Add PAN-OS 11.0 addressed issues

This commit is contained in:
2026-03-16 16:42:45 -05:00
parent d1a554d974
commit e4edafa020
34 changed files with 4410 additions and 0 deletions
@@ -0,0 +1,18 @@
---
type: Addressed
product: PAN-OS
version: 11.0.0-h1
---
## PAN-202450
Fixed an issue where the
device-client-cert was set to
expire on December 31, 2023. With this fix, the expiration date has
been extended.
## PAN-198372
Fixed an issue where the root-cert was
set to expire on December 31, 2023. With this fix, the expiration
date has been extended.
@@ -0,0 +1,43 @@
---
type: Addressed
product: PAN-OS
version: 11.0.0-h2
---
## PAN-238792
Fixed the following device certificate issues:
- The firewall was unable to automatically renew the device
certificate.
- Fetching device certificates failed incorrectly with the error
message OTP is not valid.
- Firewalls disconnected from Cortex Data Lake after renewing the
device certificate.
- The device certificate was not correctly generated on the log
forwarding card (LFC).
- WildFire cloud logs did not log thermite certificate usage
status.
## PAN-237876
Extended the firewall Panorama root CA certificate which was
previously set to expire on April 7th, 2024.
## PAN-231771
Fixed an issue where the firewall issued /box/getserv/ requests with
PAN-OS 7.1.0 and did not take device certificates.
## PAN-227568
When a device certificate is installed, renewed, or removed, the
firewall will reconnect to the WildFire cloud to use the newest
certificate.
## PAN-215576
Fixed an issue where the userID-Agent
and TS-Agent certificates were set to
expire on November 18, 2024. With this fix, the expiration date has
been extended to January 2032.
@@ -0,0 +1,9 @@
---
type: Addressed
product: PAN-OS
version: 11.0.0-h3
---
## PAN-252214
A fix was made to address CVE-2024-3400.
@@ -0,0 +1,10 @@
---
type: Addressed
product: PAN-OS
version: 11.0.0-h4
---
## PAN-272809
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and
CVE-2024-9474.
@@ -0,0 +1,143 @@
---
type: Addressed
product: PAN-OS
version: 11.0.0
---
## PAN-231823
A fix was made to address CVE-2024-5916.
## PAN-207505
Fixed an issue where Email schedules (MonitorPDF ReportsEmail Scheduler) were not supported for SaaS Application Usage (MonitorPDF ReportsSaaS Application Usage) reports.
## PAN-204615
Fixed an issue where BGP sessions could flap even when an unrelated
configuration was committed. This resulted in the BGP session going
down and getting established again. As a result, BGP routes were
exchanged again, which could lead to momentary traffic disruption if
BGP routes were in use for establishing traffic.
## PAN-202783
```caveat
PA-7000 Series firewalls with 100G NPC (Network Processing Cards) only
```
Fixed an issue where sudden,
large bursts of traffic destined for an interface that was down
caused packet buffers to fill, which stalled path monitor heartbeat
packets.
## PAN-202535
Fixed an issue where the Device Telemetry
configuration for a region was unable to be set or edited via the
web interface.
## PAN-199726
Fixed an issue with firewalls in HA configurations
where both firewalls responded with gARP messages after a switchover.
## PAN-199654
Fixed an issue where ACC reports did not
work for custom RBAC users when more than 12 access domains were
associated with the username.
## PAN-198733
```caveat
PA-5450 firewalls only
```
Fixed
an issue where tcpdump was hardcoded
to eth0 instead of bond0.
## PAN-198332
```caveat
PA-5400 Series only
```
Fixed an
issue where swapping Network Processing Cards (NPCs) caused high
root partition use.
## PAN-198244
Fixed an issue where using the load config partial CLI
command to x-paths removed address object entries from address groups.
## PAN-197383
Fixed an issue where, after upgrading to
PAN-OS 10.2 release, the firewall ran a RAID rebuild for the log
disk after ever every reboot.
## PAN-197341
Fixed an issue on Panorama where, when you created multiple device group objects with the same
name in the shared device group and any additional device groups (PanoramaDevice Groups) under the same device group hierarchy that were used
in one or more policies, renaming the object with a shared name in
any device group caused the object name to change in the policies
that it was used in. This issue occurred with device group objects
that were referenced in a Security policy rule.
## PAN-196558
Fixed an issue where IP address tag policy
updates were delayed.
## PAN-196398
```caveat
PA-7000 Series SMC-B firewalls only
```
Fixed an issue where the firewall did not capture data when the
active management interface was MGT-B.
## PAN-194615
Fixed an issue where the packet broker session
timeout value did not match the master sessions timeout value after
the firewall received a TCP FIN or RST packet. The fix ensures that
Broker session times out within 1 second after the master session
timed out.
## PAN-194152
```caveat
PA-5410, PA-5420, PA-5430, and PA-5440 firewalls in HA configurations only
```
Fixed an issue where HA1-A
and HA1-B port information didn't match to front panel mappings.
## PAN-189270
Fixed an issue that caused a memory leak
on the reportd process.
## PAN-188096
```caveat
VM-Series firewalls only
```
Fixed
an issue where, on firewalls licensed with Software NGFW Credit
(VM-FLEX-4 and higher), HA clustering was unable to be established.
## PAN-171714
Fixed an issue where, when NetBIOS format
(domain\user) was used for the IP address-to-username mapping and
the firewall received the group mapping information from the Cloud
Identity Engine, the firewall did not match the user to the correct
group.
@@ -0,0 +1,70 @@
---
type: Addressed
product: PAN-OS
version: 11.0.1-h2
---
## PAN-217431
```caveat
PA-5400 Series firewalls with DPC (Data Processing Cards) only
```
Fixed an issue with slot 2 DPCs where URL filtering
did not work as expected after upgrading to PAN-OS 10.1.9.
## PAN-216710
Fixed an issue with firewalls in active/active high availability (HA)
configurations where GlobalProtect disconnected when the original
suspected Active-Primary firewall became Active-Secondary.
## PAN-215899
Fixed an issue with Panorama appliances in HA configurations where
configuration synchronization between the HA peers failed.
## PAN-215496
Fixed an issue where 100G ports did not come up with BIDI QSFP
modules.
## PAN-215461
Fixed an issue where the packet descriptor leaked over time with GRE
tunnels and keepalives.
## PAN-211870
Fixed an issue where path monitoring failure occurred, which caused
high availability failover.
## PAN-211519
Fixed an issue where RTP/RTCP packets were dropped for SIP calls by
SIP ALG when the source NAT translation type was persistent
Dynamic IP And Port.
## PAN-210607
Fixed an issue where enabling Inline Cloud Analysis on Anti-Spyware,
Vulnerability Protection, or URL Filtering Security profiles caused
the dataplane to stop responding.
## PAN-208189
Fixed an issue when traffic failed to match and reach all
destinations if a Security policy rule includes FQDN objects that
resolve to two or more IP addresses.
## PAN-206007
Fixed an issue where a debug command generated an incomplete core
file.
## PAN-202450
Fixed an issue where the
device-client-cert was set to
expire on December 31, 2023. With this fix, the expiration date has
been extended.
@@ -0,0 +1,43 @@
---
type: Addressed
product: PAN-OS
version: 11.0.1-h3
---
## PAN-238792
Fixed the following device certificate issues:
- The firewall was unable to automatically renew the device
certificate.
- Fetching device certificates failed incorrectly with the error
message OTP is not valid.
- Firewalls disconnected from Cortex Data Lake after renewing the
device certificate.
- The device certificate was not correctly generated on the log
forwarding card (LFC).
- WildFire cloud logs did not log thermite certificate usage
status.
## PAN-237876
Extended the firewall Panorama root CA certificate which was
previously set to expire on April 7th, 2024.
## PAN-231771
Fixed an issue where the firewall issued /box/getserv/ requests with
PAN-OS 7.1.0 and did not take device certificates.
## PAN-227568
When a device certificate is installed, renewed, or removed, the
firewall will reconnect to the WildFire cloud to use the newest
certificate.
## PAN-215576
Fixed an issue where the userID-Agent
and TS-Agent certificates were set to
expire on November 18, 2024. With this fix, the expiration date has
been extended to January 2032.
@@ -0,0 +1,9 @@
---
type: Addressed
product: PAN-OS
version: 11.0.1-h4
---
## PAN-252214
A fix was made to address CVE-2024-3400.
@@ -0,0 +1,10 @@
---
type: Addressed
product: PAN-OS
version: 11.0.1-h5
---
## PAN-272809
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and
CVE-2024-9474.
@@ -0,0 +1,570 @@
---
type: Addressed
product: PAN-OS
version: 11.0.1
---
## PAN-231823
A fix was made to address CVE-2024-5916.
## PAN-216656
Fixed an issue where the firewall was unable to fully process the user list from a child group when the child group contained more than 1,500 users.
## PAN-215911
Fixed an issue that resulted in a race condition, which caused the configd process
to stop responding.
## PAN-215488
Fixed an issue where an expired Trusted Root CA was used to sign the forward proxy leaf certificate during SSL Decryption.
## PAN-210561
Fixed an issue where the all_task process repeatedly restarted due to missed heartbeats.
## PAN-210513
Fixed an issue where Captive Portal authentication via SAML did not work.
## PAN-210481
Fixed an issue where botnet reports were not generated on the firewall.
## PAN-210449
Fixed an issue where the value for shared objects used in policy rules were not displayed on multi-vsys firewalls when pushed from Panorama.
## PAN-210331
Fixed an issue where the firewall did not send device telemetry files to Cortex Data Lake with the error message send the file to CDL receiver failed.
## PAN-210327
```caveat
PA-5200 Series firewalls only
```
Fixed an issue where upgrading to PAN-OS 10.1.7, an internal loop caused an increase in the packets received per second.
## PAN-210237
Fixed an issue where system logs generated by Panorama for commit operations showed the severity as High instead of Informational.
## PAN-210080
Fixed an issue where the useridd process stopped responding when add and delete member parameters in an incremental sync query were empty.
## PAN-209799
Fixed an issue where logging was not disabled on passive nodes, which caused the logrcvr to stop responding.
## PAN-209491
Fixed an issue on the web interface where the Session Expire Time displayed a past date if the device time was in December.
## PAN-209069
Fixed an issue where IP addresses in the X-Forwarded-For (XFF) field were not logged when the IP address contained an associated port number.
## PAN-209036
Fixed an issue where the dataplane restarted, which led to slot failures occurring and a core file being generated.
## PAN-208987
```caveat
PA-5400 Series only
```
Fixed an issue where packets were not transmitted from the firewall if its fragments were received on different slots. This occurred when aggregate ethernet (AE) members in an AE interface were placed on a different slot.
## PAN-208922
A fix was made to address an issue where an authenticated
administrator was able to commit a specifically created
configuration to read local files and resources from the system
(CVE-2023-38046).
## PAN-208930
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where auto-tagging in log forwarding did not work.
## PAN-208902
Fixed an issue where, when a client sent a TCP/FIN packet, the firewall displayed the end reason as aged-out instead of tcp-fin.
## PAN-208724
Fixed an issue where port pause frame settings did not work as expected and incorrect pause frames occurred.
## PAN-208718
Additional debug information was added to capture internal details during traffic congestion.
## PAN-208711
```caveat
PA-5200 Series firewalls only
```
The CLI command debug dataplane set pow no-desched yes/no was added to address an issue where the all_pktproc process stopped responding and caused traffic issues.
## PAN-208537
Fixed an issue where the licensed-device-capacity was reduced when multiple device management license key files were present.
## PAN-208525
Fixed an issue where Security policy rules with user groups did not match when Kerberos authentication was configured for explicit proxy.
## PAN-208485
Fixed an issue where NAT policies were not visible on the CLI if they contained more than 32 characters.
## PAN-208343
Fixed an issue where telemetry regions were not visible on Panorama.
## PAN-208157
Fixed an issue where malformed hints sent from the firewall caused the logd process to stop responding on Panorama, which caused a system reboot into maintenance mode.
## PAN-207940
Fixed an issue where platforms with RAID disk checks were performed weekly, which caused logs to incorrectly state that RAID was rebuilding.
## PAN-207740
Fixed an issue that resulted in a race condition, which caused the configd process to stop responding.
## PAN-207738
Fixed an issue where the ocsp-next-update-time CLI command did not execute for leaf certificates with certificate chains that did not specify OCSP or CRL URLs. As a result, the next update time was 60 minutes even if a different time was set.
## PAN-207663
Fixed a Clientless VPN issue where JSON stringify caused issues with the application rewrite.
## PAN-207629
Fixed an issue where a selective push to firewalls failed if the
firewalls were enabled with multiple vsys and the push scope
contained shared objects in device groups.
## PAN-207610
```caveat
PA-5200 Series and PA-7000 Series firewalls only
```
Fixed an issue where Log Admin Activity was not visible on the web interface.
## PAN-207601
Fixed an issue where URL cloud connections were unable to resolve the proxy server hostname.
## PAN-207426
Fixed an issue where a selective push did not include the Share Unused Address and Service Objects with Devices option on Panorama, which caused the firewall to not receive the objects during the configuration push.
## PAN-207400
Fixed an issue on Octeon based platforms where fragmented VLAN tagged packets dropped on an aggregate interface.
## PAN-207390
Fixed an issue where, even after disabling Telemetry, Telemetry system logs were still generated.
## PAN-207260
A commit option was enabled for Device Group and Template administrators after a password change.
## PAN-207045
```caveat
PA-800 Series firewalls only
```
Fixed an issue where PAN-SFP-SX transceivers used on ports 5 to 8 did not renegotiate with peer ports after a reload.
## PAN-206963
```caveat
M-700 Appliances only
```
A CLI command was added to check the status of each physical port of a bond1 interface.
## PAN-206858
Fixed an issue where a segmentation fault occurred due to the useridd process being restarted.
## PAN-206755
Fixed an issue when a scheduled multi-device group push occurred, the configd process stopped responding, which caused the push to fail.
## PAN-206684
```caveat
PA-7000 Series firewalls with Log Forwarding Cards (LFCs) only
```
Fixed an issue where, after upgrading the firewall from a PAN-OS 10.0 release to a PAN-OS 10.1 release, the firewall did not duplicate logs to local log collectors or to Cortex Data Lake when a device certificate was already installed.
## PAN-206658
Fixed a timeout issue in the Intel ixgbe driver that resulted in internal path monitoring failure.
## PAN-206466
Fixed an issue where the push scope was displaying duplicate shared objects for each device group that were listed under the shared-object group.
## PAN-206393
```caveat
PA-5280 firewalls only
```
Fixed an issue where memory allocation errors caused decryption failures that disrupted traffic with SSL forward proxy enabled.
## PAN-206382
Fixed an issue where authentication sequences were not populated in the drop down when selecting authentication profiles during administrator creation in a template.
## PAN-206251
```caveat
PA-7000 Series firewalls with Log Forwarding Cards (LFCs) only
```
Fixed an issue where the logrcvr process did not send the system-start SNMP trap during startup.
## PAN-206233
Fixed an issue where the pan_comm process stopped responding when a content update and a cloud application update occurred at the same time.
## PAN-206128
```caveat
PA-7000 Series firewalls with NPCs (Network Processing Cards) only
```
Improved debugging capability for an issue where the firewall restarted due to heartbeat failures and then failed with the following error message: Power not OK.
## PAN-206069
Fixed an issue where the firewall was unable to boot up on older Intel CPUs.
## PAN-206017
Fixed an issue where the show dos-protection rule command displayed a character limit error.
## PAN-206005
```caveat
PA-1400 Series, PA-3400 Series, and PA-5440 firewalls only
```
Fixed an issue where the
l7_misc memory pool was undersized
and caused connectivity loss when the limit was reached.
## PAN-205877
```caveat
PA-5450 firewalls only
```
Added debug commands for an issue where a MAC address flap occurred on a neighbor firewall when connecting both MGT-A and MGT-B interfaces.
## PAN-205829
Fixed an issue where logs did not display Host-ID details for GlobalProtect users despite having a quarantine Security policy rule. This occurred due to a missed local cache lookup.
## PAN-205804
Fixed an issue on Panorama where a WildFire scheduled update for managed devices triggered multiple UploadInstall jobs per minute.
## PAN-205729
```caveat
PA-3200 Series and PA-7000 Series firewalls only
```
Fixed an issue where the CPLD watchdog timeout caused the firewall to reboot unexpectedly.
## PAN-205699
Fixed an issue where the cloud plugin configuration was automatically deleted from Panorama after a reboot or a configd process restart.
## PAN-205698
Fixed an issue where GlobalProtect authentication did not work on Apple MacOS devices when the authentication method used was CIE with SAML Authentication.
## PAN-205590
Fixed an issue where the fan tray fault LED light was on even though no alarm was reported in the system environment.
## PAN-205453
Fixed an issue where running reports or queries under a user group caused the reportd process to stop responding.
## PAN-205396
Fixed an issue where SD-WAN adaptive SaaS path monitoring did not work correctly during a next hop link down failure.
## PAN-205260
Fixed an issue where there was an IP address conflict after a reboot due to a transaction ID collision.
## PAN-205255
Fixed a rare issue that caused the dataplane to restart unexpectedly.
## PAN-205231
Fixed an issue where a commit operation remained at 55% for longer than expected if more than 7,500 Security policy rules were configured.
## PAN-205211
Fixed an issue where the reportd process stopped responding while querying logs (Monitor > Logs > <logtype>).
## PAN-205096
Fixed an issue where promoted sessions were not synced with all cluster members in an HA cluster.
## PAN-204749
Fixed an issue where sudden, large bursts of traffic destined for an interface that was down caused packet buffers to fill, which stalled path monitor heartbeat packets.
## PAN-204581
Fixed an issue where, when accessing a web application via the GlobalProtect Clientless VPN, the web application landing page continuously reloaded.
## PAN-204575
```caveat
PA-7000 Series firewalls with Log Forwarding Cards (LFCs) only
```
Fixed an issue where the firewall did not forward logs to the log collector.
## PAN-204572
Fixed an issue where python scripts were not working as expected.
## PAN-204456
Fixed an issue related to the logd process that caused high memory consumption.
## PAN-204335
Fixed an issue where Panorama became unresponsive, and when refreshed, the error 504 Gateway not Reachable was displayed.
## PAN-203964
```caveat
Firewalls in FIPS-CC mode only
```
Fixed an issue where the firewall went into maintenance mode due to downloading a corrupted software image, which resulted in the error message FIPS-CC failure. Image File Authentication Error.
## PAN-203851
Fixed an issue with firewalls in HA configurations where host information profile (HIP) sync did not work between peer firewalls.
## PAN-203681
```caveat
Panorama appliances in FIPS-CC mode only
```
Fixed an issue where a leaf certificate was unable to be imported into a template stack.
## PAN-203663
Fixed an issue where administrators were unable to change the password of a local database for users configured as a local admin user via an authentication profile.
## PAN-203453
Fixed an issue on Panorama where the log query failed due to a high number of User-ID redistribution messages.
## PAN-203430
Fixed an issue where, when the User-ID agent had collector name/secret configured, the configuration was mandatory on clients on PAN-OS 10.0 and later releases.
## PAN-203339
Fixed an issue where services failed due to the RAID rebuild not being completed on time.
## PAN-203147
```caveat
Firewalls in FIPS-CC mode only
```
Fixed an issue where the firewall unexpectedly rebooted when downloading a new PAN-OS software image.
## PAN-203137
```caveat
PA-5450 firewalls only
```
Fixed an issue where HSCI ports did not come up when QSFP DAC cables were used.
## PAN-202543
An enhancement was made to improve path monitor data collection by verifying the status of the control network.
## PAN-202248
Fixed an issue where, due to a tunnel content inspection (TCI) policy match, IPSec traffic did not pass through the firewall when NAT was performed on the traffic.
## PAN-201701
Fixed an issue where the firewall generated system log alerts if the raid for a system or log disk was corrupted.
## PAN-201580
Fixed an issue where the useridd process stopped responding due to an invalid vsys_id request.
## PAN-200845
```caveat
M-600 Appliances in Management-only mode only
```
Fixed an issue where XML API queries failed due to the configuration size being larger than expected.
## PAN-200160
Fixed a memory leak issue on Panorama related to the logd process that caused an out-of-memory (OOM) condition.
## PAN-200116
Fixed an issue where Elasticsearch displayed red due to frequent tunnel check failures between HA clusters.
## PAN-199965
Fixed an issue where the reportd process stopped responding on log collectors during query and report operations due to a race condition between request handling threads.
## PAN-199807
Fixed an issue where the dataplane frequently restarted due to high memory usage on wifclient.
## PAN-196597
Fixed an issue where the dnsproxyd process stopped
responding due to corruption.
## PAN-198306
Fixed an issue where the useridd process stopped responding when booting up the firewall.
## PAN-198266
Fixed an issue where, when predicts for UDP packets were created, a configuration change occurred that triggered a new policy lookup, which caused the dataplane stopped responding when converting the predict. This resulted in a dataplane restart.
## PAN-198038
A CLI command was added to address an issue where long-lived sessions were aging out even when there was ongoing traffic.
## PAN-197872
Fixed an issue where the useridd process generated false positive critical errors.
## PAN-197298
Fixed an issue where the audit comment archive for Security rule changes output had overlapping formats.
## PAN-196410
Fixed an issue where you were unable to customize the risk value in Risk-of-app.
## PAN-195756
Fixed an issue that caused an API request timeout when parsing requests using large header buffers.
## PAN-194805
Fixed an issue where scheduled configuration backups to the SCP
server failed with error message No ECDSA host key is
known.
## PAN-194068
```caveat
PA-5200 Series firewalls only
```
Fixed an issue where the firewall unexpectedly rebooted with the log message Heartbeat failed previously.
## PAN-192513
Fixed an issue where log migration did not work when converting a Legacy mode Panorama appliance to Log Collector mode.
## PAN-192282
```caveat
PA-415 and PA-445 firewalls only
```
Fixed an issue where, in
1G mode, the MGT and Ethernet 1/1 port LEDs incorrectly displayed as
amber instead of green.
## PAN-191222
Fixed an issue where Panorama became inaccessible when after a push to the collector group.
## PAN-190502
Fixed an issue where the Policy filter and Policy optimizer filter were required to have the exact same syntax, including nested conditions with rules that contained more than one tag when filtering via the neq operator.
## PAN-189335
Fixed an issue where the varrcvr process restarted repeatedly, which caused the firewall to restart.
## PAN-189200
Fixed an issue where sinkholes did not occur for AWS Gateway Load Balancer dig queries.
## PAN-186412
Fixed an issue where invalid packet-ptr was seen in work entries.
## PAN-186270
Fixed an issue where, when HA was enabled and a dynamic update schedule was configured, the configd process unexpectedly stopped responding during configuration commits.
## PAN-183375
Fixed an issue where traffic arriving on a tunnel with a bad IP address header checksum was not dropped.
## PAN-180948
Fixed an issue where an external dynamic list fetch failed with the error message Unable to fetch external dynamic list. Couldn't resolve host name. Using old copy for refresh.
## PAN-179174
Fixed an issue where exported PDF report of the ACC was the incorrect color after upgrading from a PAN-OS 10.1 or later release.
## PAN-178594
Fixed an issue where the descriptions of options under the set syslogng ssl-conn-validation CLI command were not accurate.
## PAN-175142
Fixed an issue on Panorama where executing a debug command caused the logrcvr process to stop responding.
## PAN-170414
Fixed an issue related to an OOM condition in the dataplane, which was caused by multiple panio commands using extra memory.
@@ -0,0 +1,52 @@
---
type: Addressed
product: PAN-OS
version: 11.0.2-h1
---
## PAN-225184
Fixed an issue where disk space utilization was higher than expected
due to excessive logging for a KNI: Out of
memory event under a specific traffic load
condition.
## PAN-222712
```caveat
PA-5450 firewalls only
```
Fixed a low frequency DPC restart
issue.
## PAN-221984
```caveat
VM-Series firewalls in Microsoft Azure environments only
```
Fixed an issue where an interface went down after a hotplug event
and was only recoverable by restarting the firewall.
## PAN-220921
Fixed an issue where return tunnel traffic was dropped with the
counter flow_tunnel_encap_err when
Enforce Symmetric Return was enabled in a
Policy Based Forwarding rule.
## PAN-195439
```caveat
VM-Series firewalls in Microsoft Azure environments only
```
Fixed an issue where the dataplane interface status went down after
a hotplug event triggered by Azure infrastructure.
## PAN-193004
Fixed an issue where /opt/pancfg
partition utilization reached 100%, which caused access to the
Panorama web interface to fail.
@@ -0,0 +1,42 @@
---
type: Addressed
product: PAN-OS
version: 11.0.2-h2
---
## PAN-230250
Fixed an issue where selected applications serving partial content
were dropped when Inline Cloud Analysis in Anti-Spyware was
enabled.
## PAN-223787
```caveat
PA-400 Series and PA-1400 Series firewalls only
```
Fixed an
issue where commits failed with the error message
Error unserializing profile objects failed to
handle CONFIG_UPDATE_START.
## PAN-222957
Fixed an issue where managed firewalls did not reflect changes pushed
by users that were not in a Superuser role.
## PAN-218107
Fixed an issue with ciphers used for SSH tunnels where packet lengths
were too large, which made the SSH tunnel unstable.
## PAN-214942
Fixed an issue where SD-WAN traffic failed over to a non-member path
after a flap of an SD-WAN virtual interface.
## PAN-204868
Fixed an issue where disk utilization was continuously high due to
the log purger not sufficiently reducing the utilization level.
@@ -0,0 +1,43 @@
---
type: Addressed
product: PAN-OS
version: 11.0.2-h3
---
## PAN-238792
Fixed the following device certificate issues:
- The firewall was unable to automatically renew the device
certificate.
- Fetching device certificates failed incorrectly with the error
message OTP is not valid.
- Firewalls disconnected from Cortex Data Lake after renewing the
device certificate.
- The device certificate was not correctly generated on the log
forwarding card (LFC).
- WildFire cloud logs did not log thermite certificate usage
status.
## PAN-237876
Extended the firewall Panorama root CA certificate which was
previously set to expire on April 7th, 2024.
## PAN-231771
Fixed an issue where the firewall issued /box/getserv/ requests with
PAN-OS 7.1.0 and did not take device certificates.
## PAN-227568
When a device certificate is installed, renewed, or removed, the
firewall will reconnect to the WildFire cloud to use the newest
certificate.
## PAN-215576
Fixed an issue where the userID-Agent
and TS-Agent certificates were set to
expire on November 18, 2024. With this fix, the expiration date has
been extended to January 2032.
@@ -0,0 +1,9 @@
---
type: Addressed
product: PAN-OS
version: 11.0.2-h4
---
## PAN-252214
A fix was made to address CVE-2024-3400.
@@ -0,0 +1,10 @@
---
type: Addressed
product: PAN-OS
version: 11.0.2-h5
---
## PAN-272809
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and
CVE-2024-9474.
@@ -0,0 +1,473 @@
---
type: Addressed
product: PAN-OS
version: 11.0.2
---
## PAN-231823
A fix was made to address CVE-2024-5916.
## PAN-221708
Fixed an issue where temporary files remained under /opt/pancfg/tmp/sw-images/ even after manually uploading the content or AV file to the firewall.
## PAN-221519
```caveat
VM-Series firewalls only
```
Fixed an issue where the all_task process stopped responding due to DPDK driver compatibility issues.
## PAN-219686
Fixed an issue where a device group push operation from Panorama
failed with the following error on managed firewalls.
vsys -> vsys1 -> plugins unexpected
here
vsys is invalid
Commit failed
## PAN-218644
Fixed an issue where the firewall generated incorrect VSA attribute codes when radius was configured with EAP based authentication protocols.
## PAN-218335
Fixed an issue with hardware destination MAC filtering on the Log Processing Card (LPC) that caused the logging card interface to be susceptible to unicast flooding.
## PAN-218264
```caveat
PA-3400 and PA-1400 Series firewalls only
```
Fixed an issue where packet drops occurred due to slow servicing of internal hardware queries.
## PAN-217681
Fixed an issue caused by out of order TCP segments where the FIN flag and TCP data was truncated in a packet, which resulted in retransmission failure.
## PAN-217581
Fixed an issue where the firewall did not initiate scheduled log uploads to the FTP server.
## PAN-217493
Fixed an issue where superusers with read-only privileges were unable to view SCEP object configurations.
## PAN-217484
Fixed an issue where the rasmgr process used 100% CPU due to a maximum duration timer not being set, which caused the GlobalProtect gateway to be unavailable.
## PAN-217477
Fixed an issue where the drop counter was incremented incorrectly. Drop counter calculations did not account for failures to send out logs from logrcvr/logd to syslog-ng.
## PAN-217284
Fixed an intermittent issue where LACP flap occurred when the LACP transmission rate was set to Fast.
## PAN-216996
Fixed an issue where, after upgrading Panorama to PAN-OS 10.1.9, multiple User-ID alerts were generated every 10 minutes.
## PAN-216821
Fixed an issue where the reportd process stopped responding after upgrading an M-200
appliance to PAN-OS 11.0.1.
## PAN-216710
Fixed an issue with firewalls in active/active HA configurations where GlobalProtect disconnected when the original suspected Active-Primary firewall became Active-Secondary.
## PAN-216590
Fixed an issue where User-ID logs in Panorama displayed incorrect results for the filter not (ugflags has user-group-found).
## PAN-216360
Fixed an issue on Panorama where No Default Selections under Push to Devices was intermittently deselected after performing a commit operation.
## PAN-216170
```caveat
PA-400 Series firewalls in HA configurations only
```
Fixed an
issue where an HA switchover took longer than expected to bring up ports
on the newly active firewall.
## PAN-216036
Fixed an issue where the all_pktproc process stopped responding, which caused the firewall to enter a nonfunctional state.
## PAN-215911
Fixed an issue that resulted in a race condition, which caused the configd process to stop responding.
## PAN-215899
Fixed an issue with Panorama appliances in high availability (HA) configurations where
configuration synchronization between the HA peers failed.
## PAN-215857
Fixed an issue where the option to reboot the entire firewall was visible to vsys admins.
## PAN-215808
Fixed an issue where after upgrading to PAN-OS 10.1, the log-forwarding rate towards the Syslog server was reduced. The overall log-forwarding rate has also been improved.
## PAN-215780
Fixed an issue where, changes to Zone Protection profiles made via XML API were not reflected in the Zone Protection configuration.
## PAN-215778
Fixed an issue where API Get requests for /config timed out due to insufficient buffer size.
## PAN-215503
Fixed a memory related issue where the MEMORY_POOL address was mapped incorrectly.
## PAN-215496
Fixed an issue where 100G ports did not come up with BIDI QSFP modules.
## PAN-215324
```caveat
PA-5400 Series firewalls with Jumbo Frames enabled only
```
Fixed an issue with CPU throttling and buffer depletion.
## PAN-215315
Fixed an issue where the dataplane stopped responding due to ager and inline packet processing occurring concurrently on different cores for the same session.
## PAN-215125
Fixed an issue where false negatives occurred for some script samples.
## PAN-214925
Fixed an issue where temporary files remained in their temporary locations even after manually uploading the files to the firewall.
## PAN-214889
Fixed an issue where commits took longer than expected due to application dependency checks.
## PAN-214847
Fixed an issue where, when certificate authentication for admin user authentication was enabled, vulnerability scans that used usernames or passwords against the management interface reported a vulnerability due to a missing HSTS header in the Access Denied response page.
## PAN-214634
Fixed an issue where an elink parser did not work.
## PAN-214337
Fixed an issue on the firewall related to the gp_broker configuration transform that led to longer commit times.
## PAN-214187
Fixed an issue where superreaders were able to execute the request restart
system CLI command.
## PAN-214100
Fixed an issue where selecting a threat name under Threat Monitor displayed the threat ID instead of the threat name.
## PAN-214037
```caveat
PA-5440, PA-5430, PA-5420, and PA-5410 firewalls only
```
Fixed an issue where firewalls in active/active HA configurations experienced packet drop when running asymmetric traffic.
## PAN-214026
Fixed an issue where, when using an ECMP weighted-round-robin algorithm, traffic was not redistributed among the links proportionally as expected from the configuration.
## PAN-213942
```caveat
PA-400 Series firewalls
```
Fixed an issue where the firewall required an explicit allow rule to forward broadcast traffic.
## PAN-213932
Fixed an issue where, when an incorrect log filter was configured, the commit did not fail.
## PAN-213746
Fixed an issue on Panorama where the Hostkey displayed as **undefined** if a SSH Service Profile
Hostkey configured in a Template from the Template Stack was
overridden.
## PAN-212848
Fixed an issue where attempting to change the disk-usage cleanup threshold to 90 resulted in the error message Server error : op command for client dagger timed out as client is not available.
## PAN-212726
Fixed an issue where RTP/RTCP packets were dropped for SIP calls by SIP ALG when the source NAT translation type was persistent Dynamic IP And Port.
## PAN-212530
Fixed an issue on log collectors where root partition reached 100% utilization.
## PAN-212409
Fixed an issue where there were duplicate IPSec Security Associations (SAs) for the same tunnel, gateway, or proxy ID.
## PAN-211997
Fixed an issue where large OSPF control packets were fragmented, which caused the neighborship to fail.
## PAN-211887
Fixed an issue on Panorama that caused recently committed changes to not be displayed when previewing the changes to push to device groups.
## PAN-211843
Fixed an issue where renaming a Zone Protection profile failed with the error message Obj does not exist.
## PAN-211602
Fixed an issue where, when viewing a WildFire Analysis Report via the web interface, the detailed log view was not accessible if the browser window was resized.
## PAN-211519
Fixed an issue where RTP/RTCP packets were dropped for SIP calls by SIP ALG when the source NAT translation type was persistent Dynamic IP And Port.
## PAN-211422
Fixed an issue where the show session packet-buffer-protection buffer-latency CLI command randomly displayed incorrect values.
## PAN-211242
Fixed an issue where missed heartbeats caused the Data Processing Card (DPC) and its corresponding Network Processing Card (NPC) to restart due to internal packet path monitoring failure.
## PAN-211041
```caveat
Panorama virtual appliances only
```
Fixed an issue where DHCP assigned interfaces did not send ICMP unreachable - Fragmentation needed messages when the received packets were higher than the maximum transmission unit (MTU).
## PAN-210921
```caveat
Panorama appliances in Legacy Mode only
```
Fixed an issue where Blocked Browsing Summary by Website in the user activity report contained scrambled characters.
## PAN-210919
Fixed an issue where the Data Processing Card remained in a Starting state after a restart.
## PAN-210875
Fixed an issue where the pan_task process stopped responding due to software packet buffer 3 trailer corruption, which caused the firewall to restart.
## PAN-210736
Fixed an issue where configuration changes related to the SSH service profile were not reflected when pushed from Panorama. With this fix, the deletion of ciphers, MAC, and kex fields of SSH server profiles and HA profiles won't clear the values under template stacks and will retain the values configured from templates.
## PAN-210661
Fixed an issue where firewalls disconnected from Cortex Data Lake after renewing the device certificate.
## PAN-210563
Fixed an issue on Panorama where Security policy rules with a Tag target did not appear in the pre-rule list of a dynamic address group that was part of the tag.
## PAN-209898
Fixed an issue where the logrcvr process stopped due to memory corruption.
## PAN-209696
Fixed an issue where link-local address communication for IPv6, BFD, and OSPFv3 neighbors was dropped when IP address spoofing check was enabled in a Zone Protection profile.
## PAN-209683
Fixed an issue where Panorama was unable to retrieve IP address-to-username mapping from a firewall on a PAN-OS 8.1 release.
## PAN-209660
Fixed an issue where a selective push from Panorama to multiple firewalls failed due to a missing configuration file, which caused a communication error.
## PAN-209617
Fixed an issue with firewalls in active/passive HA configurations where the passive firewall created an incorrect SCTP association due to the HA sync messages from the active firewall having an incorrect value.
## PAN-209275
Fixed an issue where Override cookie authentication into the GlobalProtect gateway failed when an allow list was configured under the authentication profile.
## PAN-209021
Fixed an issue where packets were fragmented when SD-WAN VPN tunnel was configured on aggregate ethernet interfaces and sub-interfaces.
## PAN-208877
Fixed an issue where the all_task process stopped responding when freeing the HTTP2 stream, which caused the dataplane to go down.
## PAN-208737
Fixed an issue where domain information wasn't populated in IP address-to-username matching after a successful GlobalProtect authentication using an authentication override cookie.
## PAN-208325
```caveat
PA-5400 Series, PA-3400 Series, and PA-400 Series only
```
Fixed an issue where the firewall was unable to automatically renew the device certificate.
## PAN-208201
Fixed an issue on the firewall where the modified date and time was incorrectly updated after a commit operation, PAN-OS upgrade, or reboot.
## PAN-207842
Fixed an issue where WildFire Analysis Reports were not visible when the WF-500 appliance was on private cloud.
## PAN-207741
Fixed an issue where Large Scale VPN (LSVPN) Portal authentication failed with the error invalid http response. return error(Authentication failed; Retry authentication when the satellite connected to more than one portal.
## PAN-207700
Fixed an issue where the show system info and show system ztp status CLI commands displayed a different Zero Touch Provisioning (ZTP) status if a firewall upgrade was initiated from Panorama before the initial commit push succeeded.
## PAN-207562
Fixed an issue where the shard count displayed by the show log-collector-es-cluster health CLI command was higher than the recommended limit. The recommended limit can be calculated with the formula 20* heap-memory * no-of-data-nodes.
## PAN-206396
Fixed an issue where HIP report flip and HIP checks failed when a user was part of multiple user groups with different domains.
## PAN-206333
Fixed an issue where the Include/Exclude IP filter under Data Distribution did not work correctly.
## PAN-206253
```caveat
PA-1400 Series and PA-3400 Series firewalls only
```
Fixed an issue where the default log rate was too low and the maximum configurable log rate was incorrectly capped, which caused the firewall to not generate logs at more than 6826 logs per second.
## PAN-205955
Fixed an issue where RAID rebuilds occurred even with healthy disks and a clean shutdown.
## PAN-205513
Fixed an issue where the stats dump file generated by Panorama for a device firewall differed from the stats dump file generated by the managed device.
## PAN-205086
Fixed an issue where DNS Security categories were able to be deleted from Spyware profiles.
## PAN-204838
Fixed an issue where the dot1q VLAN tag was missing in ARP reply packets.
## PAN-204718
```caveat
PA-5200 Series firewalls only
```
Fixed an issue where, after upgrading to PAN-OS 10.1.6-h3, a TACACS user login displayed the following error message during the first login attempt: Could not chdir to home directory /opt/pancfg/home/user: Permission denied.
## PAN-204238
Fixed an issue where, when View Rulebase as Groups was enabled, the Tags field did not display a scroll down arrow for navigation.
## PAN-204068
Fixed an issue where a newly created vsys (virtual system) in a template was not able to be pushed from Panorama to the firewall.
## PAN-203330
Fixed an issue where the certificate for an External Dynamic List (EDL) incorrectly changed from invalid to valid, which caused the EDL file to be removed.
## PAN-202963
Fixed an issue where the system log message dsc HA state is changed from 1 to 0 was generated with the severity High. With this fix, the severity was changed to Info.
## PAN-202795
Fixed an issue where file identification failed with a large HTTP header.
## PAN-201721
Fixed an issue with firewalls in HA configurations where HA setup generated the error mismatch due to device update during a content update even though the version was the same.
## PAN-200019
Fixed an issue on Panorama where Virtual Routers (Network > Virtual Routers) was not available when configuring a custom Panorama admin role (Panorama > Admin Roles).
## PAN-199557
Fixed an issue on Panorama where virtual memory usage exceeded the set limit, which caused the configd process to restart.
## PAN-197121
Fixed an issue where incorrect user details were displayed under the USER DETAIL drop-down (ACC > Network activity > User activity).
## PAN-196309
```caveat
PA-5450 firewalls only
```
Fixed an issue where a firewall configured with a Policy-Based Forwarding policy flapped when a commit was performed, even when the next hop was reachable.
## PAN-195788
Fixed an issue where zip files did not download when applying Security inspection and the following error message displayed: resources-unavailable.
## PAN-195695
Fixed an issue where the AppScope Summary report and PDF report export function did not work as expected.
## PAN-192456
Fixed an issue where GlobalProtect SSL VPN processing during a high traffic load caused the dataplane to stop responding.
## PAN-189666
Fixed an issue where GlobalProtect portal connections failed after random commits when multiple agent configurations were provisioned and configuration selection criteria using certificate profile was used.
## PAN-187763
Fixed an issue where DNS Security logs did not display a threat category, threat name, or threat ID when domain names contained 64 or more characters.
## PAN-187279
Fixed an issue where not all quarantined devices were displayed as expected.
## PAN-184630
Fixed an issue where TLS clients, such as those using OpenSSL 3.0,
enforced the TLS renegotiation extension (RFC 5746).
@@ -0,0 +1,46 @@
---
type: Addressed
product: PAN-OS
version: 11.0.3-h10
---
## PAN-252214
A fix was made to address CVE-2024-3400.
## PAN-246707
Fixed an issue where failover was not triggered when multiple
processes stopped responding.
## PAN-244493
Fixed a memory limitation with mapping subinterfaces to VPCE
endpoints for GCP IPS, Amazon Web Services (AWS) integration with
GWLB, and NSX service chain mapping.
## PAN-240347
Fixed an issue with the web interface where the
Dashboard and a Device
Group policy rule took longer than expected to
load.
## PAN-240166
Fixed an issue where, when explicit proxy was configured on the
firewall, websites loaded more slowly than expected or did not load
due to DNS using TCP.
## PAN-239279
Fixed an issue related to web proxy where the masterd
process monitoring envoy process memory restarted when it reached an
unexpected limit.
## PAN-230746
Fixed an issue on the web interface where device groups with a large
number of managed firewalls displayed the
Policy page more slowly than
expected.
@@ -0,0 +1,40 @@
---
type: Addressed
product: PAN-OS
version: 11.0.3-h12
---
## PAN-253317
```caveat
VM-Series firewalls on Microsoft Azure environments only
```
Fixed an issue where you were unable to log in to the firewall after
a private data reset.
## PAN-246960
Fixed an issue where firewalls failed to fetch content updates from
the Wildfire Private Cloud due to an Unsupported
protocol error.
## PAN-244648
```caveat
PA-5200 Series only
```
Fixed an issue where the firewall did
not boot up after a factory reset, and, with FIPS mode enabled, the
firewall rebooted into maintenance mode.
## PAN-238769
```caveat
VM-Series firewalls in FIPS-CC mode only
```
Fixed an issue
where upgrading Panorama caused all locally created Security policy rule
actions to Deny.
@@ -0,0 +1,10 @@
---
type: Addressed
product: PAN-OS
version: 11.0.3-h13
---
## PAN-272809
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and
CVE-2024-9474.
@@ -0,0 +1,16 @@
---
type: Addressed
product: PAN-OS
version: 11.0.3-h1
---
## PAN-237871
```caveat
WF-500 appliances and PAN-DB private cloud deployments only
```
Fixed an issue where the
root-cert was set to expire on
December 31, 2023. With this fix, the expiration date has been
extended.
@@ -0,0 +1,91 @@
---
type: Addressed
product: PAN-OS
version: 11.0.3-h3
---
## PAN-239769
Fixed an issue where object references in a rule were renamed, and
while doing a selective revert of the changes with Commit
changes by me caused a reference error.
## PAN-237876
Extended the firewall Panorama root CA certificate which was
previously set to expire on April 7th, 2024.
## PAN-235476
Fixed an issue where threat logs from different Security zones were
aggregated into one log.
## PAN-233039
Fixed an issue where GENEVE encapsulated packets coming from a GFE
Proxy mapped to an incorrect Security policy rule.
## PAN-231507
```caveat
PA-1400 Series firewalls only
```
Fixed an issue where, when
an HSCI interface was used as an HA2 interface, HA2 packets were
intermittently dropped on the passive firewall, which caused the HA2
connection to flap due to missing HA2 keepalive messages.
## PAN-230092
Fixed an issue where the routed process stopped
responding when committing routing-related changes if Advanced
routing was enabled.
## PAN-227568
When a device certificate is installed, renewed, or removed, the
firewall will reconnect to the WildFire cloud to use the newest
certificate.
## PAN-227064
Fixed an issue with high availability (HA) sync failure when
performing a partial commit after creating a Security policy via
REST API.
## PAN-226792
Fixed an issue where the logrcvr process stored older
content versions in the shared memory even when newer content
updates were installed.
## PAN-225886
Fixed an issue where, when explicit proxy mode was enabled for the
web proxy, intermittent errors and unexpected TCP reconnections
occurred.
## PAN-218620
Fixed an issue where scheduled configuration exports and SCP server
connection testing failed.
## PAN-215576
Fixed an issue where the userID-Agent
and TS-Agent certificates were set to
expire on November 18, 2024. With this fix, the expiration date has
been extended to January 2032.
## PAN-202361
Fixed an issue where packets queued to the pan_task
process were still transmitted when the process was not
responding.
## PAN-193004
Fixed an issue where /opt/pancfg
partition utilization reached 100%, which caused access to the
Panorama web interface to fail.
@@ -0,0 +1,153 @@
---
type: Addressed
product: PAN-OS
version: 11.0.3-h5
---
## PAN-242561
Fixed an issue where GlobalProtect tunnels disconnected shortly after
being established when SSL was used as the transfer protocol.
## PAN-241772
Fixed an issue where, when TLSv1.3 was used, an incorrect error
message invalid padding was displayed
instead of the expected error message Invalid server
certificate.
## PAN-240786
Fixed an issue on firewalls in HA configurations where VXLAN sessions
were allocated, but not installed or freed, which resulted in a
constant high session table usage that was not synced between the
firewalls. This resulted in a session count mismatch.
## PAN-240487
Fixed an issue where fan speed increased significantly after
upgrading the firewall.
## PAN-240197
Fixed an issue where configuration changes made in Panorama and
pushed to the firewall were not reflected on the firewall.
## PAN-238996
Fixed an issue where commits did not complete and remained in a
pending state due to a race condition. With this fix, the commit
will fail after 60 seconds and not remain in a pending state.
## PAN-238769
```caveat
VM-Series firewalls in FIPS-CC mode only
```
Fixed an issue
where upgrading Panorama caused all locally created Security policy
rule actions to Deny.
## PAN-236120
Fixed an issue where the /opt/panlogs partition reached capacity due
to the logdb-quota for the User-ID log folder not being matched.
## PAN-234929
Fixed an issue where tabs in the ACC such as
Network Activity
Threat Activity and Blocked
Activity did not display data when you applied a
Time filter of Last 15
Minutes, Last Hour,
Last 6 Hours, or Last 12
Hours, and the data that was displayed with the
Last 24 Hours filter was not accurate.
Reports that were run against summary logs also did not display
accurate results.
## PAN-232800
Fixed an issue where critical disk usage for /opt/pancfg increased
continuously and the system logs displayed the following message:
Disk usage for /opt/pancfg exceeds limit,
<value> percent in use.
## PAN-231802
Fixed an issue where an Advanced Routing BGP session flapped with
commits when BGP peer authentication was enabled.
## PAN-230746
Fixed an issue on the web interface where device groups with a large
number of managed firewalls displayed the
Policy page more slowly than
expected.
## PAN-229691
Fixed an issue on Panorama where configuration lock timeout errors
were observed during normal operational commands by increasing
thread stack size on Panorama.
## PAN-228515
Fixed an issue where the Elasticsearch cluster health status
displayed as yellow or red due to Elasticsearch SSH tunnel
flaps.
## PAN-228187
Fixed an issue where the management server restarted due to the
virtual memory exceeding the limit.
## PAN-227397
Fixed an issue where selective pushes on Panorama removed a
previously pushed configuration from the firewalls.
## PAN-227368
Fixed an issue where the GlobalProtect app was unable to connect to a
portal or gateway and GlobalProtect Clientless VPN users were unable
to access applications if authentication took more than 20
seconds.
## PAN-223798
Fixed an issue on the firewall where, when Advanced Routing was
enabled, PIM join messages were not sent to the RN due to a missing
OIF.
## PAN-223259
Fixed an issue where selective pushes failed with the error message
Failed to generate selective push configuration.
Unable to retrieve last in-sync configuration for the device,
either a push was never done or version is too old. Please try a
full push.
## PAN-220907
```caveat
VM-Series firewalls only
```
Fixed an issue where large
packets were dropped from the dataplane to the management plane,
which caused OSPF neighborship to fail.
## PAN-220659
Fixed an issue on the firewall where scheduled Antivirus updates
failed when external dynamic lists were configured on the
firewall.
## PAN-218928
Fixed an issue where the reportd process stopped
responding after querying logs or generating ACC reports with some
filters.
@@ -0,0 +1,642 @@
---
type: Addressed
product: PAN-OS
version: 11.0.3
---
## PAN-231823
A fix was made to address CVE-2024-5916.
## PAN-233954
Fixed an issue where the firewall was unable to retrieve correct groups from the LDAP server.
## PAN-232059
Fixed an issue with memory management when processing large certificates using TLSv1.3.
## PAN-229691
Fixed an issue on Panorama where configuration lock timeout errors were observed during normal operational commands by increasing thread stack size on Panorama.
## PAN-228877
```caveat
PA-7050 firewalls only
```
Fixed an issue with OOM conditions which caused slot restarts
due to pan_cmd consuming more than 300
MB.
## PAN-227639
Fixed an issue where the ACC displayed an incorrect DNS-base application traffic byte count.
## PAN-227376
Fixed an issue where a memory overrun caused the all_task process to stop responding.
## PAN-227179
Fixed an issue where routes were not updated in the forwarding table.
## PAN-226418
A CLI command was added to address an issue where long-lived sessions aged out even when there was ongoing traffic.
## PAN-226198
Fixed an issue on Panorama where the configd process repeatedly restarted when attempting to make configuration changes.
## PAN-225920
Fixed an issue where duplicate predict sessions didn't release NAT resources.
## PAN-225183
Fixed an issue where SSH tunnels were unstable due to ciphers used as part of the high availability SSH configuration.
## PAN-225169
Added a CLI command to view Cortex Data Lake queue usage.
## PAN-224145
Fixed an issue in multi-vsys environments where, when Panorama was on a PAN-OS 10.2 release and the firewall was on a PAN-OS 10.1 release, commits failed on the firewall when inbound inspection mode was configured in the decryption policy rule.
## PAN-223852
Fixed an issue where all_pktproc stopped responding when network packet broker or decryption broker chains failed.
## PAN-223741
Fixed an issue where the mprelay process stopped responding, which caused a slot restart when another slot rebooted.
## PAN-223501
```caveat
PA-5200 Series and PA-7000 Series firewalls only
```
Fixed an issue where diagnostic information for the dataplane in the dp-monitor.log file was not complete.
## PAN-223488
Fixed an issue where closed ElasticSearch shards were not deleted, which resulted in shard
purging not working as expected.
## PAN-223457
Fixed an issue where, if the number of group queries exceeded the Okta rate limit threshold, the firewall cleared the cache for the groups.
## PAN-223317
Fixed an issue where SSL traffic failed with the error message: Error: General TLS protocol error.
## PAN-223185
Fixed an issue where the distributord process stopped responding.
## PAN-222957
Fixed an issue where managed firewalls did not reflect changes pushed by users who were not in a
superuser role.
## PAN-222941
Fixed an issue where viewing the latest logs took longer than expected due to log indexer failures.
## PAN-222533
```caveat
VM-Series firewalls on Microsoft Azure and Amazon Web Services (AWS) environments
```
Added support for high availability (HA) link monitoring and path monitoring.
## PAN-222418
Fixed an issue where the firewall intermittently recorded a reconnection message to the authentication server as an error, even if no disconnection occurred.
## PAN-222162
Fixed an issue where the show transceiver <interface> CLI command
showed the RX and TX powers as 0.00 mW.
## PAN-221984
```caveat
VM-Series firewalls in Microsoft Azure environments only
```
Fixed an issue where an interface went down after a hotplug event and was only recoverable by restarting the firewall.
## PAN-221836
Fixed an issue where improper SNI detection caused incorrect URL categorization.
## PAN-221787
Fixed an issue where a User Principal Name (UPN) was incorrectly required in the pre-logon machine certificate.
## PAN-221647
Fixed an issue where the Apps seen value was not reflected on Panorama.
## PAN-221577
Fixed an issue where a static route for a branch or hub over the respective virtual interface was not installed in the routing table even when the tunnel to the branch or hub was active.
## PAN-221208
Fixed an issue where the tunnel monitor was unable to remain up when zone protection with Strict
IP was enabled and NAT Traversal was applied.
## PAN-221126
Fixed an issue where Email server profiles (Device > Server Profiles > Email and
Panorama > Server Profiles > Email) to forward
logs as email notifications were not forwarded in a readable
format.
## PAN-220910
Fixed an issue where an internal management plane NIC caused a kernel panic when doing a transmit due to the driver reinitializing under certain failure or change conditions on the same interface during transmit.
## PAN-220899
Fixed an issue where you were unable to choose the manual GlobalProtect gateway.
## PAN-220747
Fixed an issue where logs were not visible after restarting the log collector.
## PAN-220626
Fixed an issue where system warning logs were written every 24 hours.
## PAN-220448
Fixed an issue where the GlobalProtect client connection remained at the prelogin stage when
Kerberos SSO failed and was unable to fall back to the realm
authentication.
## PAN-220401
Fixed an issue where, during a reboot, an unexpected error message was displayed that the syslog configuration file format was too old.
## PAN-220281
```caveat
PA-7080 firewalls only
```
Fixed an issue where autocommitting changes after rebooting the
Log Forwarding Card (LFC) caused the logrcvr process to
fail to read the configuration file.
## PAN-220180
Fixed an issue where configured botnet reports (Monitor > Botnet) were not generated.
## PAN-219813
Fixed an issue where the configuration log displayed incorrect information after a multidevice
group Validate-all operation.
## PAN-219659
Fixed an issue where root partition frequently filled up and the following error message was displayed: Disk usage for / exceeds limit, xx percent in use, cleaning filesystem.
## PAN-219644
Fixed an issue where firewalls that forwarded logs to a syslog server over TLS (Objects > Log Forwarding) used the default Palo Alto Networks certificate instead of the configured custom certificate.
## PAN-219623
Fixed an issue where, when a multidynamic group validate job was pushed on the firewall, logs
displayed Panorama push instead of
ValidateAll push.
## PAN-219498
Fixed an issue where the Threat ID/Name detail in Threat logs was not
included in syslog messages sent to Splunk.
## PAN-219300
Fixed an issue where the task manager displayed only limited data.
## PAN-219253
Fixed an issue where, after making changes in a template, the Commit and Push option was grayed out.
## PAN-218988
Fixed an issue in FIPS mode where, when importing a certificate with a new private key, and the certificate used the name of an existing certificate on the Panorama, the following error message was displayed: Mismatched public and private keys.
## PAN-218947
Fixed an issue where logs were not displayed in Elasticsearch under ingestion load.
## PAN-218697
Fixed an issue where the ElasticSearch status frequently changed to red or yellow after a PAN-OS upgrade.
## PAN-218663
A fix was made to address CVE-2024-2433
## PAN-218404
Fixed an issue where ikemgr stopped responding due to receiving CREATE_CHILD messages with a malformed SA payload.
## PAN-218340
Fixed an issue where selective pushes to template stack and multi device group pushes caused a buildup of resident memory, which caused the configd process to stop responding.
## PAN-218318
Fixed an issue where the firewall changed the time zone automatically instead of retrieving the correct time zone from the NTP server.
## PAN-218273
Fixed an issue where TCP keepalive packets from the client to the server weren't forwarded when SSL decryption was enabled.
## PAN-218267
Fixed an issue where a commit and push operation from Panorama to managed firewalls did not complete or took longer to complete than expected.
## PAN-218252
Fixed an issue where the slot-1 data processor showed the status as down during an SNMP
query.
## PAN-218107
Fixed an issue with ciphers used for SSH tunnels where packet lengths were too large, which made the SSH tunnel unstable.
## PAN-218046
Fixed an issue where the Virtual Routers (Network > Virtual Routers) setting was not available when configuring a custom admin role (Device > Admin Roles).
## PAN-218001
```caveat
PA-400 Series firewalls only
```
Fixed an issue where shutdown commands rebooted the system instead of correctly triggering a shutdown.
## PAN-217650
```caveat
VM-Series firewalls and Panorama virtual appliances in Microsoft Azure environments only
```
Fixed an issue where management interface
Speed/Duplex was reported as unknown.
## PAN-217493
Fixed an issue where superusers with read-only privileges were unable to view SCEP object configurations.
## PAN-217169
Fixed an issue where the logrcvr stopped forwarding logs to the syslog server after a restart.
## PAN-217053
Fixed an issue where the configd process stopped responding after a selective push to multiple device groups failed.
## PAN-216957
Fixed an issue where allow list checks in an authentication profile did not work if the group
Distinguished Name contains the ampersand ( & ) character.
## PAN-216775
Fixed an issue where the devsrvr process stopped responding at pan_cloud_agent_get_curl_connection() and the URL cloud could not be connected.
## PAN-216366
Fixed an issue where, when custom signatures used a certain syntax, false positives were generated on devices on a PAN-OS 10.0 release.
## PAN-216214
```caveat
Panorama managed firewalls in active/active HA configurations only
```
Fixed an issue where the HA status displayed as Out of Sync (Panorama > Managed Devices > Health) if local firewall configurations were made on one of the HA peers. This caused the next HA configuration sync to overwrite the local firewall configuration made on the HA peer.
## PAN-216048
Fixed an issue where, when upgrading from a PAN-OS 9.1 release to a PAN-OS 10.0 release, commits failed with the error message: hip profiles unexpected here.
## PAN-215767
Fixed an issue where, after a high availability failover, IKE SA negotiation failed with the error message INVALID_SPI, which resulted in temporary loss of traffic over some proxy IDs.
## PAN-215655
Fixed an issue where, after a multidynamic group push, Security policy rules with the target
device tag were added to a firewall that did not have the tag.
## PAN-215338
```caveat
PA-5400 Series firewalls only
```
Fixed an issue where the inner VLAN tag for Q-in-Q traffic was stripped when forwarding.
## PAN-215317
Fixed an issue where the dataplane stopped responding unexpectedly with the error message comm exited with signal of 10.
## PAN-215066
Fixed an issue on Panorama where push scope rendering caused the Commit and Push or Push to Devices operation window to hang for several minutes.
## PAN-214990
Fixed an issue where firewall copper ports flapped intermittently when device telemetry was enabled.
## PAN-214987
Fixed an issue where Application Filter names were not random, and they matched or included internal protocol names.
## PAN-214815
Fixed an issue where SNMP queries were not replied to due to an internal process timeout.
## PAN-214727
Fixed an issue where a memory leak related to the useridd process resulted in an OOM
condition, which caused the process to stop responding.
## PAN-214669
Fixed an issue where FIN and RESET packets were sent in reverse order.
## PAN-214463
Fixed an issue where IKE re-key negotiation failed with a third-party vendor and the firewall
acting as the initiator received a response with the VENDOR_ID
payload and the error message unexpected critical
payload (type 43).
## PAN-214201
Fixed an issue where, after exporting custom reports to CSV format, the letter b appeared at the beginning of each column.
## PAN-214186
Fixed an issue where category length was incorrect, which caused the
dataplane to restart.
## PAN-213956
Fixed an issue where the firewall interface did not go down even after the peer link/switch port went down.
## PAN-213931
Fixed an issue where the logrcvr process cache was not in sync with the mapping on the firewall.
## PAN-213296
Fixed an issue where Single Log-out (SLO) was not correctly triggered from the firewall toward
the client, which caused the client to not initiate the SLO request
toward the identity provider (IdP). This resulted in the IdP not
making the SLO callback to the firewall to remove the user.
## PAN-213162
Fixed an issue where an SD-WAN object was not displayed under a child device group.
## PAN-213112
Fixed an issue where executing the show report directory-listing CLI command resulted in no output after upgrading to a PAN-OS 10.1 release.
## PAN-212978
Fixed an issue where the firewall stopped responding when executing an SD-WAN debug CLI
command.
## PAN-212726
Fixed an issue where RTP/RTCP packets were dropped for SIP calls by SIP ALG when the source NAT translation type was persistent Dynamic IP And Port.
## PAN-212577
```caveat
PA-5200 Series and PA-7080 firewalls only
```
Fixed an issue where commits took longer than expected when more than 45,000 Security policy rules were configured.
## PAN-212240
Fixed an issue where packet capture was logged for an unknown application session when packet capture logging was disabled.
## PAN-212057
Fixed an issue where Advanced Threat Prevention caused SSL delays when no URL licenses were present.
## PAN-211441
Fixed a memory leak issue related to SSL crypto operations that resulted in failed commits.
## PAN-211398
Fixed an issue where dataplane processes stopped responding when handling HTTP/2 streams.
## PAN-211384
Fixed an issue where the size of the redisthost_1 in the Redis database continuously increased, which caused an OOM condition.
## PAN-210640
Fixed an issue where applications were not displayed after authenticating into the clientless VPN.
## PAN-210502
Fixed an issue where Panorama was unable to convert to PAN-OS 9.1 syntax for WF-500
appliances.
## PAN-210456
Fixed an issue where high latency occurred on PA-850-ZTP when SSL decryption was enabled.
## PAN-210452
Fixed an issue where application packet capture (pcap) was not generated when Security policy
rules were used as a filter.
## PAN-210429
```caveat
VM-Series firewalls only
```
Fixed an issue where the HTTP service failed to come up on DHCP dataplane interfaces after rebooting the firewall, which resulted in health-check failure on HTTP/80 with a 503 error code on the public load balancer.
## PAN-210364
Fixed an issue where high latency was observed when accessing internal web applications, which interrupted development activities related to the web server.
## PAN-209585
The Palo Alto Networks QoS implementation now supports a new QoS mode called lockless QoS for PA-3400, PA-5410, PA-5420, PA-5430, and PA-5440 firewalls. For firewalls with higher bandwidth QoS requirements, the lockless QoS dedicates cores to the QoS function that improves QoS performance, resulting in improved throughput and latency.
## PAN-209375
Fixed an issue on the firewall where log filtering did not work as expected.
## PAN-209288
Fixed an issue where generating certificates with SCEP did not work.
## PAN-209172
Fixed an issue where the firewall was unable to handle GRE packets for Point-to-Point Tunneling Protocol (PPTP) connections.
## PAN-209108
Fixed an issue where a Panorama in Management Only mode was unable to display logs from log
collectors due to missing schema files.
## PAN-208567
Fixed an issue with email formatting where, when a scheduled email contained two or more attachments, only one attachment was visible.
## PAN-208438
Fixed an issue on Panorama where Security policy rules incorrectly displayed as disabled.
## PAN-208395
Fixed an issue where user authentication failed in multi-vsys environments with the error message User is not in allowlist when an authentication profile was created in a shared configuration space.
## PAN-208316
Fixed an issue where user-group names were unable to be configured as the source user via the test security-policy-match command.
## PAN-208240
Fixed an issue where, when attempting to replace an existing certificate, importing a new certificate with the same name as the existing certificate failed due to mismatched public and private keys.
## PAN-208198
Fixed an issue with firewalls in active/passive HA configurations where, after rebooting the passive firewall, interfaces were briefly shown as powered up, and then shown as down or shutdown.
## PAN-208090
Fixed an issue where the ACC report did not display data when querying the filter for the fields Source and Destination IP.
## PAN-207604
Fixed an issue where system logs continuously generated the log message Not enough space to load content to SHM.
## PAN-207577
Fixed an issue where Panorama > Setup > Interfaces was not accessible for users with custom admin roles even when the interface option was selected for the custom admin roles.
## PAN-206765
Fixed an issue where log forwarding filters involving negation did not work.
## PAN-205015
Fixed an issue where not all users were included in the user group after an incremental sync between the firewall and the Cloud Identity Engine.
## PAN-204868
Fixed an issue where disk utilization was continuously high due to the log purger not sufficiently reducing the utilization level.
## PAN-204718
```caveat
PA-5200 Series firewalls only
```
Fixed an issue where, after upgrading to PAN-OS 10.1.6-h3, a TACACS user login displayed the following error message during the first login attempt: Could not chdir to home directory /opt/pancfg/home/user: Permission denied.
## PAN-203611
Fixed an issue where URL categorization was not recognized for URLs that contained more than 100 characters.
## PAN-202524
Fixed an issue where the session ID was missing in the session details section of the ingress-backlogs XML API output.
## PAN-199819
Fixed an issue where, if a decryption profile allowed TLSv1.3, but the server only supported
TLSv1.2, and the cipher used by the first connection to the server
was a CBC SHA2 cipher suite, the connection failed.
## PAN-198509
Fixed an issue where commits failed due to insufficient CFG memory.
## PAN-198453
Fixed an issue where you were unable to resize the Description pop-up window (Policies > Security > Prerules).
## PAN-198050
Fixed an issue where Connection to update server is successful messages displayed even when connections failed.
## PAN-197339
Fixed an issue where template configuration for the User-ID agent was not reflected on the template stack on Panorama appliances on PAN-OS 10.2.1.
## PAN-196345
Fixed an issue where scheduled dynamic content updates failed to be retrieved by managed firewalls from Panorama when connectivity was slow.
## PAN-189328
Fixed an issue where traffic belonging to the same session was sent out from different ECMP enabled interfaces.
## PAN-187989
Fixed an issue where a user who did not have permissions of other access domains were able to view the commit and configuration lock.
## PAN-185360
Fixed an issue where, when Authentication Portal Authentication was configured,
l3svc_ngx_error.log and
l3svc_access.log did not roll over
after exceeding 10 megabytes, which caused the root partition to
reach full utilization.
## PAN-180082
Fixed an issue where errors in brdagent logs caused dataplane path monitoring failure.
## PAN-177227
```caveat
VM-Series firewalls on Amazon Web Services environments only
```
Fixed an issue where traffic sent from a GENEVE tunnel to the firewall was dropped if the firewall attempted to encapsulate traffic into an IPSec tunnel.
## PAN-169586
Fixed an issue where scheduled log view reports in emails didn't match the monitor page query result for the same time interval.
## PAN-160633
```caveat
PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls only
```
Fixed an issue where
the dataplane restarted repeatedly due to an internal path
monitoring failure until a power cycle.
@@ -0,0 +1,9 @@
---
type: Addressed
product: PAN-OS
version: 11.0.4-h1
---
## PAN-252214
A fix was made to address CVE-2024-3400.
@@ -0,0 +1,15 @@
---
type: Addressed
product: PAN-OS
version: 11.0.4-h2
---
## PAN-252744
```caveat
PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls
```
Fixed an issue where upgrading the firewall to
PAN-OS 11.0.4 or PAN-OS 11.0.4-h1 caused the firewall to go into a
non-functional state.
@@ -0,0 +1,9 @@
---
type: Addressed
product: PAN-OS
version: 11.0.4-h5
---
## PAN-247511
A fix was made to address CVE-2024-3596.
@@ -0,0 +1,10 @@
---
type: Addressed
product: PAN-OS
version: 11.0.4-h6
---
## PAN-272809
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and
CVE-2024-9474.
File diff suppressed because it is too large Load Diff
@@ -0,0 +1,14 @@
---
type: Addressed
product: PAN-OS
version: 11.0.5-h1
---
## PAN-261540
```caveat
PA-3400 Series firewalls only
```
Fixed an issue where the
firewall did not fully reboot after upgrading to PAN-OS 11.0.5.
@@ -0,0 +1,10 @@
---
type: Addressed
product: PAN-OS
version: 11.0.5-h2
---
## PAN-272809
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and
CVE-2024-9474.
@@ -0,0 +1,399 @@
---
type: Addressed
product: PAN-OS
version: 11.0.5
---
## PAN-255868
```caveat
PA-3400 Series firewalls only
```
Fixed an issue where the firewall entered maintenance mode after enabling kernel data collection during the silent reboot.
## PAN-255577
Fixed an issue where push scope changes remained empty and Edit selections >
OK did not work for admin-based users after
upgrading Panorama.
## PAN-253317
```caveat
VM-Series firewalls on Microsoft Azure environments only
```
Fixed an issue where you were unable to log in to the firewall after a private data reset.
## PAN-251563
Added CPLD enhancement to capture external power issues.
## PAN-251013
Fixed an issue on the web interface where the Virtual Router and Virtual System configurations for the template incorrectly showed as none.
## PAN-249019
Fixed an issue where the all_pktproc process stopped responding, which caused the firewall to become unresponsive.
## PAN-248427
Fixed an issue where push operations took longer than expected to complete.
## PAN-248105
Fixed an issue where the GlobalProtect SSL VPN tunnel immediately disconnected due to a keep-alive timeout.
## PAN-247403
```caveat
Panorama virtual appliances only
```
Fixed an issue where the push scope CLI command took longer than expected, which caused the web interface to be slow.
## PAN-246772
Fixed an issue on the firewall where the dataplane went down due to a path monitor failure caused by an OOM condition related to the pan_task process.
## PAN-246431
Fixed an issue where a Push to Device operation remained at the state None when performing a selective push to device groups and templates that included both connected and disconnected firewalls.
## PAN-246215
Fixed an issue where the sleep time for a suspended pan_task process caused configuration and policy updates to be blocked.
## PAN-245850
Fixed an issue on Panorama appliances in active/passive HA configurations where the firewalls entered an HA out-of-sync status and jobs failed on the passive appliance with the error message Could not merged running config from file.
## PAN-245125
```caveat
VM-Series firewalls in Microsoft Azure environments only
```
Fixed an issue where file descriptors were not closed due to invalid configurations.
## PAN-245041
Fixed an issue where the WF-500 appliance returned an error verdict for every sample in FIPS mode.
## PAN-244907
Fixed an issue where ports did not go down when moving from an active state to a suspended state.
## PAN-244894
Fixed an issue where turning off mprelay logging caused mprelay heartbeat failure.
## PAN-244836
A knob was introduced to toggle the default behavior of BGP in the Advanced Routing stack to not suppress duplicate updates. By default, the prefix updates are suppressed for optimization.
## PAN-244746
Fixed an issue where changes committed on Panorama were not reflected on the firewall after a successful push.
## PAN-244622
Fixed an issue where FIB repush did not work with Advanced Routing enabled.
## PAN-244548
Fixed an issue where ECMP sessions changed destination MAC addresses mid-session, which caused connections to be reset.
## PAN-244227
Fixed an issue where inconsistent FIB entries across the dataplane were not detected.
## PAN-243463
Fixed an issue where high Enhanced Application log traffic used excess system resources and
caused processes to not work.
## PAN-242309
Fixed an issue where a higher byte count (s2c) was observed for DNS-Base application.
## PAN-241018
```caveat
VM-Series firewalls in Microsoft Azure environments only
```
Fixed a Data Plane
Development Kit (DPDK) issue where interfaces remained in a
link-down stage after an Azure hot plug event.
## PAN-240596
Fixed an issue where all_task stopped responding due to an invalid memory address.
## PAN-240477
Fixed a temporary hardware issue that caused PAN-SFP-PLUS-CU-5M to not be able to link up on PA-3400 and PA-1400 Series firewalls.
## PAN-240174
Fixed an issue where, when LSVPN serial numbers and IP address authentication were enabled, IPv6 address ranges and complete IPv6 addresses that were manually added to the IP address allow or exclude list were not usable after a restart of the gp_broker process or the firewall.
## PAN-239662
Fixed an issue where the NSSA default route from the firewall was not generated to advertise even though the backbone area default route was advertised during a graceful restart.
## PAN-239337
Fixed an issue where the log_index was suspended and corrupted BDX files flooded the
index_log.
## PAN-238625
Fixed an issue where, when the physical interface went down, the SD-WAN Ethernet connection state
still showed UP/path-monitor due to the
Active URL SaaS monitor connection state remaining
UP/path-monitor.
## PAN-238610
Fixed an issue with the Panorama virtual appliance where, after the mgmtsrvr
restarted on the passive appliance, stale IP address tags were
pushed to the connected firewalls with the message
clear all registered ip
addresses.
## PAN-238592
```caveat
PA-3410 firewalls only
```
Fixed an issue where the firewall did not boot up after upgrading due to a TPM lockout condition that persisted for over 24 hours.
## PAN-237991
Fixed an issue where the log collector sent fewer logs than expected to the syslog server.
## PAN-237657
Fixed an issue with 100% CPU utilization in the varrcvr process that occurred during an incremental WildFire update.
## PAN-237614
Fixed an issue on Panorama where the API command request system disk add failed.
## PAN-237208
Fixed an issue where the reportd process stopped and the firewall rebooted.
## PAN-236261
Fixed an issue where a proxy server was used for external dynamic list communication even when
the dataplane interface was configured through service routes.
## PAN-236244
Fixed an issue where you were unable to select authentication profiles via the web interface.
## PAN-235807
Fixed an issue where static ND entries were not reachable after a reboot.
## PAN-235585
Fixed an issue where, when custom signatures and predefined signatures shared the same literal pattern part, the custom signature caused an incorrect calculation for the length of the predefined signature, which resulted in App-ID not detecting correctly.
## PAN-234489
Fixed an issue where a User Principle Name (UPN) was incorrectly required in the pre-logon machine certificate.
## PAN-234169
Fixed an issue where downloading files failed or was slower than expected due to malware scanning
even when the session was matched to a Security policy rule with no
Anti-Virus profile attached.
## PAN-233684
Fixed an issue on Panorama where Push to Devices or Commit and Push operations took longer than expected on the web interface.
## PAN-233207
Fixed an issue where the configd process stopped responding when a partial configuration revert operation was performed.
## PAN-231439
Fixed an issue where, when a VoIP call using dynamic IP and NAT was put on hold, the audio became one-way due to early termination of NAT ports.
## PAN-229832
Fixed an intermittent issue where MLAV and URL cloud connectivity were lost.
## PAN-228624
Fixed an issue where FIB entries were deleted due to a sysd process connection error.
## PAN-228386
Fixed an issue with session caching where the reportd process stopped responding due to null values.
## PAN-228043
Fixed an issue on firewalls on active/active HA configurations where packets dropped during
commit operations when forwarding traffic via an HA3 link when an
Aggregate Ethernet interface or data interface was used as an HA3
link.
## PAN-227641
Fixed an issue where Preview Changes and Change Summary when saving changes did not open a new window when clicked.
## PAN-227233
Fixed an issue where the combination signature aggregation criteria in a Vulnerability Protection
profile was incorrectly blank even though a value was set.
## PAN-226489
Fixed an issue where Panorama was unable to push scheduled Dynamic Updates to firewalls with the
error message Failed to add deploy job. Too many (30)
deploy jobs pending for device.
## PAN-226260
Fixed an issue where support for CBC ciphers with some authentication algorithms was only available in FIPS mode.
## PAN-226108
Fixed an issue where the masterd process was unable to start or stop the sysd process.
## PAN-225963
Fixed an issue where the IP address-to-user mapping was not correct.
## PAN-225228
Fixed an issue where filtering Threat logs using any value under THREAT
ID/NAME displayed the error Invalid
term.
## PAN-223418
Fixed an issue where heartbeats to the brdagent process were lost, resulting in the
process not responding, which caused the firewall to reboot.
## PAN-222253
Fixed an issue on Panorama where policy rulebase reordering under View Rulebase by Groups (Policy > <policy-rulebase>) did not persist if you reordered the policy rulebase by dragging and dropping individual policy rules and then moved the entire tag group.
## PAN-221571
Fixed an issue on the web interface where the Security policy rule hit count remained at 0 for
some rules even though the Traffic logs showed live hits.
## PAN-221041
Fixed an issue where the following error message was seen frequently in the system logs: Clearing snmpd.log due to log overflow.
## PAN-221003
Fixed an issue where you were unable to uncheck firewalls in HA configurations from the device group when Group HA Peers was enabled.
## PAN-220640
```caveat
PA-220 firewalls only
```
Fixed an issue where the firewall CPU percentage was miscalculated, and the values that were displayed were incorrect.
## PAN-220601
Fixed an issue with missing logs when one log collector in a log Collector Group became
unreachable.
## PAN-219690
Fixed an issue where GlobalProtect authentication failed when authentication was SAML with CAS and the portal was resolved with IPv6.
## PAN-218521
```caveat
M-600 Appliances in Log Collector mode only
```
) Fixed an issue where Panorama continuously rebooted and became unresponsive, which consumed excessive logging disk space and prevented new log ingestion.
## PAN-218331
Fixed an issue where you were unable to export or download packet captures from the firewall when context switching from Panorama.
## PAN-217674
Fixed an issue where RADIUS authentication failed when the destination route of the service route was configured with an IPv4 address with more than 14 characters.
## PAN-217489
Fixed an issue with firewalls in active/passive HA configurations where the passive firewall MAC flapping occurred when the passive firewall was rebooted.
## PAN-215905
```caveat
PA-3400 Series firewalls only
```
Fixed an issue where silent packet drops were observed on interfaces.
## PAN-215430
Fixed an issue where dynamic IP address NAT with SIP intermittently failed to convert RTP Predict
sessions.
## PAN-214682
Fixed an issue where the firewall sent incorrectly encoded the supported_groups extension in the Client Hello when acting as a forward proxy with decryption profile max version TLSv1.2.
## PAN-213173
Fixed an issue where Preview Changes under Scheduled Pushes did not launch the Change Preview window.
## PAN-212553
Fixed an issue where the ikemgr process stopped responding due to memory corruption, which caused VPN tunnels to go down.
## PAN-209574
Fixed an issue with HTTP2 traffic where downloading large files did not work when decryption was enabled.
## PAN-207972
Fixed an issue on the web interface where the BGP routing table did not display advertised routes.
## PAN-205482
Fixed an issue related to the configd process where Panorama displayed the error
Server not responding when editing policy
rules.
## PAN-200946
Fixed an issue with firewalls in active/passive HA configurations where GRE tunnels went down due to recursive routing when the passive firewall was booting up. When the passive firewall became active and no recursive routing was configured, the GRE tunnel remained down.
## PAN-196146
```caveat
VM-Series firewalls only
```
Fixed an issue where hostname validation failed due to the firewall not taking the hostname provided in init.cfg.
## PAN-194968
Fixed an issue on the web interface where Antivirus updates were not able to be downloaded and installed unless Apps and Threads updates were downloaded and installed first, and the Antivirus content list displayed as blank. The resulting error message from the update server was also not reflected in the web interface.
## PAN-174454
Fixed an issue where the firewall did not fetch group and user membership due to the Okta sync domain not matching the active directory sync domain.
@@ -0,0 +1,10 @@
---
type: Addressed
product: PAN-OS
version: 11.0.6-h1
---
## PAN-272809
A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and
CVE-2024-9474.
@@ -0,0 +1,17 @@
---
type: Addressed
product: PAN-OS
version: 11.0.6
---
## PAN-254181
```caveat
CN-Series firewalls only
```
Fixed an issue where firewall pods and application pods repeatedly restarted.
## PAN-253400
Fixed an issue where the logrcvr process stopped responding.