logout
+ notifications used for GlobalProtect SSL tunnels may cause the
+ pan_task
+ process to stop responding and the dataplane to restart.
+
+
+ Workaround: Select
+ Network > GlobalProtect > Gateways > <gateway-config> > Agent > <agent-config> > Connection Settings
+ and change the value of both
+ Notify Before Lifetime Expires (min)
+ and
+ Notify Before Inactivity Logout (min)
+ to 0.
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See
+ PAN-OS 11.1.13-h1 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push might
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-304576
+ |
+
+
+ Traffic interruption may occur when inspection of HTTP/2 traffic is
+ enabled.
+
+
+ Workaround: Disable HTTP/2 server push using the
+ set deviceconfig setting http2 server-push no
+ CLI command.
+
+ |
+
|
+
+ PAN-303051This issue affects PAN-OS 11.1.6-h10
+
+
+ This issue is now resolved. See
+ PAN-OS 11.1.13 Addressed Issues
+
+ |
+ + The reportd process experiences a memory + leak because it retains memory that was temporarily used for report + generation. Once a task is complete, the process fails to release this + memory for reuse, leading to continuous accumulation and eventual memory + exhaustion on the Panorama device. + | +
|
+ PAN-298505
+
+ This issue is now resolved. See
+ PAN-OS 11.1.6-h20 Addressed Issues,
+ PAN-OS 11.1.10-h7 Addressed Issues, and
+ PAN-OS 11.1.12 Addressed Issues.
+
+ |
+
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual
+ system IDs (vsys ID) changes causing auto-commit failures with
+ validation errors. This occurs when the multi-vsys firewall has
+ virtual systems managed by Panorama, and the vsys ID sequence breaks
+ when unused virtual systems are deleted and the changes are pushed to
+ the firewall.
+
+ |
+
|
+ PAN-294436
+ |
+
+
+ (PA-410, PA-440, PA-450, and PA-460 firewalls)
+ After upgrading to 11.1.6-h6, the Eth1/2, Eth1/3, Eth1/8, and HA
+ interfaces (if configured) fail to display counters and statistics in
+ the CLI and SNMP.
+
+ |
+
|
+ PAN-294179
+ This issue is now resolved. See PAN-OS 11.1.6-h17 Addressed Issues.
+ |
+ + On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. + | +
|
+ PAN-293673
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+ + When the firewall generates a high volume of logs and attempts to export + these logs to an FTP server, it may consume excessive memory leading to + all PAN-OS processes crashing. + | +
|
+ PAN-292202
+ |
+
+
+ The system logs repeatedly displayed the alert `Clearing snmpd.log due
+ to log overflow` due to the SNMP counters rolling over. This is a
+ benign message and does not impact device functionality.
+
+ |
+
|
+ PAN-291288
+ |
+ + An active firewall might unexpectedly reboot due to a + pan_task crash caused by a page + allocation failure. This issue is observed after a period of runtime + with traffic and telemetry collection. + | +
|
+ PAN-290996
+
+ This issue is now resolved. See
+ PAN-OS 11.1.6-h14 Addressed Issues,
+ PAN-OS 11.1.7-h1 Addressed Issues, and
+ PAN-OS 11.1.10-h1 Addressed Issues
+
+ |
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS)
+ counters incorrectly return a value of 0 for each virtual system
+ (VSYS), despite the firewall actively processing connections.
+
+ |
+
|
+ PAN-290235
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues.
+
+ |
+
+
+ The
+ dscd
+ process crashes continuously on MIPS platforms (for example, PA-850
+ firewalls) due to a runtime error related to an invalid memory address
+ or nil pointer dereference. This occurs when the golang library
+ upgrade in CIE is not compatible with the MIPS platform.
+
+ |
+
|
+ PAN-290088
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues.
+
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-289383
+ |
+
+
+ (PA-800 series firewalls only) Upgrading
+ firewalls to PAN-OS 11.0 or later causes SFP ports to go
+ non-operational when the firewall uses forced port mode and the
+ connected peer device operates without auto-negotiation.
+
+
+ Workaround: Enable auto-negotiation on the
+ connected peer firewall.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See
+ PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ Routed process may stop responding after changing MTU or any link
+ parameters when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-287056
+
+ This issue is now resolved. See PAN-OS 11.1.6-h14 Addressed Issues
+
+ |
+
+
+ A BGP export policy rule that matches on a next hop fails to block the
+ advertisement of static routes, and the firewall incorrectly matches
+ the egress interface IP address instead of the original next-hop IP
+ address of the static route, which causes the deny rule to fail.
+
+ |
+
|
+ PAN-286897
+
+ This issue is now resolved. See PAN-OS 11.1.6-h10 Addressed Issues
+ and
+ PAN-OS 11.1.10 Addressed Issues.
+
+ |
+
+
+ The
+ pan_task
+ process might fail when the firewall attempts to forward files to the
+ WildFire public cloud, which can cause the dataplane to experience
+ heartbeat failures.
+
+
+ Workaround: Disable the firewall WildFire Analysis
+ profile.
+
+ |
+
|
+ PAN-286848
+ |
+
+
+ ECMP incorrectly balances sessions across links based on the
+ configured metric, which leads to an imbalance in traffic distribution
+ and results in traffic assignment shifting disproportionately to
+ routes with lower metrics.
+
+ |
+
|
+ PAN-286496
+ |
+
+
+ (NGFW Clusters) URL-continue and override
+ continue selections will function like a general URL-block action.
+
+ |
+
|
+ PAN-286306
+
+ This issue is now resolved. See PAN-OS 11.1.6-h14 Addressed Issues
+
+ |
+
+
+ When getting transceiver information from ESCC for SFP 25G modules,
+ the transceiver code incorrectly displays
+ Unknown instead of
+ 25GBase-SR.
+
+ |
+
|
+ PAN-286255
+
+ This issue affects PAN-OS 11.1.6-h4
+
+
+ This issue is now resolved. See PAN-OS 11.1.6-h7 Addressed Issues.
+
+ |
+
+
+ When a firewall receives an unexpected termination request for certain
+ SSL sessions , NGFW dataplane might experience a slow buffer resource
+ leak.
+
+
+ Workaround: Disable accumulation proxy on the
+ NGFW.
+
+ |
+
|
+ PAN-286231
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-285894
+ |
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may
+ occur, which could result in firewall reboots.
+
+
+ Workaround: Disable the Preserve Pre-NAT feature
+ using the
+ set deviceconfig setting preserve-prenat-feature no
+ CLI command.
+
+ |
+
|
+ PAN-285590
+ |
+
+
+ VM-Series firewalls deployed behind an AWS GWLB might experience 100%
+ dataplane CPU utilization when an Anti-Spyware profile is applied to
+ traffic.
+
+ |
+
|
+ PAN-283467
+
+ This issue is now resolved. See PAN-OS 11.1.6-h10 Addressed Issues.
+
+ |
+
+
+ (PA-3400 Series firewalls only) The firewall
+ might unexpectedly reboot and enter maintenance mode due to a
+ ctd-agent
+ out-of-memory (OOM) condition when undergoing advanced services load
+ testing with a high volume of IoT EAL log forwarding.
+
+
+ Workaround: Limit the number of EAL logs generated
+ by the firewall using the following CLI command:
+ debug iot eal key-value EAL_PENDING_BYTES=1000.
+
+ |
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-282854
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ The Elasticsearch cluster fails to start after deploying dedicated log
+ collectors in a multi-collector environment.
+
+ Workaround: Restart all the involved log collectors.
+ |
+
|
+ PAN-282236
+ (PAN-OS 11.1.6-h3 only)
+
+ This issue is now resolved. See
+ PAN-OS 11.1.6-h4 Addressed Issues.
+
+ |
+
+
+ The firewall doesn't reassemble IPv6 packets correctly after they are
+ fragmented. IPv6 SSL sessions may not be established if the client
+ hello arrives in multiple segments.
+
+ |
+
|
+ PAN-281885
+ |
+
+
+ When exporting and importing the CSV file, the hash values of
+ pre-shared key (PSK) variables set at template and template stack
+ levels inconsistently change, resulting in both variables displaying
+ the same hash value.
+
+ |
+
|
+ PAN-280532
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues.
+
+ |
+
+
+ When you use a single syslog server over TCP for log forwarding, and
+ the connectivity to the syslog server breaks, syslog forwarding does
+ not resume even after the connectivity to the server restores.
+
+
+ Workaround: Performing one of the following tasks:
+
+
|
+
|
+ PAN-280471
+ |
+
+
+ When applying filters or searching for logs in the
+ section, you might experience slow performance.
+
+ |
+
|
+ PAN-279901
+ |
+
+
+ When decryption is enabled, segmented Client Hello packets can cause
+ website access issues and memory leaks under the following conditions:
+
+
+ To enable this fix, run the CLI command
+ bug dataplane set ssl-decrypt accumulate-client-hello disjoined
+ yes
+
+ |
+
|
+ PAN-279746
+ (PAN-OS 11.1.6-h3 only)
+
+ This issue is now resolved. See
+ PAN-OS 11.1.6-h4 Addressed Issues.
+
+ |
+
+
+ An SSL/TLS Client Hello may not be transmitted out of the firewall if
+ the Client Hello arrives in multiple TCP segments and the traffic is
+ not subject to SSL decryption (for example, SMTP over SSL).
+
+ |
+
|
+ PAN-279621
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues.
+
+ |
+
+
+ Early aging and removal of firewall session while they are still
+ active can lead to intermittent instabilities and crashes for proxy
+ traffic, the Content and Threat detection engine, and any data-path
+ processing.
+
+ |
+
|
+ PAN-279604
+ (PAN-OS 11.1.6-h1 only)
+ |
+
+
+ The scheduled SaaS application usage reports are incorrectly generated
+ and only the login page appears instead of the intended report
+ content.
+
+ |
+
|
+ PAN-279415
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ Service routes configured for a data plane interface might incorrectly
+ route traffic through the management plane interface instead. This
+ issue impacts Syslog and CRL status traffic when the service route
+ lacks a specific destination custom service route.
+
+ |
+
|
+ PAN-278322
+ |
+
+
+ VM-Series firewalls deployed behind an AWS GWLB might display an
+ incorrect or empty Source User field in traffic logs and session
+ details.
+
+ |
+
|
+ PAN-278296
+
+ (This issue affects PAN-OS 11.1.6-h6.)
+
+
+ This issue is now resolved. See PAN-OS 11.1.6-h6 Addressed Issues.
+
+ |
+
+
+ The system MAC address of the aggregate interface is the same on both
+ the active and the passive devices, causing some packets to be sent
+ incorrectly to the passive device. This is causing the AE interface on
+ the active firewall to not come up.
+
+ |
+
|
+ PAN-277417
+ Thibx
+ |
+
+
+ Memory leak issues can occur during the parsing of server certificates
+ used for SSL Inbound Inspection, preventing the firewall from
+ completing inspection.
+
+ |
+
|
+ PAN-277090
+ |
+
+
+ When you enable Advanced Routing and configure a BGP Authentication
+ profile, if you configure a Secret that includes any special
+ characters apart from these seven special characters !@#%^_-, an error
+ message displays, indicating that
+ The value in this field is invalid.
+
+
+ Workaround: Don't include any special character
+ apart from the !@#%^_- characters in the Secret for a BGP
+ Authentication profile.
+
+ |
+
|
+ PAN-277034
+
+ This issue is now resolved. See PAN-OS 11.1.10-h5 Addressed Issuesand
+ PAN-OS 11.1.6-h19 Addressed Issues
+
+ |
+ + WildFire reports might not fully display or be downloadable because some + static resources fail to load. + | +
|
+ PAN-276920
+ |
+
+
+ URL filtering response pages may load slowly or fail to display when
+ users request websites that are blocked in the URL Filtering profile
+ (site access for the corresponding URL category is
+ block,
+ continue, or
+ override) attached to the matching
+ Security policy rule. This occurs on an intermittent basis.
+
+ |
+
|
+ PAN-275905
+ (PAN-OS 11.1.6-h3 only)
+ |
+
+
+ A high volume of incoming logs to a Collector Group can significantly
+ increase CPU usage on the Elasticsearch and Management Server,
+ potentially causing process instability or crashes.
+
+ |
+
|
+ PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues
+
+ |
+
+
+ When Panorama is not internet-connected and you try to upload images
+ to the managed firewalls by using the
+ Validate option, the upload fails
+ with the following error:
+ Failed to create multi-upload job. No valid software deploy targets
+ found.
+
+ |
+
|
+ PAN-275047
+ |
+
+
+ (VM-Series firewalls only) After an upgrade,
+ the firewall is unable to send logs to the Strata Logging Service
+ (SLS) when using a specific proxy server, and the SSL connection
+ status displays as failed when attempting to forward logs through the
+ web proxy.
+
+ |
+
|
+ PAN-274146
+ |
+
+
+ VM-Series firewalls deployed behind an AWS GWLB might crash and reboot
+ unexpectedly if tunnel sessions are moving through the firewall.
+
+ |
+
|
+ PAN-272085
+
+ (This issue affects PAN-OS 11.1.6-h3.)
+
+ |
+
+
+ When DoH is enabled for DNS Security, multiple DoH transactions in a
+ single HTTP/1 connection might unexpectedly cause the firewall to
+ crash and reboot.
+
+
+ Workaround: Manually disable DoH support for DNS
+ Security using the
+ set deviceconfig setting dns-over-https enable no
+ CLI command. Alternatively, you can remove the DNS Security
+ configuration used to handle DoH traffic.
+
+ |
+
|
+ PAN-269193
+
+ This issue is now resolved. See PAN-OS 11.1.8 Addressed Issues.
+
+ |
+
+
+ When multiple application are configured for GlobalProtect Clientless
+ VPN, users are directed to the first application instead of portal
+ page with a list of application.
+
+ |
+
|
+ PAN-268705
+
+ This issue is now resolved. See PAN-OS 11.1.6-h10 Addressed Issues.
+
+ |
+
+
+ The firewall intermittently fails to process FTP traffic.
+
+
+ Workaround: Configure an application override
+ policy rule for FTP applications.
+
+ |
+
|
+ PAN-262556
+ |
+
+
+ The ElasticSearch cluster health status might continue to remain
+ yellow for an extended period after upgrading to PAN-OS 11.1
+
+ |
+
|
+ PAN-261429
+
+ This issue is now resolved. See PAN-OS 11.1.6-h10 Addressed Issues
+ and
+ PAN-OS 11.1.8 Addressed Issues.
+
+ |
+
+
+ The command
+ show auth radius-require-msg-authentic
+ might return no output.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-254240
+ |
+
+
+ In the event of an HSCI flap on an NGFW cluster node, traffic
+ reconvergence takes three to four seconds.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
|
+ PAN-252358
+ |
+
+
+ (PA-7500 Series firewalls only) In the event of
+ a corosync restart, an NGFW cluster node goes to failed state.
+
+ |
+
|
+ PAN-251551
+ |
+
+
+ (PA-7500 Series firewalls only) When an NGFW
+ cluster agent crashes and doesn't recover, leader election will take
+ approximately 45 seconds to begin and traffic failover will occur
+ during that time.
+
+ |
+
|
+ PAN-250903
+ |
+
+
+ (PA-7500 Series firewalls only) In a congestion
+ scenario on an HSCI port of an NGFW cluster node, the QoS priorities
+ of cross node traffic streams might be reversed if you're using the
+ default QoS profile with class1 to class8 set as high to low.
+
+ |
+
|
+ PAN-247974
+ |
+
+
+ (PA-7500 Series firewalls only) LACP flap is
+ expected during a device failover in an NGFW cluster due to an L2
+ ctrld restart on the new leader node.
+
+ |
+
|
+ PAN-240529
+
+ This issue is now resolved. See
+ PAN-OS 11.1.7 Addressed Issues
+
+ |
+
+
+ (PA-7500 Series firewalls only) Cloud
+ application information is missing from traffic logs on NGFW cluster
+ nodes.
+
+ |
+
|
+ PAN-237106
+
+ This issue is now resolved. See PAN-OS 11.1.8 Addressed Issues
+
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-224502
+ |
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0
+ might take longer than expected.
+
+ |
+
|
+ PAN-220180
+ |
+
+
+ Configured botnet reports () are not generated.
+
+ |
+
|
+ PAN-207733
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if
+ the DHCPv6 server goes down, after the lease time expires, the DHCPv6
+ client should enter SOLICIT state on both the Active and Passive
+ firewalls. Instead, the client is stuck in BOUND state with an IPv6
+ address having lease time 0 on the Passive firewall.
+
+ |
+
|
+ PAN-207611
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the
+ Passive firewall sometimes crashes.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-207040
+ |
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade
+ from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
+ commits fail and SD-WAN devices on Panorama have no Virtual Router
+ name.
+
+ |
+
|
+ PAN-206913
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls,
+ releasing the IPv6 address from the client (using Release in the UI or
+ using the
+ request dhcp client ipv6 release all
+ CLI command) releases the IPv6 address from the Active firewall, but
+ not the Passive firewall.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-194978
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , hovering the mouse over a power over Ethernet (PoE)
+ Link State icon does not display
+ link speed and link duplex details.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-184708
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
|
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ PAN-164885
+ |
+
+
+ On the Panorama management server, pushes to managed firewalls (
+ or Commit and Push) may fail when an
+ EDL () is configured to
+ Check for updates every 5 minutes
+ due to the commit and EDL fetch processes overlapping. This is more
+ likely to occur when multiple EDLs are configured to check for updates
+ every 5 minutes.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-308564
+ |
+
+
+ Packets are dropped on SD-WAN interfaces if they require fragmentation
+ for an interface but have the
+ Don't Fragment (DF) bit set. This
+ results in unexpected packet drops. This affects client to server
+ sessions when using SD-WAN for NGFW.
+
+
+ Workaround: Allow fragmenting packets with DF bit
+ set (debug dataplane set ip4-ignore-df yes).
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See
+ PAN-OS 11.1.13-h1 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push might
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-304576
+ |
+
+
+ Traffic interruption may occur when inspection of HTTP/2 traffic is
+ enabled.
+
+
+ Workaround: Disable HTTP/2 server push using the
+ set deviceconfig setting http2 server-push no
+ CLI command.
+
+ |
+
|
+ PAN-303051
+ This issue is now resolved. See
+ PAN-OS 11.1.13 Addressed Issues
+ |
+ + The reportd process experiences a memory + leak because it retains memory that was temporarily used for report + generation. Once a task is complete, the process fails to release this + memory for reuse, leading to continuous accumulation and eventual memory + exhaustion on the Panorama device. + | +
|
+ PAN-298505
+
+ This issue is now resolved. See
+ PAN-OS 11.1.10-h7 Addressed Issues
+ and
+ PAN-OS 11.1.12 Addressed Issues
+
+ |
+
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual
+ system IDs (vsys ID) changes causing auto-commit failures with
+ validation errors. This occurs when the multi-vsys firewall has
+ virtual systems managed by Panorama, and the vsys ID sequence breaks
+ when unused virtual systems are deleted and the changes are pushed to
+ the firewall.
+
+ |
+
|
+ PAN-294179
+
+ This issue is now resolved. See PAN-OS 11.1.10-h4 Addressed Issues.
+
+ |
+ + On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. + | +
|
+ PAN-293673
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+ + When the firewall generates a high volume of logs and attempts to export + these logs to an FTP server, it may consume excessive memory leading to + all PAN-OS processes crashing. + | +
|
+ PAN-292202
+ |
+
+
+ The system logs repeatedly displayed the alert `Clearing snmpd.log due
+ to log overflow` due to the SNMP counters rolling over. This is a
+ benign message and does not impact device functionality.
+
+ |
+
|
+ PAN-291288
+ |
+ + An active firewall might unexpectedly reboot due to a + pan_task crash caused by a page + allocation failure. This issue is observed after a period of runtime + with traffic and telemetry collection. + | +
|
+ PAN-290996
+
+ This issue is now resolved. See PAN-OS 11.1.7-h1 Addressed Issues
+ and
+ PAN-OS 11.1.10-h1 Addressed Issues
+
+ |
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS)
+ counters incorrectly return a value of 0 for each virtual system
+ (VSYS), despite the firewall actively processing connections.
+
+ |
+
|
+ PAN-290235
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues.
+
+ |
+
+
+ The
+ dscd
+ process crashes continuously on MIPS platforms (for example, PA-850
+ firewalls) due to a runtime error related to an invalid memory address
+ or nil pointer dereference. This occurs when the golang library
+ upgrade in CIE is not compatible with the MIPS platform.
+
+ |
+
|
+ PAN-290088
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-289383
+ |
+
+
+ (PA-800 series firewalls only) Upgrading
+ firewalls to PAN-OS 11.0 or later causes SFP ports to go
+ non-operational when the firewall uses forced port mode and the
+ connected peer device operates without auto-negotiation.
+
+
+ Workaround: Enable auto-negotiation on the
+ connected peer firewall.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See
+ PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ Routed process may stop responding after changing MTU or any link
+ parameters when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-287056
+
+ This issue is now resolved. See PAN-OS 11.1.10-h1 Addressed Issues
+
+ |
+
+
+ A BGP export policy rule that matches on a next hop fails to block the
+ advertisement of static routes, and the firewall incorrectly matches
+ the egress interface IP address instead of the original next-hop IP
+ address of the static route, which causes the deny rule to fail.
+
+ |
+
|
+ PAN-286897
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues.
+
+ |
+
+
+ The
+ pan_task
+ process might fail when the firewall attempts to forward files to the
+ WildFire public cloud, which can cause the dataplane to experience
+ heartbeat failures.
+
+
+ Workaround: Disable the firewall WildFire Analysis
+ profile.
+
+ |
+
|
+ PAN-286848
+ |
+
+
+ ECMP incorrectly balances sessions across links based on the
+ configured metric, which leads to an imbalance in traffic distribution
+ and results in traffic assignment shifting disproportionately to
+ routes with lower metrics.
+
+ |
+
|
+ PAN-286496
+ |
+
+
+ (NGFW Clusters) URL-continue and override
+ continue selections will function like a general URL-block action.
+
+ |
+
|
+ PAN-286255
+
+ This issue affects PAN-OS 11.1.7-h2
+
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues.
+
+ |
+
+
+ When a firewall receives an unexpected termination request for certain
+ SSL sessions , NGFW dataplane might experience a slow buffer resource
+ leak.
+
+
+ Workaround: Disable accumulation proxy on the
+ NGFW.
+
+ |
+
|
+ PAN-286231
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-285894
+ |
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may
+ occur, which could result in firewall reboots.
+
+
+ Workaround: Disable the Preserve Pre-NAT feature
+ using the
+ set deviceconfig setting preserve-prenat-feature no
+ CLI command.
+
+ |
+
|
+ PAN-283467
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues.
+
+ |
+
+
+ (PA-3400 Series firewalls only) The firewall
+ might unexpectedly reboot and enter maintenance mode due to a
+ ctd-agent
+ out-of-memory (OOM) condition when undergoing advanced services load
+ testing with a high volume of IoT EAL log forwarding.
+
+
+ Workaround: Limit the number of EAL logs generated
+ by the firewall using the following CLI command:
+ debug iot eal key-value EAL_PENDING_BYTES=1000.
+
+ |
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-281885
+ |
+
+
+ When exporting and importing the CSV file, the hash values of
+ pre-shared key (PSK) variables set at template and template stack
+ levels inconsistently change, resulting in both variables displaying
+ the same hash value.
+
+ |
+
|
+ PAN-280532
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues.
+
+ |
+
+
+ When you use a single syslog server over TCP for log forwarding, and
+ the connectivity to the syslog server breaks, syslog forwarding does
+ not resume even after the connectivity to the server restores.
+
+
+ Workaround: Performing one of the following tasks:
+
+
|
+
|
+ PAN-279901
+ |
+
+
+ When decryption is enabled, segmented Client Hello packets can cause
+ website access issues and memory leaks under the following conditions:
+
+
+ To enable this fix, run the CLI command
+ bug dataplane set ssl-decrypt accumulate-client-hello disjoined
+ yes
+
+ |
+
|
+ PAN-279746
+
+ This issue is now resolved. See PAN-OS 11.1.8 Addressed Issues.
+
+ |
+
+
+ An SSL/TLS Client Hello may not be transmitted out of the firewall if
+ the Client Hello arrives in multiple TCP segments and the traffic is
+ not subject to SSL decryption (for example, SMTP over SSL).
+
+ |
+
|
+ PAN-279621
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues.
+
+ |
+
+
+ Early aging and removal of firewall session while they are still
+ active can lead to intermittent instabilities and crashes for proxy
+ traffic, the Content and Threat detection engine, and any data-path
+ processing.
+
+ |
+
|
+ PAN-279415
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ Service routes configured for a data plane interface might incorrectly
+ route traffic through the management plane interface instead. This
+ issue impacts Syslog and CRL status traffic when the service route
+ lacks a specific destination custom service route.
+
+ |
+
|
+ PAN-278296
+ |
+
+
+ The system MAC address of the aggregate interface is the same on both
+ the active and the passive devices, causing some packets to be sent
+ incorrectly to the passive device. This is causing the AE interface on
+ the active firewall to not come up.
+
+ |
+
|
+ PAN-277417
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues.
+
+ |
+
+
+ Memory leak issues can occur during the parsing of server certificates
+ used for SSL Inbound Inspection, preventing the firewall from
+ completing inspection.
+
+ |
+
|
+ PAN-277034
+
+ This issue is now resolved. See PAN-OS 11.1.10-h5 Addressed Issues
+
+ |
+ + WildFire reports might not fully display or be downloadable because some + static resources fail to load. + | +
|
+ PAN-276920
+ |
+
+
+ URL filtering response pages may load slowly or fail to display when
+ users request websites that are blocked in the URL Filtering profile
+ (site access for the corresponding URL category is
+ block,
+ continue, or
+ override) attached to the matching
+ Security policy rule. This occurs on an intermittent basis.
+
+ |
+
|
+ PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues
+
+ |
+
+
+ When Panorama is not internet-connected and you try to upload images
+ to the managed firewalls by using the
+ Validate option, the upload fails
+ with the following error:
+ Failed to create multi-upload job. No valid software deploy targets
+ found.
+
+ |
+
|
+ PAN-275047
+ |
+
+
+ (VM-Series firewalls only) After an upgrade,
+ the firewall is unable to send logs to the Strata Logging Service
+ (SLS) when using a specific proxy server, and the SSL connection
+ status displays as failed when attempting to forward logs through the
+ web proxy.
+
+ |
+
|
+ PAN-272085
+
+ This issue is now resolved. See PAN-OS 11.1.8 Addressed Issues.
+
+ |
+
+
+ When DoH is enabled for DNS Security, multiple DoH transactions in a
+ single HTTP/1 connection might unexpectedly cause the firewall to
+ crash and reboot.
+
+
+ Workaround: Manually disable DoH support for DNS
+ Security using the following CLI command:
+ set deviceconfig setting dns-over-https enable no. Alternatively, you can remove the DNS Security configuration used
+ to handle DoH traffic.
+
+ |
+
|
+ PAN-269193
+
+ This issue is now resolved. See PAN-OS 11.1.8 Addressed Issues.
+
+ |
+
+
+ When multiple application are configured for GlobalProtect Clientless
+ VPN, users are directed to the first application instead of portal
+ page with a list of application.
+
+ |
+
|
+ PAN-268705
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues..
+
+ |
+
+
+ The firewall intermittently fails to process FTP traffic.
+
+
+ Workaround: Configure an application override
+ policy rule for FTP applications.
+
+ |
+
|
+ PAN-262556
+ |
+
+
+ The ElasticSearch cluster health status might continue to remain
+ yellow for an extended period after upgrading to PAN-OS 11.1
+
+ |
+
|
+ PAN-261429
+
+ This issue is now resolved. See
+ PAN-OS 11.1.8 Addressed Issues.
+
+ |
+
+
+ The command
+ show auth radius-require-msg-authentic
+ might return no output.
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-254240
+ |
+
+
+ In the event of an HSCI flap on an NGFW cluster node, traffic
+ reconvergence takes three to four seconds.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
|
+ PAN-252358
+ |
+
+
+ (PA-7500 Series firewalls only) In the event of
+ a corosync restart, an NGFW cluster node goes to failed state.
+
+ |
+
|
+ PAN-251551
+ |
+
+
+ (PA-7500 Series firewalls only) When an NGFW
+ cluster agent crashes and doesn't recover, leader election will take
+ approximately 45 seconds to begin and traffic failover will occur
+ during that time.
+
+ |
+
|
+ PAN-250903
+ |
+
+
+ (PA-7500 Series firewalls only) In a congestion
+ scenario on an HSCI port of an NGFW cluster node, the QoS priorities
+ of cross node traffic streams might be reversed if you're using the
+ default QoS profile with class1 to class8 set as high to low.
+
+ |
+
|
+ PAN-247974
+ |
+
+
+ (PA-7500 Series firewalls only) LACP flap is
+ expected during a device failover in an NGFW cluster due to an L2
+ ctrld restart on the new leader node.
+
+ |
+
|
+ PAN-237106
+
+ This issue is now resolved. See PAN-OS 11.1.8 Addressed Issues
+
+ |
+
+
+ LSVPN satellite certificates may be generated with serial numbers
+ exceeding 40 hexadecimal characters. This causes certificate
+ revocation and deletion operations to fail with the following error
+ messages:
+
+
+ To resolve this issue, use the following CLI commands with the LSVPN
+ satellite serial number to manually delete or revoke the affected
+ certificates:
+
+
+ Delete certificate information:delete sslmgr-store certificate-info portal name
+ <name> serialno
+ <satellite_serial>
+
+
+ Revoke satellite certificates:delete sslmgr-store satellite-info-revoke-certificate portal
+ <name> serialno
+ <list_of_satellite_serials>
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-224502
+ |
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0
+ might take longer than expected.
+
+ |
+
|
+ PAN-220180
+ |
+
+
+ Configured botnet reports () are not generated.
+
+ |
+
|
+ PAN-219644
+ |
+
+
+ Firewalls forwarding logs to a syslog server over TLS () use the default Palo Alto Networks certificate instead of the
+ custom certificate configured on the firewall.
+
+ |
+
|
+ PAN-207733
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if
+ the DHCPv6 server goes down, after the lease time expires, the DHCPv6
+ client should enter SOLICIT state on both the Active and Passive
+ firewalls. Instead, the client is stuck in BOUND state with an IPv6
+ address having lease time 0 on the Passive firewall.
+
+ |
+
|
+ PAN-207611
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the
+ Passive firewall sometimes crashes.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-207040
+ |
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade
+ from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
+ commits fail and SD-WAN devices on Panorama have no Virtual Router
+ name.
+
+ |
+
|
+ PAN-206913
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls,
+ releasing the IPv6 address from the client (using Release in the UI or
+ using the
+ request dhcp client ipv6 release all
+ CLI command) releases the IPv6 address from the Active firewall, but
+ not the Passive firewall.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-194978
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , hovering the mouse over a power over Ethernet (PoE)
+ Link State icon does not display
+ link speed and link duplex details.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-184708
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
|
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-308564
+ |
+
+
+ Packets are dropped on SD-WAN interfaces if they require fragmentation
+ for an interface but have the
+ Don't Fragment (DF) bit set. This
+ results in unexpected packet drops. This affects client to server
+ sessions when using SD-WAN for NGFW.
+
+
+ Workaround: Allow fragmenting packets with DF bit
+ set (debug dataplane set ip4-ignore-df yes).
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See
+ PAN-OS 11.1.13-h1 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push might
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-304576
+ |
+
+
+ Traffic interruption may occur when inspection of HTTP/2 traffic is
+ enabled.
+
+
+ Workaround: Disable HTTP/2 server push using the
+ set deviceconfig setting http2 server-push no
+ CLI command.
+
+ |
+
|
+ PAN-303051
+ This issue is now resolved. See
+ PAN-OS 11.1.13 Addressed Issues
+ |
+ + The reportd process experiences a memory + leak because it retains memory that was temporarily used for report + generation. Once a task is complete, the process fails to release this + memory for reuse, leading to continuous accumulation and eventual memory + exhaustion on the Panorama device. + | +
|
+ PAN-298505
+
+ This issue is now resolved. See
+ PAN-OS 11.1.10-h7 Addressed Issues
+ and
+ PAN-OS 11.1.12 Addressed Issues
+
+ |
+
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual
+ system IDs (vsys ID) changes causing auto-commit failures with
+ validation errors. This occurs when the multi-vsys firewall has
+ virtual systems managed by Panorama, and the vsys ID sequence breaks
+ when unused virtual systems are deleted and the changes are pushed to
+ the firewall.
+
+ |
+
|
+ PAN-294179
+
+ This issue is now resolved. See PAN-OS 11.1.10-h4 Addressed Issues.
+
+ |
+ + On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. + | +
|
+ PAN-293673
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+ + When the firewall generates a high volume of logs and attempts to export + these logs to an FTP server, it may consume excessive memory leading to + all PAN-OS processes crashing. + | +
|
+ PAN-292202
+ |
+
+
+ The system logs repeatedly displayed the alert `Clearing snmpd.log due
+ to log overflow` due to the SNMP counters rolling over. This is a
+ benign message and does not impact device functionality.
+
+ |
+
|
+ PAN-289432
+ |
+
+
+ Generating a certificate with the
+ block-private-key yes command on
+ Panorama fails with the error:
+
+
+ Could not get parameters for double encryption.
+ This occurred when the certificate was signed by an external
+ Certificate Authority (CA).
+
+ |
+
|
+ PAN-290996
+
+ This issue is now resolved. See PAN-OS 11.1.10-h1 Addressed Issues
+
+ |
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS)
+ counters incorrectly return a value of 0 for each virtual system
+ (VSYS), despite the firewall actively processing connections.
+
+ |
+
|
+ PAN-290235
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues.
+
+ |
+
+
+ The
+ dscd
+ process crashes continuously on MIPS platforms (for example, PA-850
+ firewalls) due to a runtime error related to an invalid memory address
+ or nil pointer dereference. This occurs when the golang library
+ upgrade in CIE is not compatible with the MIPS platform.
+
+ |
+
|
+ PAN-290088
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-289383
+ |
+
+
+ (PA-800 series firewalls only) Upgrading
+ firewalls to PAN-OS 11.0 or later causes SFP ports to go
+ non-operational when the firewall uses forced port mode and the
+ connected peer device operates without auto-negotiation.
+
+
+ Workaround: Enable auto-negotiation on the
+ connected peer firewall.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See
+ PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ Routed process may stop responding after changing MTU or any link
+ parameters when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-287056
+
+ This issue is now resolved. See PAN-OS 11.1.10-h1 Addressed Issues
+
+ |
+
+
+ A BGP export policy rule that matches on a next hop fails to block the
+ advertisement of static routes, and the firewall incorrectly matches
+ the egress interface IP address instead of the original next-hop IP
+ address of the static route, which causes the deny rule to fail.
+
+ |
+
|
+ PAN-286897
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues.
+
+ |
+
+
+ The
+ pan_task
+ process might fail when the firewall attempts to forward files to the
+ WildFire public cloud, which can cause the dataplane to experience
+ heartbeat failures.
+
+
+ Workaround: Disable the firewall WildFire Analysis
+ profile.
+
+ |
+
|
+ PAN-286848
+ |
+
+
+ ECMP incorrectly balances sessions across links based on the
+ configured metric, which leads to an imbalance in traffic distribution
+ and results in traffic assignment shifting disproportionately to
+ routes with lower metrics.
+
+ |
+
|
+ PAN-286496
+ |
+
+
+ (NGFW Clusters) URL-continue and override
+ continue selections will function like a general URL-block action.
+
+ |
+
|
+ PAN-286306
+
+ This issue is now resolved. See PAN-OS 11.1.10-h1 Addressed Issues
+
+ |
+
+
+ When getting transceiver information from ESCC for SFP 25G modules,
+ the transceiver code incorrectly displays
+ Unknown instead of
+ 25GBase-SR.
+
+ |
+
|
+ PAN-286255
+
+ This issue affects PAN-OS 11.1.7-h2
+
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues.
+
+ |
+
+
+ When a firewall receives an unexpected termination request for certain
+ SSL sessions , NGFW dataplane might experience a slow buffer resource
+ leak.
+
+
+ Workaround: Disable accumulation proxy on the
+ NGFW.
+
+ |
+
|
+ PAN-286231
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-285894
+ |
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may
+ occur, which could result in firewall reboots.
+
+
+ Workaround: Disable the Preserve Pre-NAT feature
+ using the
+ set deviceconfig setting preserve-prenat-feature no
+ CLI command.
+
+ |
+
|
+ PAN-283467
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues.
+
+ |
+
+
+ (PA-3400 Series firewalls only) The firewall
+ might unexpectedly reboot and enter maintenance mode due to a
+ ctd-agent
+ out-of-memory (OOM) condition when undergoing advanced services load
+ testing with a high volume of IoT EAL log forwarding.
+
+
+ Workaround: Limit the number of EAL logs generated
+ by the firewall using the following CLI command:
+ debug iot eal key-value EAL_PENDING_BYTES=1000.
+
+ |
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-282854
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ The Elasticsearch cluster fails to start after deploying dedicated log
+ collectors in a multi-collector environment.
+
+ Workaround: Restart all the involved log collectors.
+ |
+
|
+ PAN-281885
+ |
+
+
+ When exporting and importing the CSV file, the hash values of
+ pre-shared key (PSK) variables set at template and template stack
+ levels inconsistently change, resulting in both variables displaying
+ the same hash value.
+
+ |
+
|
+ PAN-280532
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues.
+
+ |
+
+
+ When you use a single syslog server over TCP for log forwarding, and
+ the connectivity to the syslog server breaks, syslog forwarding does
+ not resume even after the connectivity to the server restores.
+
+
+ Workaround: Performing one of the following tasks:
+
+
|
+
|
+ PAN-279901
+ |
+
+
+ When decryption is enabled, segmented Client Hello packets can cause
+ website access issues and memory leaks under the following conditions:
+
+
+ To enable this fix, run the CLI command
+ bug dataplane set ssl-decrypt accumulate-client-hello disjoined
+ yes
+
+ |
+
|
+ PAN-279621
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues.
+
+ |
+
+
+ Early aging and removal of firewall session while they are still
+ active can lead to intermittent instabilities and crashes for proxy
+ traffic, the Content and Threat detection engine, and any data-path
+ processing.
+
+ |
+
|
+ PAN-279415
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ Service routes configured for a data plane interface might incorrectly
+ route traffic through the management plane interface instead. This
+ issue impacts Syslog and CRL status traffic when the service route
+ lacks a specific destination custom service route.
+
+ |
+
|
+ PAN-277417
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues.
+
+ |
+
+
+ Memory leak issues can occur during the parsing of server certificates
+ used for SSL Inbound Inspection, preventing the firewall from
+ completing inspection.
+
+ |
+
|
+ PAN-277034
+
+ This issue is now resolved. See PAN-OS 11.1.10-h5 Addressed Issues
+
+ |
+ + |
|
+ PAN-276920
+ |
+
+
+ URL filtering response pages may load slowly or fail to display when
+ users request websites that are blocked in the URL Filtering profile
+ (site access for the corresponding URL category is
+ block,
+ continue, or
+ override) attached to the matching
+ Security policy rule. This occurs on an intermittent basis.
+
+ |
+
|
+ PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues
+
+ |
+
+
+ When Panorama is not internet-connected and you try to upload images
+ to the managed firewalls by using the
+ Validate option, the upload fails
+ with the following error:
+ Failed to create multi-upload job. No valid software deploy targets
+ found.
+
+ |
+
|
+ PAN-275047
+ |
+
+
+ (VM-Series firewalls only) After an upgrade,
+ the firewall is unable to send logs to the Strata Logging Service
+ (SLS) when using a specific proxy server, and the SSL connection
+ status displays as failed when attempting to forward logs through the
+ web proxy.
+
+ |
+
|
+ PAN-268705
+
+ This issue is now resolved. See PAN-OS 11.1.9 Addressed Issues.
+
+ |
+
+
+ The firewall intermittently fails to process FTP traffic.
+
+
+ Workaround: Configure an application override
+ policy rule for FTP applications.
+
+ |
+
|
+ PAN-262556
+ |
+
+
+ The ElasticSearch cluster health status might continue to remain
+ yellow for an extended period after upgrading to PAN-OS 11.1
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-254240
+ |
+
+
+ In the event of an HSCI flap on an NGFW cluster node, traffic
+ reconvergence takes three to four seconds.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
|
+ PAN-251551
+ |
+
+
+ When an NGFW cluster agent crashes and doesn't recover, leader
+ election will take approximately 45 seconds to begin and traffic
+ failover will occur during that time.
+
+ |
+
|
+ PAN-250903
+ |
+
+
+ In a congestion scenario on an HSCI port of an NGFW cluster node, the
+ QoS priorities of cross node traffic streams might be reversed if
+ you're using the default QoS profile with class1 to class8 set as high
+ to low.
+
+ |
+
|
+ PAN-247974
+ |
+
+
+ LACP flap is expected during a device failover in an NGFW cluster due
+ to an L2 ctrld restart on the new leader node.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-224502
+ |
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0
+ might take longer than expected.
+
+ |
+
|
+ PAN-220180
+ |
+
+
+ Configured botnet reports () are not generated.
+
+ |
+
|
+ PAN-207733
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if
+ the DHCPv6 server goes down, after the lease time expires, the DHCPv6
+ client should enter SOLICIT state on both the Active and Passive
+ firewalls. Instead, the client is stuck in BOUND state with an IPv6
+ address having lease time 0 on the Passive firewall.
+
+ |
+
|
+ PAN-207611
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the
+ Passive firewall sometimes crashes.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-207040
+ |
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade
+ from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
+ commits fail and SD-WAN devices on Panorama have no Virtual Router
+ name.
+
+ |
+
|
+ PAN-206913
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls,
+ releasing the IPv6 address from the client (using Release in the UI or
+ using the
+ request dhcp client ipv6 release all
+ CLI command) releases the IPv6 address from the Active firewall, but
+ not the Passive firewall.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-194978
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , hovering the mouse over a power over Ethernet (PoE)
+ Link State icon does not display
+ link speed and link duplex details.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-184708
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
|
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-308564
+ |
+
+
+ Packets are dropped on SD-WAN interfaces if they require fragmentation
+ for an interface but have the
+ Don't Fragment (DF) bit set. This
+ results in unexpected packet drops. This affects client to server
+ sessions when using SD-WAN for NGFW.
+
+
+ Workaround: Allow fragmenting packets with DF bit
+ set (debug dataplane set ip4-ignore-df yes).
+
+ |
+
|
+ PAN-304756
+
+ This issue is now resolved. See
+ PAN-OS 11.1.13-h1 Addressed Issues.
+
+ |
+
+
+ After you disable the shared optimization feature in Panorama, ensure
+ that you perform a full configuration push to all managed multi-vsys
+ devices to re-establish a baseline. Failure to include every device
+ group associated with the multi-vsys device during this push might
+ result in incomplete or inconsistent configurations across virtual
+ systems.
+
+ |
+
|
+ PAN-304576
+ |
+
+
+ Traffic interruption may occur when inspection of HTTP/2 traffic is
+ enabled.
+
+
+ Workaround: Disable HTTP/2 server push using the
+ set deviceconfig setting http2 server-push no
+ CLI command.
+
+ |
+
|
+ PAN-303051
+ This issue is now resolved. See
+ PAN-OS 11.1.13 Addressed Issues
+ |
+
+
+ The reportd process experiences a
+ memory leak because it retains memory that was temporarily used for
+ report generation. Once a task is complete, the process fails to
+ release this memory for reuse, leading to continuous accumulation and
+ eventual memory exhaustion on the Panorama device.
+
+ |
+
|
+ PAN-298505
+
+ This issue is now resolved. See
+ PAN-OS 11.1.10-h7 Addressed Issues
+ and
+ PAN-OS 11.1.12 Addressed Issues
+
+ |
+
+
+ After upgrading multi-vsys firewalls, the sequence of the virtual
+ system IDs (vsys ID) changes causing auto-commit failures with
+ validation errors. This occurs when the multi-vsys firewall has
+ virtual systems managed by Panorama, and the vsys ID sequence breaks
+ when unused virtual systems are deleted and the changes are pushed to
+ the firewall.
+
+ |
+
|
+ PAN-294179
+
+ This issue is now resolved. See PAN-OS 11.1.10-h4 Addressed Issues.
+
+ |
+ + On the Panorama Config Audit page, + some commit versions might display incorrect or missing data. Fields + such as, COMMITTED BY, + COMMIT DATE, and + OBJECT CHANGES + might not be visible for some commit versions. Sometimes, commit + versions can disappear after a refresh and the commit description field + might display corrupted characters. + | +
|
+ PAN-293673
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+ + When the firewall generates a high volume of logs and attempts to export + these logs to an FTP server, it may consume excessive memory leading to + all PAN-OS processes crashing. + | +
|
+ PAN-292202
+ |
+
+
+ The system logs repeatedly displayed the alert `Clearing snmpd.log due
+ to log overflow` due to the SNMP counters rolling over. This is a
+ benign message and does not impact device functionality.
+
+ |
+
|
+ PAN-289432
+ |
+
+
+ Generating a certificate with the
+ block-private-key yes command on
+ Panorama fails with the error:
+
+
+ Could not get parameters for double encryption.
+ This occurred when the certificate was signed by an external
+ Certificate Authority (CA).
+
+ |
+
|
+ PAN-290235
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues.
+
+ |
+
+
+ The
+ dscd
+ process crashes continuously on MIPS platforms (for example, PA-850
+ firewalls) due to a runtime error related to an invalid memory address
+ or nil pointer dereference. This occurs when the golang library
+ upgrade in CIE is not compatible with the MIPS platform.
+
+ |
+
|
+ PAN-290088
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ When pushing configurations from Panorama to a firewall, a memory leak
+ might occur in the firewall's
+ configd process, particularly when the
+ configurations contain shared policies. Each configuration push causes
+ the configd process to consume
+ additional memory that is not released after the commit completes.
+
+ |
+
|
+ PAN-289383
+ |
+
+
+ (PA-800 series firewalls only) Upgrading
+ firewalls to PAN-OS 11.0 or later causes SFP ports to go
+ non-operational when the firewall uses forced port mode and the
+ connected peer device operates without auto-negotiation.
+
+
+ Workaround: Enable auto-negotiation on the
+ connected peer firewall.
+
+ |
+
|
+ PAN-288097
+
+ This issue is now resolved. See
+ PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ Routed process may stop responding after changing MTU or any link
+ parameters when OSPF and PIM are enabled on the same interface.
+
+ |
+
|
+ PAN-287056
+
+ This issue is now resolved. See PAN-OS 11.1.10-h1 Addressed Issues
+
+ |
+
+
+ A BGP export policy rule that matches on a next hop fails to block the
+ advertisement of static routes, and the firewall incorrectly matches
+ the egress interface IP address instead of the original next-hop IP
+ address of the static route, which causes the deny rule to fail.
+
+ |
+
|
+ PAN-286897
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues.
+
+ |
+
+
+ The
+ pan_task
+ process might fail when the firewall attempts to forward files to the
+ WildFire public cloud, which can cause the dataplane to experience
+ heartbeat failures.
+
+
+ Workaround: Disable the firewall WildFire Analysis
+ profile.
+
+ |
+
|
+ PAN-286848
+ |
+
+
+ ECMP incorrectly balances sessions across links based on the
+ configured metric, which leads to an imbalance in traffic distribution
+ and results in traffic assignment shifting disproportionately to
+ routes with lower metrics.
+
+ |
+
|
+ PAN-286496
+ |
+
+
+ (NGFW Clusters) URL-continue and override
+ continue selections will function like a general URL-block action.
+
+ |
+
|
+ PAN-286306
+
+ This issue is now resolved. See PAN-OS 11.1.10-h1 Addressed Issues
+
+ |
+
+
+ When getting transceiver information from ESCC for SFP 25G modules,
+ the transceiver code incorrectly displays
+ Unknown instead of
+ 25GBase-SR.
+
+ |
+
|
+ PAN-286231
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ When performing a partial Commit and Push on
+ Panorama, there is a risk that unintended configuration changes might
+ be pushed to a firewall.
+
+
+ This issue is more likely to occur in the following scenarios:
+
+
+ Workaround: Perform one of the following steps:
+
+
|
+
|
+ PAN-285894
+ |
+
+
+ If the Preserve Pre-NAT feature is enabled, dataplane crashes may
+ occur, which could result in firewall reboots.
+
+
+ Workaround: Disable the Preserve Pre-NAT feature
+ using the
+ set deviceconfig setting preserve-prenat-feature no
+ CLI command.
+
+ |
+
|
+ PAN-283467
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues.
+
+ |
+
+
+ (PA-3400 Series firewalls only) The firewall
+ might unexpectedly reboot and enter maintenance mode due to a
+ ctd-agent
+ out-of-memory (OOM) condition when undergoing advanced services load
+ testing with a high volume of IoT EAL log forwarding.
+
+
+ Workaround: Limit the number of EAL logs generated
+ by the firewall using the following CLI command:
+ debug iot eal key-value EAL_PENDING_BYTES=1000.
+
+ |
+
|
+ PAN-283429
+ |
+
+
+ When you use custom certificates for the connection between Panorama
+ and a log collector, the automated renewal for the predefined
+ ElasticSearch certificates gets disrupted.
+
+
+ Workaround: Remove the custom certificates before
+ the ElasticSearch certificates expire. This allows the system to
+ correctly identify and renew the predefined ElasticSearch
+ certificates. After the renewal is complete, re-install the custom
+ certificates.
+
+ |
+
|
+ PAN-282854
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ The Elasticsearch cluster fails to start after deploying dedicated log
+ collectors in a multi-collector environment.
+
+ Workaround: Restart all the involved log collectors.
+ |
+
|
+ PAN-280532
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues.
+
+ |
+
+
+ When you use a single syslog server over TCP for log forwarding, and
+ the connectivity to the syslog server breaks, syslog forwarding does
+ not resume even after the connectivity to the server restores.
+
+
+ Workaround: Performing one of the following tasks:
+
+
|
+
|
+ PAN-279901
+ |
+
+
+ When decryption is enabled, segmented Client Hello packets can cause
+ website access issues and memory leaks under the following conditions:
+
+
+ To enable this fix, run the CLI command
+ bug dataplane set ssl-decrypt accumulate-client-hello disjoined
+ yes
+
+ |
+
|
+ PAN-279415
+
+ This issue is now resolved. See PAN-OS 11.1.11 Addressed Issues
+
+ |
+
+
+ Service routes configured for a data plane interface might incorrectly
+ route traffic through the management plane interface instead. This
+ issue impacts Syslog and CRL status traffic when the service route
+ lacks a specific destination custom service route.
+
+ |
+
|
+ PAN-277034
+
+ This issue is now resolved. See PAN-OS 11.1.10-h5 Addressed Issues
+
+ |
+ + WildFire reports might not fully display or be downloadable because some + static resources fail to load. + | +
|
+ PAN-276920
+ |
+
+
+ URL filtering response pages may load slowly or fail to display when
+ users request websites that are blocked in the URL Filtering profile
+ (site access for the corresponding URL category is
+ block,
+ continue, or
+ override) attached to the matching
+ Security policy rule. This occurs on an intermittent basis.
+
+ |
+
|
+ PAN-275601
+
+ This issue is now resolved. See PAN-OS 11.1.10 Addressed Issues
+
+ |
+
+
+ When Panorama is not internet-connected and you try to upload images
+ to the managed firewalls by using the
+ Validate option, the upload fails
+ with the following error:
+ Failed to create multi-upload job. No valid software deploy targets
+ found.
+
+ |
+
|
+ PAN-275047
+ |
+
+
+ (VM-Series firewalls only) After an upgrade,
+ the firewall is unable to send logs to the Strata Logging Service
+ (SLS) when using a specific proxy server, and the SSL connection
+ status displays as failed when attempting to forward logs through the
+ web proxy.
+
+ |
+
|
+ PAN-262556
+ |
+
+
+ The ElasticSearch cluster health status might continue to remain
+ yellow for an extended period after upgrading to PAN-OS 11.1
+
+ |
+
|
+ PAN-260851
+ |
+
+
+ From the NGFW or Panorama CLI, you can override the existing
+ application tag even if Disable Override is enabled for the
+ application () tag.
+
+ |
+
|
+ PAN-254240
+ |
+
+
+ In the event of an HSCI flap on an NGFW cluster node, traffic
+ reconvergence takes three to four seconds.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ The auto commit job may take longer than expected to complete when the
+ Panorama management server is in Panorama or Log Collector mode.
+
+ |
+
|
+ PAN-251551
+ |
+
+
+ When an NGFW cluster agent crashes and doesn't recover, leader
+ election will take approximately 45 seconds to begin and traffic
+ failover will occur during that time.
+
+ |
+
|
+ PAN-250903
+ |
+
+
+ In a congestion scenario on an HSCI port of an NGFW cluster node, the
+ QoS priorities of cross node traffic streams might be reversed if
+ you're using the default QoS profile with class1 to class8 set as high
+ to low.
+
+ |
+
|
+ PAN-247974
+ |
+
+
+ LACP flap is expected during a device failover in an NGFW cluster due
+ to an L2 ctrld restart on the new leader node.
+
+ |
+
|
+ PAN-234015
+ |
+
+
+ The X-Forwarded-For (XFF) value is not displayed in traffic logs.
+
+ |
+
|
+ PAN-224502
+ |
+
+
+ The autocommit time of the VM-Series firewall running PAN-OS 11.1.0
+ might take longer than expected.
+
+ |
+
|
+ PAN-220180
+ |
+
+
+ Configured botnet reports () are not generated.
+
+ |
+
|
+ PAN-207733
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, if
+ the DHCPv6 server goes down, after the lease time expires, the DHCPv6
+ client should enter SOLICIT state on both the Active and Passive
+ firewalls. Instead, the client is stuck in BOUND state with an IPv6
+ address having lease time 0 on the Passive firewall.
+
+ |
+
|
+ PAN-207611
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls, the
+ Passive firewall sometimes crashes.
+
+ |
+
|
+ PAN-207442
+ |
+
+
+ For M-700 appliances in an active/passive high availability () configuration, the
+ active-primary HA peer
+ configuration sync to the
+ secondary-passive HA peer may
+ fail. When the config sync fails, the job Results is
+ Successful
+ (Tasks), however the sync status on
+ the Dashboard displays as
+ Out of Sync for both HA peers.
+
+
+ Workaround: Perform a local commit on the
+ active-primary HA peer and then
+ synchronize the HA configuration.
+
+
|
+
|
+ PAN-207040
+ |
+
+
+ If you disable Advanced Routing, remove logical routers, and downgrade
+ from PAN-OS 11.0.0 to a PAN-OS 10.2.x or 10.1.x release, subsequent
+ commits fail and SD-WAN devices on Panorama have no Virtual Router
+ name.
+
+ |
+
|
+ PAN-206913
+ |
+
+
+ When a DHCPv6 client is configured on HA Active/Passive firewalls,
+ releasing the IPv6 address from the client (using Release in the UI or
+ using the
+ request dhcp client ipv6 release all
+ CLI command) releases the IPv6 address from the Active firewall, but
+ not the Passive firewall.
+
+ |
+
|
+ PAN-206909
+ |
+
+
+ The Dedicated Log Collector is unable to reconnect to the Panorama
+ management server if the configd
+ process crashes. This results in the Dedicated Log Collector losing
+ connectivity to Panorama despite the managed collector connection
+ Status () displaying connected and the
+ managed colletor Health status
+ displaying as healthy.
+
+
+ This results in the local Panorama config and system logs not being
+ forwarded to the Dedicated Log Collector. Firewall log forwarding to
+ the disconnected Dedicated Log Collector is not impacted.
+
+
+ Workaround: Restart the
+ mgmtsrvr process on the Dedicated
+ Log Collector.
+
+
|
+
|
+ PAN-197588
+ |
+
+
+ The PAN-OS ACC (Application Command Center) does not display a widget
+ detailing statistics and data associated with vulnerability exploits
+ that have been detected using inline cloud analysis.
+
+ |
+
|
+ PAN-197419
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , the power over Ethernet (PoE) ports do not display a
+ Tag value.
+
+ |
+
|
+ PAN-196758
+ |
+
+
+ On the Panorama management server, pushing a configuration change to
+ firewalls leveraging SD-WAN erroneously show the auto-provisioned BGP
+ configurations for SD-WAN as being edited or deleted despite no edits
+ or deletions being made when you
+ Preview Changes (
+ or
+ ).
+
+ |
+
|
+ PAN-195968
+ |
+
+
+ (PA-1400 Series firewalls only) When using the
+ CLI to configure power over Ethernet (PoE) on a non-PoE port, the CLI
+ prints an error depending on whether an interface type was selected on
+ the non-PoE port or not. If an interface type, such as tap, Layer 2,
+ or virtual wire, was selected before PoE was configured, the error
+ message will not include the interface name (eg. ethernet1/4). If an
+ interface type was not selected before PoE was configured, the error
+ message will include the interface name.
+
+ |
+
|
+ PAN-194978
+ |
+
+
+ (PA-1400 Series firewalls only) In
+ , hovering the mouse over a power over Ethernet (PoE)
+ Link State icon does not display
+ link speed and link duplex details.
+
+ |
+
|
+ PAN-187685
+ |
+
+
+ On the Panorama management server, the Template Status displays no
+ synchronization status () after a bootstrapped firewall is successfully added to Panorama.
+
+
+ Workaround: After the bootstrapped firewall is
+ successfully added to Panorama,
+ log in to the Panorama web interface
+ and select
+ .
+
+ |
+
|
+ PAN-187407
+ |
+
+
+ The configured Advanced Threat Prevention inline cloud analysis action
+ for a given model might not be honored under the following condition:
+ If the firewall is set to
+ Hold client request for category lookup and the action set to
+ Reset-Both and the URL cache has
+ been cleared, the first request for inline cloud analysis will be
+ bypassed.
+
+ |
+
|
+ PAN-186283
+ |
+
+
+ Templates appear out-of-sync on Panorama after successfully deploying
+ the CFT stack using the Panorama plugin for AWS.
+
+
+ Workaround: Use
+
+ to synchronize the templates.
+
+ |
+
|
+ PAN-184708
+ |
+
+
+ Scheduled report emails () are not emailed if:
+
+
+ Workaround: To receive a scheduled report email
+ for all other PDF report types:
+
+
|
+
|
+ PAN-184406
+ |
+
+
+ Using the CLI to add a RAID disk pair to an M-700 appliance causes the
+ dmdb process to crash.
+
+
+ Workaround: Contact customer support to stop the
+ dmdb process before adding a RAID disk pair to a M-700 appliance.
+
+ |
+
|
+ PAN-183404
+ |
+
+
+ Static IP addresses are not recognized when "and" operators are used
+ with IP CIDR range.
+
+ |
+
|
+ PAN-181933
+ |
+
+
+ If you use multiple log forwarding cards (LFCs) on the PA-7000 series,
+ all of the cards may not receive all of the updates and the mappings
+ for the clients may become out of sync, which causes the firewall to
+ not correctly populate the Source User column in the session logs.
+
+ |
+