diff --git a/reference/PAN-OS/addressed/11.1.6-h1.html b/reference/PAN-OS/addressed/11.1.6-h1.html new file mode 100644 index 0000000..d39ab16 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.6-h1.html @@ -0,0 +1,875 @@ +
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-278088
+ |
+
+
+ Fixed an issue where the
+ show system resources follow CLI
+ command was not available.
+
+ |
+
|
+ PAN-276546
+ |
+
+
+ Fixed an issue where a session lost the PBF rule mapping after a
+ configuration change or commit.
+
+ |
+
|
+ PAN-273994
+ |
+
+
+ A fix was made to address
+ CVE-2025-0111.
+
+ |
+
|
+ PAN-273971
+ |
+
+
+ A fix was made to address
+ CVE-2025-0108.
+
+ |
+
|
+ PAN-273300
+ |
+
+
+ Fixed an issue on Panorama where upgrading to PAN-OS 11.0.4-h2 failed
+ with a validation error.
+
+ |
+
|
+ PAN-273278
+ |
+
+
+ A fix was made to address
+ CVE-2025-0109.
+
+ |
+
|
+ PAN-273245
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where upgrading an HA firewall pair from PAN-OS 10.2.11-h1 to
+ PAN-OS 11.1.5 caused the firewalls to enter a nonfunctional loop due
+ to repeated HA path monitoring failures.
+
+ |
+
|
+ PAN-273129
+ |
+
+
+ Fixed an issue on the web interface where the
+ negate option was visible when you
+ clicked on the rule name, but not when you viewed the target options
+ from the rulebase attribute.
+
+ |
+
|
+ PAN-273085
+ |
+
+
+ Fixed an issue on the web interface where you were unable to edit or
+ create policy rules.
+
+ |
+
|
+ PAN-273026
+ |
+
+
+ Fixed an issue where traffic logs did not display correctly when
+ filters were applied.
+
+ |
+
|
+ PAN-273021
+ |
+
+
+ Fixed an issue where 25G port links did not come up due to a change in
+ the handling of 25G DAC modules.
+
+ |
+
|
+ PAN-272959
+ |
+ + Fixed an issue where the firewall generated BGP update packets larger + than 1500 bytes when the interface MTU was 1500 bytes and jumbo frames + were enabled globally. + | +
|
+ PAN-272849
+ |
+
+
+ Fixed an issue where log forwarding to a UDP syslog server stopped
+ when an unreachable TCP syslog server was configured and applied.
+
+ |
+
|
+ PAN-272538
+ |
+
+
+ Fixed an issue where the
+ configd
+ process stopped responding during a commit-all validation when there
+ were uncommitted changes and
+ share-unused-objects-with-devices
+ was set to off.
+
+ |
+
|
+ PAN-272006
+ |
+
+
+ Fixed an issue where the firewall did not trigger a kernel core dump
+ as a large core when the CPLD (Complex Programmable Logic Device) sent
+ a Non-Maskable Interrupt (NMI) to the CPU.
+
+ |
+
|
+ PAN-271926
+ |
+
+
+ Fixed an issue where TLS 1.3 decryption failed with a bad record MAC
+ error when the firewall was configured to decrypt and inspect TLS
+ traffic.
+
+ |
+
|
+ PAN-271912
+ |
+
+
+ Fixed an issue on Panorama where the
+ configd
+ process stopped responding when filtering in the configuration audit
+ window after upgrading to PAN-OS 11.1.3.
+
+ |
+
|
+ PAN-271613
+ |
+
+
+ Fixed an issue where configuration pushes from Panorama to the
+ firewall failed due to an OOXML commit error.
+
+ |
+
|
+ PAN-271314
+ |
+
+
+ Fixed an issue where pushing changes to a prefix list used for BGP
+ from Panorama affected OSPF routes.
+
+ |
+
|
+ PAN-270607
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where OSPF failed to establish after a failover from
+ the active firewall to the passive firewall.
+
+ |
+
|
+ PAN-270549
+ |
+
+
+ Fixed an issue where some TLS connections were not handled correctly,
+ which led to instability in the dataplane.
+
+ |
+
|
+ PAN-270471
+ |
+
+
+ (Firewalls in active/active configurations only) Fixed an issue where the firewall did not detect configuration
+ changes when only the interface of an IKE gateway was changed, which
+ caused IPSec tunnels to not come up after migrating the IKE gateway IP
+ address from a subinterface to a physical interface.
+
+ |
+
|
+ PAN-269956
+ |
+
+
+ Fixed an issue where the
+ all_pktproc
+ process stopped responding, which caused internal path monitor
+ failures.
+
+ |
+
|
+ PAN-269899
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected when querying for device tags.
+
+ |
+
|
+ PAN-269737
+ |
+
+
+ Fixed an issue where the followig critical error displayed repeatedly:
+ /mnt/cdrom is mounted as Read-Only.
+
+ |
+
|
+ PAN-269731
+ |
+
+
+ Fixed an issue where Panorama did not display logs from firewalls
+ after upgrading to PAN-OS 10.2.11 on devices due to Elasticsearch (ES)
+ getting restarted continuously.
+
+ |
+
|
+ PAN-269499
+ |
+
+
+ Fixed an issue where the firewall stopped responding when receiving a
+ high number of logs.
+
+ |
+
|
+ PAN-269106
+ |
+
+
+ Fixed an issue where the
+ wifclient might crash during
+ server cert verification for MICA gRPC connections and cause the
+ dataplane to restart when using a cloud-based ML detection engine
+ (MICA). On certain platforms, this caused the firewall to reboot
+ periodically.
+
+ |
+
|
+ PAN-268972
+ |
+
+
+ Fixed an issue where Panorama was slower than expected when using a
+ high number of device group tags in a non-shared context.
+
+ |
+
|
+ PAN-268815
+ |
+
+
+ Fixed an issue that caused the firewall to reboot due to the
+ wifclient exiting multiple times
+ when using IoT Security.
+
+ |
+
|
+ PAN-268465
+ |
+
+
+ Fixed an issue with firewalls in active/passive HA configurations
+ where the the total user count in the registered users was different
+ between the active and passive firewall.
+
+ |
+
|
+ PAN-267781
+ |
+
+
+ Fixed an issue where Panorama did not display the
+ Source Dynamic Address Group.
+
+ |
+
|
+ PAN-267762
+ |
+
+
+ (Panorama virtual appliances in Management-Only mode) Fixed a issue where the maximum configuration size was lower than
+ expected.
+
+ |
+
|
+ PAN-267671
+ |
+
+
+ Fixed an issue where the firewall rebooted unexpectedly due to the
+ all_task process
+ restarting with an OOM condition due to a memory leak on the
+ reportd
+ process.
+
+ |
+
|
+ PAN-267662
+ |
+
+
+ Fixed an issue where the firewall experienced a memory out-of-bounds
+ access when the firewall was configured with SD-WAN and the SD-WAN
+ plugin was loading, which caused the firewall to stop responding and
+ drop VPN tunnels.
+
+ |
+
|
+ PAN-267097
+ |
+
+
+ Fixed an issue where the replay database size increased significantly
+ due to local and special configurations not being purged after
+ commits.
+
+ |
+
|
+ PAN-266354
+ |
+
+
+ Fixed an issue where Hybrid-SWG explicit proxy connections failed when
+ the number of destination domains exceeded 1024.
+
+ |
+
|
+ PAN-265745
+ |
+
+
+ Fixed an issue where the firewall displayed incorrect MAC receive
+ error counters for VMWare devices hosted in ESXi.
+
+ |
+
|
+ PAN-265219
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ GRE traffic did not work properly.
+
+ |
+
|
+ PAN-265179
+ |
+
+
+ Fixed an issue where a kernel race condition caused the firewall to
+ reboot with a kernel panic.
+
+ |
+
|
+ PAN-264423
+ |
+
+
+ Fixed an issue where the firewall sent a 503 response when a client
+ connected to a web server when the firewall was configured as a web
+ proxy and authentication bypass for Kerberos was enabled.
+
+ |
+
|
+ PAN-262946
+ |
+
+
+ Fixed an issue on the firewall where logging in via the CLI or web
+ interface did not work due to increased memory usage.
+
+ |
+
|
+ PAN-262383
+ |
+
+
+ Fixed an issue where the firewall was unable to decompress the HTTP2
+ header, which caused the session to be classified as unknown-tcp
+ instead of web-browsing.
+
+ |
+
|
+ PAN-260461
+ |
+
+
+ Fixed an issue where traffic logs showed a non-zero destination port
+ number on ICMP echo sessions through the firewall.
+
+ |
+
|
+ PAN-260290
+ |
+
+
+ Fixed an issue for fixed model licenses to support new content size
+ requirements by reducing the total sessions supported to be equivalent
+ to their flex memory counterpart.
+
+ |
+
|
+ PAN-260235
+ |
+
+
+ Fixed an issue where the firewall sent Threat logs and URL logs to an
+ external syslog server without Security profile settings when Enhanced
+ Application Logging was enabled.
+
+ |
+
|
+ PAN-260149
+ |
+
+
+ Fixed an issue where the management plane DNS cache size was lower
+ than expected.
+
+ |
+
|
+ PAN-259078
+ |
+
+
+ Fixed an issue where WildFire Analysis reports were not generated and
+ the following error message was displayed:
+ Error 500: Internal Server Error.
+
+ |
+
|
+ PAN-258149
+ |
+
+
+ Fixed an issue where the firewall dropped the SYN-ACK when using the
+ TCP Fast Open option.
+
+ |
+
|
+ PAN-255323
+ |
+
+
+ (PA-7050 firewalls only) Fixed an issue where
+ the Network Processing Card (NPC), Data Processing Card (DPC), and Log
+ forwarding Card (LFC) remained in a starting state after an unexpected
+ power cycle.
+
+ |
+
|
+ PAN-254904
+ |
+
+
+ Fixed an issue on Panorama where a core file was generated by
+ /usr/local/bin/logd during a restart.
+
+ |
+
|
+ PAN-254293
+ |
+
+
+ Fixed an issue where an explicit proxy caused intermittent SSL
+ handshake failures to SAP applications accessing public URLs.
+
+ |
+
|
+ PAN-252381
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected when opening interfaces, virtual routers, and zones in a
+ template or template stack.
+
+ |
+
|
+ PAN-251484
+ |
+
+
+ Fixed an issue where the firewall web interface displayed incorrect
+ PPPoE configuration options under the subinterface of an Aggregate
+ Ethernet interface.
+
+ |
+
|
+ PAN-250585
+ |
+
+
+ Fixed an issue where the firewall CPU use increased after upgrading
+ from PAN-OS 10.2.4-h4 to PAN-OS 10.2.8 due to a change in system
+ resource reporting by the REST API.
+
+ |
+
|
+ PAN-248508
+ |
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) environments
+ only) Fixed an issue where the firewall did not perform MSS clamping when
+ GWLB endpoints were mapped to static subinterfaces.
+
+ |
+
|
+ PAN-246699
+ |
+
+
+ Fixed an issue on Panorama where
+ Rule Usage and
+ Apps Seen under Security policy
+ rules stopped incrementing.
+
+ |
+
|
+ PAN-233647
+ |
+
+
+ Fixed an issue where Panorama management servers generated duplicate
+ configuration logs.
+
+ |
+
|
+ PAN-233581
+ |
+
+
+ Fixed an issue on firewalls in active/active HA configurations where
+ SYN+ACK packets of asymmetric TCP sessions were dropped because of a
+ session synchronization issue.
+
+ |
+
|
+ PAN-224152
+ |
+
+
+ Fixed an issue where device tags for devices in a child device group
+ were not available in the parent shared device group.
+
+ |
+
|
+ PAN-216054
+ |
+
+
+ Fixed an issue that caused the firewall's fan speed to increase while
+ it was idle.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-286897
+ |
+
+
+ Fixed an issue where the
+ pan_task
+ process stopped responding when the firewall attempted to forward
+ files to the WildFire public cloud, which caused the dataplane to
+ experience heartbeat failures.
+
+ |
+
|
+ PAN-285590
+ |
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) GWLB environments
+ only) Fixed an issue where the firewall CPU usage reached 100% after
+ upgrading to PAN-OS 11.1.6-h1.
+
+ |
+
|
+ PAN-284066
+ |
+
+
+ Fixed an issue where, after an upgrade, the SNMP polled values for
+ IF-MIB::ifInErrors displayed a
+ high number of errors that did not match the values in the CLI show
+ interface command.
+
+ |
+
|
+ PAN-283789
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where, after an upgrade, the
+ mac receive error counter in
+ receive incoming errors increased,
+ which resulted in SNMP alerts.
+
+ |
+
|
+ PAN-283467
+ |
+
+
+ (PA-3400 Series firewalls only) Fixed an issue
+ where the firewall unexpectedly rebooted and entered maintenance mode
+ due to a ctd-agent out-of-memory (OOM) condition. This occurred during
+ advanced services load testing and a high volume of IoT EAL log
+ forwarding.
+
+ |
+
|
+ PAN-282640
+ |
+
+
+ Fixed an issue where custom reports showed incomplete data when
+ exported in CSV format from Panorama.
+
+ |
+
|
+ PAN-280477
+ |
+
+
+ Fixed an issue on the web interface were you were unable to scroll up
+ or down to view source zones in a NAT policy rule.
+
+ |
+
|
+ PAN-280335
+ |
+
+
+ Fixed an issue with an SNMPv3 EngineBoots value discrepancy that
+ prevented to SNMP server from logging.
+
+ |
+
|
+ PAN-273614
+ |
+
+
+ Fixed an issue where packets were dropped initially when a SYN cookie
+ with activation threshold 0 was enabled.
+
+ |
+
|
+ PAN-272605
+ |
+
+
+ Fixed an issue where the firewall did not display VPC endpoints when
+ there was a large amount of VPC endpoints to interface mappings.
+
+ |
+
|
+ PAN-271560
+ |
+
+
+ Fixed an issue where DNS requests to malware sites were not blocked as
+ expected, and the
+ dns-security-categories log-level
+ and action displayed default values instead of
+ unavailable.
+
+ |
+
|
+ PAN-271152
+ |
+
+
+ (PA-7000 Series firewalls in HA configurations only) Fixed an issue where the firewall failed over into a non-functional
+ state, and the LFC LED was blinking on the passive firewall.
+
+ |
+
|
+ PAN-270849
+ |
+
+
+ Fixed a memory leak issue related to the
+ configd
+ process that occurred when running consecutive commits for multiple
+ days.
+
+ |
+
|
+ PAN-269193
+ |
+
+
+ Fixed an issue where the firewall redirected the user to the first
+ application instead of the portal page with a list of applications
+ when multiple applications were configured for GlobalProtect
+ clientless VPN along with any user match.
+
+ |
+
|
+ PAN-269139
+ |
+
+
+ (Firewalls with DPDK enabled in Azure, GCP, AWS, and KVM
+ environments only) Fixed an issue where, after an upgrade to PAN-OS 11.1.4, the
+ mac receive error counter increased
+ without an error even though traffic was not impacted.
+
+ |
+
|
+ PAN-264982
+ |
+
+
+ (VM-Series firewalls on KVM only) Fixed an
+ issue where the firewall entered maintenance mode after an auto-commit
+ when sending an ARP packet through the loopback interface using an
+ IPv6 address.
+
+ |
+
|
+ PAN-264477
+ |
+
+
+ Fixed an issue where the firewall did not start Elasticsearch after a
+ commit if Elasticsearch was not previously enabled and started.
+
+ |
+
|
+ PAN-261429
+ |
+
+
+ Fixed an issue where the
+ show auth radius-require-msg-authentic
+ command CLI displayed no output.
+
+ |
+
|
+ PAN-254524
+ |
+
+
+ Fixed an issue on Panorama where, when the
+ Commit and Push button was clicked
+ during a selective
+ Commit and Push operation, the
+ window stopped responding, which caused the operation to be delayed.
+
+ |
+
|
+ PAN-284116
+ |
+
+
+ Fixed an issue where mTLS decryption bypass did not work when the
+ decryption profile was configured with the maximum TLS version as TLS
+ 1.3.
+
+ |
+
|
+ PAN-281882
+ |
+
+
+ Fixed an issue where OSPF redistributed connected routes beyond the
+ intended loopback IP address.
+
+ |
+
|
+ PAN-280698
+ |
+
+
+ Fixed an issue where the firewall removed the TCP timestamp from
+ client hello messages that did not fit in a single packet, which
+ resulted in connection issues.
+
+ |
+
|
+ PAN-280532
+ |
+
+
+ Fixed an issue where, after disabling and re-enabling the external
+ syslog server, the TCP session was not resumed, which caused all logs
+ that were forwarded to the syslog server to be dropped.
+
+ |
+
|
+ PAN-279621
+ |
+
+
+ Fixed an issue where processes stopped responding when HTTPS Forward
+ traffic was run.
+
+ |
+
|
+ PAN-278981
+ |
+
+
+ Fixed an issue where DNS domain resolutions experienced intermittent
+ delays due to the firewall not connecting to the DNS Security cloud.
+
+ |
+
|
+ PAN-262373
+ |
+
+
+ Fixed an issue where the error message
+ Failed to reload config files
+ displayed in the system logs even when device telemetry was not
+ enabled.
+
+ |
+
|
+ PAN-277417
+ |
+
+
+ Fixed an memory leak issue related to TLS inbound decryption.
+
+ |
+
|
+ PAN-274806
+ |
+
+
+ (PA-5250 firewalls only) Fixed an issue where
+ IPv6 pings experienced a high number of dropped packets when forwarded
+ to another dataplane, which resulted in ping failures. This occurred
+ when initiating a ping to the link local address of the firewall and
+ the packet drop percentage depended on the number of dataplanes.
+
+ |
+
|
+ PAN-274569
+ |
+
+
+ Fixed an issue where the QSPF transceiver interface displayed an
+ incorrect range figure on the temperature alarm.
+
+ |
+
|
+ PAN-274496
+ |
+
+
+ Fixed an issue where the root partition reached 100% which caused the
+ system to become non-functional and failover even when aggressive
+ cleaning was enabled.
+
+ |
+
|
+ PAN-273422
+ |
+
+
+ Fixed an issue where traffic failed when Inline cloud analysis
+ (Advanced Threat Prevention) was enabled in the Anti-Spyware profile
+ with the action set to anything other than
+ allow or
+ alert and the maximum latency
+ condition was reached.
+
+ |
+
|
+ PAN-272812
+ |
+
+
+ Fixed an issue where SNMP monitoring of tunnel interfaces displayed
+ zero values for received bytes and packets.
+
+ |
+
|
+ PAN-271700
+ |
+
+
+ Fixed an issue where User-ID connections were lost after an HA
+ failover.
+
+ |
+
|
+ PAN-271184
+ |
+
+
+ Fixed an issue where Device Telemetry failed due to an issue with the
+ encoding of characters in the log file path.
+
+ |
+
|
+ PAN-271151
+ |
+
+
+ Fixed an issue where the GlobalProtect client did not automatically
+ initiate a Kerberos SSO connection after logging in to Windows.
+
+ |
+
|
+ PAN-270379
+ |
+
+
+ Fixed an issue where socket files created in the /tmp directory were
+ not cleared.
+
+ |
+
|
+ PAN-270192
+ |
+
+
+ Fixed an issue where Panorama did not display the management IP
+ address of devices onboarded via ZTP.
+
+ |
+
|
+ PAN-268705
+ |
+
+
+ Fixed an intermittent issue where the firewall failed to process FTP
+ traffic after upgrading to PAN-OS 10.1.14.
+
+ |
+
|
+ PAN-267707
+ |
+
+
+ Fixed an issue where BFD sessions did not come up even when BGP
+ peering was established.
+
+ |
+
|
+ PAN-267001
+ |
+
+
+ Fixed an issue where multicast streams were unstable with ECMP and
+ dropped every 30 seconds.
+
+ |
+
|
+ PAN-266704
+ |
+
+
+ Fixed an issue where filtering BGP routes by peer name in Advanced
+ Routing Engine (ARE) did not display the correct routes.
+
+ |
+
|
+ PAN-266574
+ |
+
+
+ Fixed an issue where users were unable connect to the portal due to
+ Certificate Revocation List (CRL) checks due to the downloaded CRL
+ file being expired, which caused the CRL cache to be bypassed.
+
+ |
+
|
+ PAN-266312
+ |
+
+
+ Fixed an issue where BFD sessions took longer than expected to
+ establish after an HA failover due to BGP.
+
+ |
+
|
+ PAN-261999
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where enabling flow basic on firewalls caused ARP
+ entries to be removed on both firewalls.
+
+ |
+
|
+ PAN-261570
+ |
+
+
+ (Firewalls in active/active HA configurations only) Fixed an issue where packet loss occurred when dataport was used
+ for HA3 for asymmetrically routed traffic during commits and a virtual
+ wire was configured.
+
+ |
+
|
+ PAN-260229
+ |
+
+
+ Fixed an issue where HA path monitoring using VWire did not work as
+ expected after a reboot.
+
+ |
+
|
+ PAN-257442
+ |
+
+
+ A fix was made to address
+ CVE-2025-0123.
+
+ |
+
|
+ PAN-245064
+ |
+
+
+ (Multi-vsys firewalls only) Fixed an issue
+ where commits failed on the firewall after selecting
+ Export or push device config bundle
+ on Panorama and a force push was required.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-290996
+ |
+
+
+ Fixed an issue where SNMP walks returned a value of 0 for the CPS
+ (Connections Per Second) per vsys on firewalls after upgrading to
+ PAN-OS 11.1.6-h3, even when active connections were present.
+
+ |
+
|
+ PAN-290803
+ |
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where firewall failed to bootstrap with a custom
+ image, and VM-Series plugin information was not displayed in the
+ system information.
+
+ |
+
|
+ PAN-290239
+ |
+
+
+ (PA-455 firewalls in active/passive HA configurations only) Fixed an issue where, after an upgrade, the TCP session for syslog
+ forwarding did not resume after the syslog server service was disabled
+ and then re-enabled, which caused logs to be dropped. This occurred
+ when the syslog server was down for more than 16 minutes.
+
+ |
+
|
+ PAN-290088
+ |
+
+
+ Fixed an issue where a memory leak occurred related to the
+ configd
+ process when pushing configurations from Panorama to a firewall. This
+ occurred when the configurations contained shared policy rules.
+
+ |
+
|
+ PAN-289102
+ |
+
+
+ (PA-7500 Series, PA-5410, PA-5420, PA-5430, PA-5440, PA-5445,
+ PA-3400 Series, PA-1400 Series, PA-400 Series, VM-Series, and
+ CN-Series firewalls only) Fixed a race condition issue related to predict processing, which
+ resulted in a dataplane restart and traffic loss.
+
+ |
+
|
+ PAN-288893
+ |
+
+
+ (Firewalls in multi-vsys configurations only)
+ Fixed an issue where HTTP/2 traffic failed due when one virtual system
+ (vsys) had a decryption policy rule enabled and another vsys had a
+ no-decrypt policy rule for the same session.
+
+ |
+
|
+ PAN-287818
+ |
+
+
+ Fixed an issue where sessions timed out sooner than expected due to
+ the
+ pan_proxy_accumulation_restore_timeout
+ not initiating when the accumulation
+ session_init failed.
+
+ |
+
|
+ PAN-287734
+ |
+
+
+ Fixed an issue where
+ Scan ERR: Internal Err 1002 messages
+ were unexpectedly generated when WIF shared memory use was high.
+
+ |
+
|
+ PAN-287621
+ |
+
+
+ Added debug logs for an issue where a slow IP address pool NAT leak
+ occurred when persistent NAT was enabled, which led to NAT IP pool
+ exhaustion.
+
+ |
+
|
+ PAN-287056
+ |
+
+
+ Fixed an issue where BGP export policy rules with next-hop matching
+ failed to block the advertisement of static routes, and the firewall
+ incorrectly matched the egress interface IP address instead of the
+ original next-hop IP address of the static route, which caused the
+ deny rule to fail.
+
+ |
+
|
+ PAN-287023
+ |
+
+
+ Fixed an issue where a large number of logs caused the
+ logrcvr
+ process to stop responding.
+
+ |
+
|
+ PAN-287002
+ |
+
+
+ A fix was made to address
+ CVE-2025-0133.
+
+ |
+
|
+ PAN-286857
+ |
+
+
+ Fixed an issue where only failed Kerberos authentication events were
+ logged in auth.log, and
+ successful authentication events were not logged.
+
+ |
+
|
+ PAN-286848
+ |
+
+
+ Fixed an issue where ECMP incorrectly balanced sessions across links
+ based on the configured metric, which led to an imbalance in traffic
+ distribution and resulted in traffic assignment shifting
+ disproportionately to routes with lower metrics.
+
+ |
+
|
+ PAN-286443
+ |
+
+
+ Fixed an issue where, after an upgrade, the firewall was unable to be
+ managed via HTTPS or SSH.
+
+ |
+
|
+ PAN-286306
+ |
+
+
+ Fixed an issue where, when getting transceiver information from ESCC
+ for SFP 25G modules, the transceiver code was incorrectly updated with
+ Unknown instead of
+ 25GBase-SR.
+
+ |
+
|
+ PAN-285894
+ |
+
+
+ Fixed an issue where the
+ all_task
+ process stopped responding, which caused the firewall to reboot
+ unexpectedly, and traffic failures occurred.
+
+ |
+
|
+ PAN-285818
+ |
+
+
+ Fixed an issue where a tool was needed to display leaked NAT port
+ numbers without requiring a forced synchronization.
+
+ |
+
|
+ PAN-284908
+ |
+
+
+ Fixed an issue where retrieving filenames from OneDrive resulted in a
+ cache miss.
+
+ |
+
|
+ PAN-284073
+ |
+
+
+ Fixed an issue on the firewall that caused commits to fail and the web
+ interface to become inaccessible.
+
+ |
+
|
+ PAN-284067
+ |
+
+
+ Fixed an issue where the
+ devsrvr
+ process experienced out of memory (OOM) conditions due to the
+ show running application statistics
+ CLI command, which caused the firewall to reboot.
+
+ |
+
|
+ PAN-284003
+ |
+
+
+ Fixed an issue where clients did not receive a valid response when
+ when searching a website due to a compression error.
+
+ |
+
|
+ PAN-283979
+ |
+
+
+ Fixed an issue where the firewall became non-functional due to high
+ root partition use.
+
+ |
+
|
+ PAN-283936
+ |
+
+
+ (Panorama appliances only) Fixed an issue where
+ the
+ configd
+ process intermittently restarted, which caused Panorama to be
+ temporarily unavailable.
+
+ |
+
|
+ PAN-283331
+ |
+
+
+ Fixed an issue where selective pushes to managed devices failed when
+ the User ID Master Device was
+ configured.
+
+ |
+
|
+ PAN-282359
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected.
+
+ |
+
|
+ PAN-282277
+ |
+
+
+ Fixed an issue where an OOM condition on the
+ logrcvr
+ process caused interface flapping, and the interface unexpectedly went
+ down and then recovered without intervention.
+
+ |
+
|
+ PAN-281509
+ |
+
+
+ (Panorama appliances only) Fixed an issue where
+ log exports were slower than expected or failed when filtering logs
+ after an upgrade, which resulted in timeouts or delays in displaying
+ logs on the web interface.
+
+ |
+
|
+ PAN-280532
+ |
+
+
+ Fixed an issue where, after disabling and re-enabling the external
+ syslog server, the TCP session was not resumed, which caused all logs
+ that were forwarded to the syslog server to be dropped.
+
+ |
+
|
+ PAN-280101
+ |
+
+
+ Fixed an issue where set and edit commands took longer than expected
+ when adding address objects with a large number of dynamic groups due
+ to the completion cache being enabled. With this fix, the completion
+ cache is disabled by default.
+
+ |
+
|
+ PAN-279500
+ |
+
+
+ Fixed an issue where TLS connections failed to establish in asymmetric
+ routing environments if the firewall did not see server-to-client
+ (s2c) packets of the TLS handshake.
+
+
+ To use this fix, run the following CLI command:
+ debug dataplane set ssl-decrypt accumulate-client-hello
+ asym-disable yes.
+
+ |
+
|
+ PAN-278836
+ |
+
+
+ Fixed an issue where, after an upgrade, GlobalProtect attempted to use
+ the embedded browser instead of the default browser for gateway
+ authentication even when it was configured to use the default browser.
+
+ |
+
|
+ PAN-278812
+ |
+
+
+ Fixed an issue where authentication to GlobalProtect failed with the
+ error message
+ User not in allowed list.
+
+ |
+
|
+ PAN-278190
+ |
+
+
+ Fixed an issue on Panorama where a scheduled report with SLS data had
+ an invalid translated-query.
+
+ |
+
|
+ PAN-278150
+ |
+
+
+ Fixed an issue where the firewall removed the Authentication Key
+ Identifier (AKID) from the certificate during SSL decryption, which
+ caused Python 3.13 to fail with a certificate verification error.
+
+ |
+
|
+ PAN-277751
+ |
+
+
+ Fixed an issue where a policy-based forwarding (PBF) rule with an
+ action of no-pbf and a service of
+ TCP-22 did not match traffic after upgrading to PAN-OS 11.1.5-h1. As a
+ result, traffic was matched by a lower rule with a service of
+ any and an action of
+ forward.
+
+ |
+
|
+ PAN-276920
+ |
+
+
+ Fixed an issue where web-advertisement traffic was not immediately
+ blocked which resulted in pages loading indefinitely.
+
+ |
+
|
+ PAN-276862
+ |
+
+
+ Fixed an issue on Panorama where the
+ logd
+ process stopped responding unexpectedly.
+
+ |
+
|
+ PAN-276616
+ |
+
+
+ Fixed an issue on the firewall where half-duplex settings on Ethernet
+ was not visible.
+
+ |
+
|
+ PAN-276276
+ |
+
+
+ (PA-450 firewalls only) Fixed an issue where,
+ after an upgrade, data that was excluded using the query builder in a
+ custom report was still visible in the report, and the logs displayed
+ errors related to invalid threat names being queried.
+
+ |
+
|
+ PAN-275133
+ |
+
+
+ Fixed an issue where HTTP 503 server errors occurred while browsing
+ websites due to slow Secure Web Gateway (SWG) bypass rule lookup.
+
+ |
+
|
+ PAN-275047
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue
+ where, after an upgrade, the firewall was unable to send logs to the
+ Strata Logging Service (SLS) when using a specific proxy server, and
+ the SSL connection status displayed as failed when attempting to
+ forward logs through the web proxy.
+
+ |
+
|
+ PAN-273964
+ |
+
+
+ Fixed an issue where SNMP scans to a firewall timed out after
+ upgrading to a PAN-OS 10.2 release.
+
+ |
+
|
+ PAN-273727
+ |
+
+
+ Fixed an issue where the firewall skipped the DNS policy rule of a
+ domain external dynamic list (EDL) during an EDL refresh.
+
+
+ To use this fix, run the following CLI command and commit:
+ set deviceconfig setting ctd custom-edl-domains-continuous-reload
+ yes/no
+
+ |
+
|
+ PAN-271810
+ |
+
+
+ Fixed an issue where auto-negotiation advertised and negotiated 10/100
+ half and full duplex.
+
+ |
+
|
+ PAN-271490
+ |
+
+
+ Fixed an issue on the firewall that caused the following error message
+ to be displayed:
+ frr_ns0: failed to stop child frr_ns0_ospf6d.
+
+ |
+
|
+ PAN-271432
+ |
+
+
+ Fixed an issue where the firewall was unable to decrypt SSL traffic
+ when using forward proxy and HSM with an ECDSA signing certificate.
+
+ |
+
|
+ PAN-271215
+ |
+
+
+ A fix was made to address
+ CVE-2025-4230.
+
+ |
+
|
+ PAN-269700
+ |
+
+
+ Fixed an issue where commits to service connection firewalls from
+ Panorama failed.
+
+ |
+
|
+ PAN-269057
+ |
+
+
+ Fixed an issue where the
+ routed
+ process stopped responding due to accessing freed memory from a hash
+ table when the route vectors were resized. This occurred when a large
+ number of static routes were configured.
+
+ |
+
|
+ PAN-268922
+ |
+
+
+ (PA-3220 firewalls in high availability (HA) configurations only) Fixed an intermittent issue where the firewalls went out of sync
+ after a configuration push from Panorama.
+
+ |
+
|
+ PAN-268787
+ |
+
+
+ Fixed an issue where users were unable to log in to Panorama and the
+ following error message was displayed:
+ Timed out while getting config lock. Please try again. This occurred when pushing configurations to a large number of
+ devices.
+
+ |
+
|
+ PAN-268708
+ |
+
+
+ Fixed an issue where PDF summary and email reports displayed IPv6
+ addresses instead of IPv4 addresses.
+
+ |
+
|
+ PAN-268680
+ |
+
+
+ Fixed an issue where the
+ configd
+ process stopped responding when a configuration merge operation
+ changed.
+
+ |
+
|
+ PAN-267759
+ |
+
+
+ Fixed an issue where Prisma Access gateway downloads were slower than
+ expected.
+
+ |
+
|
+ PAN-267614
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected due to high CPU utilization on the
+ mongodb
+ process.
+
+ |
+
|
+ PAN-267328
+ |
+
+
+ Fixed an issue where the
+ all_task
+ process stopped responding, which caused the firewall to stop
+ processing traffic.
+
+ |
+
|
+ PAN-267045
+ |
+
+
+ Fixed an issue on the firewall where ICMP ping loss occurred after
+ installing a Network Processing Card (NPC) in slot 7.
+
+ |
+
|
+ PAN-265549
+ |
+
+
+ A fix was made to address
+ CVE-2025-0137.
+
+ |
+
|
+ PAN-265014
+ |
+
+
+ Fixed an issue where changes made to device groups with the same
+ prefix name were not visible in the commit scope.
+
+ |
+
|
+ PAN-264845
+ |
+
+
+ Fixed an issue where the Log Forwarding for Security Services feature
+ did not correctly filter policy rules with log forwarding profiles.
+
+ |
+
|
+ PAN-263749
+ |
+
+
+ Fixed an issue where disk space that was used by file descriptors was
+ not freed, which caused the root partition to become full and Panorama
+ to be inaccessible.
+
+ |
+
|
+ PAN-260564
+ |
+
+
+ Fixed an issue on firewalls in HA configurations where a network loop
+ was detected by switches after suspending HA on the active firewall.
+
+ |
+
|
+ PAN-260279
+ |
+
+
+ Fixed an issue where selective push operations failed with the error
+ message:
+ Failed to generate selective push configuration. Schema validation
+ failed. Please try a full push.
+
+ |
+
|
+ PAN-255020
+ |
+
+
+ Fixed an issue where the Panorama web interface did not display the
+ push scope data for custom admin users when performing a partial
+ commit and push.
+
+ |
+
|
+ PAN-226184
+ |
+
+
+ Fixed an issue where push operations from Panorama were slow due to
+ the
+ rasmgr
+ process taking longer than expected.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-298241
+ |
+
+
+ Fixed an issue where the NAT IP address pool was exhausted, which led
+ to intermittent connectivity issues with call applications and
+ outbound call failures. This occurred due to the firewall not properly
+ releasing NAT dynamic ports back to the address pool.
+
+ |
+
|
+ PAN-296519
+ |
+
+
+ Fixed an issue where a stream receiving a reconnect signal with an
+ associated error in
+ Wifclient
+ caused the entire pool to close, which resulted in a complete
+ disconnection.
+
+ |
+
|
+ PAN-295644
+ |
+
+
+ Fixed an issue where Cloud Data Lake (CDL) log forwarding streams
+ intermittently displayed as inactive.
+
+ |
+
|
+ PAN-295385
+ |
+
+
+ Fixed an issue where syslog forwarding dropped due to FQDN resolution
+ failures.
+
+ |
+
|
+ PAN-295342
+ |
+
+
+ Fixed an issue where the
+ pan_comm
+ process stopped responding due to insufficient time allocated to read
+ file descriptors when processing long messages.
+
+ |
+
|
+ PAN-295049
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process stopped responding due to memory allocation errors during
+ Redis communication.
+
+ |
+
|
+ PAN-294488
+ |
+
+
+ Fixed an issue where certificate data was missing in decryption logs
+ for No decrypt policy rules and
+ TLS1.2 traffic after upgrading, and the
+ Subject Common Name,
+ Issuer Common Name,
+ Certificate Start Date,
+ Certificate End Date,
+ Certificate Serial Number, and
+ Certificate Fingerprint fields were
+ blank in the decryption logs.
+
+ |
+
|
+ PAN-294436
+ |
+
+
+ Fixed an issue where polling failed for ethernet interfaces due to the
+ physical port counters read from the MAC being 0.
+
+ |
+
|
+ PAN-294179
+ |
+
+
+ Fixed an issue on Panorama where commit versions did not display
+ correct data in the config audit page even after a refresh.
+
+ |
+
|
+ PAN-293985
+ |
+
+
+ Fixed an issue with the Panorama web interface where admin users were
+ unable to log in and received the error message
+ 504: Gateway Timeout.
+
+ |
+
|
+ PAN-293877
+ |
+
+
+ (Firewalls with Hub vsys (virtual system) configurations enabled
+ only) Fixed an issue where, when using the Hub vsys feature to
+ redistribute Host Information Profiles (HIP) to a non-Hub vsys, HIP
+ policy enforcement failed intermittently on the active secondary
+ firewall. This occurred when traffic destined for specific non-Hub
+ vsys was routed to the active secondary, and the HIP query was not
+ triggered due to an incorrect check for the HIP mask in the Hub vsys.
+
+ |
+
|
+ PAN-293842
+ |
+
+
+ Fixed an issue where the hybrid-SWG service proxy stopped working
+ after upgrading to PAN-OS 11.1.6-h13 due to the firewall failing to
+ establish the listening interface.
+
+ |
+
|
+ PAN-293673
+ |
+
+
+ Fixed an issue where the firewall stopped all tasks due to an OOM
+ condition caused by a scheduled log export using FTP to an external
+ FTP server.
+
+ |
+
|
+ PAN-293511
+ |
+
+
+ Fixed an issue where renaming a BGP filtering profile in Panorama does
+ not update the corresponding BGP peer group in the virtual router,
+ leading to commit failures.
+
+ |
+
|
+ PAN-292242
+ |
+
+
+ Fixed an issue on M-200 and logging appliances where traffic logs were
+ intermittently truncated when forwarded using a TCP syslog
+ configuration. This issue occurred during the log forwarding stage due
+ to intermittent syslog drops caused by exceeding the forwarding queue
+ capacity.
+
+ |
+
|
+ PAN-292228
+ |
+
+
+ Fixed an issue where, after configuring dual stack GlobalProtect with
+ both IPv4 and IPv6 address pools, IPv6 return traffic was dropped with
+ the error message
+ flow-basic error; packet dropped, tunnel resolution failure.
+
+ |
+
|
+ PAN-292202
+ |
+
+
+ Fixed an issue where the system logs repeatedly displayed the alert
+ Clearing snmpd.log due to log overflow
+ due to the SNMP counters rolling over.
+
+ |
+
|
+ PAN-291940
+ |
+
+
+ Fixed an issue where the firewall established multiple TCP connections
+ to a syslog server, which caused logs to be dropped. This occurred
+ because the firewall established a new TCP session for each transfer
+ and the sessions were not closed, which resulted in a continuous
+ increase in connections over time.
+
+ |
+
|
+ PAN-291792
+ |
+
+
+ (PA-7050 firewalls on vwire instances only)
+ Fixed an issue where Bidirectional Forwarding Detection (BFD) echo
+ packets were dropped due to the firewall dropping packets with the
+ same source and destination IP addresses.
+
+ |
+
|
+ PAN-291785
+ |
+
+
+ Fixed an issue where the
+ all_task
+ process stopped responding.
+
+ |
+
|
+ PAN-291631
+ |
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) only) Fixed an issue where the firewall frequently rebooted.
+
+ |
+
|
+ PAN-291456
+ |
+
+
+ Fixed an issue where the custom completer for device groups and
+ templates received the device group name and template name from the
+ running configuration instead of the candidate configuration.
+
+ |
+
|
+ PAN-291283
+ |
+ + + | +
|
+ PAN-290919
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ file download speeds and performance was slower than expected for
+ Prisma Access mobile users when SSL decryption was enabled.
+
+
+ To use this fix, run the CLI command
+ debug dataplane set ssl-decrypt fptcp-rto min <100-500>.
+
+ |
+
|
+ PAN-290691
+ |
+
+
+ Added the CLI command
+ set system setting ctd h323_rtp_predict timeout
+ to increase the maximum timeout limit from 3600 seconds to 65535
+ seconds.
+
+ |
+
|
+ PAN-290449
+ |
+
+
+ Fixed an issue where, when multiple scheduled vulnerability reports
+ were sent in the same email, only the first attached report was
+ displayed.
+
+ |
+
|
+ PAN-289803
+ |
+
+
+ Fixed an issue on the firewall where AIPOs and ADEM licenses failed
+ when SD-WAN or GlobalProtect licenses were not present.
+
+ |
+
|
+ PAN-289406
+ |
+
+
+ Fixed an issue where, when redistributing User-ID information between
+ firewalls, the receiving firewall incorrectly received and stored
+ duplicate Host Information Profile (HIP) profiles. This occurred when
+ a GlobalProtect gateway redistributed User-ID and HIP information
+ through an intermediate firewall.
+
+ |
+
|
+ PAN-289383
+ |
+
+
+ Fixed an issue where the MPLS interface eth1/6 went down and remained
+ down, even after replacing the SFP with a supported one and adjusting
+ duplex and speed settings.
+
+ |
+
|
+ PAN-289109
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected during configuration operations and a configuration lock time
+ out occurred during a commit.
+
+ |
+
|
+ PAN-288988
+ |
+
+
+ Fixed an issue on Panorama where, after logging in to the web
+ interface as the ZTP installer administrator, the web interface was
+ blank.
+
+ |
+
|
+ PAN-288432
+ |
+
+
+ Fixed an issue where, when Advanced Routing Engine was enabled
+ firewalls configured with multiple logical routers, static routes were
+ preferred over eBGP routes even though the static routes had a higher
+ administrative distance.
+
+ |
+
|
+ PAN-288426
+ |
+ + + | +
|
+ PAN-288363
+ |
+
+
+ Fixed an issue where the MIB ID returned an incorrect value via SNMP.
+
+ |
+
|
+ PAN-287842
+ |
+
+
+ Fixed an issue where the
+ comm
+ process stopped responding due to missing heartbeats, which resulted
+ in a system alert and HA communication loss on slot1.
+
+ |
+
|
+ PAN-287688
+ |
+
+
+ Fixed an issue where the firewall failed to connect to the Palo Alto
+ Networks update server when using a customized service route with the
+ source interface as MGT.
+
+ |
+
|
+ PAN-287601
+ |
+
+
+ Fixed an issue on Panorama where commits took longer than expected.
+
+ |
+
|
+ PAN-287387
+ |
+
+
+ Fixed an issue on Panorama where API jobs failed with the error
+ message
+ Server error: Timed out while getting config lock. This occurred due to slow set request performance when setting a
+ large number of address objects in a single set call.
+
+ |
+
|
+ PAN-286931
+ |
+
+
+ Fixed an issue where syslog forwarding in PAN-OS 11.1 and later
+ releases did not support service routes when performing certificate
+ validation over TLS.
+
+ |
+
|
+ PAN-286899
+ |
+
+
+ Fixed an issue where the
+ device-group-tags CLI command
+ used an unnecessary configuration read lock.
+
+ |
+
|
+ PAN-286615
+ |
+
+
+ Fixed an issue where the firewall double-freed shared memory when the
+ shared memory usage reached 100% when sending large payloads. This
+ occurred when DLP, Advanced Advanced Threat Protection (ATP), Advanced
+ WildFire (AWF), or Advanced URL Filtering were enabled.
+
+ |
+
|
+ PAN-286475
+ |
+
+
+ Fixed an issue where the option to sort sequence numbers was missing
+ from Filters prefix list in the
+ advanced routing filters.
+
+ |
+
|
+ PAN-286299
+ |
+
+
+ Fixed an issue on firewalls running PAN-OS 11.1 releases where, after
+ being offboarded from Panorama, the firewall XML configuration file
+ retained template information from the previous Panorama
+ configuration. As a result, when the firewall and its configuration
+ were imported to another Panorama appliance, all configurations in the
+ Network and
+ Device tab became read-only.
+
+ |
+
|
+ PAN-286231
+ |
+
+
+ Fixed an issue where a simultaneous selective push from Panorama to
+ multiple firewalls with different base configurations resulted in
+ configuration corruption, which caused the firewall to go down.
+
+ |
+
|
+ PAN-285436
+ |
+
+
+ Fixed an issue where a selective push from Panorama caused the
+ firewall Security policy rules to be removed on firewalls associated
+ with the device group. This occurred when the base configuration
+ version chosen for the selective push preceded the device
+ configuration import operation, which caused the imported
+ configuration to not be included in the pushed configuration.
+
+ |
+
|
+ PAN-285285
+ |
+
+
+ Fixed an issue where commits remained at 98% completion when static
+ route configuration cleanup was in progress.
+
+ |
+
|
+ PAN-284117
+ |
+
+
+ (Panorama appliances in Log Collector mode only) Fixed an issue where the
+ vm_agent
+ process restarted after an upgrade.
+
+ |
+
|
+ PAN-283813
+ |
+
+
+ Fixed an issue on Panorama where the web interface performance was
+ slower than usual when retrieving read-only configurations from
+ Panorama.
+
+ |
+
|
+ PAN-283522
+ |
+
+
+ Fixed an issue where the SAML single log out (SLO) URL was not
+ correctly displayed in the web interface after it was changed in the
+ SAML profile.
+
+ |
+
|
+ PAN-283165
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected after a period of inactivity due to the Panorama management
+ server unnecessarily reading the
+ running-config.xml file.
+
+ |
+
|
+ PAN-281776
+ |
+
+
+ Fixed an issue on the Panorama web interface where the error message
+ PPPoEv6 Client Interface cannot be enabled with DHCPv6 client
+ was generated when overriding aggregate interfaces even when no DHCPv6
+ or PPPoE was configured.
+
+ |
+
|
+ PAN-281721
+ |
+
+
+ Fixed an issue where the firewall generated high-severity system
+ alerts indicating that the configuration size exceeded the maximum
+ recommended size, even when the configuration size was within the
+ expected limits.
+
+ |
+
|
+ PAN-281488
+ |
+
+
+ Fixed an issue where searching configuration logs for an
+ audit_uuid
+ did not return a result if the rule was created with a clone
+ operation.
+
+ |
+
|
+ PAN-281096
+ |
+
+
+ Fixed an issue on HA clusters where, when link and path monitoring was
+ configured and the failover condition was set to
+ all, disconnecting and reconnecting
+ monitored ethernet ports caused the firewall to switch to a
+ nonfunctional role, which resulted in all interfaces except the HA
+ interface going down.
+
+ |
+
|
+ PAN-279901
+ |
+
+
+ An issue was fixed where the firewall dropped fragmented TLS
+ ClientHello packets, which blocked access to certain websites. This
+ occurred because the packets arrived truncated, in varying sizes and
+ orders, and the firewall's heuristics failed to handle them correctly.
+
+
+ To enable this fix, run:
+ debug dataplane set ssl-decrypt accumulate-client-hello disjoined
+ yes
+
+ |
+
|
+ PAN-279829
+ |
+
+
+ Fixed an issue where NAT pool leaks occurred during a test when RTSP
+ traffic hit NAT rules.
+
+ |
+
|
+ PAN-279706
+ |
+
+
+ (M-600 appliances only) Fixed an issue where
+ Panorama did not update all
+ panreplay
+ database entries after performing a commit and full push to all
+ devices.
+
+ |
+
|
+ PAN-279690
+ |
+
+
+ Fixed an issue where the
+ all_pktproc
+ process stopped responding, which caused the firewall to unexpectedly
+ restart.
+
+ |
+
|
+ PAN-279415
+ |
+
+
+ Fixed an issue where service routes configured to use a data plane
+ interface incorrectly used the management plane interface for traffic
+ transmission. This issue affected syslog and CRL status traffic when a
+ custom service route was not configured.
+
+ |
+
|
+ PAN-279400
+ |
+
+
+ Fixed an issue where, when
+ Restrict Certificate Extensions was
+ enabled on decryption profiles, the basic constraints extension was
+ overwritten incorrectly.
+
+ |
+
|
+ PAN-279366
+ |
+
+
+ Fixed an issue where the firewall used an unnecessary configuration
+ lock when running operational commands.
+
+ |
+
|
+ PAN-277234
+ |
+
+
+ Fixed an issue where a device group import resulted in a Security
+ policy rule being created with
+ Application set to
+ none.
+
+ |
+
|
+ PAN-277178
+ |
+
+
+ Fixed an issue on Panorama where you were unable to delete a shared
+ object due to the rulebase incorrectly referencing the shared object
+ instead of the device group-specific object when the name was used.
+
+
+ To use this fix, delete the original shared object after cloning it to
+ a device group with the same name.
+
+ |
+
|
+ PAN-276795
+ |
+
+
+ Fixed an issue where the GlobalProtect client displayed an error
+ message when you clicked
+ Check Now and
+ Preferred Releases and
+ Base Releases were unchecked (Device > Software).
+
+ |
+
|
+ PAN-275272
+ |
+
+
+ Fixed an issue where a dataplane restart was not triggered as expected
+ when internal packet path monitoring failure occurred.
+
+ |
+
|
+ PAN-274064
+ |
+
+
+ Fixed an issue on Panorama where the
+ request batch license info CLI
+ command displayed entries for devices that were no longer attached to
+ Panorama.
+
+ |
+
|
+ PAN-273153
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected due to excessive polling of the
+ MonitorDirect.getTasks API by the
+ Task Manager.
+
+ |
+
|
+ PAN-271438
+ |
+
+
+ Fixed an issue where the firewall calculated available memory
+ incorrectly on CENTOS devices, which caused the firewall to display
+ high memory usage alerts even when sufficient memory was available.
+
+ |
+
|
+ PAN-271425
+ |
+
+
+ (Firewalls in active/active HA configurations only) Fixed an issue with SSL inbound decryption on firewalls on a vwire
+ setup with asymmetric routing.
+
+
+ To use this fix, enter the CLI command
+ set system setting ssl-decrypt ha-vwire-mac-learn global yes
+ on both firewalls in an HA pair.
+
+ |
+
|
+ PAN-269659
+ |
+
+
+ Fixed an issue on the firewall where you were unable to configure more
+ than 500 DHCP relay servers even though the supported limit was 4096.
+
+ |
+
|
+ PAN-269155
+ |
+
+
+ Fixed an issue where an OOM condition occurred, which caused processes
+ to stop responding.
+
+ |
+
|
+ PAN-268522
+ |
+
+
+ Fixed an issue where the firewall failed to connect to the update
+ server with a customized service route when the source interface was
+ set to MGT and the source address
+ was set as IPv4.
+
+ |
+
|
+ PAN-268002
+ |
+
+
+ Fixed an issue where URL filtering response pages were not displayed
+ for sites that were blocked as a result of SSL/TLS handshake
+ inspection.
+
+ |
+
|
+ PAN-267330
+ |
+
+
+ Fixed an issue where the firewall dropped inbount RTP traffic after
+ using Webex Screen Sharing due to the firewall removing the NAT cache
+ when the predict timed out, which caused a new NAT to be established
+ that conflicted with existing sessions. To use this fix, run the CLI
+ command
+ set system setting ctd h323_rtp_predict timeout
+ <120-3600>
+ to increase the timeout limit.
+
+ |
+
|
+ PAN-265782
+ |
+
+
+ Fixed an issue on Panorama where, after you enabled multihop in a BFD
+ profile, you were unable to disable it via the web interface.
+
+ |
+
|
+ PAN-265111
+ |
+
+
+ Fixed an issue where fragmented SSL hello packets were reordered when
+ going out of the SC/ZTT towards the datacenter.
+
+ |
+
|
+ PAN-263465
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process stopped responding due to a memory leak and buffer overrun.
+
+ |
+
|
+ PAN-262599
+ |
+
+
+ Fixed an issue where the firewall displayed incorrect policy cache
+ usage and configuration memory usage during a commit, which caused the
+ configuration commit to fail with a
+ CONFIG_UPDATE_START error. This
+ occurred when a large number of External Dynamic Lists (EDLs), shared
+ addresses, and policy rules were configured.
+
+ |
+
|
+ PAN-261677
+ |
+
+
+ Fixed an issue where multiple
+ smartctl
+ processes entered a d state due
+ to failure to read from the kernel partition, which resulted in high
+ CPU and management impact.
+
+ |
+
|
+ PAN-260827
+ |
+
+
+ Fixed an issue where the firewall consumed excessive CPU while
+ processing traffic for a workload running on a GKE cluster, which
+ caused reduced throughput.
+
+ |
+
|
+ PAN-260661
+ |
+
+
+ Fixed an issue where daily email reports generated from the custom
+ report did not display the report details in PDF or CSV files.
+
+ |
+
|
+ PAN-256670
+ |
+
+
+ Fixed an issue where scheduled email reports were sent without PDF
+ attachments if the firewall was in FIPS-CC mode.
+
+ |
+
|
+ PAN-255860
+ |
+
+
+ (PA-5200 firewalls only) Fixed an issue where
+ the
+ all_pktproc
+ process stopped responding when the firewall was under a heavy traffic
+ load.
+
+ |
+
|
+ PAN-251442
+ |
+
+
+ Fixed an issue where the firewall rebooted into maintenance mode if
+ the authentication process restarted repeatedly.
+
+ |
+
|
+ PAN-251035
+ |
+
+
+ Fixed an issue where selective push operations did not push
+ certificate changes to the firewall.
+
+ |
+
|
+ PAN-241230
+ |
+
+
+ Fixed an issue where the SNMP get request status value for Panorama
+ connections was incorrect.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-300906
+ |
+
+
+ Fixed an issue where XML API commands failed with a
+ Method not found (policy_xml)
+ error in dagger.log. The issue was due to missing XML-related
+ functions for inline-cloud-proxy and session-distribution commands in
+ dagger files handling.
+
+ |
+
|
+ PAN-300096
+ |
+
+
+ Fixed an issue where a local commit on a firewall breaks template
+ stack overrides, preventing the enabling of LACP (Link Aggregation
+ Control Protocol). After a local commit, the LACP enable check was
+ unexpectedly unchecked, causing an outage. Attempting to re-enable
+ LACP through the web interface was unsuccessful, requiring manual
+ removal of the LACP configuration from the Panorama CLI.
+
+ |
+
|
+ PAN-297972
+ |
+
+
+ Fixed an issue where a dataplane crash occurred when traffic matched
+ Inline Cloud Analysis pre-filtering signatures, even when Inline Cloud
+ Analysis features were not enabled.
+
+ |
+
|
+ PAN-297240
+ |
+
+
+ Fixed an issue where attempting to generate reports in a WildFire FIPS
+ Private Cloud or WF-500 deployment returned 401 errors.
+
+ |
+
|
+ PAN-296490
+ |
+
+
+ (FIPS CC mode enabled only) Fixed an issue
+ where Panorama on GCP reboots every hour after upgrading to
+ 11.1.6-h10. Panorama will run for up to an hour and then crash.
+
+ |
+
|
+ PAN-296453
+ |
+
+
+ Fixed an issue where decryption exclusion lists were not working for
+ untrusted certificates, and SSL sessions were still being decrypted
+ even after adding them to the exclusion list. This occurred because
+ the firewall was not adding sessions to the exclude cache until after
+ receiving a non-RFC alert (BadCertificate) from the server. The fix
+ ensures that the first session is added to the exclude cache, allowing
+ subsequent sessions to skip decryption. This issue affects firewalls
+ configured as clients in server-client communication.
+
+ |
+
|
+ PAN-295944
+ |
+
+
+ Fixed an issue where static routes remained active in the FIB and RIB
+ even when the associated physical port interface was down, which
+ resulted in traffic being incorrectly routed through a non-operational
+ interface.
+
+ |
+
|
+ PAN-295560
+ |
+
+
+ Fixed an issue where, after upgrading Panorama and Log Collectors,
+ tunnel logs were not visible in Panorama or Splunk even though traffic
+ and threat logs were received.
+
+ |
+
|
+ PAN-294893
+ |
+
+
+ Fixed an issue where firewalls with the
+ Send handshake messages to CTD for inspection
+ setting enabled caused incorrect security policy rules to be matched.
+ Specifically, traffic not identified as openai-base or openai-chatgpt
+ applications was incorrectly matched by the
+ ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS rule. Additionally, the expected
+ response page for blocked URLs was not displayed.
+
+ |
+
|
+ PAN-294524
+ |
+
+
+ Fixed an issue where firewalls and Panorama management servers were
+ unable to view or download WildFire reports from a WF-500 appliance,
+ resulting in a 401 error in the report tab.
+
+ |
+
|
+ PAN-292393
+ |
+
+
+ Fixed an issue where TFTP file transfers intermittently timed out in
+ active-active HA pairs when the TFTP control channel was processed by
+ one firewall and the data channel was processed by the other. This
+ occurred because the firewall receiving the data channel failed to
+ match the predicted session due to asynchronous processing of HA
+ messages.
+
+ |
+
|
+ PAN-292229
+ |
+
+
+ Fixed an issue where Panorama was unable to retrieve userid logs from
+ the firewall for subscribed user-ip-mappings after Panorama was
+ rebooted.
+
+ |
+
|
+ PAN-291288
+ |
+
+
+ Fixed an issue where the firewall rebooted unexpectedly due to a
+ pan_task
+ process restart related to page allocation failures.
+
+ |
+
|
+ PAN-289249
+ |
+
+
+ Fixed an issue where a memory leak occurred on the
+ reportd
+ process when a WildFire update was initiated while device telemetry
+ data collection was in progress. This resulted in an OOM condition.
+
+ |
+
|
+ PAN-287803
+ |
+
+
+ Fixed an issue where, after upgrading firewalls to PAN-OS 11.1.6-h1,
+ certain websites weren't accessible when the accumulation proxy was
+ enabled. The proxy did not use the same DF bit state as the original
+ traffic, causing it to be fragmented and dropped elsewhere in the
+ network.
+
+ |
+
|
+ PAN-287782
+ |
+
+
+ Fixed an issue where firewalls configured in vwire mode modified DSCP
+ values from AF11 to CS0 on traffic passing through the firewall, even
+ when QoS policy rules and DSCP rewrite settings were not configured.
+
+ |
+
|
+ PAN-287622
+ |
+
+
+ Fixed an issue where IPv6 traffic was affected after upgrading the
+ firewall to PAN-OS 11.1.6-h4 and later versions. With SSL decryption
+ enabled and a decryption policy configured for the traffic, the
+ firewall dropped packets due to receiving a
+ Packet Too Big ICMP message. This
+ occurred because the PathMTU information update was incorrect for the
+ TCB (pan-server) when the firewall was acting as a server.
+ Additionally, the flow label under the IPv6 header was set to zero
+ while the packet was being transmitted out of the firewall.
+
+ |
+
|
+ PAN-287423
+ |
+
+
+ Fixed an issue where content loading issues occurred on IPv6 websites
+ due to the firewall incorrectly setting the IPv6 header flow label to
+ 0.
+
+ |
+
|
+ PAN-285648
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process crashed on PA-7050 firewalls due to system log processing
+ threads becoming blocked when the queue was full. This resulted in a
+ heartbeat failure.
+
+ |
+
|
+ PAN-283053
+ |
+
+
+ Fixed an issue where the firewall experienced high disk space
+ utilization, which caused the firewall to become non-functional.
+
+ |
+
|
+ PAN-282854
+ |
+
+
+ Fixed an issue where the Elasticsearch cluster did not start after
+ deploying dedicated log collectors in a multi-collector environment.
+
+ |
+
|
+ PAN-277306
+ |
+
+
+ Fixed an issue where the XML API and REST API failed to run commands
+ and displayed an error.
+
+ |
+
|
+ PAN-277135
+ |
+
+
+ Fixed an issue where the firewall stopped responding when a DNS client
+ closed or reset a TCP connection while the firewall was sending a
+ response.
+
+ |
+
|
+ PAN-277034
+ |
+
+
+ Fixed an issue where WildFire reports were not fully displayed and
+ were not downloadable due to static resources not being found.
+
+ |
+
|
+ PAN-267450
+ |
+
+
+ Fixed an issue where the
+ reportd
+ process stopped responding with a SIGSEGV at
+ schedule_report_es_response.
+
+ |
+
|
+ PAN-260185
+ |
+
+
+ Fixed an issue where a dataplane crash occurred in Inline Cloud
+ Analysis action lookup because there were no vulnerability or
+ anti-spyware profiles in the security policy rule.
+
+ |
+
|
+ PAN-253963
+ |
+
+
+ (Panorama appliances in Panorama mode and Log Collector mode
+ only) Fixed an issue where autocommits took longer than expected to
+ complete.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-303737
+ |
+
+
+ Fixed an issue where XML API commands failed with a
+ Method not found (policy_xml)
+ error in dagger.log. The issue was due to session-distribution
+ commands in dagger files handling.
+
+ |
+
|
+ PAN-299772
+ |
+
+
+ (VM-Series firewalls in active/passive configurations only) Fixed an issue where, after an HA failover event, the newly active
+ firewall DHCP client interfaces failed to obtain IP addresses
+ automatically. This occurred because the DHCP client processes did not
+ initiate the necessary DHCP discover or renew requests
+
+ |
+
|
+ PAN-298654
+ |
+
+
+ Fixed an issue where the firewall generate false positive threat logs
+ during updates to a large domain list (EDL) when a DNS lookup for a
+ domain being added or removed occurred during the update process. This
+ resulted in a threat log being generated for a different, unrelated
+ domain that remained on the list.
+
+ |
+
|
+ PAN-298505
+ |
+
+
+ Fixed an issue where, after upgrading an HA pair of PA-7050 firewalls,
+ the vsys ID changed in sequence, causing autocommit failures with
+ validation errors. This occurred when the multi-vsys firewall had
+ virtual systems created and pushed from Panorama, and the vsys ID was
+ not in a correct sequence because the unused vsys was deleted from
+ Panorama and pushed to devices.
+
+ |
+
|
+ PAN-297797
+ |
+
+
+ Fixed an issue where, during a refresh of a large External Dynamic
+ List (EDL), traffic that matched a domain on the list was incorrectly
+ identified as a different domain, which resulted in false positive
+ threat logs.
+
+ |
+
|
+ PAN-295221
+ |
+
+
+ Fixed an issue where, after upgrading Panorama and Log Collectors from
+ PAN-OS 10.2.9 to PAN-OS 11.1.6-h6, Traffic and Threat logs were not
+ forwarded to a Splunk server over UDP.
+
+ |
+
|
+ PAN-293848
+ |
+
+
+ Fixed an issue where Panorama failed to push the default value of
+ None for the secondary NTP server
+ address to managed firewalls, resulting in a commit validation error.
+ This occurred even when configuring the secondary NTP server address
+ as
+ None
+ in Panorama's web interface, and affected both newly deployed and
+ long-standing production firewalls after upgrading.
+
+ |
+
|
+ PAN-291716
+ |
+
+
+ Fixed an issue where PA-460 firewalls experienced out-of-memory (OOM)
+ conditions, leading to device crashes and reboots.
+
+ |
+
|
+ PAN-289859
+ |
+
+
+ (Panorama virtual appliances only) Fixed an
+ issue where Panorama failed to mount logging disks larger than 2TB due
+ to a partitioning error.
+
+ |
+
|
+ PAN-288388
+ |
+
+
+ Fixed an issue where, after an EDL certificate update or repository
+ migration, authentication failures caused the firewall to not fall
+ back to the last successfully cached EDL entries, which led to policy
+ rules that referenced the EDL to not be enforced.
+
+ |
+
|
+ PAN-287693
+ |
+
+
+ Fixed an issue where Panorama did not use the configured proxy
+ settings to check WildFire private cloud content and instead connected
+ directly to the WildFire device using the management interface. This
+ occurred even when
+ Use Proxy Settings for Private Cloud
+ was enabled.
+
+ |
+
|
+ PAN-284872
+ |
+
+
+ Fixed an issue where ENA (Elastic Network Adapter) extended statistics
+ (conntrack allowance metric) were unavailable in DPDK 22.11.x. This
+ metric is now available through AWS Cloudwatch.
+
+ |
+
|
+ PAN-277682
+ |
+
+
+ Fixed an issue where moving an address object from a device group to
+ shared and renaming it did not
+ reflect in the address group, which caused commits to fail.
+
+ |
+
|
+ PAN-262444
+ |
+
+
+ Fixed an issue where the firewall did not refresh the external dynamic
+ list due to the first entry in the list being removed from the global
+ external list and breaking out of the loop.
+
+ |
+
|
+ PAN-257515
+ |
+
+
+ Fixed an issue where Possible Domain Fronting Detection for HTTP/2
+ generated false positives. With this change, domain fronting is
+ limited to HTTP/1.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-299815
+ |
+
+
+ Fixed an issue on multi-vsys firewalls where a host was not removed
+ from the quarantine list after receiving a redistribution message from
+ Panorama. This occurred when Panorama was configured to redistribute
+ quarantine messages to a firewall cluster, and the GlobalProtect
+ configuration and redistribution were built out in a vsys other than
+ vsys1.
+
+ |
+
|
+ PAN-299615
+ |
+
+
+ Fixed an issue where, when the Network Packet Broker feature was
+ enabled, forward TLS (non-decrypted) traffic was not working as
+ expected when there were segmented client hellos and a no-decrypt rule
+ existed. This issue occurred when Zone Protection profiles were
+ configured for trust/untrust zones but not attached to NPB zones.
+
+ |
+
|
+ PAN-297782
+ |
+
+
+ Fixed an issue on Panorama where reassociating a vsys from one device
+ group to another in a multi-vsys environment resulted in another vsys
+ from the same firewall being removed from the original device group.
+ This resulted in the device being moved into the
+ no device groups attached group, a
+ superuser was required to manually reattach the device.
+
+ |
+
|
+ PAN-297775
+ |
+
+
+ Fixed an issue where, after upgrading to an affected PAN-OS release,
+ the Visible Virtual Systems field
+ started to reference the vsys name instead of the vsys ID, which
+ caused inter-vsys routing to fail. This occurred when a vsys display
+ name matched one of the vsys IDs.
+
+ |
+
|
+ PAN-296752
+ |
+
+
+ Fixed an issue where the firewall experienced high management CPU
+ usage and repeatedly rebooted when attempting to retrieve SMART data.
+
+ |
+
|
+ PAN-295470
+ |
+
+
+ Fixed an issue on the firewall where the
+ useridd
+ process continuously increased its memory consumption, which resulted
+ in an OOM condition that caused the firewall to restart.
+
+ |
+
|
+ PAN-293847
+ |
+
+
+ Fixed an issue where EAL logs for traffic matching the
+ intrazone-default Security policy rule were not forwarded to the IoT
+ Security portal.
+
+ |
+
|
+ PAN-292261
+ |
+
+
+ Fixed an issue where the firewall repeatedly reported an unreachable
+ syslog server as back online when
+ the server remained unavailable. This resulted in misleading
+ alternating connection status messages in the system logs.
+
+ |
+
|
+ PAN-291661
+ |
+
+
+ Fixed an issue on Panorama appliances and Log Collectors where, after
+ an upgrade, Elasticsearch intermittently entered into a Red state
+ before automatically recovering.
+
+ |
+
|
+ PAN-291653
+ |
+
+
+ Fixed an issue where the GlobalProtect host ID field was
+ intermittently blank in traffic logs on Prisma Access, even when the
+ user was connected and had the correct host ID information. This
+ occurred when the IP address to host ID entry expired and the entry
+ was re-insterted without the dataplane flag being set.
+
+ |
+
|
+ PAN-289405
+ |
+
+
+ (VM-Series firewalls only) Added the CLI
+ command
+ no-refresh-discard-session to
+ address an issue where the discarded session time to live (TTL) did
+ not refresh at the default value.
+
+ |
+
|
+ PAN-289067
+ |
+
+
+ Fixed an issue where, after upgrading Panorama in a High Availability
+ (HA) pair, the configuration logs stopped synchronizing from the
+ primary Panorama to the secondary Panorama. This issue occurred
+ because the log forwarding flag was permanently disabled due to the
+ connection state not being active when the
+ log-fwd-ctrl message was
+ received.
+
+ |
+
|
+ PAN-288930
+ |
+
+
+ Fixed an issue where traffic from cloud applications intermittently
+ matched an incorrect
+ cloud-apps policy rule when ACE
+ (App-ID Cloud Engine) was enabled.
+
+ |
+
|
+ PAN-288761
+ |
+
+
+ Fixed an issue on the firewall where the
+ logrcvr
+ process stopped responding.
+
+ |
+
|
+ PAN-288097
+ |
+
+
+ Fixed an issue where on the firewall where the
+ routed
+ process stopped responding after changing the MTU or any link state
+ parameters when OSPF and PIM were enabled on the same interface.
+
+ |
+
|
+ PAN-287314
+ |
+
+
+ Fixed an issue with firewalls in active/passive HA configurations
+ where an OOM condition occurred and caused a failover due to a memory
+ leak associated with the
+ logrcvr
+ process.
+
+ |
+
|
+ PAN-285169
+ |
+
+
+ Fixed an issue on Panorama where Kerberos superusers were unable to
+ edit policy rules because the target device tab was grayed out.
+
+ |
+
|
+ PAN-283954
+ |
+
+
+ Fixed an issue where the
+ configd
+ process stopped responding due to a circular reference between address
+ groups.
+
+ |
+
|
+ PAN-282093
+ |
+
+
+ Enhanced the CLI command
+ request legacy reset to delete
+ the legacy certificate files that were being used to connect with the
+ secondary Panorama appliance.
+
+ |
+
|
+ PAN-274797
+ |
+
+
+ Fixed an issue where a DPC on slot 3 failed intermittently due to the
+ pktlog_forwarding process
+ restarting, which resulted in an unexpected HA failover.
+
+ |
+
|
+ PAN-272539
+ |
+
+
+ (Panorama appliances on Microsoft Azure environments only) Fixed an issue where user to IP address mapping was missing for
+ some users connected to specific Prisma Access gateways, which caused
+ the collection layer Azure firewall to not form the mapping.
+
+ |
+
|
+ PAN-272175
+ |
+
+
+ Fixed an issue where session rematch caused ACE cloud application
+ traffic to match the wrong policy rule.
+
+ |
+
|
+ PAN-271507
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ the DPC on slot 3 intermittently stopped responding due an
+ all_pktproc
+ restart.
+
+ |
+
|
+ PAN-258039
+ |
+
+
+ Fixed an issue where the firewall displayed the incorrect rule name
+ when a threat log was generated for Inline Cloud Analyzed CMD
+ Injection Traffic Detection.
+
+ |
+
|
+ PAN-251715
+ |
+
+
+ Fixed an issue where the firewall closed the SSL connection to the
+ user ID agent.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-306226
+ |
+
+
+ Fixed an issue where the TLS handshake did not complete and the
+ session did not go through. This occurred if the HTTP header insertion
+ applied to an HTTP CONNECT request passing through the firewall, the
+ scan-handshake feature was enabled, the session matched a decryption
+ policy rule with the decrypt action, and if the TLS client hello was
+ in a single packet and TLS 1.2 or below.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-306502
+ |
+
+
+ Fixed an issue where TLS connection failure occurred when traffic was
+ over TLS1.2 or below, header insertion was enabled on the firewall,
+ send TLS handshake to CTD was
+ enabled, and traffic hit a decryption policy rule configured with the
+ no-decrypt action.
+
+ |
+
|
+ PAN-304636
+ |
+
+
+ Fixed an issue where BGP aggregate routes were not created and discard
+ routes were not installed in the routing table.
+
+ |
+
|
+ PAN-306226
+ |
+
+
+ Fixed an issue where the TLS handshake did not complete and the
+ session did not go through. This occurred if the HTTP header insertion
+ applied to an HTTP CONNECT request passing through the firewall, the
+ scan-handshake feature was enabled, the session matched a decryption
+ policy rule with the decrypt action, and if the TLS client hello was
+ in a single packet and TLS 1.2 or below.
+
+ |
+
|
+ PAN-304496
+ |
+
+
+ Fixed an issue where, after unregistering an IP tag and registering a
+ different IP tag for the same IP address via XML API, the dynamic
+ address group membership was not updated on the dataplane, which
+ resulted in Security policy rules being enforced incorrectly.
+
+ |
+
|
+ PAN-303954
+ |
+
+
+ Fixed an issue where, when configuring Safenet HSMs in HA and
+ authentication HSM manually, the second HSM server failed to
+ authenticate due to the firewall overwriting the first HSM server's
+ certificate with the second HSM server's certificate.
+
+ |
+
|
+ PAN-303051
+ |
+
+
+ Fixed an issue on Panorama where a memory leak occurred related to the
+ reportd
+ process due to retaining memory that was temporarily used for report
+ generation instead of releasing the memory for reuse, which resulted
+ in continuous accumulation and memory exhaustion.
+
+ |
+
|
+ PAN-301801
+ |
+
+
+ Fixed an issue on Log Collectors where the Elasticsearch process
+ fluctuated intermittently between green and red states, which led to
+ interruptions in log collection. This issue occurred when the number
+ of shards exceeded the cluster's maximum supported threshold of
+ greater than 1000 shards per Elasticsearch instance.
+
+ |
+
|
+ PAN-300637
+ |
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where the firewall unexpectedly rebooted due to
+ repeated
+ varrcvr
+ process restarts.
+
+ |
+
|
+ PAN-300548
+ |
+
+
+ Fixed an issue where using the IKEv2 multiplier setting for VPN
+ re-authentication resulted in the firewall not re-authenticating at
+ the expected intervals when both sides initiated rekeying. The
+ internal re-authentication counter incremented when the local side
+ triggered the rekey, but not when the peer side triggered it.
+
+ |
+
|
+ PAN-297975
+ |
+
+
+ Fixed an issue where Panorama was unable to push the Trusted Root CA
+ configuration to Log Collectors via a Collector Group push due to the
+ Log Collector not supporting the
+ trusted-root-CA configuration.
+
+ |
+
|
+ PAN-297708
+ |
+
+
+ Fixed an issue where a long-lived session with many Machine Learning
+ (ML) model triggers caused a memory leak of feature states associated
+ with the ML model runs. This resulted in Spyware_State failure
+ increases, allocation max outs, and impaired policy matching.
+
+ |
+
|
+ PAN-297610
+ |
+
+
+ Fixed an issue where the firewall became unresponsive after an upgrade
+ due to the
+ fsck
+ command scanning drive partitions in parallel with the root partition,
+ which caused the process to take an extended amount of time.
+
+ |
+
|
+ PAN-297295
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the firewall repeatedly restarted due to high
+ packet rates on the synthetic path in DPDK mode.
+
+ |
+
|
+ PAN-288158
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the firewall became inaccessible via the web interface and SSH and
+ remained in an initializing state.
+
+ |
+
|
+ PAN-287611
+ |
+
+
+ Fixed an issue where, after upgrading, the firewall incorrectly
+ calculated the UDP checksum for RTP traffic after NAT and Security
+ policy application, which led to dropped packets and silent calls in
+ applications.
+
+ |
+
|
+ PAN-284866
+ |
+
+
+ Fixed an issue where the LFC failed to validate Certificate Revocation
+ Lists (CRL) for SSL syslog connections, which caused a failure to
+ forward logs to external syslog servers.
+
+ |
+
|
+ PAN-278126
+ |
+
+
+ Fixed an issue where the number of registered IP Tags on Panorama did
+ not match the number of registered IP Tags on the managed firewalls
+ due to a change in file format between PAN-OS releases.
+
+ |
+
|
+ PAN-274697
+ |
+
+
+ Fixed an issue where push operations from Panorama failed on passive
+ firewalls when an application was removed from a Security policy rule
+ and the policy rule was referenced in a device group.
+
+ |
+
|
+ PAN-270554
+ |
+
+
+ Fixed an issue where the GlobalProtect client (UWP) or metered hotspot
+ connections triggered TLS resumption for GlobalProtect portal
+ authentication, which caused the portal authentication to fail with a
+ valid cert required error.
+
+ |
+
|
+ PAN-260090
+ |
+
+
+ Fixed an issue where commit all operations failed when the application
+ openair-psa was used as a keyword
+ on a remote network instance that was upgraded to an affected release.
+
+ |
+
|
+ PAN-257616
+ |
+
+
+ Fixed an issue where selective push operations from Panorama to
+ managed firewalls failed with the error message
+ Failed to generate selective push configuration. Schema validation
+ failed. Please try a full push.
+
+ |
+
|
+ PAN-257362
+ |
+
+
+ Fixed an issue where GlobalProtect traffic destined for the internet
+ did not follow the path-based forwarding (PBF) rule and was sent out
+ the wrong interface.
+
+ |
+
|
+ PAN-255253
+ |
+
+
+ Fixed an issue where the firewall did not establish a syslog
+ connection to the probe VM syslog server in ADEM Regressions.
+
+ |
+
|
+ PAN-242602
+ |
+
+
+ Fixed an issue where GlobalProtect clients experienced slow SMB-V3
+ download throughput when passing through a Prisma IPSec tunnel and the
+ firewall and the SMB-V3 session owner dataplane was the same as the
+ IPSec-ESP tunnel on the multi-dataplane firewall.
+
+ |
+
|
+ PAN-241694
+ |
+
+
+ Fixed an issue where memory leaks related to the
+ devsrvr
+ process occurred when downloading and pushing updates from the App-ID
+ Cloud Engine to the dataplane.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-308060
+ |
+
+
+ (Firewalls in active/active HA configurations only) Fixed an issue where the BFD session went down and did not recover
+ even though the BGP remained in an established state, which caused the
+ firewall to cease route learning and advertisement with the peer, even
+ though BGP keep-alives were exchanged correctly.
+
+ |
+
|
+ PAN-307795
+ |
+
+
+ Fixed an issue where Panorama incorrectly generated system logs
+ indicating a lost connection to its peer after an upgrade even when
+ High Availability was not configured.
+
+ |
+
|
+ PAN-305412
+ |
+
+
+ Fixed an issue where the Logging Service License Status displays a
+ license failure when the license status transitions from valid to
+ expired and then back to valid even when the connection to the
+ Security Logging Service (SLS) was working.
+
+ |
+
|
+ PAN-305301
+ |
+
+
+ Fixed an issue where the timing of GlobalProtect lifetime expiry or
+ inactivity logout notifications used for GlobalProtect SSL tunnels
+ could cause the
+ pan_task
+ process to stop responding and the dataplane to restart.
+
+ |
+
|
+ PAN-303959
+ |
+
+
+ Fixed an issue where traffic is incorrectly identified as
+ unknown-tcp/unknown-udp due to App-ID resource leak and eventually
+ dropped.
+
+ |
+
|
+ PAN-302551
+ |
+
+
+ Fixed an issue where the firewall displayed as disconnected in the SLS
+ due to the serial number not being retrieved
+
+ |
+
|
+ PAN-301975
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where the passive firewall incorrectly triggered PBP alerts even
+ with low packet rates.
+
+ |
+
|
+ PAN-301912
+ |
+
+
+ Fixed an issue where Panorama stopped responding when deploying
+ dynamic updates to managed devices.
+
+ |
+
|
+ PAN-301600
+ |
+
+
+ Fixed an issue on the firewall where, after upgrading Panorama, OSPF
+ adjacencies remained in the exchange start state, which resulted in an
+ incomplete routing table.
+
+ |
+
|
+ PAN-301456
+ |
+
+
+ Fixed an issue on Panorama where the
+ debug system reset-ztp CLI command was
+ unavailable.
+
+ |
+
|
+ PAN-301409
+ |
+
+
+ Fixed an issue where Panorama failed to perform a selective push to a
+ managed device when device tags were added or modified on the policy
+ rules. The selective push failed with the error message
+ Failed to generate selective push configuration. Schema validation
+ failed. Please try a full push.
+
+ |
+
|
+ PAN-300837
+ |
+
+
+ Fixed an issue where firewalls experienced multiple reboots due to the
+ pan_task
+ process restarting with a SIGSEGV signal. This occurred because the
+ client-to-firewall side assumed TLS 1.3 for the firewall-server side.
+
+ |
+
|
+ PAN-299751
+ |
+
+
+ Fixed an issue where the firewall was unable to connect to the
+ Subscription License Service (SLS) due to a public and private key
+ pair mismatch with the device certificate.
+
+ |
+
|
+ PAN-298907
+ |
+
+
+ Fixed an issue on PA-VM in AWS where, in a two-arm deployment
+ integrated with Gateway Load Balancer (GWLB), the firewall did not
+ preserve the GENEVE source port for internet traffic, resulting in
+ increased latency. The fix ensures the firewall preserves the outer
+ UDP source port of GENEVE encapsulation when sending traffic back to
+ GWLB.
+
+ |
+
|
+ PAN-298872
+ |
+
+
+ (PA-400 Series firewalls in HA configurations only) Fixed an issue where ports went down after an HA failover.
+
+ |
+
|
+ PAN-297263
+ |
+
+
+ (PA-5220 firewalls only) Fixed an issue where
+ the
+ ikemgr
+ process crashed intermittently, causing IPSec tunnels to go down
+ randomly. The fix ensures that the IKE security association data
+ structures are accessed in a thread-safe manner. This prevents the
+ ikemgr
+ process from referencing an invalid memory pointer during teardown
+ operations and provides stability.
+
+ |
+
|
+ PAN-296208
+ |
+
+
+ Fixed an issue where the firewall did not accept address groups in the
+ filter condition of a Log Forwarding Match list.
+
+ |
+
|
+ PAN-290241
+ |
+
+
+ Fixed an issue where the
+ useridd
+ process became unresponsive, which caused User-ID CLI commands to time
+ out.
+
+ |
+
|
+ PAN-289652
+ |
+
+
+ Fixed an issue related to external URL lists where pushing
+ configuration changes from Panorama failed.
+
+ |
+
|
+ PAN-288427
+ |
+
+
+ Fixed an issue on Panorama where commit jobs were not queued and the
+ system reported that the
+ useridd
+ was not connected.
+
+ |
+
|
+ PAN-287921
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the maximum registered IP address for was incorrectly set to 100,000
+ instead of the expected 500,000.
+
+ |
+
|
+ PAN-285208
+ |
+
+
+ Fixed an issue where the firewall did not automatically recover after
+ a machine check exception (MCE) occurred.
+
+ |
+
|
+ PAN-281588
+ |
+
+
+ Fixed an issue where packet buffer depletion occurred due to the a
+ high number of
+ tcp_pkt_queued packets when Jumbo
+ was enabled.
+
+ |
+
|
+ PAN-272731
+ |
+
+
+ Fixed an issue on Panorama where commits took longer than expected due
+ to the
+ show object dynamic-address-group all
+ CLI command holding the devicetable lock for an extended period.
+
+ |
+
|
+ PAN-263691
+ |
+
+
+ Fixed an issue where the firewall rebooted unexpectedly due to a
+ memory leak in the
+ all_task
+ process.
+
+ |
+
|
+ PAN-253921
+ |
+
+
+ Fixed an issue where the firewall displayed the following error
+ message:
+ critical userid registe 0 fail to integrate the update of
+ registered ip addresses since 2 seconds ago; critical system log
+ alerts observed.
+
+ |
+
|
+ PAN-185731
+ |
+
+
+ Fixed an issue where the firewall was unable to parse the URL path and
+ host when the host header was located in a different packet, which
+ resulted in the firewall not logging the URL path in the first packet.
+ The fix is disabled by default. The following CLI commands can be used
+ to enable/disable the feature:
+
+
|
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-316911
+ |
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) environments
+ only) Fixed an issue where a newly bootstrapped firewall required a
+ management server restart, relicensing, or license push from Panorama
+ to invoke the device certificate.
+
+ |
+
|
+ PAN-314061
+ |
+
+
+ Fixed an issue where traffic was disrupted during IPSec rekey
+ operations due to a 2 second delay in sending the DELETE message for
+ the previous Security Association (SA) to the peer gateway after a new
+ SA was negotiated.
+
+ |
+
|
+ PAN-313850
+ |
+
+
+ (PA-1400 Series firewalls in HA configurations only) Fixed an issue where a split-brain condition occurred and HA1/HA2
+ links went down while upgrading when the HA configuration used
+ dataplane interfaces for HA1 and a combination of HSCI and Ethernet
+ interfaces for HA2.
+
+ |
+
|
+ PAN-313623
+ |
+
+
+ Fixed an issue where the
+ /opt/pancfg/mgmt/ssl/private/
+ directory on Palo Alto Networks devices with TPM support became 100%
+ utilized due to an accumulation of undeleted
+ .pub_pem files. This occurred
+ because executing the
+ show device-certificate status
+ CLI command initiated a process that generated these files but failed
+ to remove them, which prevented the fetching of new device
+ certificates.
+
+ |
+
|
+ PAN-312706
+ |
+
+
+ Fixed an issue where the firewalls restarted due to a function lacking
+ a NULL-pointer sanity check.
+
+ |
+
|
+ PAN-311250
+ |
+
+
+ (Panorama appliances and Log Collectors only)
+ Fixed an issue where logs from multiple devices were not visible on
+ Panorama even though the Elasticsearch health status on the dedicated
+ Log Collectors appeared green.
+
+ |
+
|
+ PAN-309300
+ |
+
+
+ Fixed an issue where management plane system resources configuration
+ size exceeded 28 MB for over 4 hours, and the following error message
+ was displayed:
+ Configuration size reaching device capacity limit.
+
+ |
+
|
+ PAN-308786
+ |
+
+
+ (Panorama appliances only) Fixed an issue where traffic log queries
+ using the device_name filter
+ returned no results, and complex log queries that included negation
+ operators produced incorrect outputs.
+
+ |
+
|
+ PAN-308654
+ |
+
+
+ Fixed an issue where the Elasticsearch Close Indices process closed
+ more indices than expected and dropped the number of open shards below
+ the minimum of 800 per Elasticsearch instance. This occurred because
+ the process did not correctly account for the number of Elasticsearch
+ instances when calculating the maximum number of allowed open shards.
+
+ |
+
|
+ PAN-308507
+ |
+
+
+ (Panorama managed firewalls only) Fixed an
+ issue where the firewall intermittently failed to maintain active log
+ forwarding streams to Cortex Data Lake even when duplicate logging and
+ enhanced application logging were enabled.
+
+ |
+
|
+ PAN-306555
+ |
+
+
+ Fixed an issue where the firewall stopped responding, which led to
+ service outages.
+
+ |
+
|
+ PAN-304718
+ |
+ + Fixed an issue where OSPF and BGP outages occurred due to an + all_task + process restart during clientless VPN content rewrite processing. + | +
|
+ PAN-304696
+ |
+
+
+ Fixed an issue where the Cloud User-ID connection timed out because
+ the firewall took too long to process the OCSP response.
+
+ |
+
|
+ PAN-298945
+ |
+
+
+ Fixed an issue where OSCP HTTP POST requests were not formatted
+ correctly, which caused failures with strict responders.
+
+ |
+
|
+ PAN-298617
+ |
+
+
+ Optimized the commit workflow to reduce the size of the effective
+ configuration, resulting in lower memory consumption.
+
+ |
+
|
+ PAN-297005
+ |
+
+
+ Fixed an issue where exporting custom reports resulted in empty CSV
+ files.
+
+ |
+
|
+ PAN-296694
+ |
+
+
+ Fixed an issue where the firewall rebooted due to the
+ useridd
+ process repeatedly restarting during an IP-port data type writes to
+ the redis from multiple sources such as TSA or XML in a scale
+ environment.
+
+ |
+
|
+ PAN-296202
+ |
+
+
+ (Firewalls in active/active HA configurations only) Added a log enhancement to capture an issue where, when a commit
+ operation was in progress, newly deployed IP address tags that used
+ the XML API were not immediately reflected in address group
+ resolution, which delayed IP address mapping to address groups and
+ caused traffic to be incorrectly allowed or denied.
+
+ |
+
|
+ PAN-291067
+ |
+
+
+ Fixed an issue where the
+ devsrvr
+ process periodically exceeded its virtual memory limit and restarted,
+ which led to intermittent outages.
+
+ |
+
|
+ PAN-290157
+ |
+
+
+ Fixed an issue on Panorama where the
+ configd
+ process stopped responding when filtering in the
+ Config Audit window, which caused
+ Panorama to restart unexpectedly.
+
+ |
+
|
+ PAN-288175
+ |
+
+
+ Addressed a stack buffer overflow memory leak under plugin management
+ code path.
+
+ |
+
|
+ PAN-287584
+ |
+
+
+ Fixed an issue on the web interface where the address object pop up
+ window only displayed a maximum of four address objects in the policy
+ rule even after expanding the window.
+
+ |
+
|
+ PAN-278688
+ |
+
+
+ Fixed an issue where DNS Security threat logs were not displayed on
+ the firewall when packet capture was enabled and the domain name
+ length was 62 characters.
+
+ |
+
|
+ PAN-273158
+ |
+
+
+ (PA-7000 Series firewalls only) Fixed an issue
+ where an incorrect ASIC configuration caused silent packet drops or
+ application slowness when receiving a mix of jumbo and non-jumbo
+ packets.
+
+ |
+
|
+ PAN-271643
+ |
+
+
+ Fixed an issue where, when a commit job ID was higher than 65535, the
+ XML API truncated the ID to a 16-bit unsigned integer due to an
+ incorrect type case during printing, which resulted in an incorrect
+ job ID being reported compared to the CLI output for the same commit.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-279604
+ |
+
+
+ Fixed an issue where scheduled SaaS application usage reports were
+ generated incorrectly, and the login page was displayed instead of the
+ report content.
+
+ |
+
|
+ PAN-274791
+ |
+
+
+ Fixed an issue where the firewall might reboot when traffic matches
+ with certain Advanced features (such as Advanced Threat Prevention and
+ Advanced URL Filtering with properly configured URL
+ Filtering/Anti-Spyware/Vulnerability security profiles) and Shared
+ Pool Type 32 becomes depleted.
+
+ |
+
|
+ PAN-274592
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where the firewall did not fail over when the active firewall
+ experienced data plane issues.
+
+ |
+
|
+ PAN-273949
+ |
+
+
+ Fixed an issue where the firewall generated the following error
+ message in the
+ snmpd
+ logs:
+ pan_get_keystr_from_cryptod(pan_snmpinterface.c:181): Key
+ X2F1dGhfa2V5 import from cryptod failed.
+
+ |
+
|
+ PAN-273019
+ |
+
+
+ Fixed an intermittent issue where SSL decryption failed.
+
+ |
+
|
+ PAN-271723
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where the
+ all_task
+ process stopped responding, which caused the passive firewall to
+ repeatedly reboot.
+
+ |
+
|
+ PAN-270248
+ |
+
+
+ Fixed an issue where the firewall failed to forward logs to a SNMP
+ trap server if the SNMP manager IP address was unable to be resolved.
+
+ |
+
|
+ PAN-269091
+ |
+
+
+ Fixed an issue where the
+ varrcvr
+ process stopped responding.
+
+ |
+
|
+ PAN-268909
+ |
+
+
+ Fixed an issue where IP address tags were removed from firewalls after
+ a management server or
+ useridd
+ process restart. This occurred when a Panorama serial-number based
+ configuration was used for User-ID redistribution.
+
+ |
+
|
+ PAN-268800
+ |
+
+
+ Fixed an issue where a large number of logs caused the
+ logrcvr
+ process to stop responding.
+
+ |
+
|
+ PAN-267995
+ |
+
+
+ Fixed an issue where after migrating to a new platform, DLP verdicts
+ were not displayed in the Cloud Manager or logs.
+
+ |
+
|
+ PAN-267204
+ |
+
+
+ Fixed an issue where Panorama port 9300 did not adhere to restricted
+ TLS versions and ciphers.
+
+ |
+
|
+ PAN-266559
+ |
+
+
+ Fixed an issue where partial commits failed when objects that were
+ referenced in a high number of Security policy rules were renamed.
+
+ |
+
|
+ PAN-266116
+ |
+
+
+ Fixed an issue where URLs did not work due to certificate revocation
+ list (CRL) requests failing.
+
+ |
+
|
+ PAN-263291
+ |
+
+
+ Fixed an issue where Microsoft Outlook did not work as expected when
+ the GlobalProtect clientless VPN was configured.
+
+ |
+
|
+ PAN-261998
+ |
+
+
+ Fixed an issue where the firewall configuration process restarted
+ during an External Dynamic List refresh or a commit and push
+ operation.
+
+ |
+
|
+ PAN-260300
+ |
+
+
+ (PA-5410, PA-5420, PA-5430, PA-5440 and PA-5445 firewalls only) Fixed an issue related to the
+ all_pktproc
+ process where DPC slot 3 stopped responding.
+
+ |
+
|
+ PAN-259076
+ |
+
+
+ Fixed an issue where the firewall displayed an OCSP/CRL check failure
+ when accessing websites.
+
+ |
+
|
+ PAN-258570
+ |
+
+
+ Fixed an issue where the firewall might reboot unexpectedly due to the
+ varrcvr
+ process progressively using more memory when WildFire file forwarding
+ is handling PE files.
+
+ |
+
|
+ PAN-255619
+ |
+
+
+ Fixed an intermittent issue where file downloads from websites failed
+ when decrypting HTTP/2 traffic.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-282236
+ |
+
+
+ Fixed an issue where large IPv6 packets were reassembled on the
+ firewall when the packets arrived fragmented over an IPv4 tunnel.
+
+ |
+
|
+ PAN-280471
+ |
+
+
+ Fixed an issue where navigating
+
+ was slower than expected.
+
+ |
+
|
+ PAN-279746
+ |
+
+
+ Fixed an issue where SMTP packets were not sent out when the Client
+ Hello arrived at the firewall in multiple out-of-order segments and
+ the traffic was not subject to SSL decryption.
+
+ |
+
|
+ PAN-279191
+ |
+
+
+ Fixed an issue where a GlobalProtect gateway stopped responding when
+ handling HTTP/1.1 traffic with web inspection enabled.
+
+ |
+
|
+ PAN-278684
+ |
+
+
+ (PA-445 firewalls only) Fixed an issue where
+ the firewall did not properly power cycle during a reboot.
+
+ |
+
|
+ PAN-277147
+ |
+
+
+ Fixed an issue where daily scheduled reports were not generated and
+ emailed.
+
+ |
+
|
+ PAN-276062
+ |
+
+
+ Fixed an issue where importing a firewall with a large number of
+ address objects into Panorama did not work and remained at 99%
+ completion.
+
+ |
+
|
+ PAN-275905
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected and Elasticsearch CPU usage was high.
+
+ |
+
|
+ PAN-275754
+ |
+
+
+ Added support for bootstrapping Panorama virtual appliances on ESXi.
+
+ |
+
|
+ PAN-275032
+ |
+
+
+ (M-600 appliances only) Fixed an issue where
+ the Elasticsearch cluster certificate (CC) status displayed with a
+ past expiration date, which caused all shards to be unassigned.
+
+ |
+
|
+ PAN-273141
+ |
+
+
+ Fixed an issue where GlobalProtect clients experienced slow file
+ transfer download throughput when passing through an IPSec tunnel.
+
+ |
+
|
+ PAN-272085
+ |
+
+
+ Fixed an issue where the firewall might crash and reboot when DoH is
+ enabled for DNS Security and multiple DoH transactions are sent in a
+ single HTTP/1 connection.
+
+ |
+
|
+ PAN-270744
+ |
+
+
+ Fixed an issue where API calls to Panorama failed with the error
+ Server error : Timed out while getting config lock. Please try
+ again.
+
+ |
+
|
+ PAN-269291
+ |
+ + Fixed an issue where the scheduled report generation script did not + return debug information. + | +
|
+ PAN-268279
+ |
+
+
+ Fixed an issue where autocommits failed if the management IPv6 gateway
+ was the same as the dataplane interface IP address.
+
+ |
+
|
+ PAN-267650
+ |
+
+
+ Fixed an issue where the firewall did not detect the eth1/1 and eth1/2
+ interfaces when you created a firewall on an ESXi 8 server.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-282022
+ |
+
+
+ Fixed the support limitation for the Panorama M-600 and M-700
+ appliances.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-282022
+ |
+
+
+ Fixed the support limitation for the Panorama M-600 and M-700
+ appliances.
+
+ |
+
|
+ PAN-281885
+ |
+
+
+ Fixed an issue where, when exporting and importing CSV files, the hash
+ values of pre-shared key variables set at template and template stack
+ levels changed inconsistently, which resulted in both variables
+ displaying the same hash value.
+
+ |
+
|
+ PAN-281269
+ |
+
+
+ (PA-5220, PA-5250, and PA-5420 firewalls) Fixed
+ an issue where the firewall management server memory usage
+ continuously increased.
+
+ |
+
|
+ PAN-281264
+ |
+
+
+ Fixed an issue where the
+ routed
+ process memory usage continuously increased when Advanced Routing was
+ enabled.
+
+ |
+
|
+ PAN-280505
+ |
+
+
+ Fixed an issue where the web interface did not display a message to
+ commit prior changes before attempting a partial configuration load.
+
+ |
+
|
+ PAN-280243
+ |
+
+
+ Fixed an issue where the firewall lost the pre-shared key
+ configuration assigned from a PSK variable when an unrelated device
+ group configuration was loaded.
+
+ |
+
|
+ PAN-279336
+ |
+
+
+ Fixed an issue where the CLI did not display a message to commit prior
+ changes before loading a partial configuration.
+
+ |
+
|
+ PAN-279176
+ |
+
+
+ Fixed an issue where the configuration audit displayed inaccurate
+ information after partially loading the configuration via the CLI,
+ which caused the audit to flag the configuration as deleted or
+ changed.
+
+ |
+
|
+ PAN-279065
+ |
+
+
+ Fixed an issue where the firewall sent logs with
+ connection succeeded to the syslog
+ server every time a connection was established, which resulted in
+ excessive logs.
+
+ |
+
|
+ PAN-278296
+ |
+
+
+ Fixed an issue where the system MAC address of the aggregate interface
+ was the same on the active firewall and the passive firewall after an
+ upgrade.
+
+ |
+
|
+ PAN-277762
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ unexpected failovers occurred on firewalls running PAN-OS 11.2.2-h2.
+
+ |
+
|
+ PAN-277631
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process discarded logs due to a full queue.
+
+ |
+
|
+ PAN-275718
+ |
+
+
+ Fixed an issue where Panorama stopped forwarding logs to a Syslog
+ server after upgrading to PAN-OS 11.1.5-h1.
+
+ |
+
|
+ PAN-275713
+ |
+
+
+ Fixed an issue where the
+ dscd
+ process stopped responding when
+ Endpoint Serial Number was enabled,
+ which resulted in the
+ Active Directory returning a list of
+ serial numbers for a specific firewall from the Cloud Identity Engine.
+
+ |
+
|
+ PAN-275077
+ |
+
+
+ Fixed an issue where DNS Security intermittently logs malicious domain
+ URLs as Alert instead of taking a Sinkhole action, even when
+ configured to Sinkhole malicious DNS domains.
+
+ |
+
|
+ PAN-274750
+ |
+
+
+ Fixed an issue where the detailed log view in Panorama did not display
+ all packet details for traffic logs received from the cloud.
+
+ |
+
|
+ PAN-273694
+ |
+
+
+ Fixed an issue where the firewall rebooted due to an out-of-bounds
+ memory access that occurred as a result of the SIP content length
+ value being split across packets.
+
+ |
+
|
+ PAN-273453
+ |
+
+
+ Fixed an issue where restarting the firewall did not initiate an
+ autocommit job, which caused the firewall to stop responding and the
+ HA interface to go down.
+
+ |
+
|
+ PAN-272746
+ |
+
+
+ (PA-440 firewalls only) Fixed an issue where
+ the firewall entered an unstable state after committing changes or
+ onboarding to Panorama.
+
+ |
+
|
+ PAN-272171
+ |
+
+
+ Fixed an issue where the firewall dropped the AAAA DNS server response
+ and caused delays in traffic from Ubuntu or Linux clients when DNS
+ Security was enabled.
+
+ |
+
|
+ PAN-271498
+ |
+
+
+ (PA-7000 Series firewalls, PA-5200 firewalls, and PA-5400f firewalls
+ in FIPS mode only) Fixed an issue where decrypted traffic repeatedly failed and
+ frequent reboots were required.
+
+ |
+
|
+ PAN-271351
+ |
+
+
+ A fix was made to address
+ CVE-2025-0116.
+
+ |
+
|
+ PAN-270193
+ |
+
+
+ Fixed an issue where the Panorama management server changed its
+ certificate authority (CA) unexpectedly, which caused managed
+ firewalls to disconnect.
+
+ |
+
|
+ PAN-269052
+ |
+
+
+ Fixed an issue where traffic was blocked by a URL filtering profile
+ even though the Security policy rule did not have a URL filtering
+ profile configured.
+
+ |
+
|
+ PAN-268629
+ |
+
+
+ Fixed an issue where traffic did not match the correct security policy
+ when using an application-filter that references a cloud application.
+ This occurred when a high number of cloud applications were attached
+ with a custom tag.
+
+ |
+
|
+ PAN-267518
+ |
+
+
+ Fixed an issue where WildFire submission logs incorrectly reported
+ allowed malicious samples even when they were blocked by threat
+ prevention profiles.
+
+ |
+
|
+ PAN-266695
+ |
+
+
+ Fixed an issue on Panorama where a cyclic nested address group
+ configuration caused the
+ configd
+ process to stop responding after a commit.
+
+ |
+
|
+ PAN-262063
+ |
+
+
+ Fixed an issue where the firewall did not display the converted
+ configurations before a commit and reboot, and the commit failed when
+ attempting to migrate from MS to FRR mode.
+
+ |
+
|
+ PAN-261825
+ |
+
+
+ Fixed an issue where traffic was dropped when Data Loss Prevention or
+ Advanced URL Filtering were enabled. This occurred when the payload
+ size was greater than 3.5 KB.
+
+ |
+
|
+ PAN-261739
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the firewall displayed 0 for the physical port
+ counters read from MAC.
+
+ |
+
|
+ PAN-261597
+ |
+
+
+ Fixed an issue where the
+ all_pktproc process stopped
+ responding, which caused the firewall to become unavailable.
+
+ |
+
|
+ PAN-261312
+ |
+
+
+ Fixed an issue where a commit for a policy and configuration dump
+ overlapped, which resulted in a null pointer exception.
+
+ |
+
|
+ PAN-260059
+ |
+
+
+ Fixed an issue where
+ Device Telemetry Regions did not
+ show up with the latest content due to content files not being parsed
+ for the region list when Telemetry was turned off.
+
+ |
+
|
+ PAN-259767
+ |
+
+
+ Fixed an issue where GlobalProtect users were unable to connect when
+ the option
+ Block sessions if the certificate was not issued to the
+ authenticating device
+ was enabled in the certificate profile.
+
+ |
+
|
+ PAN-258743
+ |
+
+
+ Fixed an issue where, when you attempted to select a redistribution
+ profile when creating a BGP Redistribute policy rule, the firewall
+ displayed an empty dropdown.
+
+ |
+
|
+ PAN-258680
+ |
+
+
+ Fixed an issue on Panorama where, when you removed Security profile
+ groups from a Security policy rule via the CLI and committed the
+ change, the Security policy rule was deleted.
+
+ |
+
|
+ PAN-257183
+ |
+
+
+ Fixed an issue where the firewall dropped DNS traffic when using DNS
+ Security.
+
+ |
+
|
+ PAN-256904
+ |
+
+
+ Fixed an issue where the firewall inconsistently blocked URLs due to
+ intermittent URL category misidentification.
+
+ |
+
|
+ PAN-253127
+ |
+
+
+ Fixed an issue where, after upgrading to PAN-OS 11.0.2-h3, the
+ hardware pool DFLT became highly utilized, and the packet buffer
+ gradually increased.
+
+ |
+
|
+ PAN-251724
+ |
+
+
+ Fixed an issue where users matched incorrect Security policy rules
+ with a HIP profile.
+
+ |
+
|
+ PAN-235733
+ |
+
+
+ Fixed an issue where the displayed NTP information was incorrect if
+ the DNS servers timed out.
+
+ |
+
|
+ PAN-234993
+ |
+
+
+ Fixed an issue where CPU base gateway auto-scaling failed, which
+ caused performance issues.
+
+ |
+
|
+ PAN-233868
+ |
+
+
+ Fixed an issue where the firewall took an incorrect action for
+ overlapping custom and edl-url-categories in a policy rule.
+
+ |
+
|
+ PAN-212889
+ |
+
+
+ Fixed an issue on Panorama where different threat names were used when
+ querying a threat under
+ Threat Monitor (Monitor > App Scope) and the ACC. This resulted in the ACC displaying no data after
+ clicking a threat name in
+ Threat Monitor and filtering it in
+ the global filters.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-286255
+ |
+
+
+ Fixed an issue where, when the firewall received an unexpected
+ termination request for SSL sessions, the dataplane experienced a slow
+ buffer resource leak.
+
+ |
+
|
+ PAN-285941
+ |
+
+
+ Fixed an issue where high memory consumption occurred on the
+ logrcvr
+ process.
+
+ |
+
|
+ PAN-285651
+ |
+
+
+ (Panorama appliances in active/passive HA configurations on
+ Microsoft Azure environments only) Fixed an issue on Panorama that caused firewalls to disconnect
+ unexpectedly.
+
+ |
+
|
+ PAN-285597
+ |
+
+
+ Fixed an issue where a
+ routed
+ process memory leak occurred when advanced routing was enabled.
+
+ |
+
|
+ PAN-282391
+ |
+
+
+ Fixed an issue on Panorama where a memory leak occurred after cloning
+ a template, resulting in an increase in memory use, which caused OOM
+ errors.
+
+ |
+
|
+ PAN-282206
+ |
+
+
+ Fixed an issue where configuring Secure Web Gateway (SWG) in
+ no-auth mode led to latency when no
+ decryption policy rules or
+ No-decrypt policy rules were
+ present.
+
+ |
+
|
+ PAN-282069
+ |
+
+
+ Fixed an issue on Panorama where Security policy rules were removed
+ from device groups when you cloned or edited Security policy rules
+ that used more than 63 characters.
+
+ |
+
|
+ PAN-281649
+ |
+
+
+ Fixed an issue where the index size limit was incorrectly calculated
+ and indices rolled over earlier than expected, which resulted in high
+ memory and OOM errors.
+
+ |
+
|
+ PAN-280942
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process stopped responding.
+
+ |
+
|
+ PAN-279691
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where the firewall didn't synchronize IPSec SAs
+ (security associations) to the passive firewall if the tunnel was not
+ initially established by the active firewall.
+
+ |
+
|
+ PAN-274671
+ |
+ + + | +
|
+ PAN-274570
+ |
+
+
+ Fixed an issue where the
+ devsrvr
+ process restarted after a failed commit due to an invalid memory
+ access.
+
+ |
+
|
+ PAN-271701
+ |
+
+
+ Fixed an issue where Advanced Services, App-ID Cloud Engine (ACE), and
+ Enhanced Application Log stopped working due to incorrect memory usage
+ accounting, which caused memory usage to remain at 99% after an
+ extended period of time.
+
+ |
+
|
+ PAN-271273
+ |
+
+
+ Fixed an issue where dynamic update downloads failed when
+ IPv6 firewalling was enabled on the
+ firewall and both IPv4 and IPv6 were configured on the management
+ interface.
+
+ |
+
|
+ PAN-271175
+ |
+
+
+ Fixed an issue where the
+ all_task
+ process stopped responding with a SIGABRT.
+
+ |
+
|
+ PAN-269027
+ |
+
+
+ Fixed an issue related to external dynamic lists that caused commit
+ times on the firewall to be higher than expected.
+
+ |
+
|
+ PAN-268614
+ |
+
+
+ Fixed an issue on the web interface where, when all rules were
+ highlighted when a read-only admin user clicked the
+ Highlight Unused Rules checkbox.
+
+ |
+
|
+ PAN-268118
+ |
+
+
+ Fixed an issue on firewalls in active/passive HA configurations where,
+ after a failover, irrelevant routing FIB entries were seen in the
+ routing table on the newly active firewall.
+
+ |
+
|
+ PAN-267444
+ |
+
+
+ Fixed an issue where large file downloads or uploads failed or
+ remained in an incomplete state when using DLP HTTP2 mirror mode.
+
+ |
+
|
+ PAN-260015
+ |
+
+
+ Fixed an issue on the firewall where the dataplane restarted due to
+ insufficient allocation of memory buffers.
+
+ |
+
|
+ PAN-256867
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process stopped responding while processing session logs for
+ forwarding to the LFC.
+
+ |
+
|
+ PAN-255914
+ |
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) environments
+ only) Fixed an issue where a newly bootstrapped firewall required a
+ management server restart, relicensing, or license push from Panorama
+ to invoke the device certificate.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-273215
+ |
+
+
+ Fixed an issue where a syntax error in the index generation script
+ caused a high management plane CPU load after upgrading.
+
+ |
+
|
+ PAN-271913
+ |
+
+
+ Fixed an issue on firewalls in high availability (HA) configurations
+ where, when using the Cloud Identity Engine (CIE), the firewall
+ experienced consistent memory leaks on the active firewall, which
+ caused unexpected failovers.
+
+ |
+
|
+ PAN-270224
+ |
+
+
+ Fixed an issue where indices were not opened after a query.
+
+ |
+
|
+ PAN-269539
+ |
+
+
+ Fixed an issue where whitespace was added before the timestamp in
+ syslog logs forwarded from Panorama.
+
+ |
+
|
+ PAN-269000
+ |
+
+
+ Fixed an issue where the firewall stopped responding due to a NULL
+ pointer dereference when path monitoring failed.
+
+ |
+
|
+ PAN-268951
+ |
+
+
+ Fixed a CPS counter query issue that caused SNMP polling timeouts on
+ the firewall.
+
+ |
+
|
+ PAN-268727
+ |
+
+
+ Fixed an issue where traffic was dropped when the accumulation proxy
+ was enabled and header insertion modified packets.
+
+ |
+
|
+ PAN-268474
+ |
+
+
+ Fixed an issue on the firewall where the PAN-DB URL Filtering license
+ displayed as Valid even when the
+ firewall did not have the license, which caused traffic to drop.
+
+ |
+
|
+ PAN-268419
+ |
+
+
+ Fixed an issue where
+ Managed Devices > Summary
+ displayed incorrect subcolumns.
+
+ |
+
|
+ PAN-268319
+ |
+
+
+ Fixed an issue where
+ Receive Time and
+ Time Generated were not visible as
+ attributes in the Filter Builder for
+ system logs and URL filtering logs.
+
+ |
+
|
+ PAN-268229
+ |
+
+
+ Fixed an issue where the firewall stopped responding during session
+ setup for ECMP hit-count updates.
+
+ |
+
|
+ PAN-268228
+ |
+
+
+ Fixed an issue where Panorama administrators were unable to select
+ Edit Selection when pushing changes
+ to devices if they logged in using TACACS authentication.
+
+ |
+
|
+ PAN-267934
+ |
+
+
+ Fixed an issue where commits remained at 98%, which resulted in the
+ BGP connection flapping.
+
+ |
+
|
+ PAN-267590
+ |
+
+
+ Fixed a lock usage error that caused the
+ ikemgr
+ process to stop responding.
+
+ |
+
|
+ PAN-267348
+ |
+
+
+ Fixed an issue on the Panorama web interface where
+ WildFire Activity by File Type in
+ the ACC did not display the file type name.
+
+ |
+
|
+ PAN-267321
+ |
+
+
+ Fixed an issue where packets were dropped when BFD inter-dataplane
+ packet forwarding failed.
+
+ |
+
|
+ PAN-267285
+ |
+
+
+ Fixed an issue where a port was able to be connected from outside the
+ network. With this fix, the port is restricted to the local interface.
+
+ |
+
|
+ PAN-267091
+ |
+
+
+ Fixed an issue on Panorama where Elasticsearch repeatedly restarted.
+
+ |
+
|
+ PAN-266900
+ |
+
+
+ Fixed an issue on the Panorama web interface where you were unable to
+ click OK after selecting an install
+ package type and file from the dropdown and selecting a firewall.
+
+ |
+
|
+ PAN-266639
+ |
+
+
+ Fixed an issue where administrators were unable to edit or add virtual
+ router configurations when a filter was applied to the viewer.
+
+ |
+
|
+ PAN-266581
+ |
+
+
+ Fixed an issue where a failed SSL connection to a syslog server
+ resulted in a
+ /tmp/srvr.crt.xxxxxx file not
+ being removed, which caused index node (inode) exhaustion.
+
+ |
+
|
+ PAN-266167
+ |
+
+
+ Fixed an issue where the
+ restart option for IPSec tunnels was
+ greyed out (Network > IPSec Tunnels > IKE Info).
+
+ |
+
|
+ PAN-266003
+ |
+
+
+ Fixed an issue on the firewall where a configuration policy push
+ caused both active and passive firewalls to go down when a high number
+ of spyware profiles and vulnerability profiles were pushed to the
+ dataplane.
+
+ |
+
|
+ PAN-265621
+ |
+
+
+ Fixed an issue where the
+ restart option for IPSec tunnels was
+ greyed out when you attempted to restart the tunnel from
+ Network > IPSec Tunnels > IKE Info.
+
+ |
+
|
+ PAN-265399
+ |
+
+
+ Fixed an issue where DNS queries for uppercase internal domain (SRV
+ record) timed out when DNS Security was enabled.
+
+ |
+
|
+ PAN-265366
+ |
+
+
+ Fixed an issue where firewall experienced frequent reboots when ipv6
+ trafic is routed to explicit proxy, causing explicit proxy to crash.
+
+ |
+
|
+ PAN-265160
+ |
+
+
+ Fixed an issue where the firewall created multiple connections to a
+ syslog server and remained in the FINWAIT1 state, which caused logs to
+ drop while being forwarded to the syslog server.
+
+ |
+
|
+ PAN-264981
+ |
+
+
+ Fixed an issue on the Panorama web interface where it took longer than
+ expected to edit Security policy rules.
+
+ |
+
|
+ PAN-264883
+ |
+
+
+ (PA-7080 appliances with LPCs only) Fixed an
+ issue where syslog forwarding over TCP stopped after upgrading.
+
+ |
+
|
+ PAN-264678
+ |
+
+
+ Fixed an issue where
+ Preview Changes did not display
+ configuration changes in
+ Commit and push >
+ Push Scope.
+
+ |
+
|
+ PAN-264662
+ |
+
+
+ Fixed an issue where HTTP POST requests were blocked for URLs that had
+ the block-continue category
+ configured.
+
+ |
+
|
+ PAN-263843
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ the firewall received no-license packet buffers instead of memory
+ based packet buffer numbers.
+
+ |
+
|
+ PAN-263208
+ |
+
+
+ (PA-5440 and PA-5445 firewalls only) Fixed an
+ issue where interrupts were generated at a certain packet rate, and
+ dataplane processes missed heartbeats, which caused the dataplane to
+ go down.
+
+ |
+
|
+ PAN-263012
+ |
+
+
+ Fixed an issue where commits failed from a Panorama appliance with a
+ default master key to a firewall with a master key configured and a VM
+ Information source configured.
+
+ |
+
|
+ PAN-262973
+ |
+
+
+ Fixed an issue where changes made by a custom role Panorama
+ administrator did not display in the push scope for other custom role
+ administrators when a full commit was performed.
+
+ |
+
|
+ PAN-262540
+ |
+
+
+ Fixed an issue where application traffic transactions that reused TCP
+ ports did not work with decryption.
+
+ |
+
|
+ PAN-262511
+ |
+
+
+ Fixed an issue on firewalls in HA configurations where OSPF neighbors
+ were not established after an HA failover.
+
+ |
+
|
+ PAN-260796
+ |
+
+
+ Fixed an issue where servers were not accessible through an active SSL
+ GlobalProtect VPN tunnel until a new connection was established or the
+ session was cleared on the firewall.
+
+ |
+
|
+ PAN-260604
+ |
+
+
+ Fixed an issue where the firewall displayed inaccurate throughput
+ utilization stats in NetFlow analyzer tools.
+
+ |
+
|
+ PAN-260417
+ |
+
+
+ Fixed an issue on Panorama where
+ UpdateLicDB was triggered every
+ few minutes when firewalls with PAYG licenses were onboarded.
+
+ |
+
|
+ PAN-257736
+ |
+
+
+ (PA-5450 firewalls only) Fixed an issue where
+ traffic to benign applications was impacted by holding TCP sequential
+ segments for MLC inspection and not releasing the full chain after a
+ benign verdict was received.
+
+ |
+
|
+ PAN-256552
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ stopped responding, which caused the firewall to restart.
+
+ |
+
|
+ PAN-255747
+ |
+
+
+ Fixed an issue on the firewall where CLI commands returned
+ Server error: op command for client dagger timed out as client is
+ not available.
+
+ |
+
|
+ PAN-255653
+ |
+
+
+ Fixed an HA failover issue where, when Management Processing Card
+ (MPC) or Base Card (BC) failures occurred, the HA link went down,
+ which caused fpp-down events on one firewall.
+
+ |
+
|
+ PAN-253485
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where dataplane packet capture filter configuration
+ failed on the active firewall with the error
+ op command for client dagger timed out as client is not
+ available.
+
+ |
+
|
+ PAN-252669
+ |
+
+
+ Fixed an issue where the
+ ikemgr
+ process stopped responding with a
+ SIGSEGV error.
+
+ |
+
|
+ PAN-251973
+ |
+
+
+ Fixed an issue where the firewall did not detect evasions due to TCP
+ checksum offloading not being enabled.
+
+ |
+
|
+ PAN-249581
+ |
+
+
+ Fixed an issue where stale BGP routes were advertised to peers even
+ when they were not present in the local RIB table.
+
+ |
+
|
+ PAN-249384
+ |
+
+
+ Fixed an issue on Panorama where configuration locks were observed
+ during a partial rulebase commit.
+
+ |
+
|
+ PAN-243920
+ |
+
+
+ Fixed an issue where the firewall name was truncated in the logs when
+ the name used more than 31 characters.
+
+ |
+
|
+ PAN-233197
+ |
+
+
+ Fixed an issue where the CLI command to set the FEC parameter for the
+ front panel ports was not supported on platforms supporting 25G and
+ 100G.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-279604
+ |
+
+
+ Fixed an issue where scheduled SaaS application usage reports were
+ generated incorrectly, and the login page was displayed instead of the
+ report content.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-290996
+ |
+
+
+ Fixed an issue where SNMP walks returned a value of 0 for the CPS
+ (Connections Per Second) per vsys on firewalls after upgrading to
+ PAN-OS 11.1.6-h3, even when active connections were present.
+
+ |
+
|
+ PAN-289304
+ |
+
+
+ (PA-7500 firewalls only) Fixed an issue where
+ SNMP polling failed due to the
+ snmpd
+ process becoming unresponsive to incoming requests, which resulted in
+ high CPU usage.
+
+ |
+
|
+ PAN-289102
+ |
+
+
+ (PA-7500 Series, PA-5410, PA-5420, PA-5430, PA-5440, PA-5445,
+ PA-3400 Series, PA-1400 Series, PA-400 Series, VM-Series, and
+ CN-Series firewalls only) Fixed a race condition issue related to predict processing, which
+ resulted in a dataplane restart and traffic loss.
+
+ |
+
|
+ PAN-286897
+ |
+
+
+ Fixed an issue where the
+ pan_task
+ process stopped responding when the firewall attempted to forward
+ files to the WildFire public cloud, which caused the dataplane to
+ experience heartbeat failures.
+
+ |
+
|
+ PAN-286306
+ |
+
+
+ Fixed an issue where, when getting transceiver information from ESCC
+ for SFP 25G modules, the transceiver code was incorrectly updated with
+ Unknown instead of
+ 25GBase-SR.
+
+ |
+
|
+ PAN-286255
+ |
+
+
+ Fixed an issue where, when the firewall received an unexpected
+ termination request for SSL sessions, the dataplane experienced a slow
+ buffer resource leak.
+
+ |
+
|
+ PAN-285941
+ |
+
+
+ Fixed an issue where high memory consumption occurred on the
+ logrcvr
+ process.
+
+ |
+
|
+ PAN-285651
+ |
+
+
+ (Panorama appliances in active/passive HA configurations on
+ Microsoft Azure environments only) Fixed an issue on Panorama that caused firewalls to disconnect
+ unexpectedly.
+
+ |
+
|
+ PAN-285597
+ |
+
+
+ Fixed an issue where a
+ routed
+ process memory leak occurred when advanced routing was enabled.
+
+ |
+
|
+ PAN-285590
+ |
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) GWLB environments
+ only) Fixed an issue where the firewall CPU usage reached 100% after
+ upgrading to PAN-OS 11.1.6-h1.
+
+ |
+
|
+ PAN-284116
+ |
+
+
+ Fixed an issue where mTLS decryption bypass did not work when the
+ decryption profile was configured with the maximum TLS version as TLS
+ 1.3.
+
+ |
+
|
+ PAN-284066
+ |
+
+
+ Fixed an issue where, after an upgrade, the SNMP polled values for
+ IF-MIB::ifInErrors displayed a
+ high number of errors that did not match the values in the CLI show
+ interface command.
+
+ |
+
|
+ PAN-283789
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where, after an upgrade, the
+ mac receive error counter in
+ receive incoming errors increased,
+ which resulted in SNMP alerts.
+
+ |
+
|
+ PAN-283467
+ |
+
+
+ (PA-3400 Series firewalls only) Fixed an issue
+ where the firewall unexpectedly rebooted and entered maintenance mode
+ due to a ctd-agent out-of-memory (OOM) condition. This occurred during
+ advanced services load testing and a high volume of IoT EAL log
+ forwarding.
+
+ |
+
|
+ PAN-282391
+ |
+
+
+ (Panorama appliances and Log Collectors only)
+ Fixed an issue where a VLD memory leak caused increased memory use,
+ which resulted in OOM errors.
+
+ |
+
|
+ PAN-282236
+ |
+
+
+ Fixed an issue where large IPv6 packets were reassembled incorrectly
+ on the firewall when the packets arrived fragmented over an IPv4
+ tunnel.
+
+ |
+
|
+ PAN-282206
+ |
+
+
+ Fixed an issue where configuring Secure Web Gateway (SWG) in
+ no-auth mode led to latency when no
+ decryption policy rules or
+ No-decrypt policy rules were
+ present.
+
+ |
+
|
+ PAN-282069
+ |
+
+
+ Fixed an issue on Panorama where Security policy rules were removed
+ from device groups when you cloned or edited Security policy rules
+ that used more than 63 characters.
+
+ |
+
|
+ PAN-282022
+ |
+
+
+ Fixed the support limitation for the Panorama M-600 and M-700
+ appliances.
+
+ |
+
|
+ PAN-281885
+ |
+
+
+ Fixed an issue where, when exporting and importing CSV files, the hash
+ values of pre-shared key variables set at template and template stack
+ levels changed inconsistently, which resulted in both variables
+ displaying the same hash value.
+
+ |
+
|
+ PAN-281649
+ |
+
+
+ Fixed an issue where the index size limit was incorrectly calculated
+ and indices rolled over earlier than expected, which resulted in high
+ memory and OOM errors.
+
+ |
+
|
+ PAN-281269
+ |
+
+
+ ($$PA-5420 firewalls$$) Fixed an issue where
+ the firewall management server memory usage continuously increased.
+
+ |
+
|
+ PAN-281264
+ |
+
+
+ Fixed an issue where the
+ routed
+ process memory usage continuously increased when Advanced Routing was
+ enabled.
+
+ |
+
|
+ PAN-280942
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process stopped responding.
+
+ |
+
|
+ PAN-280698
+ |
+
+
+ Fixed an issue where the firewall removed the TCP timestamp from
+ client hello messages that did not fit in a single packet, which
+ resulted in connection issues.
+
+ |
+
|
+ PAN-280505
+ |
+
+
+ Fixed an issue where the web interface did not display a message to
+ commit prior changes before attempting a partial configuration load.
+
+ |
+
|
+ PAN-280477
+ |
+
+
+ Fixed an issue on the web interface were you were unable to scroll up
+ or down to view source zones in a NAT policy rule.
+
+ |
+
|
+ PAN-280471
+ |
+
+
+ Fixed an issue where navigating
+ Panorama > Monitor > Logs was
+ slower than expected.
+
+ |
+
|
+ PAN-280243
+ |
+
+
+ Fixed an issue where the firewall lost the pre-shared key
+ configuration assigned from a PSK variable when an unrelated device
+ group configuration was loaded.
+
+ |
+
|
+ PAN-279983
+ |
+
+
+ (PA-1400 Series firewalls only) Fixed an issue
+ on the web interface where
+ Enable Bonjour Reflector was not
+ displayed (Network > Interfaces > Ethernet Interface).
+
+ |
+
|
+ PAN-279746
+ |
+
+
+ Fixed an issue where SMTP packets were not sent out when the Client
+ Hello arrived at the firewall in multiple out-of-order segments and
+ the traffic was not subject to SSL decryption.
+
+ |
+
|
+ PAN-279691
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where the firewall didn't synchronize IPSec SAs
+ (security associations) to the passive firewall if the tunnel was not
+ initially established by the active firewall.
+
+ |
+
|
+ PAN-279621
+ |
+
+
+ Fixed an issue where processes stopped responding when HTTPS Forward
+ traffic was run.
+
+ |
+
|
+ PAN-279336
+ |
+
+
+ Fixed an issue where the CLI did not display a message to commit prior
+ changes before loading a partial configuration.
+
+ |
+
|
+ PAN-279191
+ |
+
+
+ Fixed an issue where a GlobalProtect gateway stopped responding when
+ handling HTTP/1.1 traffic with web inspection enabled.
+
+ |
+
|
+ PAN-279176
+ |
+
+
+ Fixed an issue where the configuration audit displayed inaccurate
+ information after partially loading the configuration via the CLI,
+ which caused the audit to flag the configuration as deleted or
+ changed.
+
+ |
+
|
+ PAN-279065
+ |
+
+
+ Fixed an issue where the firewall sent logs with
+ connection succeeded to the syslog
+ server every time a connection was established, which resulted in
+ excessive logs.
+
+ |
+
|
+ PAN-278296
+ |
+
+
+ Fixed an issue where the system MAC address of the aggregate interface
+ was the same on the active firewall and the passive firewall after an
+ upgrade.
+
+ |
+
|
+ PAN-278088
+ |
+
+
+ Fixed an issue where the
+ show system resources follow CLI
+ command was not available.
+
+ |
+
|
+ PAN-277762
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ unexpected failovers occurred on firewalls running PAN-OS 11.2.2-h2.
+
+ |
+
|
+ PAN-277631
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process discarded logs due to a full queue.
+
+ |
+
|
+ PAN-277417
+ |
+
+
+ Fixed an memory leak issue related to TLS inbound decryption.
+
+ |
+
|
+ PAN-276062
+ |
+
+
+ Fixed an issue where importing a firewall with a large number of
+ address objects into Panorama did not work and remained at 99%
+ completion.
+
+ |
+
|
+ PAN-275905
+ |
+
+
+ Fixed an issue where the Panorama web interface was slower than
+ expected and Elasticsearch CPU usage was high.
+
+ |
+
|
+ PAN-275718
+ |
+
+
+ Fixed an issue where Panorama stopped forwarding logs to a Syslog
+ server after upgrading to PAN-OS 11.1.5-h1.
+
+ |
+
|
+ PAN-275713
+ |
+
+
+ Fixed an issue where the
+ dscd
+ process stopped responding when
+ Endpoint Serial Number was enabled,
+ which resulted in the
+ Active Directory returning a list of
+ serial numbers for a specific firewall from the Cloud Identity Engine.
+
+ |
+
|
+ PAN-275077
+ |
+
+
+ Fixed an issue where DNS Security intermittently logs malicious domain
+ URLs as Alert instead of taking a Sinkhole action, even when
+ configured to Sinkhole malicious DNS domains.
+
+ |
+
|
+ PAN-275032
+ |
+
+
+ (M-600 appliances only) Fixed an issue where
+ the Elasticsearch cluster certificate (CC) status displayed with a
+ past expiration date, which caused all shards to be unassigned.
+
+ |
+
|
+ PAN-274791
+ |
+
+
+ Fixed an issue where the firewall might reboot when traffic matches
+ with certain Advanced features (such as Advanced Threat Prevention and
+ Advanced URL Filtering with properly configured URL
+ Filtering/Anti-Spyware/Vulnerability security profiles) and Shared
+ Pool Type 32 becomes depleted.
+
+ |
+
|
+ PAN-274750
+ |
+
+
+ Fixed an issue where the detailed log view in Panorama did not display
+ all packet details for traffic logs received from the cloud.
+
+ |
+
|
+ PAN-274671
+ |
+
+
+ Fixed an issue where empty traffic
+ logdb folders were generated for
+ each day even when traffic logs were not received by the
+ logrcvr
+ process.
+
+ |
+
|
+ PAN-274592
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where the firewall did not fail over when the active firewall
+ experienced data plane issues.
+
+ |
+
|
+ PAN-274570
+ |
+
+
+ Fixed an issue where the
+ devsrvr
+ process restarted after a failed commit due to an invalid memory
+ access.
+
+ |
+
|
+ PAN-274314
+ |
+
+
+ (PA-1400 Series firewalls, PA-3400 Series firewalls, and PA-5400
+ Series firewalls only) Fixed an issue where, when the
+ pan_task
+ process restarted, control plane packets were dropped, which could
+ impact LACP and pings to host interfaces.
+
+ |
+
|
+ PAN-273949
+ |
+
+
+ Fixed an issue where the firewall generated the following error
+ message in the
+ snmpd
+ logs:
+ pan_get_keystr_from_cryptod(pan_snmpinterface.c:181): Key
+ X2F1dGhfa2V5 import from cryptod failed.
+
+ |
+
|
+ PAN-273694
+ |
+
+
+ Fixed an issue where the firewall rebooted due to an out-of-bounds
+ memory access that occurred as a result of the SIP content length
+ value being split across packets.
+
+ |
+
|
+ PAN-273453
+ |
+
+
+ Fixed an issue where restarting the firewall did not initiate an
+ autocommit job, which caused the firewall to stop responding and the
+ HA interface to go down.
+
+ |
+
|
+ PAN-273422
+ |
+
+
+ Fixed an issue where traffic failed when Inline cloud analysis
+ (Advanced Threat Prevention) was enabled in the Anti-Spyware profile
+ with the action set to anything other than
+ allow or
+ alert and the maximum latency
+ condition was reached.
+
+ |
+
|
+ PAN-273308
+ |
+
+
+ A fix was made to address
+ CVE-2025-0130.
+
+ |
+
|
+ PAN-273141
+ |
+
+
+ Fixed an issue where GlobalProtect clients experienced slow file
+ transfer download throughput when passing through an IPSec tunnel.
+
+ |
+
|
+ PAN-273129
+ |
+
+
+ Fixed an issue on the web interface where the
+ negate option was visible when you
+ clicked on the rule name, but not when you viewed the target options
+ from the rulebase attribute.
+
+ |
+
|
+ PAN-273026
+ |
+
+
+ Fixed an issue where traffic logs did not display correctly when
+ filters were applied.
+
+ |
+
|
+ PAN-273021
+ |
+
+
+ Fixed an issue where 25G port links did not come up due to a change in
+ the handling of 25G DAC modules.
+
+ |
+
|
+ PAN-273019
+ |
+
+
+ Fixed an intermittent issue where SSL decryption failed.
+
+ |
+
|
+ PAN-272812
+ |
+
+
+ Fixed an issue where SNMP monitoring of tunnel interfaces displayed
+ zero values for received bytes and packets.
+
+ |
+
|
+ PAN-272746
+ |
+
+
+ (PA-440 firewalls only) Fixed an issue where
+ the firewall entered an unstable state after committing changes or
+ onboarding to Panorama.
+
+ |
+
|
+ PAN-272605
+ |
+
+
+ Fixed an issue where the firewall did not display VPC endpoints when
+ there was a large amount of VPC endpoints to interface mappings.
+
+ |
+
|
+ PAN-272171
+ |
+
+
+ Fixed an issue where the firewall dropped the AAAA DNS server response
+ and caused delays in traffic from Ubuntu or Linux clients when DNS
+ Security was enabled.
+
+ |
+
|
+ PAN-272085
+ |
+
+
+ Fixed an issue where the firewall unexpectedly stopped responding and
+ rebooted when DoH was enabled for DNS Security and multiple DoH
+ transactions were sent in a single HTTP/1 connection.
+
+ |
+
|
+ PAN-271915
+ |
+
+
+ Fixed an issue where the push scope did not populate when attempting
+ to push a policy to a device group.
+
+ |
+
|
+ PAN-271723
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where the
+ all_task
+ process stopped responding, which caused the passive firewall to
+ repeatedly reboot.
+
+ |
+
|
+ PAN-271701
+ |
+
+
+ Fixed an issue where Advanced Services, App-ID Cloud Engine (ACE), and
+ Enhanced Application Log stopped working due to incorrect memory usage
+ accounting, which caused memory usage to remain at 99% after an
+ extended period of time.
+
+ |
+
|
+ PAN-271700
+ |
+
+
+ Fixed an issue where User-ID connections were lost after an HA
+ failover.
+
+ |
+
|
+ PAN-271560
+ |
+
+
+ Fixed an issue where DNS requests to malware sites were not blocked as
+ expected, and the
+ dns-security-categories log-level and action displayed default values instead of
+ unavailable.
+
+ |
+
|
+ PAN-271498
+ |
+
+
+ (PA-7000 Series firewalls, PA-5200 firewalls, and PA-5400f firewalls
+ in FIPS mode only) Fixed an issue where decrypted traffic repeatedly failed and
+ frequent reboots were required.
+
+ |
+
|
+ PAN-271351
+ |
+
+
+ A fix was made to address
+ CVE-2025-0116.
+
+ |
+
|
+ PAN-271273
+ |
+
+
+ Fixed an issue where the
+ all_task
+ process stopped responding with a SIGABRT.
+
+ |
+
|
+ PAN-271151
+ |
+
+
+ Fixed an issue where the GlobalProtect client did not automatically
+ initiate a Kerberos SSO connection after logging in to Windows.
+
+ |
+
|
+ PAN-270849
+ |
+
+
+ Fixed a memory leak issue related to the
+ configd
+ process that occurred when running consecutive commits for multiple
+ days.
+
+ |
+
|
+ PAN-270744
+ |
+
+
+ Fixed an issue where API calls to Panorama failed with the error
+ Server error : Timed out while getting config lock. Please try
+ again.
+
+ |
+
|
+ PAN-270379
+ |
+
+
+ Fixed an issue where socket files created in the /tmp directory were
+ not cleared.
+
+ |
+
|
+ PAN-270248
+ |
+
+
+ Fixed an issue where the firewall failed to forward logs to a SNMP
+ trap server if the SNMP manager IP address was unable to be resolved.
+
+ |
+
|
+ PAN-270193
+ |
+
+
+ Fixed an issue where the Panorama management server changed its
+ certificate authority (CA) unexpectedly, which caused managed
+ firewalls to disconnect.
+
+ |
+
|
+ PAN-269737
+ |
+
+
+ Fixed an issue where the following critical error displayed
+ repeatedly:
+ /mnt/cdrom is mounted as Read-Only.
+
+ |
+
|
+ PAN-269291
+ |
+
+
+ Fixed an issue where the scheduled report generation script did not
+ return debug information.
+
+ |
+
|
+ PAN-269193
+ |
+
+
+ Fixed an issue where the firewall redirected the user to the first
+ application instead of the portal page with a list of applications
+ when multiple applications were configured for GlobalProtect
+ clientless VPN along with any user match.
+
+ |
+
|
+ PAN-269139
+ |
+
+
+ (Firewalls with DPDK enabled in Azure, GCP, AWS, and KVM
+ environments only) Fixed an issue where, after an upgrade to PAN-OS 11.1.4, the
+ mac receive error counter
+ increased without an error even though traffic was not impacted.
+
+ |
+
|
+ PAN-269091
+ |
+
+
+ Fixed an issue where the
+ varrcvr
+ process stopped responding.
+
+ |
+
|
+ PAN-269052
+ |
+
+
+ Fixed an issue where traffic was blocked by a URL filtering profile
+ even though the Security policy rule did not have a URL filtering
+ profile configured.
+
+ |
+
|
+ PAN-269027
+ |
+
+
+ Fixed an issue related to external dynamic lists that caused commit
+ times on the firewall to be higher than expected.
+
+ |
+
|
+ PAN-268909
+ |
+
+
+ Fixed an issue where IP address tags were removed from firewalls after
+ a management server or
+ useridd
+ process restart. This occurred when a Panorama serial-number based
+ configuration was used for User-ID redistribution.
+
+ |
+
|
+ PAN-268800
+ |
+
+
+ Fixed an issue where a large number of logs caused the
+ logrcvr
+ process to stop responding.
+
+ |
+
|
+ PAN-268705
+ |
+
+
+ Fixed an intermittent issue where the firewall failed to process FTP
+ traffic after upgrading to PAN-OS 10.1.14.
+
+ |
+
|
+ PAN-268629
+ |
+
+
+ Fixed an issue where traffic did not match the correct security policy
+ when using an application-filter that referenced a cloud application.
+ This occurred when a high number of cloud applications were attached
+ with a custom tag.
+
+ |
+
|
+ PAN-268614
+ |
+
+
+ Fixed an issue on the web interface where, when all rules were
+ highlighted when a read-only admin user clicked the
+ Highlight Unused Rules checkbox.
+
+ |
+
|
+ PAN-268279
+ |
+
+
+ Fixed an issue where autocommits failed if the management IPv6 gateway
+ was the same as the dataplane interface IP address.
+
+ |
+
|
+ PAN-268127
+ |
+
+
+ Fixed an issue where tagging devices in Panorama did not work as
+ expected.
+
+ |
+
|
+ PAN-268118
+ |
+
+
+ Fixed an issue on firewalls in active/passive HA configurations where,
+ after a failover, irrelevant routing FIB entries were seen in the
+ routing table on the newly active firewall.
+
+ |
+
|
+ PAN-267995
+ |
+
+
+ Fixed an issue where after migrating to a new platform, DLP verdicts
+ were not displayed in the Cloud Manager or logs.
+
+ |
+
|
+ PAN-267671
+ |
+ + + | +
|
+ PAN-267518
+ |
+
+
+ Fixed an issue where WildFire submission logs incorrectly reported
+ allowed malicious samples even when they were blocked by threat
+ prevention profiles.
+
+ |
+
|
+ PAN-267444
+ |
+
+
+ Fixed an issue where large file downloads or uploads failed or
+ remained in an incomplete state when using DLP HTTP2 mirror mode.
+
+ |
+
|
+ PAN-267204
+ |
+
+
+ Fixed an issue where Panorama port 9300 did not adhere to restricted
+ TLS versions and ciphers.
+
+ |
+
|
+ PAN-266695
+ |
+
+
+ Fixed an issue on Panorama where a cyclic nested address group
+ configuration caused the
+ configd
+ process to stop responding after a commit.
+
+ |
+
|
+ PAN-266559
+ |
+
+
+ Fixed an issue where partial commits failed when objects that were
+ referenced in a high number of Security policy rules were renamed.
+
+ |
+
|
+ PAN-266354
+ |
+
+
+ Fixed an issue where Hybrid-SWG explicit proxy connections failed when
+ the number of destination domains exceeded 1024.
+
+ |
+
|
+ PAN-266116
+ |
+
+
+ Fixed an issue where URLs did not work due to certificate revocation
+ list (CRL) requests failing.
+
+ |
+
|
+ PAN-265745
+ |
+
+
+ Fixed an issue where the firewall displayed incorrect MAC receive
+ error counters for VMWare devices hosted in ESXi.
+
+ |
+
|
+ PAN-264477
+ |
+
+
+ Fixed an issue where the firewall did not start Elasticsearch after a
+ commit if Elasticsearch was not previously enabled and started.
+
+ |
+
|
+ PAN-264423
+ |
+
+
+ Fixed an issue where the firewall sent a 503 response when a client
+ connected to a web server when the firewall was configured as a web
+ proxy and authentication bypass for Kerberos was enabled.
+
+ |
+
|
+ PAN-263291
+ |
+
+
+ Fixed an issue where Microsoft Outlook did not work as expected when
+ the GlobalProtect clientless VPN was configured.
+
+ |
+
|
+ PAN-262063
+ |
+
+
+ Fixed an issue where the firewall did not display the converted
+ configurations before a commit and reboot, and the commit failed when
+ attempting to migrate from MS to FRR mode.
+
+ |
+
|
+ PAN-261998
+ |
+
+
+ Fixed an issue where the firewall configuration process restarted
+ during an External Dynamic List refresh or a commit and push
+ operation.
+
+ |
+
|
+ PAN-261825
+ |
+
+
+ Fixed an issue where traffic was dropped when Data Loss Prevention or
+ Advanced URL Filtering were enabled. This occurred when the payload
+ size was greater than 3.5 KB.
+
+ |
+
|
+ PAN-261739
+ |
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the firewall displayed 0 for the physical port
+ counters read from MAC.
+
+ |
+
|
+ PAN-261597
+ |
+
+
+ Fixed an issue where the
+ all_pktproc
+ process stopped responding, which caused the firewall to become
+ unavailable.
+
+ |
+
|
+ PAN-261429
+ |
+
+
+ Fixed an issue where the show
+ auth radius-require-msg-authentic
+ command CLI displayed no output.
+
+ |
+
|
+ PAN-261312
+ |
+
+
+ Fixed an issue where a commit for a policy and configuration dump
+ overlapped, which resulted in a null pointer exception.
+
+ |
+
|
+ PAN-260300
+ |
+
+
+ (PA-5410, PA-5420, PA-5430, PA-5440 and PA-5445 firewalls only) Fixed an issue related to the
+ all_pktproc
+ process where DPC slot 3 stopped responding.
+
+ |
+
|
+ PAN-260149
+ |
+
+
+ Fixed an issue where the management plane DNS cache size was lower
+ than expected.
+
+ |
+
|
+ PAN-260059
+ |
+
+
+ Fixed an issue where
+ Device Telemetry Regions did not
+ show up with the latest content due to content files not being parsed
+ for the region list when Telemetry was turned off.
+
+ |
+
|
+ PAN-260015
+ |
+
+
+ Fixed an issue on the firewall where the dataplane restarted due to
+ insufficient allocation of memory buffers.
+
+ |
+
|
+ PAN-259767
+ |
+
+
+ Fixed an issue where GlobalProtect users were unable to connect when
+ the option
+ Block sessions if the certificate was not issued to the
+ authenticating device
+ was enabled in the certificate profile.
+
+ |
+
|
+ PAN-259076
+ |
+
+
+ Fixed an issue where the firewall displayed an OCSP/CRL check failure
+ when accessing websites.
+
+ |
+
|
+ PAN-258743
+ |
+
+
+ Fixed an issue where, when you attempted to select a redistribution
+ profile when creating a BGP Redistribute policy rule, the firewall
+ displayed an empty dropdown.
+
+ |
+
|
+ PAN-258680
+ |
+
+
+ Fixed an issue on Panorama where, when you removed Security profile
+ groups from a Security policy rule via the CLI and committed the
+ change, the Security policy rule was deleted.
+
+ |
+
|
+ PAN-258570
+ |
+
+
+ Fixed an issue where the firewall might reboot unexpectedly due to the
+ varrcvr
+ process progressively using more memory when WildFire file forwarding
+ is handling PE files.
+
+ |
+
|
+ PAN-257183
+ |
+
+
+ Fixed an issue where the firewall dropped DNS traffic when using DNS
+ Security.
+
+ |
+
|
+ PAN-256904
+ |
+
+
+ Fixed an issue where the firewall inconsistently blocked URLs due to
+ intermittent URL category misidentification.
+
+ |
+
|
+ PAN-256867
+ |
+
+
+ Fixed an issue where the
+ logrcvr
+ process stopped responding while processing session logs for
+ forwarding to the LFC.
+
+ |
+
|
+ PAN-255914
+ |
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) environments
+ only) Fixed an issue where a newly bootstrapped firewall required a
+ management server restart, relicensing, or license push from Panorama
+ to invoke the device certificate.
+
+ |
+
|
+ PAN-255619
+ |
+
+
+ Fixed an intermittent issue where file downloads from websites failed
+ when decrypting HTTP/2 traffic.
+
+ |
+
|
+ PAN-254293
+ |
+
+
+ Fixed an issue where an explicit proxy caused intermittent SSL
+ handshake failures to SAP applications accessing public URLs.
+
+ |
+
|
+ PAN-253778
+ |
+
+
+ (PA-7500 Series firewalls in a cluster configuration only) Fixed an issue where users were able to enable or disable certain
+ configurations.
+
+ |
+
|
+ PAN-253127
+ |
+
+
+ Fixed an issue where, after upgrading to PAN-OS 11.0.2-h3, the
+ hardware pool DFLT became highly utilized, and the packet buffer
+ gradually increased.
+
+ |
+
|
+ PAN-251724
+ |
+
+
+ Fixed an issue where users matched incorrect Security policy rules
+ with a HIP profile.
+
+ |
+
|
+ PAN-248157
+ |
+
+
+ Fixed an issue where the firewall showed three different sets of name
+ validation rules when generating, importing, or editing a certificate.
+
+ |
+
|
+ PAN-245064
+ |
+
+
+ (Multi-vsys firewalls only) Fixed an issue
+ where commits failed on the firewall after selecting
+ Export or push device config bundle
+ on Panorama and a force push was required.
+
+ |
+
|
+ PAN-235733
+ |
+
+
+ Fixed an issue where the displayed NTP information was incorrect if
+ the DNS servers timed out.
+
+ |
+
|
+ PAN-234993
+ |
+
+
+ Fixed an issue where CPU base gateway auto-scaling failed, which
+ caused performance issues.
+
+ |
+
|
+ PAN-233868
+ |
+
+
+ Fixed an issue where the firewall took an incorrect action for
+ overlapping custom and edl-url-categories in a policy rule.
+
+ |
+
|
+ PAN-216054
+ |
+
+
+ Fixed an issue that caused the firewall fan speed to increase while it
+ was idle.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-300227
+ |
+
+
+ Fixed an issue where the firewall dropped packets due to the incoming
+ flow being hashed to a flow bucket that was full.
+
+ |
+
|
+ PAN-290453
+ |
+
+
+ Fixed an issue where PA-7500 firewalls experienced silent traffic
+ drops. During migration from PA-7050 to PA-7500 firewalls connected in
+ series, intermittent connection losses occurred for some applications.
+ Traffic leaving the PA-7050 was not received or processed by the
+ PA-7500, even with direct connections and replaced cables/SFPs. Global
+ counters did not indicate any drops on the PA-7500.
+
+ |
+
|
+ PAN-289304
+ |
+
+
+ (PA-7500 firewalls only) Fixed an issue where
+ SNMP polling failed due to the
+ snmpd
+ process becoming unresponsive to incoming requests, which resulted in
+ high CPU usage.
+
+ |
+
|
+ PAN-279604
+ |
+
+
+ Fixed an issue where scheduled SaaS application usage reports were
+ generated incorrectly, and the login page was displayed instead of the
+ report content.
+
+ |
+
|
+ PAN-253778
+ |
+
+
+ (PA-7500 Series firewalls in a cluster configuration only) Fixed an issue where users were able to enable or disable certain
+ configurations.
+
+ |
+
|
+ Issue ID
+ |
+
+ Description
+ |
+
|---|---|
|
+ PAN-273245
+ |
+
+
+ (Firewalls in HA configurations only) Fixed an
+ issue where upgrading an HA firewall pair from PAN-OS 10.2.11-h1 to
+ PAN-OS 11.1.5 caused the firewalls to enter a nonfunctional loop due
+ to repeated HA path monitoring failures.
+
+ |
+
|
+ PAN-272849
+ |
+
+
+ Fixed an issue where log forwarding to a UDP syslog server stopped
+ when an unreachable TCP syslog server was configured and applied.
+
+ |
+
|
+ PAN-272538
+ |
+
+
+ Fixed an issue where the
+ configd
+ process stopped responding during a commit-all validation when there
+ were uncommitted changes and
+ share-unused-objects-with-devices
+ was set to off.
+
+ |
+
|
+ PAN-272006
+ |
+
+
+ Fixed an issue where the firewall did not trigger a kernel core dump
+ as a large core when the CPLD (Complex Programmable Logic Device) sent
+ a Non-Maskable Interrupt (NMI) to the CPU.
+
+ |
+
|
+ PAN-271926
+ |
+
+
+ Fixed an issue where TLS 1.3 decryption failed with a bad record MAC
+ error when the firewall was configured to decrypt and inspect TLS
+ traffic.
+
+ |
+
|
+ PAN-271912
+ |
+
+
+ Fixed an issue on Panorama where the
+ configd
+ process stopped responding when filtering in the configuration audit
+ window after upgrading to PAN-OS 11.1.3.
+
+ |
+
|
+ PAN-271828
+ |
+
+
+ Fixed an issue where, after an accumulation proxy changed to
+ no-decrypt or no proxy, only the Client Hello was sent to Content
+ Threat Detection.
+
+ |
+
|
+ PAN-271314
+ |
+
+
+ Fixed an issue where pushing changes to a prefix list used for BGP
+ from Panorama affected OSPF routes.
+
+ |
+
|
+ PAN-270607
+ |
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where OSPF failed to establish after a failover from
+ the active firewall to the passive firewall.
+
+ |
+
|
+ PAN-270471
+ |
+
+
+ (Firewalls in active/active configurations only) Fixed an issue where the firewall did not detect configuration
+ changes when only the interface of an IKE gateway was changed, which
+ caused IPSec tunnels to not come up after migrating the IKE gateway IP
+ address from a subinterface to a physical interface.
+
+ |
+
|
+ PAN-269956
+ |
+
+
+ Fixed an issue where the
+ all_pktproc
+ process stopped responding, which caused internal path monitor
+ failures.
+
+ |
+
|
+ PAN-269731
+ |
+
+
+ Fixed an issue where Panorama did not display logs from firewalls
+ after upgrading to PAN-OS 10.2.11 on devices due to Elasticsearch (ES)
+ getting restarted continuously.
+
+ |
+
|
+ PAN-269337
+ |
+
+
+ Fixed an issue where the cluster compatibility timer was limited to
+ 300 to 3600 seconds.
+
+ |
+
|
+ PAN-268465
+ |
+
+
+ Fixed an issue with firewalls in active/passive HA configurations
+ where the total user count in the registered users was different
+ between the active and passive firewall.
+
+ |
+
|
+ PAN-267781
+ |
+
+
+ Fixed an issue where Panorama did not display the
+ Source Dynamic Address Group.
+
+ |
+
|
+ PAN-267097
+ |
+
+
+ Fixed an issue where the replay database size increased significantly
+ due to local and special configurations not being purged after
+ commits.
+
+ |
+
|
+ PAN-265219
+ |
+
+
+ (VM-Series firewalls only) Fixed an issue where
+ GRE traffic did not work properly.
+
+ |
+
|
+ PAN-265179
+ |
+
+
+ Fixed an issue where a kernel race condition caused the firewall to
+ reboot with a kernel panic.
+
+ |
+
|
+ PAN-262946
+ |
+
+
+ Fixed an issue on the firewall where logging in via the CLI or web
+ interface did not work due to increased memory usage.
+
+ |
+
|
+ PAN-262043
+ |
+
+
+ Fixed an issue where Voice over WiFi (VoWiFi) stopped working after
+ switching from a PA-5200 Series firewall to a PA-7500 Series firewall
+ in NGFW clustering mode with NATT IPSec Passthrough and NAT policy
+ enabled. To use this fix, enter the CLI command
+ show tunnel-acceleration, disable
+ tunnel acceleration, and reboot the PA-7500 Series firewall.
+
+ |
+
|
+ PAN-260235
+ |
+
+
+ Fixed an issue where the firewall sent Threat logs and URL logs to an
+ external syslog server without Security profile settings when Enhanced
+ Application Logging was enabled.
+
+ |
+
|
+ PAN-259078
+ |
+
+
+ Fixed an issue where WildFire Analysis reports were not generated and
+ the following error message was displayed:
+ Error 500: Internal Server Error.
+
+ |
+
|
+ PAN-258149
+ |
+
+
+ Fixed an issue where the firewall dropped the SYN-ACK when using the
+ TCP Fast Open option.
+
+ |
+
|
+ PAN-246699
+ |
+
+
+ Fixed an issue on Panorama where
+ Rule Usage and
+ Apps Seen under Security policy
+ rules stopped incrementing.
+
+ |
+
|
+ PAN-240529
+ |
+
+
+ Fixed an issue where cloud application information was not displayed
+ in the traffic log in NGFW cluster nodes.
+
+ |
+
|
+ PAN-212889
+ |
+
+
+ Fixed an issue on Panorama where different threat names were used when
+ querying a threat under
+ Threat Monitor (Monitor > App Scope) and the ACC. This resulted in the ACC displaying no data after
+ clicking a threat name in
+ Threat Monitor and filtering it in
+ the global filters.
+
+ |
+