Add 9.1 issue data

This commit is contained in:
2026-03-20 16:38:51 -05:00
parent 07909917e0
commit ea9bd911aa
61 changed files with 12042 additions and 4 deletions
@@ -6,6 +6,10 @@ source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
Fixed a Denial-of-Service (DoS) vulnerability in the GlobalProtect portal and gateway ([CVE-2021-3063](https://security.paloaltonetworks.com/CVE-2021-3063)).
## PAN-178283
Fixed an intermittent issue where connections to the URL cloud went down due to a failure to resolve DNS.
@@ -0,0 +1,47 @@
---
type: Addressed
product: PAN-OS
version: 9.1.0
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-130069
Fixed an issue where the firewall incorrectly interpreted an external dynamic list MineMeld instability error code as an empty external dynamic list.
## PAN-125546
Fixed an issue where a process failed to restart even when the system logs displayed the following message: virtual memory exceeded, restarting.
## PAN-125515
Fixed an issue on VM-Series firewalls where the firewall dropped all traffic traversing from the dataplane to the management plane.
## PAN-125008
Fixed an issue on the firewalls where traffic logs generated with incorrect policy rule names when the security policy rule names contained more than 58 characters.
## PAN-123322
```caveat
PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls only
```
Fixed an intermittent issue where a process (all_pktproc) stopped responding due to a Work Query Entry (WQE) corruption that was caused by duplicate child sessions.
## PAN-122421
Fixed an issue where third-party VPN clients were unable to connect to GlobalProtect using IPSec due to a stale IKE/IPSec security association (SA).
## PAN-114856
A change was made to limit debug log visibility to superusers only.
## PAN-111708
```caveat
PA-3200 Series firewalls only
```
Fixed a rare software issue that caused the dataplane to restart unexpectedly. To leverage this fix, you must run the debug dataplane set pow no-desched yes CLI command (increases CPU utilization).
@@ -0,0 +1,493 @@
---
type: Addressed
product: PAN-OS
version: 9.1.10
source: common-crawl
crawl: CC-MAIN-2026-12
---
## WF500-5568
Fixed an issue where a firewall in FIPS mode running PAN-OS 8.1.18 or a later version failed to connect with a WildFire appliance in normal mode.
## WF500-5513
Fixed an issue where cloud queries failed, which generated system logs. The issue occurred because a hash was not found in the cloud.
## PAN-169551
Fixed an issue where custom URL categories hit incorrect URL categories, which caused the firewall to miss or deny the security policies for the configured custom URL.
## PAN-168298
Fixed an issue where a firewall superuser using an LDAP authentication profile that was pushed from Panorama was unable to save the filter under **Monitor > Logs**.
## PAN-167306
```caveat
VM-Series firewalls on Microsoft Azure only
```
Fixed an issue where, when a second disk was added, /opt/panlogs was mounted on an incorrect partition.
## PAN-167098
Fixed an issue where a configd process memory corruption occurred when Panorama was exposed to multiple XML API calls on Dynamic Address Groups updates.
## PAN-166570
Fixed an issue where authentication failure messages were overwritten when a commit was in progress.
## PAN-166328
```caveat
PA-7000 Series firewalls with NPCs only
```
Fixed an issue where path monitoring failure occurred while hot inserting a 100G NPC (network processing card) into the firewall.
## PAN-166306
Fixed an issue where commit jobs failed when validating HIP objects and profiles.
## PAN-166296
Fixed an issue where an unavailable certificate revocation list (CRL) from the server side caused an infinite loop on a process (sslmgr), which resulted in it not responding for other tasks.
## PAN-166241
A fix was made to address an improper restriction of XML external identity (XXE) reference in the PAN-OS web interface that enabled an authenticated administrator to read any arbitrary file from the file system and send a specifically crafted request to the firewall that caused the service to crash ([CVE-2021-3055](https://security.paloaltonetworks.com/CVE-2021-3055)).
## PAN-166021
Fixed an issue where log queries that included a username did not return with any output.
## PAN-164922
Fixed an issue on Panorama where a context switch to a managed firewall running PAN-OS 8.1.0 to PAN-OS 8.1.19 failed.
## PAN-164846
Fixed an issue where packet buffers were depleted.
## PAN-164646
Fixed an issue where tunnel monitoring in the Large Scale VPN (LSVPN) displayed as down in both the CLI and the web interface due to incorrect dataplane ownership.
## PAN-164571
Fixed an issue where DHCP leases were not properly synchronized between high availability peers after a device or dhcpd process restart. With this fix, the DHCP lease details display correctly on both the active and the passive device.
## PAN-164392
Fixed an issue where an out-of-memory (OOM) condition occurred due to a memory leak related to a process (logrcvr).
## PAN-164338
Fixed an issue where, when using the CLI or API, configurations for policy rule services or applications that either used custom settings and default settings together, or used multiple default settings together, successfully commit instead of failing or displaying a warning.
**Note** To use this fix, you must delete previous application or service settings in the configuration.
## PAN-164056
Fixed a memory issue for LSVPNs with multiple dataplane systems.
## PAN-163587
Fixed an issue on Panorama where a user with an admin role was able to set the **Block IP List** option via the CLI but not the web interface.
## PAN-162663
Fixed an intermittent issue on the firewall where packets dropped in decrypted SSL/TLS sessions.
## PAN-162600
Fixed an issue where, when the GlobalProtect client sent UDP/4501 traffic that was destined for the GlobalProtect gateway inside the GlobalProtect tunnel, the firewall still processed the traffic, which caused routing loops.
## PAN-162594
Fixed an issue where blank configuration for tokens in a content-driven FreeDNS Afraid.org Dynamic API v1 DDNS configuration were not enabled.
## PAN-161869
Fixed an issue where a core dump occurred on a process (flow_ctrl) after a commit if a policy-based forwarding (PBF) rule referenced an interface that had a DHCP IP address assignment.
## PAN-161544
Fixed an issue where the **Device Name**field was missing when GlobalProtect logs were exported to CSV from the Panorama management server.
## PAN-161260
Fixed a memory leak issue related to a process (useridd) that occurred when processing high amount of HIP reports as well as aa memory leak issue related to the sslvpn process that occurred when the firewall was configured as a GlobalProtect satellite.
## PAN-161112
Fixed an issue where a process (useridd) repeatedly exceeded the virtual memory limit, which caused the process to stop responding.
## PAN-161025
Fixed an issue in Panorama where an administrator with the role of Panorama administrator did not have the option to download or install GlobalProtect clients (**Panorama > Device Deployment > GlobalProtect**).
## PAN-160997
Fixed an issue where the metadata from the firewall's authentication profile was unable to export. This issue occurred when the authentication profile and the SAML Identity Provider sever profile were created with **VSYS** in the **Location** and pushed from Panorama template stack values. To utilize this fix, you must upgrade both Panorama and the firewall.
## PAN-160870
```caveat
ZTP-capable firewalls only
```
Fixed an issue where the default Zero Touch Provisioning (ZTP) configuration was still present on the firewall even when ZTP was disabled, which caused commit failures.
## PAN-160540
Fixed an issue where tunnel traffic was dropped intermittently when a Quality of Service (QoS) Profile was assigned but the profile had no limits defined.
## PAN-160247
Fixed an issue where system logs incorrectly displayed as **Critical**.
## PAN-160238
Fixed an issue where intermittent VXLAN packet drops occurred if the TCI was not configured for inspecting VXLAN traffic. This issue occurred when traffic was migrated from a firewall running a PAN-OS version earlier than PAN-OS 9.0 to a firewall running PAN-OS 9.0 or later.
## PAN-160053
Fixed an issue in Panorama where a process (configd) stopped responding due to a race condition in the mongodb process.
## PAN-159973
Fixed an issue where a local commit in the Panorama management server caused the status to get out of sync on the managed WildFire appliance.
## PAN-159592
Fixed an issue where a Japanese keyword search displayed garbled characters during SAML authentication.
## PAN-159499
Fixed an issue where you were unable to select the configured QoS profile under the template stack.
## PAN-159295
Fixed an issue where scheduled configuration export files saved in the /tmp folder in root were not periodically purged, which caused the root partition to fill up.
## PAN-159224
Fixed an memory leak issue related to a process (mgmtsrvr), which was caused by a certificate loading operation.
## PAN-159054
Fixed an issue where you were unable to add more than 500 DHCP relay agent objects in the firewall templates from Panorama.
## PAN-158932
Fixed an issue where an increase was observed on spyware_state, which caused latency.
## PAN-158161
Fixed an issue where the PBF monitor was failing on the tunnel interface when QoS was enabled.
## PAN-158119
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where TFTP traffic with a high packet rate was not offloaded even after hitting an application override policy with a custom application.
## PAN-158020
Fixed an issue where HIP reports were not visible on the web interface due to a domain override configuration.
## PAN-157964
Fixed an issue where adding a container application from the **Apps Seen** list did not remove the child application from the list.
## PAN-157908
Fixed an issue where false system alarms for the IP tag log database exceeded the alarm threshold value.
## PAN-157903
Fixed an issue where the **To** field of an email was truncated in threat logs when the original email exceeded 512 bytes.
## PAN-157632
Fixed an intermittent issue where the firewall dropped GPRS tunneling protocol (GTP-U) traffic with the message TEID=0x00000000.
## PAN-157570
Fixed an issue where device deployment from Panorama to the firewalls failed with the error message Failed to get DLSRVR client key. This issue occurred only on firewalls where the request system-private-data-reset CLI command had been issued in the past.
## PAN-157479
Fixed an issue on the firewall where a process (useridd) stopped responding when group-mapping profiles were configured with an LDAP server profile with the type **e-directory**.
## PAN-157472
```caveat
PA_5200 Series firewalls only
```
Fixed an issue where, after a factory reset, the firewall displayed the following error message: data_plane_X: Exited 1 times, must be manually recovered..
## PAN-157447
Fixed an issue where a process (flow_mgmt) repeatedly restarted with a segmentation violation (SIGSEGV) signal and the following trace: flow_mgmt:pan_flow_dos_ager_invoke pan_sw_timer_100ms pan_sw_timer_invoke.
## PAN-157311
Fixed an issue where, if the **OK** button is clicked before tags are loaded when editing an address object that contained tags via the firewall web interface, associated tags are removed.
## PAN-157213
```caveat
ZTP firewalls only
```
Fixed an issue where the firewall failed to connect to Panorama when ZTP was disabled.
## PAN-157074
Fixed an issue where a process (configd) stopped responding, which caused corruption.
## PAN-157035
```caveat
PA-5200 Series firewalls only
```
Fixed an intermittent issue where multicast packets traversing the firewall in VLAN configurations experienced higher drop rates than expected.
## PAN-157027
Fixed an issue where, when stateless GTP-U traffic hit a multi-dataplane firewall, an inter-dataplane fragmentation loop occurred, which caused high dataplane resource usage.
## PAN-156240
A fix was made to address an issue where a cryptographically weak pseudo-random number (PRNG) was used during authentication to the PAN-OS interface. As a result, attackers with the capability to observe their own authentication secrets over a long duration on the firewall had the ability to impersonate another authenticated web interface administrators session ([CVE-2021-3047](https://security.paloaltonetworks.com/CVE-2021-3047)).
## PAN-156113
Fixed an issue where the management interface incorrectly used the configured default gateway for local network traffic when service routes were configured.
## PAN-156098
Fixed an issue where netflow packets sent from the firewall contained excess padding, which resulted in the packet length exceeding 1400 bytes.
## PAN-155772
Fixed an issue where the Panorama web interface did not display the secondary IP address configuring it under the template stack.
## PAN-155758
```caveat
7000-Series firewalls only
```
Fixed an issue where, when a subinterface was configured as a Log Card interface, the commit failed unless an IP address was assigned to the parent interface.
## PAN-155659
Fixed an issue where individual users were unable to populate the **allowed user/user group** field when configuring the GlobalProtect Clientless VPN.
## PAN-155657
Fixed an issue where the default log level for mprelay was set to INFO and caused commits to stop working on VM-Series firewalls in AWS using EBS backed volumes when route monitor is configured.
## PAN-155593
Fixed an issue where the firewall was unable to match HIP objects with a 3-digit code version.
## PAN-155459
Fixed an issue where an interface placed in a pre-defined zone was removed by the SD-WAN plugin after a commit to the firewall.
## PAN-155126
Fixed an issue where editing the LDAP server IP address (**Device > Templates > Server Profiles > LDAP > LDAP Server Profile**) removed the bind password.
## PAN-154603
Fixed an issue where, when SSL/TLS was required, LDAP server authentication attempted StartTLS first.
## PAN-154526
Fixed an issue where a process (genindex.sh) caused high memory usage on the management plane. Due to the resulting OOM condition, multiple processes stopped responding.
## PAN-154441
Fixed an issue where the Radius EAP authentication stopped working and the authd process restarted.
## PAN-154433
Fixed an issue where the firewall was unable to detect end-user IP address spoofing on the GTP-U for a user data session when using an IPv6 address.
## PAN-154362
Fixed an issue where Panorama failed to push dynamic user groups to the managed firewalls.
## PAN-154334
Fixed an issue where the inactivity logout timeout did not reflect on the GlobalProtect mapping timeout.
## PAN-154145
```caveat
VM-Series firewalls only
```
Fixed an issue where the management plane CPU was incorrectly reported to be high.
## PAN-154109
Fixed an issue where using XML special characters in the **Uninstalled GlobalProtect APP** password in the application configuration (**Networks > GlobalProtect > Portals > Agent > App**) disrupted portal connectivity.
## PAN-153952
Fixed an issue where the firewall treated external dynamic list entries with nested carets as invalid.
## PAN-153592
Fixed an issue where, after upgrading Panorama from PAN-OS 8.1.9 to PAN-OS 9.1.3, the option to preview changes for dynamic address groups or templates from Panorama did not work.
## PAN-153288
Fixed an issue where the software QoS shaping queue processing was not properly applied on multicast traffic.
## PAN-153228
Fixed an issue where, when IPSec tunnels had **tunnel-monitor** enabled, tunnel activation was sent every 3 seconds, even when the configured value was different. With this fix, tunnel activation will be sent according to the configured intervals and thresholds.
## PAN-151909
Modified the diff algorithm for when a configuration audit was performed because certain objects incorrectly displayed as either **New** or **Modified/Unchanged** due to the XML format being added.
## PAN-151751
Fixed an issue where GlobalProtect logs did not populate on the destination syslog server in Log Event Extended Format (LEEF) and common event format (CEF).
## PAN-151679
Fixed an issue where it was possible via the CLI to create a Security policy rule with the **any** and **application-default** options simultaneously configured.
## PAN-151302
```caveat
PA-7000 Series firewalls with Log Forwarding Cards (LFC) only
```
Fixed an issue where the logging rate for the LFC was not displayed in **Panorama > Managed Devices > Health**.
## PAN-151273
Fixed an issue where the commit event was not recorded in the config logs during a **Commit and Push** on the Panorama management server.
## PAN-150530
Fixed an issue where, when printing External Dynamic List (EDL) log messages, the messages repeated until the end of the description.
## PAN-150388
```caveat
PA-220 Series firewalls only
```
Fixed an issue where a process (mgmtsrvr) stopped responding when viewing logs in the web interface.
## PAN-150337
A fix was made to address a reflect cross-site scripting (XSS) vulnerability in the PAN-OS web interface that enabled an authenticated network-based attacker to mislead another authenticated PAN-OS administrator to click on a specially crafted link that performed arbitrary actions in the web interface as the targeted authenticated administrator ([CVE-2021-3052](https://security.paloaltonetworks.com/CVE-2021-3052)).
## PAN-150110
Fixed an issue where Elasticsearch restarted unexpectedly when it ran out of memory. This was due to the vm.max-map-count value being set incorrectly in the newer version of Elasticsearch (starting from PAN-OS 9.0). With this fix, the value is set correctly.
## PAN-150080
Fixed an issue where, even when tunnel interface is set to **down**, the following alert displayed: Tunnel GRE_Tunnels is going down(critical).
## PAN-149867
Fixed an issue where a process (authd) ignored null domain authentication profiles in a sequence and only returned non-null domains to GlobalProtect.
## PAN-147827
Fixed an issue where, when SIP traffic traversing the firewall was sent with a high QoS Differentiated Services Code Point (DSCP) value, the DSCP value was reset to the default setting (CS0).
## PAN-147781
A fix was made to address an issue where an OS command argument injection vulnerability in the PAN-OS web interface enabled an authenticated administrator to read any arbitrary file from the file system ([CVE-2021-3045](https://security.paloaltonetworks.com/CVE-2021-3045)).
## PAN-147736
Fixed an issue on the firewall web interface where the Cortex Data Lake **Logging Service Status** pop-up window did not show correct information.
## PAN-147193
Fixed an issue with the Panorama web interface where, when all device groups and templates were selected, a load configuration operation failed. This was caused by the XML cache rebuilding for each device group and template iteration.
## PAN-146250
Fixed an issue where, in two separate but simultaneous sessions, the same software packet buffer was owned and processed.
## PAN-146048
Fixed an issue where a satellite firewall was unable to authenticate to an LSVPN gateway when the issued certificate from Simple Certificate Enrollment Protocol (SCEP) had encryption bits set to 3072. With this fix, the maximum private key size of 3072 bits, along with the 1024-bit size and the 2048-bit size, is able to authenticate when selected to create the SCEP profile.
## PAN-145190
Fixed an issue where administrators were unable to delete the **GlobalProtect Data File** update schedule (**Device > Dynamic Updates**).
## PAN-144305
Fixed an issue where merged configurations were unable to be exported from Panorama-managed firewalls using the PAN-OS XML API.
## PAN-144057
Fixed a rare issue where, when aggregate ethernet (AE) groups were deleted and re-added, the AE interface no longer had an SDB node to send link the location to. As a result, the dataplane was unable to identify a connected route for the interface address.
## PAN-143699
Fixed an issue where the firewall status was inaccurate (**Panorama > Device Deployment**).
## PAN-142199
Fixed an issue memory leak issue where a process (devsrvr) consumed excess memory, which resulted in OOM conditions.
## PAN-141750
Fixed an issue in Panorama where the GlobalProtect gateway configuration in the template stack for mobile users was not able to be overwritten.
## PAN-141495
Fixed an issue where the following settings were not pushed from Panorama to the firewall: **Minimum Length**, **Failed Attempts**, and **Lockout Time** (**Template > Device > Setup > Management**).
## PAN-140565
Added zram support to PAN-OS platforms.
## PAN-140443
Fixed an issue where period Windows Management Instrumentation (WMI) probing did not work until a process (useridd) was restarted.
## PAN-138869
Fixed an issue where some threat logs in Panorama were not displayed when filtered by Threat-ID name.
## PAN-136635
Fixed an issue where HIP-related objects were missing transformation logic, which caused commit failures.
## PAN-114642
Fixed an issue where firewall logs incorrectly include the end-user IP address in GTP message logs when you configure PAA IE with IPv4 and IPv6 dual stack in the Create Session Response message.
## PAN-113093
Fixed an intermittent issue where, when the DNS Security cloud was not reachable, DNS responses had bad UDP checksums.
## PAN-111553
Fixed an issue on the Panorama management server where the "Include Device and Network Templates" setting (*Commit>Push to Devices>Edit Selections" or "Commit>Commit and Push>Edit Selections*) was disabled by default and caused your push attempts to fail. With this fix, your push will "Include Device and Network Templates" by default.
@@ -0,0 +1,45 @@
---
type: Addressed
product: PAN-OS
version: 9.1.11-h2
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-178814
Fixed an issue where autocommits failed when upgrading from a PAN-OS 8.1 release to a PAN-OS 9.1 release due to large configurations with a high number of policies with reference to IP addresses.
## PAN-176661
Fixed an issue in Simple Certificate Enrollment Protocol (SCEP) ([CVE-2021-3060](https://security.paloaltonetworks.com/CVE-2021-3060)).
## PAN-176655
A fix was made to address an OS command injection vulnerability in the PAN-OS CLI that enabled an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges ([CVE-2021-3061](https://security.paloaltonetworks.com/CVE-2021-3061)).
## PAN-158334
A fix was made to address an OS command injection vulnerability in the PAN-OS CLI that enabled an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges ([CVE-2021-3061](https://security.paloaltonetworks.com/CVE-2021-3061)).
## PAN-176653
A fix was made to address an OS command injection vulnerability in the PAN-OS web interface that enabled an authenticated administrator with permissions to use XML API to execute arbitrary OS commands to escalate privileges ([CVE-2021-3058](https://security.paloaltonetworks.com/CVE-2021-3058)).
## PAN-176618
A fix was made to address an OS command injection vulnerability in PAN-OS that existed when performing dynamic updates ([CVE-2021-3059](https://security.paloaltonetworks.com/CVE-2021-3059)).
## PAN-176461
Fixed an issue where a process (mdb) stopped responding after downgrading from a PAN-OS 9.1 release to an earlier release due to discrepancies in the mongodb process version.
To utilize this fix, first install a PAN-OS 9.0 release on the web interface, and then, prior to reboot, run the following CLI command: debug mongo clear instance mdb. Running this command removes any historical operational data (such as rule hit counts, monitoring data, and so on) collected on Panorama.
## PAN-176131
Fixed an issue where the Simple Network Management Protocol (SNMP) object identifier (OID) for panSessionCps did not show the correct session count.
## PAN-169173
Fixed an issue where, if you continuously performed partial commits of a configuration with a high number of Dynamic Address Groups, Panorama became unresponsive and commits were slower than expected.
@@ -0,0 +1,11 @@
---
type: Addressed
product: PAN-OS
version: 9.1.11-h3
source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
Fixed a Denial-of-Service (DoS) vulnerability in the GlobalProtect portal and gateway ([CVE-2021-3063](https://security.paloaltonetworks.com/CVE-2021-3063)).
@@ -0,0 +1,15 @@
---
type: Addressed
product: PAN-OS
version: 9.1.11-h4
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-202450
Fixed an issue where the device-client-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
## PAN-198372
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
@@ -0,0 +1,15 @@
---
type: Addressed
product: PAN-OS
version: 9.1.11-h5
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-237935
Extended the offline PAN-DB, Panorama, and WildFire certificates which were previously set to expire on September 2, 2024.
## PAN-215576
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
@@ -0,0 +1,467 @@
---
type: Addressed
product: PAN-OS
version: 9.1.11
source: common-crawl
crawl: CC-MAIN-2026-12
---
## WF500-5509
```caveat
WF-500 appliance only
```
Fixed an issue where cloud inquiries were logged under the **SD-WAN** subtype.
## PAN-174448
Fixed an issue where Zero-Touch Provisioning (ZTP) configuration wasn't removed after disabling it, which resulted in predefined configurations to be loaded after a reboot.
## PAN-174326
A fix was made to address an OS command injection vulnerability in the PAN-OS web interface that enabled an authenticated administrator to execute arbitrary OS commands to escalate privileges ([CVE-2021-3050](https://security.paloaltonetworks.com/CVE-2021-3050)).
## PAN-173848
Fixed an issue where DNS Security web service was not reachable and retransmission did not occur.
## PAN-172490
Fixed an issue on firewalls in a high availability (HA) configuration where HA-2 links continuously flapped on HSCI interfaces after upgrading to PAN-OS 8.1.19.
## PAN-172464
Fixed an issue where unicast DHCP discover or request packets were silently dropped.
## PAN-171290
Fixed an issue where Panorama deployed in Google Cloud Platform (GCP) failed to the renew management server DHCP IP.
## PAN-171174
Console debug output was enhanced to address issues that led to a loss of SSH and web interface access.
## PAN-170936
Fixed an issue where the firewall egressed offloaded frames out of order after an explicit commit (**Commit** on the firewall or **Commit All Changes** on Panorama) or an implicit comment such as an Antivirus update, Dynamic Update, or WildFire update.
**Note** This issue persists for a network-related configuration and commit.
## PAN-170825
Fixed an issue where, when a partial **Preview Change** job failed, a process (configd) stopped responding.
## PAN-170740
Fixed an issue with the google-docs-uploading application that occurred if a Security policy rule was applied to a Security profile and traffic was decrypted.
## PAN-170314
Fixed an issue where PAN-DB URL cloud updates failed because a process (devsrvr) did not fetch serial numbers, which prevented the PAN_DB URL cloud from connecting after first deployment.
## PAN-170103
Fixed an issue where a process (ikemgr) stopped responding while making configuration changes. This issue occurred if Site-to-Site IPSec was using certification-based authentication.
## PAN-169793
Fixed an issue where using cookies to authenticate MacOS users didn't work due to the client agent not providing the phpsessionid set from the sent GlobalProtect messages during the connection. As a result, the firewall was unable to find and include the portal authentication cookie in the response message.
## PAN-169197
Fixed a rare issue where generating a tech support file caused the useridd process to stop responding.
## PAN-169064
Fixed an issue where the management CPU remained at 100% due to a large number of configured User-ID agents.
## PAN-168921
Fixed an issue in an HA active/active configuration where traffic with complete packets showed up as incomplete and were disconnected due to a non-session owner device closing the session prematurely.
## PAN-167989
Fixed a timing issue between downloading and installing threads that occurred when Panorama pushed content updates and the firewall fetched content updates simultaneously.
## PAN-167872
Fixed an issue related to a process (all_pktproc) that occurred in long-lived sessions that spanned two content upgrades.
## PAN-167858
Fixed an issue where a DNS Security inspection identified a TCP DNS request that had two requests in one segment as a malformed packet and dropped the packet.
## PAN-167805
Fixed an intermittent issue where traffic ingressing through a VPN tunnel failed to match predict session, which resulted in child sessions failing.
## PAN-167637
Fixed an issue where users connecting to the US East gateway encountered a delay in DNS responses.
## PAN-167266
Fixed an issue on multi-dataplane firewalls with high CPU use on dataplane 0 that caused an internal loop of forward/host sessions on the firewall.
## PAN-167099
Fixed a configuration management issue that resulted in a process (ikemgr) failing to recognize changes in subsequent commits.
## PAN-166836
Fixed an issue where session failed due to resource unavailability.
## PAN-166572
Fixed an issue where a process (configd) restarted when browsing policies on Panorama.
## PAN-166557
Fixed an issue where ElasticSearch didn't register to the masterd process when setting up a new Log Collector configuration.
## PAN-166081
Fixed an issue where role based admin users with tag disabled were unable to view applications under **Objects** > **Application**.
## PAN-165913
Fixed an issue on United States GlobalProtect portals where HTTP health checks failed and no authentication events occurred for about 10 minutes.
## PAN-165843
Fixed an issue on the firewalls where generating SCEP Certificates did not work when the value of a Relative Distinguished Name (RDN) in the subject string contained a space.
## PAN-165661
Fixed an issue in an HA active/active configuration where an administrative shutdown message was not sent to the BGP peer when the firewall went into a suspended state, which delayed convergence.
## PAN-165660
Fixed an issue where, in scenarios with Fragmented Session Initiation Protocol (SIP), where the first packet arrived out of order, bypassing App-ID and Content and Threat Detection (CTD). With this fix, the out-of-order packet is transmitted after it has been queued and processed by App-ID and CTD.
## PAN-165179
Fixed an issue where Panorama missed address group objects during a template configuration due to Panorama not sending the required strings for a query.
## PAN-165120
Fixed an issue where the Application Command Center (ACC) did not display data when the Device Group was set with **VSYS** in its name.
## PAN-165025
Fixed an issue where, when default interzone and intrazone Security policy rules were overwritten, the rules did not display hit counts.
## PAN-164422
```caveat
VM-Series firewalls only
```
A fix was made to address improper access control that enabled an attacker with authenticated access to GlobalProtect portals and GlobalProtect gateways to connect to the EC2 instance metadata endpoint for VM-Series firewalls hosted on Amazon Web Services (AWS) ([CVE-2021-3062](https://security.paloaltonetworks.com/CVE-2021-3062)).
## PAN-164431
```caveat
VM-Series firewalls only
```
Fixed an issue where the firewall rebooted into maintenance mode after installing a capacity license in FIPS-CC mode.
## PAN-164429
Fixed an issue where the Panorama web interface displayed an unavailable setting.
## PAN-164402
A CLI command was added to immediately disable or enable restarting the syslog-ng connection during an FQDN refresh IP address change.
## PAN-163800
Fixed an intermittent issue where the presence of an Anti-Spyware profile in a Security policy rule that matched DNS traffic caused DNS responses to be malformed in transit.
## PAN-163695
Fixed an issue where multiple dataplane process (all_task, flow_mgmt, flow_ctrl, and pktlog_forwarding) stopped responding and caused the dataplane to restart. This issue occurred when the firewall received unexpected packets during an SSL handshake when SSL inbound inspection was configured.
## PAN-162884
Fixed a rare issue where an external dynamic list (EDL) entry became corrupt due to an erroneous string being inserted while generating the list.
## PAN-161618
Fixed an issue where the commit time increased after upgrading from PAN-OS 9.0 to PAN-OS 9.1.
## PAN-161289
Fixed an issue where predict session didn't update the associated rules when Security policies shifted after a commit.
## PAN-161218
The following CLI commands were added to enable the customer to set the dataplane utilization limit: debug dataplane show ctd wildfire max -debug dataplane set ctd wildfire max <0-5000> The default setting is the recommended value of 500; a value of 0 removes dataplane CTD limits.
## PAN-161208
Fixed an issue where the **Service Route Configuration** (**Device > Setup > Services > Service Route Configuration**) was unchangeable when the web interface language was set to a language other than English.
## PAN-160831
Fixed an intermittent issue where importing a new firewalls configuration into Panorama failed due to conflicting virtual system (vsys) names, even when the **Device Group Name Prefix** was used to make the name unique.
## PAN-160544
Fixed an issue where a user was able to clone, edit, and commit a configuration that had been locked by another user.
## PAN-160254
Fixed a memory leak issue related to a process (reportd) where memory was not freed after an ElasticSearch request.
## PAN-160253
Fixed an issue where only one medium-severity system log was generated if either the EDL file wasn't updated at the remote end or the downloaded file wasn't a text file.
## PAN-160150
Fixed an intermittent issue where, when a race condition occurred, a process (rasmgr) stopped responding, which caused GlobalProtect user authentication failure.
## PAN-159954
Fixed an issue where scheduled configuration bundle exports via Secure Copy (SCP) displayed following error message in the system log: Failed to export config bundle after already displaying a Success message in the log.
## PAN-159936
Fixed an issue where BGP routing stopped advertising a redistributed route when a similar new redistributed route was configured.
## PAN-159922
Fixed an issue where, when the DNS Security feature was enabled, Linux clients experienced a delay in resolving domain names if the clients simultaneously attempted A and AAAA resolution.
## PAN-159700
Fixed an issue where importing PAN-TRAPS.my to the SNMP manager caused the following error to display: Registration failed, registration failed, because there are unreferenced definition names in the MIB file.
## PAN-159536
Fixed an issue where, when the CLI command oscp-exclude-nonce-yes was enabled for a certificate profile, a nonce value was still included in the Online Certificate Status Protocol (OCSP) request.
## PAN-159435
Fixed an issue where SD-WAN routes weren't withdrawn after a bootup when all SD-WAN tunnels were down.
## PAN-159293
Fixed an issue where the Certification Revocation List (CRL) in Distinguished Encoding Rules (DER) format incorrectly returned errors despite being able to successfully pull the CRL to verify that the syslog server certificate was still valid.
## PAN-159122
Fixed an issue where, when a new tag was created, a custom application with the same name was also created.
## PAN-158958
Fixed an issue where the debug sslmgr view crl command failed when ampersand (&) character was included in the URL for the certificate revocation list (CRL).
## PAN-158654
Fixed a memory leak issue in the management server process.
## PAN-158649
Fixed an issue where commits to the Prisma Access Remote networks from Panorama were failing when the management server on the cloud firewall failed to exit cleanly and reported the following error: pan_check_cert_status(pan_crl_ocsp.c:284): sysd write failed (TIMEOUT)
## PAN-158450
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where, for SNMPv2-MIB:sysServices, snmpwalk returned the following error message: No Such Instance currently exists at this OID.
## PAN-158439
Fixed a memory leak on the management server process on Firewall.
## PAN-158372
Fixed a buffer overflow issue related to the useridd process.
## PAN-158337
Fixed an issue where warnings displayed during a commit or validate when BGP peers used in an import/export rule were disabled.
## PAN-158043
Fixed an issue where the firewall dropped packets due to a race condition.
## PAN-157938
```caveat
VM-Series firewalls with multiple DHCP interfaces only
```
Fixed an issue where leases renewed more quickly than needed, which caused unnecessary SPF recalculations.
## PAN-157835
Fixed an issue where DNS Proxy rules that contained uppercase characters were not normalized to lowercase, which prevented the rules from being matched.
## PAN-157725
Fixed an issue where, when decryption was enabled, the following error was displayed: Cannot contact reCAPTCHA. Check your connection and try again.
## PAN-157715
Fixed an intermittent issue where SMB file transfer operations failed due to packet drops that were caused by the Content and Threat Detection (CTD) queue filling up quickly. This fix introduces a new CLI command which, when enabled, prevents these failures: set system setting ctd nonblocking-pattern-match-qsizecheck [enable|disable].
## PAN-157710
Fixed an issue where admin users with custom roles were unable to create VLANs.
## PAN-157620
```caveat
VM-Series firewalls deployed in Amazon Web Services (AWS) instance types M5 and C5 only
```
Fixed an issue where a Panorama Virtual Appliance in an HA configuration entered a suspended state due to a virtual machine (VM) memory size mismatch.
## PAN-157518
Fixed an issue where using tags to target a device group in a Security policy rule did not work, and the rule was displayed in all device groups (**Preview Rules**).
## PAN-157459
Fixed an issue where, after updating an address in an Address Group, a commit did not update GlobalProtect split tunnel access routes.
## PAN-157089
```caveat
Panorama appliances in Log Collector mode only
```
The following CLI command was added to disable No valid device certificate found messages in the system log: debug skip-cert-renewal-check-syslog yes.
## PAN-157027
Fixed an issue where, when stateless GTP-U traffic hit a multi-dataplane firewall, an inter-dataplane fragmentation loop occurred, which caused high dataplane resource usage.
## PAN-157026
Fixed an issue where the firewall did not display unified logs.
## PAN-156766
Fixed an issue where, after upgrading to PAN-OS 9.1.5, VM-Series firewalls in HA configurations went into a non-functional state due to a virtual machine (VM) license mismatch.
## PAN-156482
Fixed a packet buffer issue where HTTP2 packets were held for category lookup and the HTTP request was across multiple packets.
## PAN-156393
Fixed an issue where NetFlow updates were sent without honoring the configured active timeout value.
## PAN-156388
Fixed an issue where a process (useridd) stopped responding while attempting to remove all HIP reports on the disk.
## PAN-155563
Fixed an intermittent issue where the Panorama Cloud Services plugin reported the following error for its Cortex Data Lake status: Failed to validate server certificate for endpoint api.paloaltonetworks.com.
## PAN-154905
```caveat
Panorama appliances on PAN-OS 10.0 releases only
```
Fixed an issue with Security policy rule configuration where, in the **Source** and **Destination** tabs, the **Query Traffic** setting was not available for Address Groups.
## PAN-154876
Fixed an issue where the web interface did not display **Release Date** when updating the dynamic updates manually.
## PAN-153382
Fixed an issue where the per-minute resource monitor was three minutes behind.
## PAN-153308
Fixed an issue that caused the mouse cursor to remove focus from the search bar when hovering over a hyperlink inside of a cell menu (e.g., source zone, source address, destination zone, destination address, etc.).
## PAN-153113
Fixed an issue where the GlobalProtect gateway failed with the following error message: gateway does not exist.
## PAN-151469
Fixed an issue where packets were dropped unexpectedly due to errors parsing the IP version field.
## PAN-149911
Fixed an issue where URL filtering logs for credential phishing displayed a slash character (/) in the URL field.
## PAN-149853
Fixed an issue on Panorama where the **loc** attribute was not set as **shared** when creating dynamic-address-group-specific configurations during a Panorama commit.
## PAN-147684
Fixed an issue where a daemon (ikemgr) repeatedly restarted, which resulted in the firewall rebooting.
## PAN-143426
Fixed a memory leak issue where a process (devsrvr) restarted due to the memory limit being exceeded.
## PAN-141494
Fixed an issue with the group-mapping mode credential detection feature that failed to block users when logging in using corporate credentials.
## PAN-138859
Fixed an issue on Panorama appliances where exporting or pushing a device configuration bundle to PA-5000, PA-5200, PA-7000, or PA-7000b series firewalls failed with the following error message: Config bundle is too large to be exported to device.
## PAN-138727
A fix was made to address a time-of-check to time-of-use (TOCTOU) race condition in the PAN-OS web interface that enabled an authenticated administrator with permission to upload plugins to execute arbitrary code with root user privileges ([CVE-2021-3054](https://security.paloaltonetworks.com/CVE-2021-3054)).
## PAN-136505
```caveat
PA-5200 Series and PA-7000 Series firewalls with Log Processing Cards (LPCs) only
```
Fixed an issue where the log quota (**Logging and Reporting Settings > Session Log Storage > Session Log Quota)** exceeded 100%.
## PAN-134390
Fixed an issue where commits didn't complete due to a race condition in the log receiver.
## PAN-133782
Fixed an issue where Panorama was not accessible via the web interface due to insufficient available disk space in the opt/mongobuffer partition, which caused the mongodb process to stop responding.
## PAN-130003
Fixed an issue where the show logging-status CLI command did not display any output on the firewall even though the firewall was connected to Panorama and was successfully forwarding logs.
## PAN-124956
```caveat
VM-Series firewalls only
```
Fixed an issue where packet buffer protection was not supported.
## PAN-118846
Fixed an issue where you were unable to locally override a user-group-mapping setting pushed from Panorama.
## PAN-116515
Fixed an issue where IKE Gateway configurations with different crypto profiles on the same IP address with dynamic peers failed with the following error message: IKEv1 gateway should use the same crypto profiles configured on the same interface or local IP address.
With this fix, you are able to configure IKE Gateways with different crypto profiles on the same IP address with dynamic peers when IKEv1 auto mode is applied.
## PAN-108197
Fixed an issue in a multi-tenant deployment where, when a user-made configuration changed, the changes were unable to be committed, and the web interface displayed the following error message: No pending change to commit. With this fix, users with multiple access domains will now be able to see plugin information.
@@ -0,0 +1,15 @@
---
type: Addressed
product: PAN-OS
version: 9.1.12-h3
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-184592
A fix was made to address a remote code execution vulnerability in Elasticsearch included with Panorama management servers known as Log4Shell ([CVE-2021-44228](https://security.paloaltonetworks.com/CVE-2021-44228)).
## PAN-183767
Fixed an issue where downloading Dynamic Updates files failed when connected to the static update server at us-static.updates.paloaltonetworks.com.
@@ -0,0 +1,11 @@
---
type: Addressed
product: PAN-OS
version: 9.1.12-h4
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-184445
Fixed an issue where, after upgrading Panorama and enabling **Share Unused Address and Service Objects with Devices**, address objects using tags to dynamic address groups were removed after a full commit.
@@ -0,0 +1,15 @@
---
type: Addressed
product: PAN-OS
version: 9.1.12-h7
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-237935
Extended the offline PAN-DB, Panorama, and WildFire certificates which were previously set to expire on September 2, 2024.
## PAN-215576
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
@@ -0,0 +1,422 @@
---
type: Addressed
product: PAN-OS
version: 9.1.12
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-181076
Fixed an issue where commit failures occurred when an External Dynamic List (EDL) that contained many IP addresses was used in a Security policy.
## PAN-179750
A CLI command was added to set the virtual memory limit in dedicated log collectors.
## PAN-179581
Fixed an issue on firewalls in high availability configurations where a process (brdagent) stopped responding on a suspended active peer, which caused the suspended firewall to continue sending traffic.
## PAN-179356
```caveat
5200-Series firewalls only
```
Fixed an issue where configuration commits failed due to the dataplane running out of memory in the policy cache.
## PAN-178953
Fixed an issue with the GlobalProtect Clientless VPN where, when an application sent a negative max age value on a cookie, part of the cookie was retained by PAN-OS and used for the subsequent connection on the user session.
## PAN-178363
Fixed an issue where a process (mgmtsrvr) wasn't restarted after the virtual memory limit was exceeded.
## PAN-176862
```caveat
VM-Series firewalls only
```
Fixed an issue where the firewall didn't attempt to connect to a log collector when the management IP address used DHCP.
## PAN-176461
Fixed an issue where a process (mdb) stopped responding after downgrading from a PAN-OS 9.1 release to an earlier release due to discrepancies in the mongodb process version.
**Note**: To utilize this fix, first install a PAN-OS 9.0 release on the web interface, and then, prior to reboot, run the following CLI command: debug mongo clear instance mdb.
## PAN-176364
Fixed an issue where multiple operations (such as a commit or dynamic updates) failed due to a race condition in the cryptod fallback mechanism.
## PAN-176131
Fixed an issue where the Simple Network Management Protocol (SNMP) object identifier (OID) for panSessionCps did not show the correct session count.
## PAN-176032
Fixed an issue where a process (authd) process stopped responding, which caused authentication to fail.
## PAN-175934
Fixed an issue where packed-based zone protection settings (such as Strict IP Address Check) were not applied to return traffic.
## PAN-175652
Fixed an issue where SSL decryption failed for websites when they were accessed from Google Chrome version 92 or higher.
## PAN-175307
Fixed an issue where Panorama commits were slower than expected and the configd process stopped responding due to a memory leak.
## PAN-174894
Fixed an issue where, when the time-to-live (TTL) value for symmetric MAC entries weren't updated to other dataplanes and HA peers, timeouts occurred for traffic using policy-based forwarding (PBF) with symmetric returns.
## PAN-174886
Fixed an issue where scheduled customer reports displayed as empty when the configured destination was an address group.
## PAN-174864
Fixed an issue on the Panorama interface where **Deploying Master Key** to low-end devices resulted in a **Failed to communicate** message, even when the new master key was updated on the end device. This issue occurred because a master key deployment had insufficient time to process due to a connection timeout.
## PAN-174161
Fixed an issue in Panorama that occurred when attempting to **disable override** on an object from a child device group did not work after cloning and renaming the object.
## PAN-174055
Fixed an issue where SNMP readings reported as 0 for dataplane interface packet statistics for Amazon Web Services (AWS) m5n.4xlarge instance types. This issue occurred because the physical port counters read from MAC addresses were reported as 0.
## PAN-173978
Fixed an issue where the Elasticsearch process continuously restarted if zero-length files were present.
## PAN-173893
Fixed a memory leak issue related to the (useridd) process that occurred when group mapping is enabled.
## PAN-173753
Fixed an issue where a bar or point on a **Network Monitor** graph had to be clicked more than once to properly redirect to the corresponding ACC report.
## PAN-173545
Fixed an issue where exporting a device summary to CSV failed and displayed the following error message: Error while exporting.
## PAN-173509
Fixed an issue where Superuser administrators with read-only privileges (**Device > Administrators and Panorama > Administrators**) were unable to view the hardware ACL blocking setting and duration in the CLI using the following commands:
- show system setting hardware-acl-blocking-enable
- show system setting hardware-acl-blocking-duration
## PAN-173157
Fixed an issue with the HA1 monitor hold timer where the configured value was not assigned to the HA1 backup interface, which used the default hold timer (3000 milliseconds), which resulted in failover events taking longer than expected.
## PAN-173076
```caveat
Panorama appliances in FIPS mode only
```
Fixed an issue where the FIPS Panorama / FIPS firewall schema didn't prune non-FIPS options from the GlobalProtect Clientless VPN.
## PAN-172834
Fixed a memory leak issue related to the useridd process that occurred when processing IP-address-to-username mappings.
## PAN-172783
Fixed an issue on an HA active/passive configuration where old GPRS tunneling protoc0l (GTP-U) tunnel sessions did not sync to the passive firewall during some upgrades, such as upgrading from a PAN-OS 8.1 release version to a 9.0 release version or upgrading from a 9.0 release version to a 9.1 release version.
## PAN-172775
Fixed an issue in Panorama where the configd process stopped responding due to a memory issue with memcpy bson_append.
## PAN-172748
```caveat
VM-Series firewalls only
```
Fixed an issue where a process (all_task) stopped responding.
## PAN-172396
Fixed a memory leak issue related to the useridd process.
## PAN-172324
Fixed an issue on the Panorama web interface where custom vulnerability signature IDs weren't populated in the drop-down when creating a custom combination signature.
## PAN-172316
Fixed an issue where the internal interface flow control that caused the monitoring process to incorrectly determine the interface to be malfunctioning.
## PAN-172200
Fixed an issue where a process (configd) restarted due to memory corruption in the show dynamic-address-group CLI command during commits, commit and push operations, and high availability Panorama syncs.
## PAN-171696
```caveat
PA-800 and PA-400 Series firewalls and PA-220 firewalls only
```
Fixed an issue where the management plane CPU was incorrectly reported to be high.
## PAN-171367
Fixed an issue in active/active HA configuration where session disconnected during an upgrade from a PAN-OS 9.0 release to a PAN-OS 9.1 release.
## PAN-171203
Fixed an issue in an HA configuration where, when one firewall was active and its peer was in a suspended state, the suspended firewall continued to send traffic, which triggered the detection of duplicate MAC addresses.
## PAN-171159
Fixed a memory leak on the configd process on Panorama caused during multi-clone operations for rules.
## PAN-170936
Fixed an issue where the firewall egressed offloaded frames out of order after an explicit commit (**Commit** on the firewall or **Commit All Changes** on Panorama) or an implicit comment such as an Antivirus update, Dynamic Update, or WildFire update.
**Note** This issue persists for a network-related configuration and commit.
## PAN-170595
Fixed an issue with Content and Threat Detection where traffic patterns created a bus error, which caused the all_pktproc process to stop responding and the dataplane to restart.
## PAN-170466
Fixed an memory reference issue related to the devsrvr process that caused the process to stop responding.
## PAN-169899
Fixed an issue on firewalls with offload processors where the ECMP forced symmetric return feature didn't work for CRE traffic after the session was offloaded.
## PAN-169347
Fixed an issue where a process (authd) stopped responding due to an invalid null pointer.
## PAN-169300
Debug logs were added to troubleshoot WildFire submission issues.
## PAN-169173
Fixed an issue where, if you continuously performed partial commits of a configuration with a high number of Dynamic Address Groups, Panorama became unresponsive and commits were slower than expected.
## PAN-168261
Fixed a cosmetic issue where the WildFire submission log displayed the sha256 of the original email link.
## PAN-168189
Fixed an issue where, even when there was active multicast traffic, the firewall sent Protocol Independent Multicast (PIM) prune messages.
## PAN-167560
Fixed an issue where the Panorama appliance didn't return inherited device group locations pertaining to Security policies for REST API queries.
## PAN-167329
Fixed an issue where Zero Touch Provisioning (ZTP) flow did not complete.
## PAN-167115
Fixed an issue where, after upgrading to 10.0.3, admin sessions on Panorama were not logged out after the idle timeout expired.
## PAN-167087
Fixed an issue where the focus was not set on the free text field when requesting a token code on the Authentication Portal.
## PAN-166686
Fixed an issue where EDNS responses dropped when the original request was DNS.
## PAN-166202
Fixed an issue with an extra character in HTTP Strict Transport Security (HSTS) regression tests when accessing the GlobalProtect gateway.
## PAN-166180
Fixed an issue with snmpv3 trap not processed by snmptrap receiver after firewall reboot.
## PAN-166091
Fixed an issue where the firewall dropped policy-based forwarding (PBF) keepalive responses.
## PAN-165433
Fixed an intermittent issue where Cortex Data Lake failed to reconnect after a disconnect if a management IP address used for logging had an IP address assignment type of DHCP.
## PAN-165147
Fixed an issue where, when there was a high volume of traffic for sessions with **Application Block Pages** enabled, other regular packets were dropped.
## PAN-162374
Fixed an issue where the firewall rebooted unexpectedly and displayed the following message: Reboot SYSTEM REBOOT Masterd Initiated.
## PAN-162174
Fixed an issue where, when the firewall received a configuration from Panorama with no URL category, it was automatically configured as **Any**.
## PAN-161964
Fixed an issue where email header from fields in threat logs were truncated due to line folding in the original message.
## PAN-161940
Fixed an issue where the firewall did not honor the peer RX interval timeout in a Bidirectional Forwarding Detection (BFD) INIT state.
## PAN-161726
Fixed an issue where the show high-availability all output incorrectly displayed the VM-Series firewall license type on physical firewalls.
## PAN-161496
Fixed an issue when calculating the incremental checksum after a post-NAT translation where the arguments to pan_in_cksm32_diff overflowed the 32-bit integer.
## PAN-161031
Fixed an issue where authentication via LDAP server failed in FIPS-CC mode when the LDAP server profile was configured with the root certificate chain and **Verify server certificate for SSL sessions** options enabled.
## PAN-160708
Fixed an issue where the dataplane restarted after configuring a **deny_all** policy.
## PAN-158931
Fixed an issue where the email header subject field in the threat logs were truncated due to line folding in the original message.
## PAN-158753
```caveat
Panorama virtual appliances in Legacy mode only
```
Fixed an issue where GlobalProtect logs were not forwarded to the external syslog server over TCP.
## PAN-158056
Fixed an issue where DDNS updates generated contradictory system logs, the first displaying that the update failed with critical severity and the second displaying that the update was successful.
## PAN-157365
```caveat
PA-7050 firewalls only
```
Fixed an issue where a process (all_pktproc) stopped responding after an upgrade.
## PAN-156478
Fixed an issue where a process (allpktproc) restarted while processing SMTP traffic.
## PAN-155448
Fixed an issue where credential detection didn't work in IP address-to-username mapping mode because the firewall compared the unnormalized IP-address-to-username mapping format to the normalized username extracted from the payload where the username and password were submitted.
## PAN-154305
Fixed an issue where a process (mgmtsrvr) stopped responding when a license fetch operation was performed.
## PAN-153527
Fixed an issue where DNS security wasn't triggered when the DNS Security profile was incorrectly internally duplicated to a null DNS Security profile.
## PAN-151264
Fixed an issue where using the ampersand (&) character in URLs submitted via XML API caused an error.
## PAN-150848
Fixed an issue where the firewall dropped TCP FIN traffic due to the server-to-client FIN traffic being out of order.
## PAN-150445
Fixed an issue where the firewall did not translate IP addresses in Layer 7 payloads as per NAT translation for Oracle Application Server traffic.
## PAN-149314
Fixed an issue where lookup of a security rule with a custom URL category on a multi-virtual system (vsys) failed when vsys<id>+ was not in the beginning the category name.
## PAN-148554
Fixed an issue where the user was able to bypass URL credential phishing by changing the username from lower case to upper case.
## PAN-147256
```caveat
Firewalls in HA configurations only
```
Fixed an issue where connections to the SafeNet hardware security module (HSM) were lost after upgrading to a new major PAN-OS release.
## PAN-147228
Fixed an issue where an application's domain name didn't resolve if the cache was disabled on the DNS Proxy object being used in the GlobalProtect Clientless VPN.
## PAN-145833
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where the firewall stopped recording dataplane diagnostic data in dp-monitor.log after a few hours of uptime.
## PAN-144340
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where some slots in the firewall did not get registered as up in a process (useridd), which caused the process to ignore IP address-to-user mappings to those slots.
## PAN-141454
Fixed an issue where the output of the CLI command show running resource-monitor ingress-backlogs displayed an incorrect total utilization value.
## PAN-141037
Fixed an issue where Windows-1252 encoded filenames triggered an Unknown Binary File (52081) type signature.
## PAN-129147
Fixed an intermittent issue on the web interface where new threat IDs did not appear under **Exception** settings (**Objects > Security Profiles > Anti-Spyware > Exceptions** or **Objects > Security Profiles > Vulnerability Protection > Exceptions**).
## PAN-128590
Fixed an issue where connection collisions occurred between BGP peers.
## PAN-123935
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where packets with a specific MAC address were misinterpreted as 802.1QA tunneled packets, which resulted in incorrect VLAN tags that caused the packets to be dropped.
## PAN-119198
Fixed an issue where ECMP strict-source-path did not work with IPSec.
## PAN-113046
```caveat
PA-5200 Series firewalls only
```
Fixed an issue where a process (*brdagent*) stopped responding, which caused the management plane to stop responding.
## PAN-112674
Fixed an issue where an escape ( \ ) character was added to HTTP logs when a log contained a comma.
@@ -0,0 +1,19 @@
---
type: Addressed
product: PAN-OS
version: 9.1.13-h1
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-187151
Fixed an issue where tunnel-monitoring interface was incorrectly shown as up instead of down.
## PAN-186937
Fixed an issue where the firewall dropped packets decrypted using the SSL Decryption feature and Encapsulating Security Payload (ESP) IPSec packets that originated from the same firewall. This occurred when **Strict IP Address Check** was enabled in the zone protection profile (**Packet Based Attack** > **IP Drop**) and the packet's source IP address was the same as the egress interface address.
## PAN-171104
Fixed an issue where a race-condition check returned a false negative, which caused a process (all_task) to stop responding and generate a core file.
@@ -0,0 +1,15 @@
---
type: Addressed
product: PAN-OS
version: 9.1.13-h3
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-190175
A fix was made to address an OpenSSL infinite loop vulnerability in the PAN-OS software ([CVE-2022-0778](https://security.paloaltonetworks.com/CVE-2022-0778)).
## PAN-190223
A fix was made to address an OpenSSL infinite loop vulnerability in the PAN-OS software ([CVE-2022-0778](https://security.paloaltonetworks.com/CVE-2022-0778)).
@@ -0,0 +1,19 @@
---
type: Addressed
product: PAN-OS
version: 9.1.13-h4
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-202450
Fixed an issue where the device-client-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
## PAN-198372
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
## PAN-193004
Fixed an issue where /opt/pancfg partition utilization reached 100%, which caused access to the Panorama web interface to fail.
@@ -0,0 +1,31 @@
---
type: Addressed
product: PAN-OS
version: 9.1.14-h1
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-194395
Fixed an issue where the firewall dropped all decrypted outbound (SSL Forward Proxy) HTTP/2 traffic and cleartext HTTP/2 traffic after an upgrade to PAN-OS 9.1.14, which caused websites that used HTTP/2 to become inaccessible.
## PAN-191463
Fixed an issue where the firewall did not handle packets at Fastpath when the interface pointer was null.
## PAN-188036
Fixed an issue where SIP TCP sequence numbers were calculated incorrectly when SIP cleartext proxy was disabled.
## PAN-182244
Fixed an issue where Session Initiation Protocol (SIP) REGISTER packets did not get transmitted when application-level gateway (ALG) and SIP Proxy were enabled, which caused a SIP-registration issue in environments where TCP retransmission occurred.
## PAN-174347
Fixed an issue where sequence numbers were calculated incorrectly for traffic that was subject to SIP ALG when SIP TCP Clear Text Proxy was disabled.
## PAN-89479
Fixed an issue in SIP over TCP and HTTP header insertion features where PAN-OS built-in clear text proxy inserted extra data into the TCP stream when the initial data packets were received out of order.
@@ -0,0 +1,31 @@
---
type: Addressed
product: PAN-OS
version: 9.1.14-h4
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-195628
Fixed an issue that caused the pan_task process to miss heartbeats and stop responding.
## PAN-195482
Fixed an issue on multi-dataplane platforms where IPSec tunnels continuously flapped.
## PAN-194456
Fixed an issue where the sysd process disconnected from the pan_dha process after a high availability (HA) failover or reboot.
## PAN-192999
A fix was made to address [CVE-2022-0028](https://security.paloaltonetworks.com/CVE-2022-0028).
## PAN-192726
Fixed an issue where the firewall dropped TCP traffic inside IPSec tunnels.
## PAN-189114
Fixed an issue where the dataplane went down, which caused an HA failover.
@@ -0,0 +1,15 @@
---
type: Addressed
product: PAN-OS
version: 9.1.14-h7
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-202450
Fixed an issue where the device-client-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
## PAN-198372
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
@@ -0,0 +1,15 @@
---
type: Addressed
product: PAN-OS
version: 9.1.14-h8
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-237935
Extended the offline PAN-DB, Panorama, and WildFire certificates which were previously set to expire on September 2, 2024.
## PAN-215576
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
@@ -0,0 +1,171 @@
---
type: Addressed
product: PAN-OS
version: 9.1.14
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-189665
```caveat
FIPS-CC enabled firewalls only
```
Fixed an issue where the firewall was unable to connect to log collectors after an upgrade due to missing cipher suites.
## PAN-189468
Fixed an issue where the firewall onboard packet processor used by the PAN-OS content-inspection (CTD) engine can generate high dataplane resource usage when overwhelmed by a session with an unusually high number of packets. This can result in resource-unavailable messages due to the content inspection queue filling up. Factors related to the likelihood of an occurrence include enablement of content-inspection based features that are configured in such a way that might process thousands of packets in rapid succession (such as SMB file transfers). This can cause poor performance for the affected session and other sessions using the same packet processor. PA-3000 series and VM-Series firewalls are not impacted.
## PAN-189010
Fixed an issue on Panorama where a deadlock in the configd process caused both the web interface and the CLI to be inaccessible.
## PAN-188336
Fixed an issue with the dnsproxyd process that caused the firewall to unexpectedly reboot.
## PAN-187151
Fixed an issue where tunnel-monitoring interface was incorrectly shown as up instead of down.
## PAN-186937
Fixed an issue where the firewall dropped packets decrypted using the SSL Decryption feature and Encapsulating Security Payload (ESP) IPSec packets that originated from the same firewall. This occurred when **Strict IP Address Check** was enabled in the zone protection profile (**Packet Based Attack > IP Drop**) and the packet's source IP address was the same as the egress interface address.
## PAN-185616
Fixed an issue where the firewall sent fewer logs to the system log server than expected. With this fix, the firewall accommodates a larger send queue for syslog forwarding to TCP syslog receivers.
## PAN-184621
Fixed an issue on FIPS-enabled devices where modifying any configuration of an existing GlobalProtect portal failed with the following error message: Operation failed : Malformed request.
## PAN-184068
```caveat
PA-5220 firewalls only
```
Fixed an issue where the firewall generated pause frames, which caused network latency.
## PAN-183826
Fixed an issue where, after clicking **WildFire Analysis Report**, the web interface failed to display the report with the following error message: refused to connect.
## PAN-183788
Fixed an issue with SCEP certificate enrollment where the incorrect Registration Authority (RA) certificate was chosen to encrypt the enrollment request.
## PAN-182173
```caveat
Panorama appliances in HA configurations only
```
Fixed an issue where, when using Prisma Access multitenancy, the passive appliance didn't correctly update the tenant information after the tenant was deleted on the active appliance.
## PAN-181039
Fixed an issue with DNS cache depletion that caused continuous DNS retries.
## PAN-180147
Fixed an issue where the bcm.log and brdagent_stdout.log-<datestamp> files filled up the root disk space.
## PAN-177671
Fixed an issue where, when SIP traffic traversing the firewall was sent with a high Quality of Service (QoS) differentiated service code (DSCP) value, the DSCP value was reset to the default setting (CS0) for the first data packet.
## PAN-177063
Fixed an issue where decrypting large packets introduced congestion during content inspection, which caused processes to stop responding due to missed heartbeats.
## PAN-177133
```caveat
Firewalls in HA configurations only
```
Fixed an issue where the HA1 heartbeat backup flapped with the following error message: Unable to send icmp packet:(errno: 105) No buffer space available.
## PAN-176703
Fixed an issue that occurred after upgrading to a PAN-OS 9.0 or later release where commits to the firewall configuration failed with the following error message: statistics-service is invalid.
## PAN-176437
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where multiple processes stopped responding, which caused the firewall to reboot.
## PAN-175883
Fixed an issue where the following operational mode commands were not reboot persistent:
- set system setting ctd pkt-proc-loop-low <value>
- set system setting ctd pkt-proc-loop-high <value>
- set system setting ctd max-sess-hash-limit <value>
## PAN-175509
Fixed an issue where a deadlock on CONFIG_LOCK caused both the web interface and CLI commands to time out until the mgmtsrvr process was restarted.
## PAN-175161
Fixed an issue where changing SSL connection validation settings for system logs caused the mgmtsrvr process to stop responding.
## PAN-175016
Fixed an issue where PDF summary reports were empty when they were generated by a user in a custom admin role.
## PAN-174998
```caveat
M-200 and M-500 appliances only
```
Fixed a capacity issue that was caused by high operational activity and large configurations. This fix increases the virtual memory limit on the configd process to 32GB.
## PAN-174988
```caveat
PA-220 Series firewalls only
```
Fixed an issue where the `runtime-state` parameter was missing in the CLI command `request high-availability sync-to-remote`.
## PAN-172766
Fixed an issue on Panorama where a commit push to managed firewalls failed with sctp-init is invalid error even though SCTP settings were not configured in the corresponding template.
## PAN-171104
Fixed an issue where a race-condition check returned a false negative, which caused a process (all_task) to stop responding and generate a core file.
## PAN-166368
Fixed an issue on Panorama where long FQDN queries did not resolve due to the character limit being 64 characters.
## PAN-163245
Fixed an issue where a commit-all or push to the firewall from Panorama failed with the following error message: client routed requesting last config in the middle of a commit/validate. Aborting current commit/validate.
## PAN-162047
```caveat
Firewalls in active/passive high availability configurations only
```
Fixed a routing table mis-sync issue where routes were missing on the passive firewall when GRE tunnels with keepalives were configured.
## PAN-152026
Fixed an issue where the session browser did not display results when filtered for IPv6 addresses with more than 31 characters.
## PAN-130172
Fixed an issue where Dynamic User Group lists were missing after disabling group-mapping configurations under that virtual system (vsys).
@@ -0,0 +1,191 @@
---
type: Addressed
product: PAN-OS
version: 9.1.15
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-201872
Fixed an issue where SMB performance caused overall network latency after an upgrade.
## PAN-201136
Fixed an issue where IGMP packets were offloaded with frequent IGMP Join and Leave messages from the client.
## PAN-197859
Fixed an issue where firewalls running LSVPN with tunnel monitoring enabled where, after an upgrade to PAN-OS 9.1.14 or a later PAN-OS release, LSVPN tunnels flapped.
## PAN-195628
Fixed an issue that caused the pan_task process to miss heartbeats and stop responding.
## PAN-195625
Fixed an issue where authd frequently created SSL sessions, which resulted in a out of memory (OOM) condition.
## PAN-194025
Fixed an issue where the ikemgr process stopped responding due to a timing issue, which caused VPN tunnels to go down.
## PAN-193579
Fixed an issue where new logs viewed from the CLI (show log <log_type>) and new syslogs forwarded to a syslog server contained additional, erroneous entries.
## PAN-193132
```caveat
PA-220 firewalls only
```
Fixed an issue where a commit and push from Panorama caused high dataplane CPU utilization.
## PAN-193008
Fixed an issue that caused the processing of incoming packets to take more time than expected, which caused latency-sensitive traffic and applications timeouts.
## PAN-192404
Fixed an issue where ARP broadcasts occurring in the same time interval and network segment as high availability (HA) path monitoring pings triggered an ARP cache request, which prevented the firewall from sending ICMP echo requests to the monitored destination IP address and caused an HA path monitoring failover.
## PAN-192052
Fixed an issue where, when next hop MAC address entries weren't found on the offload processor for active traffic, update messages flooded the firewall, which caused resource contention and traffic disruption.
## PAN-191726
Fixed an issue where an SCP export of the device state from the firewall added single quotes ( ' ) to the filename.
## PAN-191463
Fixed an issue where the firewall did not handle packets at Fastpath when the interface pointer was null.
## PAN-191288
Fixed an issue where the firewall restarted due to a dnsproxy process crash.
## PAN-191269
Fixed an issue where the NAT pool leaked for passive mode FTP predict sessions.
## PAN-189867
Fixed an issue where, when logging in to the GlobalProtect gateway, the authentication cookie was not reused.
## PAN-189861
Fixed an issue on firewalls in HA configurations where intermittent system alerts on the active firewall caused the pan_comm process to restart continuously.
## PAN-189762
Fixed an issue where a predict session didn't match with the traffic when both source NAT and destination NAT were enabled.
## PAN-189414
Fixed an issue where TCP packets were dropped during the first zone transfer when DNS security was enabled.
## PAN-189214
Fixed an issue where, when the Advanced Threat Prevention license was present on a firewall without a Threat Prevention license, the antivirus signature update packages that were normally available to install (**Device > Dynamic Updates**) were not displayed.
## PAN-189114
Fixed an issue where the dataplane went down, which caused a HA failover.
## PAN-188867
Fixed an issue where the firewall dropped packets when the session payload was too large.
## PAN-188338
Fixed an issue where canceling a commit caused the commit process to remain at 70% and the firewall had to be rebooted.
## PAN-188036
Fixed an issue where SIP TCP sequence numbers were calculated incorrectly when SIP cleartext proxy was disabled.
## PAN-186024
Fixed an issue where URL category match did not work for External Dynamic List URLS due to a leak related to the devsrvr process.
## PAN-184291
Fixed an issue where the GlobalProtect portal generated a cookie with a domain as NULL instead of empty-domain, which caused users to be identified incorrectly.
## PAN-183327
```caveat
Firewalls in HA configurations only
```
Fixed an issue where policy based forwarding (PBF) sessions between virtual systems (vsys) weren't pushed to the high availability peer.
## PAN-183184
Fixed an issue where enabling SSL decryption with a Hardware Security Model (HSM) caused a dataplane restart.
## PAN-182244
Fixed an issue where Session Initiation Protocol (SIP) REGISTER packets did not get transmitted when application-level gateway (ALG) and SIP Proxy were enabled, which caused a SIP-registration issue in environments where TCP retransmission occurred.
## PAN-181366
Fixed an issue where the firewall sent an incorrect IP address on ICMP sessions in NetFlow packets when NAT was applied to the target traffic.
## PAN-181098
```caveat
PA-800 Series firewalls only
```
Fixed an issue where the firewall rebooted during a software install job due to a kernel panic situation.
## PAN-180916
Fixed an issue where DNS security caused the (time-to-live) value of the pointer record (PTR) to be overwritten with a value of 30 seconds.
## PAN-178243
Fixed an issue where **Shared Gateway** was not visible in the **Virtual System** drop down when configuring a Layer3 aggregate subinterface.
## PAN-177562
Fixed an issue where PDF reports were not translated to the configured local language.
## PAN-176341
Fixed an issue where a delay to detect when an interface was down after a cable pull caused traffic to be black-holed to the downed link for 10 or more seconds.
## PAN-174660
Fixed an issue where the devsrvr process stopped responding after a local or Panorama pushed commit. This occurred when a single NAT policy contained more than 64 address objects.
## PAN-173437
Fixed an issue where the firewall did not detect that the management port was down the first time after booting up the system.
## PAN-168635
Fixed an issue on the firewall where, when attempting to change the master key, the existing master key was not validated first. As a result, all firewall keys were corrupted.
## PAN-168179
Fixed an issue where DHCP IP address renewal failed on the management interface
## PAN-159702
Fixed an issue where FQDN refresh did not work with the error message No name servers found!, and no subsequent retries occurred.
## PAN-151469
Fixed an issue where packets were dropped unexpectedly due to errors parsing the IP version field.
## PAN-135527
Fixed an issue where verbose mode did not display additional data for the fe20 flow lookup command.
## PAN-82223
Fixed an issue where links to severity level GIFs in HIP Check log entry details did not work.
@@ -0,0 +1,19 @@
---
type: Addressed
product: PAN-OS
version: 9.1.16-h3
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-227523
A fix was made to address a customer bug ([CVE-2023-38802](https://security.paloaltonetworks.com/CVE-2023-38802)).
## PAN-202450
Fixed an issue where the device-client-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
## PAN-198372
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
@@ -0,0 +1,15 @@
---
type: Addressed
product: PAN-OS
version: 9.1.16-h5
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-237935
Extended the offline PAN-DB, Panorama, and WildFire certificates which were previously set to expire on September 2, 2024.
## PAN-215576
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
@@ -0,0 +1,223 @@
---
type: Addressed
product: PAN-OS
version: 9.1.16
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-235168
Fixed an issue where disk space became full even after clearing old logs and content images.
## PAN-216656
Fixed an issue where the firewall was unable to fully process the user list from a child group when the child group contained more than 1,500 users.
## PAN-215911
Fixed an issue that resulted in a race condition, which caused the configd process to stop responding.
## PAN-215488
Fixed an issue where an expired Trusted Root CA was used to sign the forward proxy leaf certificate during SSL Decryption.
## PAN-211997
Fixed an issue where large OSPF control packets were fragmented, which caused the neighborship to fail.
## PAN-211602
Fixed an issue where, when viewing a WildFire Analysis Report via the web interface, the **detailed log view** was not accessible if the browser window was resized.
## PAN-209696
Fixed an issue where link-local address communication for IPv6, BFD, and OSPFv3 neighbors was dropped when IP address spoofing check was enabled in a Zone Protection profile.
## PAN-207740
Fixed an issue that resulted in a race condition, which caused the configd process to stop responding.
## PAN-205453
Fixed an issue where running reports or queries under a user group caused the reportd process to stop responding.
## PAN-203563
Fixed an issue with Content and Threat Detection allocation storage space where performing a commit failed with a CUSTOM_UPDATE_BLOCK error message.
## PAN-203402
Fixed an intermittent issue where forward session installs were delayed, which resulted in latencies.
## PAN-203147
```caveat
Firewalls in FIPS-CC mode only
```
Fixed an issue where the firewall unexpectedly rebooted when downloading a new PAN-OS software image.
## PAN-201910
PAN-OS security profiles might consume a large amount of memory depending on the profile configuration and quantity. In some cases, this might reduce the number of supported security profiles below the stated maximum for a given platform.
## PAN-201639
Fixed an issue with Saas Application Usage reports where **Applications with Risky Characteristics** displayed only two applications per section.
## PAN-199612
Fixed a sync issue with firewalls in active/active HA configurations.
## PAN-198871
Fixed an issue when both URL and Advanced URL licenses were installed, the expiry date was not correctly checked.
## PAN-198693
Fixed an issue where decrypted SSH sessions were interrupted with a decryption error.
## PAN-198038
A CLI command was added to address an issue where long-lived sessions were aging out even when there was ongoing traffic.
## PAN-197919
Fixed an issue where, when path monitoring for a static route was configured with a new Ping Interval value, the value was not used as intended.
## PAN-197847
Fixed an issue where disabling the enc-algo-aes-128-gcm cipher did not work when using an SSL/TLS profile.
## PAN-197729
Fixed an issue where repeated configuration pushes from Panorama resulted in a management server memory leak.
## PAN-197576
Fixed an issue where commits pushed from Panorama caused a memory leak related to the mgmtsrvr process.
## PAN-197219
Fixed an issue where the following error message was not sent from multi-factor authentication PingID and did not display in the browser: Your company has enhanced its VPN authentication with PingID. Please install the PingID app for iOS or Android, and use pairing key:<key>. To connect, type "ok".
## PAN-195790
Fixed an issue where syslog traffic that was sent from the management interface to the syslog server even when a destination IP address service route was configured.
## PAN-195583
Fixed an issue where, after renaming an object, configuration pushes from Panorama failed with the commit error **object name is not an allowed keyword**.
## PAN-194175
Fixed an issue on Panorama where a commit push to managed firewalls failed when objects were added as source address exclusions in a Security policy and **Share Unused Address and Service Objects with Devices** was unchecked.
## PAN-193808
Fixed a memory leak issue in the mgmtsrvr process that resulted in an OOM condition.
## PAN-193763
Fixed an issue on the firewall where the dataplane CPU spiked, which caused traffic to be affected during commits or content updates.
## PAN-192681
Fixed an issue where HIP database storage on the firewall reached full capacity due to the firewall not purging older HIP reports.
## PAN-190950
Fixed an issue where creating or modifying a GlobalProtect portal configuration failed in FIPS mode with the following error message: clientless-vpn enc-algo-rc4 unexpected here.
## PAN-189518
Fixed an issue where incoming DNS packets with looped compression pointers caused the dnsproxyd process to stop responding.
## PAN-189379
Fixed an issue where FQDN based Security policy rules did not match correctly.
## PAN-187829
Fixed an issue where the web_backend and httpd processes leaked descriptors, which caused activities that depended on the processes, such as logging in to the web interface, to fail.
## PAN-187761
Fixed an issue where, during HA failover, the newly passive firewall continued to pass traffic after the active firewall had already taken over.
## PAN-184537
Fixed an issue where GlobalProtect requested for passwords that contained non ASCII characters (ö) to be reentered when refreshing the connection.
## PAN-183319
Fixed an issue on Panorama where commits remained at 99% due to multiple firewalls sending out CSR singing requests every 10 minutes.
## PAN-183297
Fixed an issue where, when the firewall received a large amount of user information, the firewall was unable to output IP-address to username mapping information via XML API.
## PAN-183126
Fixed an issue on Panorama where you were able to attempt to push a number of active schedules to the firewall that was greater than the firewall's maximum capacity.
## PAN-182845
Fixed an issue that caused devices to be removed from Panorama when one device was added by one user, but a Commit and Push operation was completed by a second user before the first user completed a Commit of the added device change.
## PAN-181839
Fixed an issue where Panorama Global Search reported **No Matches found** while still returning results for matching entries on large configurations.
## PAN-181759
```caveat
Firewalls in active/active HA configurations only
```
Fixed an issue where firewall configuration files were not synced.
## PAN-181295
Fixed an issue where clicking on a rule in the **App Dependency** tab after a commit or commit all did not display the rule correctly.
## PAN-179624
Fixed an issue where setting the password complexity to **Require Password Change on First Login** caused the user to be prompted with certificate authentication.
## PAN-177942
Fixed an issue where, when grouping HA peers, access domains that were configured using multi-vsys firewalls deselected devices or virtual systems that were in other configured access domains.
## PAN-177054
Fixed an issue where, when you disabled a NAT rule, the **Destination Translation** value **none** displayed in blue and was still able to be modified to a different value.
## PAN-175176
Fixed an issue in which CBC ciphers for TLS traffic to port 28443 on Panorama were enabled.
## PAN-174680
Fixed an issue where, when adding new configurations, Panorama didn't display a list of suggested template variables when typing in a relevant field.
## PAN-173179
Fixed an issue where the rem_addr field in Terminal Access Controller Access-Control System (TACACS+) authentication displayed the management or service route IP address of the firewall instead of the source IP address of the user.
## PAN-161958
Fixed an issue where the FQDN refresh timer was pushed from Panorama appliances on PAN-OS 9.0 and later releases to firewalls running a PAN-OS 8.1 release.
## PAN-158511
Fixed an issue where configurations loaded and committed to Panorama changed external dynamic list references on Security policy rules to **NONE** when Antivirus Protection was not installed.
## PAN-143930
Fixed an issue where a process (routed) restarted due to the number of BGP peers exceeding the supported configuration.
## PAN-78762
Fixed an issue where you were unable to reset a VPN tunnel via the firewall web interface (**Network > IPSec Tunnels > Tunnel Info > Restart**).
@@ -0,0 +1,99 @@
---
type: Addressed
product: PAN-OS
version: 9.1.17
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-237935
Extended the offline PAN-DB, Panorama, and WildFire certificates which were previously set to expire on September 2, 2024.
## PAN-228043
Fixed an issue on firewalls on active/active HA configurations where packets dropped during commit operations when forwarding traffic via an HA3 link when an aggregate ethernet interface or data interface was used as an HA3 link.
## PAN-223317
Fixed an issue where SSL traffic failed with the error message: Error: General TLS protocol error.
## PAN-221637
Fixed an issue where User ID logs for logout events displayed incorrect factor completion times.
## PAN-218404
Fixed an issue where ikemgr stopped responding due to receiving CREATE_CHILD messages with a malformed SA payload.
## PAN-217681
Fixed an issue caused by out of order TCP segments where the TCP retransmission failed when the TCP segment had the FIN flag and the TCP data was truncated.
## PAN-215576
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
## PAN-210883
Fixed an issue where SSL proxy traffic was dropped when DoS Zone protection was enabled.
## PAN-207003
Fixed an issue where the logrcvr process netflow buffer was not reset which resulted in duplicate netflow records.
## PAN-202593
Fixed an issue where expanding Global Find results displayed only the top level and second level of a searched item.
## PAN-199557
Fixed an issue on Panorama where virtual memory usage exceeded the set limit, which caused the configd process to restart.
## PAN-198372
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
## PAN-198174
Fixed an issue where, when viewing traffic or threat logs from the **Application Command Center** (ACC) or **Monitor** tabs, performing a reverse DNS lookup caused the dnsproxy process to restart if DNS server settings were not configured.
## PAN-197935
Fixed an intermittent issue where XML API IP address tag registration failed on firewalls in a multivsys environment.
## PAN-197426
Fixed an issue on Panorama where, when attempting to view the **Monitor** page, the error message **invalid term** was displayed.
## PAN-196956
Fixed an issue where URL filtering logs did not display matching entries when filtered by device name.
## PAN-192431
Fixed an issue where unmanaged tags were set to NULL, which caused unmanaged devices to match the HIP rule for managed devices. As a result, you were unable to distinguish between managed and unmanaged devices.
## PAN-191867
Fixed an issue where CPU stalls resulted in a slot restart.
## PAN-190903
Fixed an issue where MAC addresses in threat capture were swapped between the source MAC and destination MAC addresses.
## PAN-189182
Fixed an issue where the change summary didn't work after upgrading the Panorama appliance.
## PAN-184630
Fixed an issue where TLS clients, such as those using OpenSSL 3.0, enforced the TLS renegotiation extension (RFC 5746).
## PAN-160633
```caveat
PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls only
```
Fixed an issue where the dataplane restarted repeatedly due to an internal path monitoring failures until a power cycle.
@@ -0,0 +1,103 @@
---
type: Addressed
product: PAN-OS
version: 9.1.1
source: common-crawl
crawl: CC-MAIN-2026-12
---
## WF500-5185
```caveat
WF-500 Series only
```
Fixed an issue where high disk use was observed due to an inadequate rotation of log files.
## WF500-5137
Fixed an issue where the show wildfire global last-device-registration all CLI command incorrectly returned an error message: Failed, even when you registered the firewall correctly.
## PAN-134096
Fixed an issue where uploads for custom logos failed.
## PAN-133329
Fixed an issue on Panorama where when viewing **Unused** Rule Usage in Policy Optimizer, devices without a hit count had the incorrect date and time instead of displaying no values. Now, if the rule has not been used, the dates and times are displayed with a hyphen (-).
## PAN-133048
```caveat
PA-5200 and PA-7000 Series only
```
Fixed an issue where traffic was processed asymmetrically when using Internet Protocol (IP) classifiers on virtual wire (vwire) subinterfaces.
## PAN-133040
Fixed an issue on WF-500 where a VM-Series firewall controller crashed, which caused the WF-500 to stop file analysis.
## PAN-132449
Fixed an issue where the pan_task process crashed when debug was set as debug dataplane packet-diag set log counter flow_fwd_drop_noxmit.
## PAN-130262
Fixed a rare issue where 200 OK messages were dropped during the offload of traffic for App-ID inspection.
## PAN-129692
Fixed an issue where VM-Series firewalls on Microsoft Azure experienced traffic latency due to an incompatible driver.
## PAN-129658
Fixed an issue where GTP inspection stopped functioning after unrelated changes in policy and a commit followed by a high availability (HA) failover.
## PAN-128269
```caveat
PA-5250, PA-5260, and PA-5280 firewalls with 100GB AOC cables only
```
Fixed an issue where after you upgraded the first peer in a high availability (HA) configuration to a PAN-OS 9.0 release, the High Speed Chassis Interconnect (HSCI) port did not come up due to an FEC mismatch until after you finished upgrading the second peer.
## PAN-125122
A fix was made to address a cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS and Panorama that disclosed an authenticated PAN-OS administrator's PAN-OS session cookie ([CVE-2020-2013](https://security.paloaltonetworks.com/CVE-2020-2013)).
## PAN-124212
Fixed an issue where DHCP configuration was overriding the maximum transmission unit (MTU) information set on the management interface by the user.
## PAN-120350
Fixed an issue where an Address Resolution Protocol (ARP) broadcast storm potentially overloaded the Log Processing Card (LPC) and caused the device to reboot.
## PAN-120105
Fixed an issue where email header information intermittently was not present in threat logs.
## PAN-118091
Fixed an issue where application dependency warnings were displayed after a commit when the policy rules containing the dependent applications used different sources (one used user and the other used groups).
## PAN-116383
Fixed an issue with Panorama on AWS where the configuration of the high availability (HA) pair became out of sync due to different plugin versions being detected even though the same versions were installed on both peers.
## PAN-111611
Fixed an issue where the connection between the firewall and Cortex Data Lake flapped if connections decreased.
## PAN-108992
A fix was made to address an improper authorization vulnerability in PAN-OS ([CVE-2020-1998](https://security.paloaltonetworks.com/CVE-2020-1998)).
## PAN-100734
A fix was made to address a buffer flow vulnerability in the PAN-OS management interface where authenticated users were able to crash system processes or execute arbitrary code with root privileges ([CVE-2020-2015](https://security.paloaltonetworks.com/CVE-2020-2015)).
## PAN-100415
A fix was made to address an external control of filename vulnerability in the command processing of PAN-OS ([CVE-2020-2003](https://security.paloaltonetworks.com/CVE-2020-2003)).
@@ -0,0 +1,403 @@
---
type: Addressed
product: PAN-OS
version: 9.1.2
source: common-crawl
crawl: CC-MAIN-2026-12
---
## WF500-5343
Fixed an issue on WF-500 that caused cloud queries to fail when the cloud verdict did not match the local verdict.
## PAN-142084
Fixed an issue where upgrading a Panorama management server deployed on Amazon Web Services (AWS) using a C5 or M5 instance type to PAN-OS 9.1.1 caused the Panorama Virtual Appliance to stop responding.
## PAN-140509
Fixed an issue where performing private data resets during custom Amazon Machine Image (AMI) creation removed CloudWatch directories and caused the CloudWatch plugin to fail.
## PAN-140157
A fix was made to address a vulnerability where the password for a configured system proxy server for a PAN-OS appliance was displayed in cleartext when using the CLI in PAN-OS ([CVE-2020-2048](https://security.paloaltonetworks.com/CVE-2020-2048)).
## PAN-138003
Fixed an issue where a process (rasmgr) exited, which caused the firewall to reboot due to a null pointer dereference error when usr_info was null.
## PAN-137966
Fixed a configuration lock issue where Panorama timed out due to a process (configd) being unable to read another process (mongod).
## PAN-137709
Fixed an issue where dynamic DNS (DDNS) failed due to a Lua script error.
## PAN-137191
Fixed an issue where the **Custom URL Category** default action changed from **allow** to **none** after upgrading to PAN-OS 9.1.0.
## PAN-136724
Fixed an issue with a process (snmpd) and booting errors.
## PAN-136698
Fixed an issue where a process (all_pktproc) stopped responding and the dataplane restarted when the firewall processed a malformed GPRS tunneling protocol (GTP) packet.
## PAN-136696
Fixed an issue where the dataplane restarted due to excessive logs from the pan_comm process.
## PAN-136608
Fixed an issue in Panorama where the Security policy **Target** displayed the serial number of the targeted device instead of the hostname.
## PAN-136607
Fixed an issue with GPRS tunneling protocol (GTP) event packet capture (pcap) where enabling **Packet Capture** did not work.
## PAN-136453
Fixed an issue where performing a private data reset using the request system private-data-reset CLI command caused the unit to boot into maintenance mode.
## PAN-136390
```caveat
PA-7000 Series with 100GB NPC only
```
Fixed an issue during firewall bootup where the following error message: Bootloader upgrade failed, ret 255 appeared when small form-factor pluggable (SPF) modules were installed.
## PAN-136304
Fixed an issue where clientless VPN rewrite failed due to incorrect parsing of the HTML webpage.
## PAN-135909
Fixed an issue where connections leading to the web interface were abruptly interrupted due to a double free condition (gPanUiPhpGlobal_secure_config_reset), which led to unexpected process restarts and core file generation.
## PAN-135703
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where the switch ports connected to Quad Small Form-factor Pluggable (QSFP+) interfaces were up while Network Processing Cards (NPCs) were still rebooting.
## PAN-135587
Fixed an issue where the GlobalProtect gateway was unable to parse a large list of IP addresses assigned on a local machine.
## PAN-135570
Fixed an issue where management access to a VM-Series firewall deployed in Amazon Web Services (AWS) cloud was slow due to high disk input/output (I/O) operations caused by expired Large Scale VPN (LSVPN) certificates.
## PAN-135452
Fixed an issue where configuration related to virtual machine (VM) information sources caused a process (userid) to crash, which led to a firewall reboot.
## PAN-135260
```caveat
PA-7000 Series firewalls running PAN-OS® 8.1.12 only
```
Fixed an intermittent issue where the dataplane process (all_pktproc_X) on a Network Processing Card (NPC) restarted when processing IPSec tunnel traffic.
## PAN-135141
Fixed an issue where the Log Processing Card (LPC) did not come up intermittently in a fully loaded PA-7000 Series.
## PAN-135103
A fix was made to address a format string vulnerability on PA-7000 Series firewalls with a Log Forwarding Card (LFC) ([CVE-2020-1992](https://security.paloaltonetworks.com/CVE-2020-1992)).
## PAN-135089
Fixed an issue where the CPU for a process (ikemgr) spiked when third-party VPN clients connected to the GlobalProtect gateway with more than three DNS servers configured.
## PAN-135039
Fixed an issue in Panorama where a memory leak occurred during a high availability (HA) sync commit.
## PAN-134981
Fixed an issue with a memory leak in a process (user-id) due to failed LDAP over SSL (LDAPS) requests.
## PAN-134810
Fixed an issue where **Resolve** in the web interface did not work for FQDN address objects with more than 63 characters.
## PAN-134714
Fixed an issue where Safe Search was not enabled after an application change.
## PAN-134571
Fixed an issue where DNS security incorrectly set bits to zero on compressed DNS packets, which caused DNS malformation.
## PAN-134547
Fixed an issue where the passive firewall in an active/passive high availability (HA) configuration deleted BGP-learned routes synchronized from the active firewall if the BGP configuration included the redistribution of the learned routes.
## PAN-134546
Fixed a rare issue on the firewall where a process (flow_mgmt) restarted due to an invalid packet received through the GlobalProtect agent or clientless VPN.
## PAN-134488
Fixed an issue where a process (all_pktproc) crashed while processing Clientless VPN traffic.
## PAN-134370
Fixed an issue where a process (mp-relay) restarted due to missing routes or next hops.
## PAN-134309
Fixed an issue where a process (devsrvr) restarted when it hit the limit of the number of custom patterns available in the allocated memory.
## PAN-134244
Fixed an issue where connections proxied by the firewall (such as SSL Decryption, GlobalProtect portal and gateway connections, and SIP over TCP) failed due to insufficient buffer allocation. Some connections failed with the following error message: proxy decrypt failure.
## PAN-134038
Fixed an issue where custom signatures did not properly detect the User-Agent header when the Origin header was also present.
## PAN-133915
Fixed an issue on Panorama where configuring a BGP import rule from the CLI failed with the following error message: Server error : permission denied for the command set.
## PAN-133912
Fixed an issue where querying traffic logs based on address objects and address groups did not work.
## PAN-133883
Fixed an issue where a race condition caused "pan_task" and "pan_com" to exit unexpectedly.
## PAN-133880
Fixed an issue where RADIUS authentication failed due to an FQDN resolution failure after the VM-Series firewall rebooted.
## PAN-133731
Fixed an issue on the Panorama Virtual Appliance where the show interface all CLI command did not list any output.
## PAN-133614
Fixed an issue on the Panorama Virtual Appliance where SNMP Object IDs (OIDs) were missing for interfaces other than the **Management** interface.
## PAN-133609
Fixed an issue where the Authentication Portal did not work due to a large number of HTTP requests with unsupported Authorization headers.
## PAN-133582
Fixed an issue in the firewalls where some Dynamic Address Groups pushed from Panorama were missing member IP addresses.
## PAN-133527
A fix was made to address a NULL pointer dereference vulnerability in PAN-OS ([CVE-2020-1995](https://security.paloaltonetworks.com/CVE-2020-1995)).
## PAN-133491
Fixed an issue where Internet Protocol (IP) to user mappings were not synced from the HUB virtual system (vsys) to the non-hub vsys.
## PAN-133448
Fixed an issue where the mprelay process could crash during commit if the devsrvr process was restarted before or during the commit.
## PAN-133440
Fixed an issue where fragmented traffic caused high dataplane use and firewall performance issues.
## PAN-133411
Fixed an issue where after making configuration changes and selecting **Preview Changes**, a 500 Internal Server Error message displayed due to a memory leak.
## PAN-133378
Fixed an issue in Panorama where a process (configd) restarted while doing a commit using a RADIUS super admin role.
## PAN-133289
Fixed an issue where improper parsing of the URL database caused high device-server CPU usage.
## PAN-133288
Fixed an issue where the API key limit in the *HTTP server profile was 128 characters.
## PAN-133211
Fixed an issue where the policy order was not maintained when moved to a different device group.
## PAN-133179
Fixed a rare issue where the show ntp CLI command showed the status as rejected even when the NTP was synced with at least one NTP server.
## PAN-133042
```caveat
PA-5200 and PA-7000 Series firewalls only
```
Fixed an issue where firewalls dropped certain GPRS tunneling protocol (GTP) traffic even when gtp nodrop was enabled.
## PAN-132995
```caveat
PA-7000 Series and PA-3200 Series firewalls only
```
Fixed an issue where when jumbo frames were enabled, the maximum transmission unit (MTU) size limit was lower than expected.
## PAN-132766
Fixed an issue in Panorama where custom region objects were not visible in the GlobalProtect Portal **External Gateway** drop-down.
## PAN-132715
Fixed an issue where a child dynamic address group was not added as a member of the parent group.
## PAN-132697
Fixed an issue where the GlobalProtect portal did not generate certificate signing requests (CSRs) due to failed Simple Certificate Enrollment Protocol (SCEP) authentication cookie validation.
## PAN-132658
Fixed an issue where a nullification method for steam control transmission protocol (SCTP) data chunks did not work.
## PAN-131993
Fixed an issue where a process (reportd) would crash while running a log query.
## PAN-131501
Fixed an issue when configuring Clientless VPN and executing the portal-getconfig CLI command where user groups were retrieved but were not freed, which caused a memory leak on a process (sslvpn).
## PAN-131491
Fixed an issue where the **ACC** risk meter displayed as zero for long time periods with a large amount of logs.
## PAN-130776
Fixed an issue on Panorama where Applications and Threats content update deployment failed due to the content version date check.
## PAN-130573
Fixed an issue where the software pool for Regex results was depleted and caused connection failures.
## PAN-130447
Fixed an issue where the firewall dropped offloaded traffic every time there was an explicit commit (**Commit** on the firewall locally or **Commit All Changes** in Panorama) or an implicit commit (such as an Antivirus update, Dynamic Update, or WildFire® update) on the firewall.
## PAN-129281
Fixed an issue where a process (useridd) restarted due to a buffer overflow when the time-to-live (TTL) and **Idle Timeout** values were set to **Never**, a timing issue between user group context and a process (sysd) callback, and a group mapping issue when multiple group mappings fetched the same groups with different override domains.
## PAN-128879
Fixed an issue where the PAN-OS XML API inject was not working for IP address to user mappings or for the import of software, content, and plugins.
## PAN-128398
Fixed an issue where performing a factory reset or enabling FIPS mode would cause the VM-Series plugin to revert to the default VM-Series plugin 1.0.0.
## PAN-127438
Fixed an issue where GlobalProtect portal configuration selection based on certificate template OID failed.
## PAN-127260
Fixed an issue where the /opt/pancfg partition became full due to a large amount of botnet reports that were not automatically deleted.
## PAN-125534
```caveat
PA-5200 Series and PA-7000 Series firewalls only
```
Fixed an issue where firewalls experienced high packet descriptor (on-chip) usage during uploads to the WildFire Cloud or WF-500 appliance.
## PAN-125501
Fixed an issue where URL information in a URL **Custom Report** was blank when the report contained flexible size fields (such as **URL Category List**).
## PAN-124658
Fixed an issue where the timer system call activated more frequently than expected, which caused higher than expected CPU usage.
## PAN-123637
```caveat
PA-3200 Series firewalls only
```
Fixed an issue where configuring 1G small form-factor pluggable (SFP) ports on the firewall in forced speed mode (of 1G) rendered the link unusable when the peer device also had forced speed mode (of 1G) enabled.
## PAN-122004
```caveat
PA-5200 Series firewalls only
```
Fixed an issue where the Quad Small Form-factor Pluggable (QSFP) 28 ports 21 and 22 did not respond when plugged in with a Finisar 100G AOC cable.
## PAN-121626
```caveat
PA-3200 Series firewalls only
```
Fixed an intermittent issue where firewalls dropped packets, which caused issues such as traffic latency, slow file transfers, reduced throughput, internal path monitoring failures, and application failures.
## PAN-119452
An enhancement was made to improve subsequent loading times of device groups after the first load.
## PAN-117043
Fixed an issue where using special characters in the tag names of the Security policy rules returned the following error message when committing or pushing a configuration: group-tag is invalid.
## PAN-116480
Fixed an issue in Panorama where the show system search-engine-quota CLI command, the show log-collector serial-number <log-collector_SN> CLI command, and **Statistics** (**Panorama > Managed Collectors > Statistics**) showed incorrect log retention data.
## PAN-116002
Fixed an issue where an incorrect optimization could cause IP address-to-user mapping to not update within 60 seconds.
## PAN-114966
Fixed an issue where trunk interfaces were not working on Hyper-V.
## PAN-114533
Fixed an issue where traffic was blocked by safe search enforcement before matching the intended allow rule.
## PAN-110960
Fixed an issue on Panorama M-Series and virtual appliances where commits failed when you configured an address group object in the Include List (*Network > Zone > <zone-name> > Include List*).
## PAN-110441
```caveat
PA-5200 Series firewall only
```
Fixed an intermittent issue where the internal path monitoring failed, which caused the firewall to unexpectedly restart.
## PAN-107207
Fixed an issue where the VPN tunnel operational status incorrectly displays "up" even though the VPN tunnel is down.
## PAN-98933
Fixed an issue on an M-Series appliances in a high availability (HA) active/passive configuration where the schedules (*Device > Dynamic Updates*) were unresponsive after a failover or restart of Panorama.
## PAN-88136
Fixed a rare issue where a URL update caused the dataplane to restart.
@@ -0,0 +1,583 @@
---
type: Addressed
product: PAN-OS
version: 9.1.3
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-148988
A fix was made to address a Security Assertion Markup Language (SAML) authentication issue ([CVE-2020-2021](https://security.paloaltonetworks.com/CVE-2020-2021)).
## PAN-148068
Fixed an issue where SSL connections were blocked if you enabled decryption with the option to block sessions that have expired certificates. This issue included servers that sent an expired AddTrust certificate authority (CA) in the certificate chain.
## PAN-147424
Fixed an issue with internal buffer and file sizes where logs were discarded due to slow log purging when the incoming log rate was high.
## PAN-145195
```caveat
and PAN-145149
```
A fix was made to address a buffer overflow vulnerability in PAN-OS that allowed an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a malicious request to the Captive Portal or Multi-Factor Authentication interface ([CVE-2020-2040](https://security.paloaltonetworks.com/CVE-2020-2040)).
## PAN-145151
```caveat
and PAN-145149
```
A fix was made to address a buffer overflow vulnerability in PAN-OS that allowed an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a malicious request to the Captive Portal or Multi-Factor Authentication interface ([CVE-2020-2040](https://security.paloaltonetworks.com/CVE-2020-2040)).
## PAN-145150
```caveat
and PAN-145149
```
A fix was made to address a buffer overflow vulnerability in PAN-OS that allowed an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a malicious request to the Captive Portal or Multi-Factor Authentication interface ([CVE-2020-2040](https://security.paloaltonetworks.com/CVE-2020-2040)).
## PAN-145026
Fixed an issue where Cortex Data Lake certificates on the firewall were not automatically renewed after the certificates expired.
## PAN-144782
Fixed an issue where a configuration audit created a large number of opresult.out files, which filled up the session/pan/user_tmp directory in opt/pancfg. This caused a slow Panorama response until a device restart was performed or the files were manually deleted from the root of the device.
## PAN-144646
Fixed an issue where a process (varrcvr) stopped responding on the PA-7000 Series Log Forwarding Card (LFC) when it received a verdict from the WildFire cloud.
## PAN-144221
```caveat
Microsoft Azure only
```
Fixed an issue where a process (brdagent) stopped responding, which caused the firewall to restart unexpectedly.
## PAN-144073
Fixed an issue where on the Panorama management server, hub and branch firewall latency, jitter, and packet loss data was not updated when monitoring SD-WAN link performance (**Panorama > SD-WAN > Monitoring**).
## PAN-143957
Fixed an issue where, after loading a saved configuration snapshot by API, a custom role-based administrator required Superuser privileges to perform a full commit.
## PAN-143845
Fixed an issue where the firewall repeatedly rebooted due to a process (rasmgr) restarting when GlobalProtect was used in pre-logon mode.
## PAN-143537
```caveat
VM-Series firewalls only
```
Fixed an issue where disk utilization of the root partition increased until it reached 100%.
## PAN-143493
Fixed an memory issue associated with a process (mgmtsrvr) due to a large number of ACK packets in logs on Panorama or the log collector.
## PAN-143442
Fixed an issue where Amazon Web Services (AWS) Nitro System based VM-Series firewalls unexpectedly rebooted due to input/output (I/O) errors caused by improper NMVE I/O timeout settings.
## PAN-143169
Fixed an issue where running a test security-policy-match API command truncated the rule name to 31 characters.
## PAN-143130
Fixed an issue where, in Panorama, cloning a shared Security policy rule failed if done via the web interface and resulted in a process (configd) restarting with the following error message: Failed security rule(s): undefined The request could not be handled.
## PAN-142674
Fixed an issue where a process (brdagent) failed in a high availability (HA) configuration using High Speed Chassis Interconnect (HSCI) ports due to a memory leak.
## PAN-142302
Fixed an issue where the firewalls faced connection issues with Cortex Data Lake.
## PAN-142089
Fixed an internal logging issue for a daemon (authd).
## PAN-141923
Fixed an issue where authentication stopped working after a commit and a process (authd) exited, which caused other processes to exit.
## PAN-141844
Fixed an issue where promiscuous VLAN mode did not work with the new host drivers being used on the ESXi and single-root input/output virtualization (SR-IOV) with VLAN tagging did not work as expected. Both Data Plane Development Kit and packet mmap mode did not work.
## PAN-141563
Fixed an issue where Slot 8 path monitoring failure occurred due to a memory buildup in a process (logrcvr) that was caused by slow communication and connection between log forwarding and Cortex Data Lake.
## PAN-141262
Fixed an issue where the resolution of FQDN for a policy on the web interface did not work as expected if the FQDN contained capital letters.
## PAN-141239
Fixed an issue where dataplane free memory was depleted, which affected new GlobalProtect connections to the firewall.
## PAN-141221
Fixed an issue where a commit or content update operation with an error was not prevented from executing in the dataplane, which caused corruption in the dataplane policy cache.
## PAN-140982
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where a process (mprelay) on the control plane was restarted due to an internal heartbeat miss.
## PAN-140846
Fixed an issue where the dataplane restarted during a commit when **Netflow** was enabled.
## PAN-140669
Fixed a memory leak issue caused by a process (mgmtsrvr).
## PAN-140628
Fixed an issue where a memory leak on a process (useridd) caused multiple processes to restart during device serial number checks.
## PAN-140618
Fixed an issue on Panorama where SNMP monitoring of the logging rate per device was incorrect.
## PAN-140575
Fixed an issue where a process (masterd) did not restart another process (logrcvr) on the Log Forwarding Card (LFC) after the process (logrcvr) crashed.
## PAN-140465
```caveat
VM-Series firewalls only
```
Fixed connection issues between IPv6 peers when the IPv6 neighbor cache was synchronized in an HA cluster where, after failover, the newly active firewall did not send multicast neighbor solicitation from its global unicast address.
## PAN-140389
Fixed an issue on Panorama in Legacy mode where configuring Network File System (NFS) log storage (**Device > Setup > Operations**) caused all plugin installations to fail.
## PAN-140386
Fixed an intermittent issue where the firewall used IP addresses instead of domain names for URL category lookup after upgrading to 9.0.6.
## PAN-140375
Fixed an issue where a process (logrcvr) exited due to a race condition.
## PAN-140270
Added additional debugging to periodically collect the debug dataplane internal pdt bcm counters graphical CLI command's output in the Tech Support File (TSF).
## PAN-140121
Fixed an issue where a process (authid) used a large amount of memory due to many incomplete authentication requests, which caused an out-of-memory (OOM) condition.
## PAN-140043
```caveat
PA-7050 firewalls running on PA-7000 100G NPCs only
```
Fixed an issue where the PA-7000 100G NPC Native Implemented Function (NIF) initialization took longer than expected, which caused internal path monitoring failure and sent the firewall into a non-functional state while rebooting.
## PAN-139935
Fixed an issue in the URL process where a process (devsrvr) stopped responding.
## PAN-139858
Fixed an issue where **Policy > Security > Test Policy Match** did not work when the source user or group length was greater than 20 characters.
## PAN-139727
Fixed an issue where disabling predefined trusted root certificates did not have any effect.
## PAN-139718
Fixed an issue where the firewall failed stateful inspection for GTP forward relocation requests greater than 1,500 bytes and could not parse Access Point Name (APN) information in forward relocation requests.
## PAN-139661
Fixed an issue that led to exhaustion of memory, which resulted in path monitoring failures when Cortex Data Lake was configured.
## PAN-139595
Fixed an issue on Panorama in Legacy mode where a process (logd) repeatedly restarted while processing incoming logs and caused Panorama to reboot.
## PAN-139555
Fixed an issue where after upgrading the passive firewall, the outer UDP sessions synced from the active firewall did not retain the rule information and after failover, GPRS tunneling protocol (GTP) inspection did not work.
## PAN-139391
Fixed an issue where unique GlobalProtect portal profiles were not selected in the correct order.
## PAN-139371
Fixed an issue where a commit failed with the following error message: destination is invalid when using objects from static routes.
## PAN-138870
Fixed an issue where a process (configd) restarted and administrators received one of the following error messages: Timed out while getting config lock. Please try again or Please wait while the server reboots... due to a database error.
## PAN-138813
Fixed a performance drop issue seen when using API to configure larger sets of objects (more than 25 objects).
## PAN-138739
Fixed an issue where, in an HA active/active configuration in a virtual wire deployment with asymmetric traffic, decryption did not work for some sites.
## PAN-138674
Fixed an issue where custom role-based admins were able to reset the rule hit counter for disabled device groups.
## PAN-138648
Fixed an issue with internal buffer and file sizes where logs were discarded due to slow log purging when the incoming log rate was high.
## PAN-138476
Fixed an intermittent issue where logs were delayed or missing when querying for logs by applying filters. To leverage this fix, you must upgrade Panorama to 9.0.9 and the Cloud Services plugin to 1.6.0-h1.
## PAN-138213
Fixed an issue where a Panorama **Custom Report** based on the **Detailed Logs > Panorama Data > Traffic** database was not able to report on decrypted sessions.
## PAN-138037
Fixed an issue where the host information profile (HIP) match message was automatically enabled when modifying the GlobalProtect Agent settings.
## PAN-138034
Fixed an issue where virtual machine (VM) information source Dynamic Address Groups overrode static address groups, which caused traffic to hit the wrong Security policy rule.
## PAN-137902
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where hot swapping a PA-7000 100G NPC with a PA-7000 20G NPC caused packet buffer leak and slot restarts.
## PAN-137885
```caveat
VM-Series firewalls in Microsoft Azure environment only
```
Fixed an issue where a firewall with accelerated networking enabled was unable to process packets efficiently because of underlying Microsoft drivers. To leverage this fix, you must upgrade to VM-Series Plugin 1.0.12.
## PAN-137867
```caveat
PA-7000 Series firewalls only, running with both a PA-7000 100G NPC and a PA-7000 20G NPC
```
Fixed an issue where IPSec traffic caused dataplane restarts.
## PAN-137777
Fixed an issue where GlobalProtect logs failed to send to syslog servers over a TCP connection.
## PAN-137716
Fixed an issue where, for users with admin roles, logs for only one device group were displayed due to a query string with multiple device groups.
## PAN-137673
Fixed an issue where a memory leak associated with a process (devsrvr) caused an out-of-memory (OOM) condition on the firewall.
## PAN-137656
Fixed an issue where the show config diff CLI command did not work correctly and produced unexpected output.
## PAN-137401
Fixed an issue where the authentication policy did not redirect users for Captive Portal authentication if the attached authentication profile did not have **Enable Additional Authentication Factors** selected.
## PAN-137387
Fixed an issue where URL filtering used the IP address instead of the hostname, which led to incorrect URL categorization.
## PAN-137251
Fixed an issue where a Panorama appliance running PAN-OS 9.1.0 was unable to export address objects and displayed the following error message: Error while exporting.
## PAN-137152
Fixed an issue where SSL decrypted traffic was dropped due to a certificate status error during session resumption.
## PAN-136957
Fixed an issue where access was denied if a password contained more than 63 characters.
## PAN-136950
Fixed an issue where, on a firewall managed by Panorama, the XML API based IP tags were lost after a firewall reboot or process (**useridd**) restart.
## PAN-136791
Fixed an issue where, in a particular scenario, the first response to a SIP INVITE message created incorrect appinfo2ip entries and caused Via header translation failure.
## PAN-136765
Fixed an issue where an FQDN update that resolved to the same IP address of another FQDN across different policies caused the other FQDN to be deleted due to missing FQDN aggregation.
## PAN-136726
Fixed an issue on the firewall where the dataplane pan-task process (all_pktproc) stopped responding while inspecting Server Message Block (SMB) traffic.
## PAN-136716
```caveat
Panorama virtual appliances only
```
Fixed an issue where SNMP monitoring of ifSpeed reported the interface speed as 0 for interfaces other than eth0.
## PAN-136703
```caveat
PA-3000 Series and PA-800 Series firewalls only
```
Fixed an issue with insufficient memory allocation for configurations to accommodate the PAN-OS 9.0 Dynamic Address Group feature.
## PAN-136649
Fixed an issue where PA-7000 20GXM and PA-7000 20GQXM Network Processing Cards (NPCs) failed to process some sessions for Layer 7 inspection due to internal maximum threshold value that was not set.
## PAN-136623
Fixed an issue where a process (useridd) failed due to internal user groups that were loading from the disk taking over the lock.
## PAN-136612
Fixed an issue where fragmented packets leaked, which caused the depletion of Work Query Entry (WQE) pools.
## PAN-136582
Fixed an issue where, when the app-version from the request header was long, the converted XML was truncated, which caused parsing to fail by a process (rasmgr) due to a limitation on the buffer length.
## PAN-136470
Fixed an issue where a process (all_pktproc) restarted while processing packets with 0.0.0.0 and destination protocol 251 that internally mapped to GTP-C traffic, which caused the dataplane to restart.
## PAN-136173
Fixed an issue where dataplane interfaces remained down after active firewall bootup or a high availability (HA) failover.
## PAN-136007
Fixed an issue where generating subordinate ECDSA Certificate Authority (CA) certificates from the web interface failed if the **Common Name** field contained a space.
## PAN-135946
Fixed an intermittent issue where Panorama was unable to query logs from the log collector due to large file sizes in es_cache_cron.log.
## PAN-135865
Fixed an issue that prevented Panorama from being switched out of management-only mode when deployed in Amazon Web Services (AWS) instance types M5 and C5.
## PAN-135844
Fixed an issue where a commit job failed due to a process (mgmtsrvr) exiting.
## PAN-135796
Fixed an issue where the firewall dropped DNS requests for root servers when the action of the DNS security signature was set to **alert** or **sinkhole** in an **Anti-Spyware** Security profile.
## PAN-135684
Fixed an issue with log collectors on Panorama where large index sizes caused higher CPU usage than expected when disk space usage was high.
## PAN-135547
Fixed an issue on Panorama where administrators were unable to delete a shared address object even when it was not referenced in the configuration.
## PAN-135504
Fixed an issue where the GlobalProtect client used IPv6 during gateway login but used IPv4 during IPsec tunnel creation, which caused it to fallback to SSL.
## PAN-135418
Fixed an issue on the firewall where configuring uppercase **User Domain** values in authentication profiles led to a failure in GlobalProtect Agent configuration selection based on the domain user match condition.
## PAN-135356
Fixed an issue where policies that contained objects did not display correctly when exported to CSV or PDF format.
## PAN-135321
Fixed an issue where all NAT rules using the same FQDN entries as translated IP addresses were not updated when the IP addresses changed for those FQDNs.
## PAN-135314
Fixed an issue where, with a new Panorama appliance running PAN-OS 9.1.0 and a firewall running an earlier version, the following error message displayed: interface sdwan is not a valid reference.
## PAN-135262
A fix was made to address a vulnerability involving information exposure through log files where an administrator's password or other sensitive information was logged in cleartext while using the CLI in PAN-OS software. The opcmdhistory.log file was introduced to track operational command (op-command) usage but did not mask all sensitive information ([CVE-2020-2044](https://security.paloaltonetworks.com/CVE-2020-2044)).
## PAN-135158
Fixed an issue where setting an IPv6 destination filter for the packet-diag option returned an error regarding a character limit.
## PAN-134979
Fixed an issue where TMP files were not deleted, which caused the root partition to run out of disk space and caused issues with accessing the firewall.
## PAN-134624
```caveat
VM-Series firewalls only
```
Fixed an issue where the VLAN interface failed to obtain the MAC address when the interface was used as a DHCP relay agent.
## PAN-134431
Fixed an issue with Security Assertion Markup Language (SAML) authentication where the firewall used old authd_id values, which resulted in failed authentication.
## PAN-133885
Fixed an issue where DNS proxy failed due to incorrect mapping of the DNS transaction ID.
## PAN-133727
Fixed an issue where Session Initiation Protocol (SIP) messages were not parsed correctly when the packet was received in separate segments, which caused the receiver to receive corrupted messages.
## PAN-133673
Fixed an issue that caused a procses (ikemgr) to exit when site-to-site VPNs experienced connectivity interruptions.
## PAN-133495
Fixed an issue where the Terminal Server (TS) Agent disconnected on the firewall after a failover or reboot.
## PAN-133285
Fixed an issue on the firewalls where configuring a default Online Certificate Status Protocol (OCSP) URL in front of an intermediate certificate authority (CA) in a certificate profile did not override the OCSP URL during the validation of client certificates issued by the intermediate CA.
## PAN-132922
Fixed an issue where service objects were unable to be deleted if they were configured to exceed firewall limits.
## PAN-131973
Fixed an issue where both firewalls in an HA active/passive configuration stopped responding at the same time.
## PAN-130562
Fixed an issue where, in VM-Series firewalls deployed using init-cfg.txt in the bootstrap process and set in an HA configuration, the configuration did not display as synchronized due to the initcfg configuration.
## PAN-130168
Fixed an issue where a process (pan_comm) stopped responding due to operation commands run during a commit.
## PAN-128761
A fix was made to address an OS command injection vulnerability in the PAN-OS management interface that allowed authenticated administrators to execute arbitrary OS commands with root privileges ([CVE-2020-2037](https://security.paloaltonetworks.com/CVE-2020-2037)).
## PAN-128078
Fixed an issue where a process (mgmtsrvr) stopped responding and was inaccessible through SSH or HTTPS until the firewall was power cycled.
## PAN-127434
Fixed an issue where reports for URLs were not generating the correct data output.
## PAN-127318
Fixed an issue where the firewall intermittently dropped DNS A or AAAA queries received over IPSec tunnels due to a session installation failure.
## PAN-126938
Fixed an issue where multiple daemons restarted due to MP ARP overflow.
## PAN-125730
Fixed an issue where packets tagged with IP protocol 252 were incorrectly treated as GPRS tunneling protocol (GTP) traffic, which caused the packet processor to terminate.
## PAN-125410
Fixed an issue where a new GPRS tunneling protocol version 2 control plane (GTPv2-C) session reused GTP-C tunnel parameters within two seconds after deleting the old GTP-C session, which caused a session conflict on the firewall.
## PAN-121598
Fixed an issue where the PAN-OS XML API packet capture (pcap) export failed with the following error message: Missing value for parameter device_name. Now, device_name and sessionid are no longer required parameters.
## PAN-119118
Fixed an issue where license and content error files received from the update and license servers were not saved to disk.
## PAN-118468
```caveat
VM-Series firewalls on VMware ESXi only
```
Fixed an issue where the firewall stays in a boot loop and enters maintenance mode after adding a 60GB disk.
## PAN-116843
Fixed an issue on Panorama where, when navigating through **Policies**, the following error message displayed: show rule hit count op-command failed.
## PAN-115093
Fixed an issue where the firewall generated excessive logs for content decoder (CTD) errors.
## PAN-114540
Fixed an issue where renaming a template stack did not change the value and reset to the original value after you commit the change.
## PAN-114427
Fixed an issue where an empty host name in the HTTP header caused a web server process (*websrvr*) to stop responding when you accessed the captive portal redirect page.
## PAN-112988
Fixed an issue where a process (*useridd*) leaked memory, which caused the firewall to drop traffic and display the following error message: Out-of-memory condition detected, kill process.
## PAN-112539
Fixed an issue where the firewall stopped forwarding logs to the log collector from the Log Processing Card (LPC) after a commit push from Panorama due to a race condition.
## PAN-112120
Fixed an issue where threat **Name** field of a threat **Custom Report** displayed the threat ID instead of the threat name.
## PAN-111614
Fixed an issue with summary reports where displayed dates were incorrect due to the date range calculation not considering the change in year.
## PAN-102202
Fixed an issue where the OSPF summary Link State Advertisement (LSA) for the default 0.0.0.0/0 route were not advertised by the Area Border Router (ABR).
## PAN-98803
Fixed an issue where the IP address-to-tag mappings for Dynamic Address Groups did not display as expected on Panorama after you configured the Panorama plugin to monitor virtual machines or endpoints in your AWS, Azure, or Cisco ACI environment without installing the NSX plugin.
## PAN-98694
Fixed an issue on a PA-5200 Series firewall in a high availability (HA) active/passive configuration where the firewall dropped TCP-FIN packets after a failover.
@@ -0,0 +1,261 @@
---
type: Addressed
product: PAN-OS
version: 9.1.7
source: common-crawl
crawl: CC-MAIN-2026-12
---
## PAN-158691
Fixed an issue with GPRS tunneling protocol (GTP) event packet capture (pcap) where enabling **Packet Capture** did not work.
## PAN-156375
Fixed an issue where multiple all_pktoproc daemons restarted while processing HTTP/2 traffic in sw_offload.
## PAN-156017
Fixed an issue where a host information profile (HIP) report XML buffer caused a memory leak.
## PAN-155517
Fixed an issue where a sudden increase in URL-cloud data challenged the cache capacity of the device.
## PAN-155453
Fixed an issue in the configuration logs where the destination zone was masked by asterisks.
## PAN-155053
Fixed an issue where user information in the Clientless VPN wasn't handled properly in high availability (HA) configurations, which resulted in the firewall being unable to create more user sessions.
## PAN-154323
Fixed an issue in Panorama where frequent API requests caused the Panorama web interface to become unresponsive. This issue occurred because the web interface automatically refreshed after each request.
## PAN-154016
Fixed an issue where auto-commits failed for VM-Series firewalls bootstrapped with new content installation during bootstrap. The firewalls displayed the following error message: Details:Error: Undefined application <application-name>.
## PAN-153791
Fixed an issue in dpdk code that cause a system restart on a process (brdagent).
## PAN-153526
```caveat
PA-7000 Series firewalls with 100G NPC (Network Processing Cards) only
```
Fixed an issue where multicast groups were not set correctly, which caused ARP entries to display as incomplete and not update to correct values.
## PAN-153207
Fixed an issue for VM-Series firewalls deployed on Azure where a process (pan_comm) restarted if DPDK was on.
## PAN-153174
Fixed an issue where using XML API to download pcap did not work if the pcap file was larger than 8MB.
## PAN-153107
Fixed an issue where a dataplane process stopped responding while processing fragmented traffic on GTP-U tunnels.
## PAN-152912
Fixed an issue where a content update caused the Panorama XML cache build to fail. This resulted references of the used objects on Panorama being removed, which caused commits on the managed firewalls to fail.
## PAN-152762
Fixed an issue where role-based administrators were unable to import certificate key pairs onto firewalls.
## PAN-152746
Fixed an issue where the firewall dropped GTPv2-x Create Session Response packets with the following error message: bad port 84b.
## PAN-152743
Fixed an issue where, when initial flows from both directions reached the firewall at the same time, a race condition occurred, which caused the firewall to display the following error message: Duplicate flows detected while inserting <number>, flow <number> with the same key. The flow keys were identical due to the flows having the same SRC and DST ports.
## PAN-152098
Fixed an issue where the Policy Optimizer for some device groups showed incorrect data with a - character in the rule usage column.
## PAN-151872
Fixed an issue where MAC addresses containing certain characters in sequential order caused an issue with TCP connections
## PAN-151691
Fixed an issue where the number of items under **Add match criteria** for Dynamic Address Groups did not update after setting a search filter string.
## PAN-151584
Fixed an issue where the firewall changed the TTL (time-to-live) value in DNS responses to 0 when the firewall failed to resolve the DNS Security service, which caused a large amount of DNS requests to be sent to the DNS server.
## PAN-151486
Fixed an issue where user activity reports failed to run when the firewall was in FIPS mode.
## PAN-151483
Fixed an issue where, when an out-of-order stream of TCP packets was subjected to HTTP header insertion, the packets were duplicated.
## PAN-151458
Fixed an issue on firewalls with HA active/active configurations where GlobalProtect gateways timed out on-demand connections. This occurred because the **Inactivity Logout** timer did not reset.
## PAN-151214
Fixed an issue where an XML API call to display configuration logs truncated the change-preview field of the logs if the entry had more than 64 characters.
## PAN-151210
Fixed an issue where the dynamic address group learned in the parent dynamic group was not pushed to the child dynamic address group if the child dynamic address group was not configured with notify groups under the respective plugin.
When using the CLI command debug dau settings device-group recursive yes/no, clear previous dynamic address group entries from the Panorama database using the CLI command debug dau clear database device-group <dynamic address group name> for all dynamic address groups under the hierarchy for the dynamic address group configured in the monitoring definition. Also, do a full sync from the plugins configured using the command request plugins <plugin-name> sync.
## PAN-150968
Fixed a rare issue with HTTP/2 decryption that caused packet header bytes to be corrupted, which caused packet drops.
## PAN-150852
Fixed an issue with SMTP that occurred when attachment file names were longer than the allocated buffer. If the file name was longer than the buffer and Layer 7 inspection was enabled, the file was dropped, which caused session errors and an email to not be sent.
## PAN-150247
Fixed an issue on the firewall where GlobalProtect Clientless VPN portal landing page customization for the navbar_bg_color variable did not take effect.
## PAN-149915
Fixed an issue where a Panorama virtual appliance was unable to manage more than 2,500 firewalls when 28 or more CPU cores were available.
## PAN-149645
Fixed an issue in a virtual wire deployment configured with **Link State Pass Through** enabled where, when one member port went down, the peer port took longer than expected to change the status to **Down**.
## PAN-149641
Fixed an issue where firewalls stopped refreshing IP tag information when configured with the **VM Information Sources** feature with a VMWare vCenter Server.
## PAN-149547
Fixed an issue where, after a change in Security policies, traffic logs for inner GTP-U sessions did not show IMSI or IMEI fields following a commit.
## PAN-149339
Fixed an issue where, when an ECMP route changed, the flow table in the offload engine was not updated.
## PAN-149327
Fixed an issue where the show gtp info CLI command returned an error.
## PAN-149297
Fixed a buffer overflow issue on the management server, which forced the administrator to log out on the web interface.
## PAN-149207
Fixed an issue where the clear log acc CLI command did not remove URL summary logs.
## PAN-149101
Fixed an issue where the first SYN message of an FTP-DATA connection was dropped on non-session-owner appliances in an HA active/active configuration.
## PAN-148818
Fixed an issue where the decryption profile was configured without the **Block sessions with expired certificates** option, but the firewall still blocked websites that were signed by an Expired AddTrust Root CA (certificate authority).
## PAN-148767
Fixed an issue where the firewall incorrectly created GTP-U sessions from Create Session Request and Create Session Response packets.
## PAN-147959
Fixed an issue where the last commit state did not change to config sent to device when pushing a device group configuration in the **Managed Device > Summary** page on Panorama.
## PAN-147720
Fixed an issue where the firewall management server crashed when a report with a duration of 7 or more days was run.
## PAN-147385
Fixed an issue where firewall buffers were depleted with GTP traffic due to the mishandling of conflicting sessions.
## PAN-146373
```caveat
VM-Series firewalls only
```
Fixed an issue where a memory leak occurred on a process (vm_agent) due to host synchronization check.
## PAN-146236
Fixed an issue where the firewall was unable to properly create stream control transmission protocol (SCTP) sessions for multi-homed environments when multiple endpoints on the same SCTP associations sent INIT/INIT-ACK chunks during handshakes.
## PAN-144376
Fixed an issue in a multi-vsys environment where the firewall dropped RTP predict sessions and was unable to match them to their parent sessions due to a zone change.
## PAN-142604
Fixed an issue where virtual memory of a process (configd) continuously increased until it stopped responding.
## PAN-142548
Fixed an memory leak issue in a process (configd) that caused the firewall to be inaccessible.
## PAN-142103
Fixed an issue where administrators were logged out of the web interface while making changes.
## PAN-141719
Fixed an issue where the **before-change-preview** and **after-change-preview** filters were usable even though they did not return configuration logs.
## PAN-141255
Removed the fields **device SN** and **device name** on Panorama from the predefined filter used in **Log Forwarding** and **Log Settings**.
## PAN-140985
Fixed an issue where Cortex Data Lake traffic was identified as ssl instead of paloalto-logging-service.
## PAN-140222
Fixed an issue where logs were not forwarded to the syslog server with the following error message: profile: Syslog (1) is duplicated.
## PAN-137233
Fixed an issue where authenticating to GlobalProtect via expired SAML requests (waiting more than 10 minutes) still sent authentication to the SAML server. This invalidated the previously connected gateway and connected users to the second best gateway.
## PAN-129314
Fixed an issue where the internal SQLite3 database was locked, which caused a process (useridd) to stop responding and group mapping retrieval to fail. This issue also caused the group mapping list to not display from the CLI.
## PAN-124579
Fixed an issue where a process (all_task_3) restarted, which caused the tunnels to reset.
## PAN-119161
```caveat
PA-7000 Series firewalls only
```
Fixed an issue where firewalls were unable to start up a Network Processing Card (NCP) due to a process (brdagent) restarting repeatedly.
## PAN-110720
Fixed an issue where a high volume of traffic over SSL VPN caused a process (all_pktproc) to unexpectedly stop responding.
## PAN-100489
Fixed an issue where the **Group found** flag was set to **NO** on User-ID logs on the web interface, even when the user belonged to a group retrieved from the Active Directory (AD) server.
## PAN-79640
Fixed an issue where the firewall intermittently logged incorrect actions for WildFire submissions and reports.
@@ -6,6 +6,42 @@ source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
If you use Panorama to retrieve logs from Cortex Data Lake (CDL), new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to CDL and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
## BLANK-000000
Upgrading a PA-220 firewall takes up to an hour or more.
## BLANK-000000
PA-220 firewalls are experiencing slower web interface and CLI performance times.
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## APPORTAL-3313
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
## APPORTAL-3309
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
## APL-8269
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
@@ -6,6 +6,50 @@ source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
Not all screenshots are updated in the documentation for 10.0.
## BLANK-000000
New features for PAN-OS 10.0.2 are not included in on-device help. Refer to [docs.paloaltonetworks.com](https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-web-interface-help.html) for the latest version.
## BLANK-000000
If you use Panorama to retrieve logs from Cortex Data Lake (CDL), new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to CDL and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
## BLANK-000000
Upgrading a PA-220 firewall takes up to an hour or more.
## BLANK-000000
PA-220 firewalls are experiencing slower web interface and CLI performance times.
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## APPORTAL-3313
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
## APPORTAL-3309
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
## APL-8269
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
@@ -6,6 +6,42 @@ source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
If you use Panorama to retrieve logs from Cortex Data Lake (CDL), new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to CDL and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
## BLANK-000000
Upgrading a PA-220 firewall takes up to an hour or more.
## BLANK-000000
PA-220 firewalls are experiencing slower web interface and CLI performance times.
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## APPORTAL-3313
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
## APPORTAL-3309
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
## APL-8269
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
@@ -6,6 +6,42 @@ source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
If you use Panorama to retrieve logs from Cortex Data Lake (CDL), new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to CDL and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
## BLANK-000000
Upgrading a PA-220 firewall takes up to an hour or more.
## BLANK-000000
PA-220 firewalls are experiencing slower web interface and CLI performance times.
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## APPORTAL-3313
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
## APPORTAL-3309
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
## APL-8269
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
@@ -6,6 +6,42 @@ source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
If you use Panorama to retrieve logs from Cortex Data Lake (CDL), new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to CDL and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
## BLANK-000000
Upgrading a PA-220 firewall takes up to an hour or more.
## BLANK-000000
PA-220 firewalls are experiencing slower web interface and CLI performance times.
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## APPORTAL-3313
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
## APPORTAL-3309
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
## APL-8269
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
@@ -6,6 +6,42 @@ source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
If you use Panorama to retrieve logs from Cortex Data Lake (CDL), new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to CDL and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
## BLANK-000000
Upgrading a PA-220 firewall takes up to an hour or more.
## BLANK-000000
PA-220 firewalls are experiencing slower web interface and CLI performance times.
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## APPORTAL-3313
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
## APPORTAL-3309
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
## APL-8269
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
@@ -6,6 +6,42 @@ source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
If you use Panorama to retrieve logs from Cortex Data Lake (CDL), new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to CDL and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
## BLANK-000000
Upgrading a PA-220 firewall takes up to an hour or more.
## BLANK-000000
PA-220 firewalls are experiencing slower web interface and CLI performance times.
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## APPORTAL-3313
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
## APPORTAL-3309
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
## APL-8269
For data retrieved from Cortex Data Lake, the Threat Name column in **Panorama** > **ACC** > **threat-activity** appears blank.
@@ -6,6 +6,42 @@ source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
If you use Panorama to retrieve logs from Strata Logging Service, new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to Strata Logging Service and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
## BLANK-000000
Upgrading a PA-220 firewall takes up to an hour or more.
## BLANK-000000
PA-220 firewalls are experiencing slower web interface and CLI performance times.
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## APPORTAL-3313
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
## APPORTAL-3309
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
## APL-15000
When you move a firewall from one Strata Logging Service instance to another, it can take up to an hour for the firewall to begin sending logs to the new instance.
@@ -6,6 +6,42 @@ source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
If you use Panorama to retrieve logs from Strata Logging Service, new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to Strata Logging Service and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
## BLANK-000000
Upgrading a PA-220 firewall takes up to an hour or more.
## BLANK-000000
PA-220 firewalls are experiencing slower web interface and CLI performance times.
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less than the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## APPORTAL-3313
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
## APPORTAL-3309
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
## APL-15000
When you move a firewall from one Strata Logging Service instance to another, it can take up to an hour for the firewall to begin sending logs to the new instance.
@@ -6,6 +6,42 @@ source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
If you use Panorama to retrieve logs from Strata Logging Service, new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to Strata Logging Service and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
## BLANK-000000
Upgrading a PA-220 firewall takes up to an hour or more.
## BLANK-000000
PA-220 firewalls are experiencing slower web interface and CLI performance times.
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less than the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## APPORTAL-3313
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
## APPORTAL-3309
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
## APL-15000
When you move a firewall from one Strata Logging Service instance to another, it can take up to an hour for the firewall to begin sending logs to the new instance.
@@ -6,6 +6,42 @@ source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
If you use Panorama to retrieve logs from Strata Logging Service, new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to Strata Logging Service and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
## BLANK-000000
Upgrading a PA-220 firewall takes up to an hour or more.
## BLANK-000000
PA-220 firewalls are experiencing slower web interface and CLI performance times.
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less than the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## APPORTAL-3313
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
## APPORTAL-3309
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
## APL-15000
When you move a firewall from one Strata Logging Service instance to another, it can take up to an hour for the firewall to begin sending logs to the new instance.
@@ -6,6 +6,42 @@ source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
If you use Panorama to retrieve logs from Strata Logging Service, new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to Strata Logging Service and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
## BLANK-000000
Upgrading a PA-220 firewall takes up to an hour or more.
## BLANK-000000
PA-220 firewalls are experiencing slower web interface and CLI performance times.
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less than the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## APPORTAL-3313
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
## APPORTAL-3309
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
## APL-15000
When you move a firewall from one Strata Logging Service instance to another, it can take up to an hour for the firewall to begin sending logs to the new instance.
@@ -6,6 +6,42 @@ source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
If you use Panorama to retrieve logs from Strata Logging Service, new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to Strata Logging Service and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
## BLANK-000000
Upgrading a PA-220 firewall takes up to an hour or more.
## BLANK-000000
PA-220 firewalls are experiencing slower web interface and CLI performance times.
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less than the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## APPORTAL-3313
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
## APPORTAL-3309
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
## APL-15000
When you move a firewall from one Strata Logging Service instance to another, it can take up to an hour for the firewall to begin sending logs to the new instance.
@@ -6,6 +6,42 @@ source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
If you use Panorama to retrieve logs from Strata Logging Service, new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to Strata Logging Service and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
## BLANK-000000
Upgrading a PA-220 firewall takes up to an hour or more.
## BLANK-000000
PA-220 firewalls are experiencing slower web interface and CLI performance times.
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less than the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## APPORTAL-3313
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
## APPORTAL-3309
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
## APL-15000
When you move a firewall from one Strata Logging Service instance to another, it can take up to an hour for the firewall to begin sending logs to the new instance.
@@ -6,6 +6,42 @@ source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
If you use Panorama to retrieve logs from Strata Logging Service, new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to Strata Logging Service and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
## BLANK-000000
Upgrading a PA-220 firewall takes up to an hour or more.
## BLANK-000000
PA-220 firewalls are experiencing slower web interface and CLI performance times.
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less than the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## APPORTAL-3313
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
## APPORTAL-3309
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
## APL-15000
When you move a firewall from one Strata Logging Service instance to another, it can take up to an hour for the firewall to begin sending logs to the new instance.
@@ -6,6 +6,42 @@ source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
If you use Panorama to retrieve logs from Strata Logging Service, new log fields (including for Device-ID, Decryption, and GlobalProtect) are not visible on the Panorama web interface.
**Workaround:** Enable [duplicate logging](https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake/start-sending-logs-to-cortex-data-lake-panorama-managed) to send the logs to Strata Logging Service and Panorama. This workaround does not support Panorama virtual appliances in [Management Only mode](https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/panorama-overview/panorama-models.html).
## BLANK-000000
Upgrading a PA-220 firewall takes up to an hour or more.
## BLANK-000000
PA-220 firewalls are experiencing slower web interface and CLI performance times.
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less than the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## APPORTAL-3313
Changes to an IoT Security subscription license take up to 24 hours to have effect on the IoT Security app.
## APPORTAL-3309
An IoT Security production license cannot be installed on a firewall that still has a valid IoT Security eval or trial license.
**Workaround:** Wait until the 30-day eval or trial license expires and then install the production license.
## APL-15000
When you move a firewall from one Strata Logging Service instance to another, it can take up to an hour for the firewall to begin sending logs to the new instance.
@@ -0,0 +1,484 @@
---
type: Known
product: PAN-OS
version: 9.1.10
source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## PLUG-380
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
## PAN-223365
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
`admin``request restart system`
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
## PAN-199557
On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive.
**Workaround:** Manually reboot the `Active` Panorama HA peer.
## PAN-197341
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
For example:
1. You create a parent device group `DG-A` and a child device group `DG-B`.
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
## PAN-178194
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
## PAN-154266
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
## PAN-154247
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
**Workaround:** Log out and back in to the Panorama web interface.
## PAN-153803
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
## PAN-146573
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
## PAN-146485
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
## PAN-144889
```caveat
PAN-OS 9.1.2-h1 and later releases only
```
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
## PAN-140959
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
## PAN-134456
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
**Workaround:** Use a destination-based service route for the SNMP trap server.
## PAN-134053
ACC does not filter WildFire logs from Dynamic User Groups.
## PAN-130550
```caveat
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
```
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
## PAN-127813
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches dont communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
## PAN-127550
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
## PAN-127474
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
## PAN-127206
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
## PAN-124956
```caveat
This issue is now resolved. See PAN-OS 9.1.11 Addressed Issues.
```
There is an issue where VM-Series firewalls do not support packet buffer protection.
## PAN-123277
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
## PAN-123040
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules dont display. A workaround exists for this issue. Please contact Support for information about the workaround.
## PAN-120440
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
## PAN-120303
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
- Modify the PAN-DB Server IP address on the managed firewall.
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
2. **Commit** your changes.
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
4. **Commit** your changes.
- Restart the firewall (devsrvr) process.
1. Log in to the firewall CLI.
2. Restart the devsrvr process: `debug software restart process device-server`
## PAN-118065
```caveat
M-Series Panorama management servers in Management Only mode
```
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
## PAN-116017
```caveat
Google Cloud Platform (GCP) only
```
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
## PAN-115816
```caveat
Microsoft Azure only
```
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
**Workaround:** Reboot the firewall.
## PAN-114495
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
## PAN-112694
```caveat
Firewalls with multiple virtual systems only
```
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
## PAN-112456
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
## PAN-111928
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
## PAN-111866
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
**Workaround:** Perform one of the following tasks.
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
- Manually select the devices that belong to the modified device group and template configurations.
## PAN-111729
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
## PAN-111670
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
## PAN-111251
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
## PAN-110794
DGA-based threats shown in the firewall threat log display the same name for all such instances.
## PAN-109759
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
## PAN-109526
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
## PAN-106675
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
## PAN-104780
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
## PAN-103276
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
## PAN-101688
```caveat
Panorama plugins
```
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
## PAN-101537
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
**Workaround:** Specify the vsys in the query string:
`admin>` `set system target-vsys <vsys-name>`
`admin>` `show log <log-type> direction equal <direction> query equal vsys eq <vsys-name> <dst> | <src> in <object-name>`
## PAN-98520
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
## PAN-97757
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
## PAN-97524
```caveat
Panorama management server only
```
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
## PAN-96985
The `request shutdown system` command does not shut down the Panorama management server.
## PAN-96960
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
## PAN-96446
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
## PAN-95773
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
## PAN-95511
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
## PAN-95028
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
## PAN-94846
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
## PAN-94093
HTTP Header Insertion does not work when jumbo frames are received out of order.
## PAN-93968
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
## PAN-93607
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesnt list the SCTP Protection profile in its drop-down list of available profiles.
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
## PAN-93532
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
## PAN-93193
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
- Switch to the firewall **Context** on the Panorama management server.
- Commit changes when a dynamic update is being installed.
- Generate a custom report when a dynamic update is being installed.
- Generate custom reports during a commit.
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
## PAN-91802
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
## PAN-83610
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
## PAN-83236
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
## PAN-83215
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
## PAN-81521
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
## PAN-77125
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode dont close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
## PAN-75457
```caveat
PAN-OS 8.0.1 and later releases
```
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
## PAN-73530
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
## PAN-73401
```caveat
PAN-OS 8.0.1 and later releases
```
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
**Workaround:** There are three possible workarounds to sync the controller nodes:
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
- Configure a worker list on the cluster controller:
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
or
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
Both commands result in Panorama reporting that the controller nodes are in sync.
## PAN-71329
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
## PAN-70906
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
## PAN-69505
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
## PAN-41558
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
## PAN-40079
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
## PAN-39636
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
## PAN-38255
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
## PAN-31832
The following issues apply when configuring a firewall to use a hardware security module (HSM):
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
@@ -0,0 +1,476 @@
---
type: Known
product: PAN-OS
version: 9.1.11
source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## PLUG-380
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
## PAN-223365
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
`admin``request restart system`
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
## PAN-199557
On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive.
**Workaround:** Manually reboot the `Active` Panorama HA peer.
## PAN-197341
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
For example:
1. You create a parent device group `DG-A` and a child device group `DG-B`.
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
## PAN-178194
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
## PAN-154266
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
## PAN-154247
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
**Workaround:** Log out and back in to the Panorama web interface.
## PAN-153803
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
## PAN-146573
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
## PAN-146485
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
## PAN-144889
```caveat
PAN-OS 9.1.2-h1 and later releases only
```
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
## PAN-140959
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
## PAN-134456
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
**Workaround:** Use a destination-based service route for the SNMP trap server.
## PAN-134053
ACC does not filter WildFire logs from Dynamic User Groups.
## PAN-130550
```caveat
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
```
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
## PAN-127813
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches dont communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
## PAN-127550
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
## PAN-127474
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
## PAN-127206
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
## PAN-123277
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
## PAN-123040
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules dont display. A workaround exists for this issue. Please contact Support for information about the workaround.
## PAN-120440
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
## PAN-120303
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
- Modify the PAN-DB Server IP address on the managed firewall.
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
2. **Commit** your changes.
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
4. **Commit** your changes.
- Restart the firewall (devsrvr) process.
1. Log in to the firewall CLI.
2. Restart the devsrvr process: `debug software restart process device-server`
## PAN-118065
```caveat
M-Series Panorama management servers in Management Only mode
```
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
## PAN-116017
```caveat
Google Cloud Platform (GCP) only
```
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
## PAN-115816
```caveat
Microsoft Azure only
```
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
**Workaround:** Reboot the firewall.
## PAN-114495
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
## PAN-112694
```caveat
Firewalls with multiple virtual systems only
```
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
## PAN-112456
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
## PAN-111928
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
## PAN-111866
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
**Workaround:** Perform one of the following tasks.
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
- Manually select the devices that belong to the modified device group and template configurations.
## PAN-111729
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
## PAN-111670
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
## PAN-111251
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
## PAN-110794
DGA-based threats shown in the firewall threat log display the same name for all such instances.
## PAN-109759
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
## PAN-109526
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
## PAN-106675
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
## PAN-104780
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
## PAN-103276
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
## PAN-101688
```caveat
Panorama plugins
```
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
## PAN-101537
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
**Workaround:** Specify the vsys in the query string:
`admin>` `set system target-vsys <vsys-name>`
`admin>` `show log <log-type> direction equal <direction> query equal vsys eq <vsys-name> <dst> | <src> in <object-name>`
## PAN-98520
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
## PAN-97757
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
## PAN-97524
```caveat
Panorama management server only
```
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
## PAN-96985
The `request shutdown system` command does not shut down the Panorama management server.
## PAN-96960
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
## PAN-96446
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
## PAN-95773
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
## PAN-95511
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
## PAN-95028
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
## PAN-94846
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
## PAN-94093
HTTP Header Insertion does not work when jumbo frames are received out of order.
## PAN-93968
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
## PAN-93607
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesnt list the SCTP Protection profile in its drop-down list of available profiles.
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
## PAN-93532
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
## PAN-93193
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
- Switch to the firewall **Context** on the Panorama management server.
- Commit changes when a dynamic update is being installed.
- Generate a custom report when a dynamic update is being installed.
- Generate custom reports during a commit.
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
## PAN-91802
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
## PAN-83610
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
## PAN-83236
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
## PAN-83215
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
## PAN-81521
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
## PAN-77125
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode dont close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
## PAN-75457
```caveat
PAN-OS 8.0.1 and later releases
```
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
## PAN-73530
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
## PAN-73401
```caveat
PAN-OS 8.0.1 and later releases
```
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
**Workaround:** There are three possible workarounds to sync the controller nodes:
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
- Configure a worker list on the cluster controller:
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
or
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
Both commands result in Panorama reporting that the controller nodes are in sync.
## PAN-71329
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
## PAN-70906
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
## PAN-69505
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
## PAN-41558
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
## PAN-40079
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
## PAN-39636
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
## PAN-38255
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
## PAN-31832
The following issues apply when configuring a firewall to use a hardware security module (HSM):
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
@@ -0,0 +1,494 @@
---
type: Known
product: PAN-OS
version: 9.1.12
source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## PLUG-380
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
## PAN-223365
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
`admin``request restart system`
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
## PAN-199557
On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive.
**Workaround:** Manually reboot the `Active` Panorama HA peer.
## PAN-197341
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
For example:
1. You create a parent device group `DG-A` and a child device group `DG-B`.
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
## PAN-186937
```caveat
This issue is now resolved. See PAN-OS 9.1.14 Addressed Issues.
```
The firewall drops Encapsulating Security Payload (ESP) IPsec packets that originate from the same firewall. This behavior occurs when you enable **Strict IP Address Check** in the Zone Protection profile (Packet Based Attack Protection tab, IP Drop section) and the packets source IP address is the same as the egress interface address.
**Workaround**: Disable the **Strict IP Address Check** option in the Zone Protection profile. Alternatively, downgrade to 9.1.11 or earlier or upgrade to 10.0.0 or later if you want to enable the **Strict IP Address Check**.
## PAN-178194
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
## PAN-159295
```caveat
This issue is now resolved. See PAN-OS 9.1.13 Addressed Issues.
```
Scheduled configuration export files saved in the /tmp folder are not periodically purged, which causes the root partition to fill up.
## PAN-154266
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
## PAN-154247
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
**Workaround:** Log out and back in to the Panorama web interface.
## PAN-153803
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
## PAN-146573
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
## PAN-146485
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
## PAN-144889
```caveat
PAN-OS 9.1.2-h1 and later releases only
```
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
## PAN-140959
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
## PAN-134456
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
**Workaround:** Use a destination-based service route for the SNMP trap server.
## PAN-134053
ACC does not filter WildFire logs from Dynamic User Groups.
## PAN-130550
```caveat
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
```
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
## PAN-127813
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches dont communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
## PAN-127550
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
## PAN-127474
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
## PAN-127206
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
## PAN-123277
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
## PAN-123040
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules dont display. A workaround exists for this issue. Please contact Support for information about the workaround.
## PAN-120440
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
## PAN-120303
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
- Modify the PAN-DB Server IP address on the managed firewall.
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
2. **Commit** your changes.
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
4. **Commit** your changes.
- Restart the firewall (devsrvr) process.
1. Log in to the firewall CLI.
2. Restart the devsrvr process: `debug software restart process device-server`
## PAN-118065
```caveat
M-Series Panorama management servers in Management Only mode
```
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
## PAN-116017
```caveat
Google Cloud Platform (GCP) only
```
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
## PAN-115816
```caveat
Microsoft Azure only
```
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
**Workaround:** Reboot the firewall.
## PAN-114495
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
## PAN-112694
```caveat
Firewalls with multiple virtual systems only
```
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
## PAN-112456
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
## PAN-111928
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
## PAN-111866
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
**Workaround:** Perform one of the following tasks.
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
- Manually select the devices that belong to the modified device group and template configurations.
## PAN-111729
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
## PAN-111670
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
## PAN-111251
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
## PAN-110794
DGA-based threats shown in the firewall threat log display the same name for all such instances.
## PAN-109759
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
## PAN-109526
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
## PAN-106675
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
## PAN-104780
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
## PAN-103276
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
## PAN-101688
```caveat
Panorama plugins
```
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
## PAN-101537
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
**Workaround:** Specify the vsys in the query string:
`admin>` `set system target-vsys <vsys-name>`
`admin>` `show log <log-type> direction equal <direction> query equal vsys eq <vsys-name> <dst> | <src> in <object-name>`
## PAN-98520
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
## PAN-97757
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
## PAN-97524
```caveat
Panorama management server only
```
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
## PAN-96985
The `request shutdown system` command does not shut down the Panorama management server.
## PAN-96960
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
## PAN-96446
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
## PAN-95773
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
## PAN-95511
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
## PAN-95028
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
## PAN-94846
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
## PAN-94093
HTTP Header Insertion does not work when jumbo frames are received out of order.
## PAN-93968
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
## PAN-93607
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesnt list the SCTP Protection profile in its drop-down list of available profiles.
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
## PAN-93532
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
## PAN-93193
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
- Switch to the firewall **Context** on the Panorama management server.
- Commit changes when a dynamic update is being installed.
- Generate a custom report when a dynamic update is being installed.
- Generate custom reports during a commit.
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
## PAN-91802
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
## PAN-83610
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
## PAN-83236
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
## PAN-83215
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
## PAN-81521
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
## PAN-77125
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode dont close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
## PAN-75457
```caveat
PAN-OS 8.0.1 and later releases
```
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
## PAN-73530
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
## PAN-73401
```caveat
PAN-OS 8.0.1 and later releases
```
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
**Workaround:** There are three possible workarounds to sync the controller nodes:
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
- Configure a worker list on the cluster controller:
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
or
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
Both commands result in Panorama reporting that the controller nodes are in sync.
## PAN-71329
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
## PAN-70906
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
## PAN-69505
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
## PAN-41558
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
## PAN-40079
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
## PAN-39636
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
## PAN-38255
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
## PAN-31832
The following issues apply when configuring a firewall to use a hardware security module (HSM):
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
@@ -0,0 +1,498 @@
---
type: Known
product: PAN-OS
version: 9.1.15
source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## PLUG-380
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
## PAN-223365
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
`admin``request restart system`
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
## PAN-221015
On M-600 appliances in Panorama or Log Collector mode, the `es-1` and `es-2` ElasticSearch processes fail to restart when the M-600 appliance is rebooted. The results in the Managed Collector `ES` health status (**Panorama** > **Managed Collectors** > **Health Status**) to be degraded.
**Workaround:** [Log in to the Panorama or Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) experiencing degraded ElasticSearch health and restart all ElasticSearch processes.
`admin>``debug elasticsearch es-restart optional all`
## PAN-199557
On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive.
**Workaround:** Manually reboot the `Active` Panorama HA peer.
## PAN-197919
```caveat
This issue is now resolved. See PAN-OS 9.1.16 Addressed Issues.
```
When path monitoring for a static route is configured with a new Ping Interval value, that value does not get used as intended.
**Workaround**: Disable and re-enable path monitoring for that static route to change that Ping Interval value.
## PAN-197859
On firewalls running LSVPN with tunnel monitoring enabled, upgrades to 9.1.14 or later cause the LSVPN tunnels to flap.
## PAN-197341
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
For example:
1. You create a parent device group `DG-A` and a child device group `DG-B`.
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
## PAN-178194
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
## PAN-154266
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
## PAN-154247
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
**Workaround:** Log out and back in to the Panorama web interface.
## PAN-153803
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
## PAN-146573
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
## PAN-146485
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
## PAN-144889
```caveat
PAN-OS 9.1.2-h1 and later releases only
```
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
## PAN-140959
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
## PAN-134456
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
**Workaround:** Use a destination-based service route for the SNMP trap server.
## PAN-134053
ACC does not filter WildFire logs from Dynamic User Groups.
## PAN-130550
```caveat
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
```
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
## PAN-127813
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches dont communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
## PAN-127550
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
## PAN-127474
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
## PAN-127206
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
## PAN-123277
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
## PAN-123040
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules dont display. A workaround exists for this issue. Please contact Support for information about the workaround.
## PAN-120440
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
## PAN-120303
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
- Modify the PAN-DB Server IP address on the managed firewall.
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
2. **Commit** your changes.
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
4. **Commit** your changes.
- Restart the firewall (devsrvr) process.
1. Log in to the firewall CLI.
2. Restart the devsrvr process: `debug software restart process device-server`
## PAN-118065
```caveat
M-Series Panorama management servers in Management Only mode
```
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
## PAN-116017
```caveat
Google Cloud Platform (GCP) only
```
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
## PAN-115816
```caveat
Microsoft Azure only
```
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
**Workaround:** Reboot the firewall.
## PAN-114495
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
## PAN-112694
```caveat
Firewalls with multiple virtual systems only
```
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
## PAN-112456
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
## PAN-111928
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
## PAN-111866
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
**Workaround:** Perform one of the following tasks.
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
- Manually select the devices that belong to the modified device group and template configurations.
## PAN-111729
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
## PAN-111670
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
## PAN-111251
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
## PAN-110794
DGA-based threats shown in the firewall threat log display the same name for all such instances.
## PAN-109759
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
## PAN-109526
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
## PAN-106675
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
## PAN-104780
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
## PAN-103276
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
## PAN-101688
```caveat
Panorama plugins
```
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
## PAN-101537
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
**Workaround:** Specify the vsys in the query string:
`admin>` `set system target-vsys <vsys-name>`
`admin>` `show log <log-type> direction equal <direction> query equal vsys eq <vsys-name> <dst> | <src> in <object-name>`
## PAN-98520
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
## PAN-97757
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
## PAN-97524
```caveat
Panorama management server only
```
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
## PAN-96985
The `request shutdown system` command does not shut down the Panorama management server.
## PAN-96960
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
## PAN-96446
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
## PAN-95773
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
## PAN-95511
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
## PAN-95028
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
## PAN-94846
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
## PAN-94093
HTTP Header Insertion does not work when jumbo frames are received out of order.
## PAN-93968
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
## PAN-93607
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesnt list the SCTP Protection profile in its drop-down list of available profiles.
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
## PAN-93532
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
## PAN-93193
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
- Switch to the firewall **Context** on the Panorama management server.
- Commit changes when a dynamic update is being installed.
- Generate a custom report when a dynamic update is being installed.
- Generate custom reports during a commit.
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
## PAN-91802
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
## PAN-83610
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
## PAN-83236
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
## PAN-83215
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
## PAN-81521
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
## PAN-77125
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode dont close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
## PAN-75457
```caveat
PAN-OS 8.0.1 and later releases
```
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
## PAN-73530
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
## PAN-73401
```caveat
PAN-OS 8.0.1 and later releases
```
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
**Workaround:** There are three possible workarounds to sync the controller nodes:
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
- Configure a worker list on the cluster controller:
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
or
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
Both commands result in Panorama reporting that the controller nodes are in sync.
## PAN-71329
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
## PAN-70906
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
## PAN-69505
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
## PAN-41558
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
## PAN-40079
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
## PAN-39636
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
## PAN-38255
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
## PAN-31832
The following issues apply when configuring a firewall to use a hardware security module (HSM):
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
@@ -0,0 +1,482 @@
---
type: Known
product: PAN-OS
version: 9.1.16
source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## PLUG-380
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
## PAN-223365
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
`admin``request restart system`
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
## PAN-221015
On M-600 appliances in Panorama or Log Collector mode, the `es-1` and `es-2` ElasticSearch processes fail to restart when the M-600 appliance is rebooted. The results in the Managed Collector `ES` health status (**Panorama** > **Managed Collectors** > **Health Status**) to be degraded.
**Workaround:** [Log in to the Panorama or Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) experiencing degraded ElasticSearch health and restart all ElasticSearch processes.
`admin>``debug elasticsearch es-restart optional all`
## PAN-197859
On firewalls running LSVPN with tunnel monitoring enabled, upgrades to 9.1.14 or later cause the LSVPN tunnels to flap.
## PAN-197341
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
For example:
1. You create a parent device group `DG-A` and a child device group `DG-B`.
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
## PAN-178194
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
## PAN-154266
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
## PAN-154247
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
**Workaround:** Log out and back in to the Panorama web interface.
## PAN-153803
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
## PAN-146573
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
## PAN-146485
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
## PAN-144889
```caveat
PAN-OS 9.1.2-h1 and later releases only
```
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
## PAN-140959
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
## PAN-134456
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
**Workaround:** Use a destination-based service route for the SNMP trap server.
## PAN-134053
ACC does not filter WildFire logs from Dynamic User Groups.
## PAN-130550
```caveat
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
```
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
## PAN-127813
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches dont communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
## PAN-127550
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
## PAN-127474
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
## PAN-127206
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
## PAN-123277
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
## PAN-123040
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules dont display. A workaround exists for this issue. Please contact Support for information about the workaround.
## PAN-120440
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
## PAN-120303
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
- Modify the PAN-DB Server IP address on the managed firewall.
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
2. **Commit** your changes.
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
4. **Commit** your changes.
- Restart the firewall (devsrvr) process.
1. Log in to the firewall CLI.
2. Restart the devsrvr process: `debug software restart process device-server`
## PAN-118065
```caveat
M-Series Panorama management servers in Management Only mode
```
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
## PAN-116017
```caveat
Google Cloud Platform (GCP) only
```
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
## PAN-115816
```caveat
Microsoft Azure only
```
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
**Workaround:** Reboot the firewall.
## PAN-114495
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
## PAN-112694
```caveat
Firewalls with multiple virtual systems only
```
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
## PAN-112456
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
## PAN-111928
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
## PAN-111866
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
**Workaround:** Perform one of the following tasks.
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
- Manually select the devices that belong to the modified device group and template configurations.
## PAN-111729
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
## PAN-111670
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
## PAN-111251
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
## PAN-110794
DGA-based threats shown in the firewall threat log display the same name for all such instances.
## PAN-109759
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
## PAN-109526
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
## PAN-106675
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
## PAN-104780
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
## PAN-103276
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
## PAN-101688
```caveat
Panorama plugins
```
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
## PAN-101537
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
**Workaround:** Specify the vsys in the query string:
`admin>` `set system target-vsys <vsys-name>`
`admin>` `show log <log-type> direction equal <direction> query equal vsys eq <vsys-name> <dst> | <src> in <object-name>`
## PAN-98520
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
## PAN-97757
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
## PAN-97524
```caveat
Panorama management server only
```
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
## PAN-96985
The `request shutdown system` command does not shut down the Panorama management server.
## PAN-96960
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
## PAN-96446
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
## PAN-95773
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
## PAN-95511
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
## PAN-95028
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
## PAN-94846
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
## PAN-94093
HTTP Header Insertion does not work when jumbo frames are received out of order.
## PAN-93968
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
## PAN-93607
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesnt list the SCTP Protection profile in its drop-down list of available profiles.
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
## PAN-93532
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
## PAN-93193
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
- Switch to the firewall **Context** on the Panorama management server.
- Commit changes when a dynamic update is being installed.
- Generate a custom report when a dynamic update is being installed.
- Generate custom reports during a commit.
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
## PAN-91802
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
## PAN-83610
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
## PAN-83236
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
## PAN-83215
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
## PAN-81521
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
## PAN-77125
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode dont close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
## PAN-75457
```caveat
PAN-OS 8.0.1 and later releases
```
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
## PAN-73530
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
## PAN-73401
```caveat
PAN-OS 8.0.1 and later releases
```
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
**Workaround:** There are three possible workarounds to sync the controller nodes:
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
- Configure a worker list on the cluster controller:
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
or
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
Both commands result in Panorama reporting that the controller nodes are in sync.
## PAN-71329
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
## PAN-70906
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
## PAN-69505
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
## PAN-41558
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
## PAN-40079
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
## PAN-39636
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
## PAN-38255
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
## PAN-31832
The following issues apply when configuring a firewall to use a hardware security module (HSM):
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
@@ -0,0 +1,492 @@
---
type: Known
product: PAN-OS
version: 9.1.17
source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## PLUG-380
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
## PAN-242561
```caveat
This issue is now resolved. See PAN-OS 9.1.18 Addressed Issues.
```
GlobalProtect tunnel might disconnect shortly after being established when SSL is used as a transport protocol.
**Workaround**: Disable Internet Protocol version 6 (TCP/IPv6) on the PANGP Virtual Network Adapter.
## PAN-223365
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
`admin``request restart system`
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
## PAN-221015
On M-600 appliances in Panorama or Log Collector mode, the `es-1` and `es-2` ElasticSearch processes fail to restart when the M-600 appliance is rebooted. The results in the Managed Collector `ES` health status (**Panorama** > **Managed Collectors** > **Health Status**) to be degraded.
**Workaround:** [Log in to the Panorama or Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) experiencing degraded ElasticSearch health and restart all ElasticSearch processes.
`admin>``debug elasticsearch es-restart optional all`
## PAN-197859
On firewalls running LSVPN with tunnel monitoring enabled, upgrades to 9.1.14 or later cause the LSVPN tunnels to flap.
## PAN-197341
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
For example:
1. You create a parent device group `DG-A` and a child device group `DG-B`.
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
## PAN-178194
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
## PAN-154266
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
## PAN-154247
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
**Workaround:** Log out and back in to the Panorama web interface.
## PAN-153803
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
## PAN-146573
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
## PAN-146485
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
## PAN-144889
```caveat
PAN-OS 9.1.2-h1 and later releases only
```
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
## PAN-140959
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
## PAN-134456
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
**Workaround:** Use a destination-based service route for the SNMP trap server.
## PAN-134053
ACC does not filter WildFire logs from Dynamic User Groups.
## PAN-130550
```caveat
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
```
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
## PAN-127813
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches dont communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
## PAN-127550
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
## PAN-127474
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
## PAN-127206
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
## PAN-123277
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
## PAN-123040
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules dont display. A workaround exists for this issue. Please contact Support for information about the workaround.
## PAN-120440
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
## PAN-120303
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
- Modify the PAN-DB Server IP address on the managed firewall.
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
2. **Commit** your changes.
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
4. **Commit** your changes.
- Restart the firewall (devsrvr) process.
1. Log in to the firewall CLI.
2. Restart the devsrvr process: `debug software restart process device-server`
## PAN-118065
```caveat
M-Series Panorama management servers in Management Only mode
```
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
## PAN-116017
```caveat
Google Cloud Platform (GCP) only
```
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
## PAN-115816
```caveat
Microsoft Azure only
```
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
**Workaround:** Reboot the firewall.
## PAN-114495
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
## PAN-112694
```caveat
Firewalls with multiple virtual systems only
```
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
## PAN-112456
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
## PAN-111928
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
## PAN-111866
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
**Workaround:** Perform one of the following tasks.
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
- Manually select the devices that belong to the modified device group and template configurations.
## PAN-111729
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
## PAN-111670
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
## PAN-111251
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
## PAN-110794
DGA-based threats shown in the firewall threat log display the same name for all such instances.
## PAN-109759
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
## PAN-109526
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
## PAN-106675
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
## PAN-104780
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
## PAN-103276
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
## PAN-101688
```caveat
Panorama plugins
```
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
## PAN-101537
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
**Workaround:** Specify the vsys in the query string:
`admin>` `set system target-vsys <vsys-name>`
`admin>` `show log <log-type> direction equal <direction> query equal vsys eq <vsys-name> <dst> | <src> in <object-name>`
## PAN-98520
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
## PAN-97757
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
## PAN-97524
```caveat
Panorama management server only
```
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
## PAN-96985
The `request shutdown system` command does not shut down the Panorama management server.
## PAN-96960
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
## PAN-96446
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
## PAN-95773
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
## PAN-95511
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
## PAN-95028
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
## PAN-94846
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
## PAN-94093
HTTP Header Insertion does not work when jumbo frames are received out of order.
## PAN-93968
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
## PAN-93607
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesnt list the SCTP Protection profile in its drop-down list of available profiles.
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
## PAN-93532
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
## PAN-93193
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
- Switch to the firewall **Context** on the Panorama management server.
- Commit changes when a dynamic update is being installed.
- Generate a custom report when a dynamic update is being installed.
- Generate custom reports during a commit.
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
## PAN-91802
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
## PAN-83610
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
## PAN-83236
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
## PAN-83215
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
## PAN-81521
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
## PAN-77125
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode dont close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
## PAN-75457
```caveat
PAN-OS 8.0.1 and later releases
```
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
## PAN-73530
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
## PAN-73401
```caveat
PAN-OS 8.0.1 and later releases
```
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
**Workaround:** There are three possible workarounds to sync the controller nodes:
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
- Configure a worker list on the cluster controller:
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
or
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
Both commands result in Panorama reporting that the controller nodes are in sync.
## PAN-71329
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
## PAN-70906
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
## PAN-69505
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
## PAN-41558
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
## PAN-40079
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
## PAN-39636
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
## PAN-38255
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
## PAN-31832
The following issues apply when configuring a firewall to use a hardware security module (HSM):
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
@@ -0,0 +1,482 @@
---
type: Known
product: PAN-OS
version: 9.1.18
source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## PLUG-380
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
## PAN-223365
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
`admin``request restart system`
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
## PAN-221015
On M-600 appliances in Panorama or Log Collector mode, the `es-1` and `es-2` ElasticSearch processes fail to restart when the M-600 appliance is rebooted. The results in the Managed Collector `ES` health status (**Panorama** > **Managed Collectors** > **Health Status**) to be degraded.
**Workaround:** [Log in to the Panorama or Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) experiencing degraded ElasticSearch health and restart all ElasticSearch processes.
`admin>``debug elasticsearch es-restart optional all`
## PAN-197859
On firewalls running LSVPN with tunnel monitoring enabled, upgrades to 9.1.14 or later cause the LSVPN tunnels to flap.
## PAN-197341
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
For example:
1. You create a parent device group `DG-A` and a child device group `DG-B`.
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
## PAN-178194
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
## PAN-154266
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
## PAN-154247
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
**Workaround:** Log out and back in to the Panorama web interface.
## PAN-153803
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
## PAN-146573
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
## PAN-146485
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
## PAN-144889
```caveat
PAN-OS 9.1.2-h1 and later releases only
```
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
## PAN-140959
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
## PAN-134456
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
**Workaround:** Use a destination-based service route for the SNMP trap server.
## PAN-134053
ACC does not filter WildFire logs from Dynamic User Groups.
## PAN-130550
```caveat
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
```
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
## PAN-127813
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches dont communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
## PAN-127550
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
## PAN-127474
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
## PAN-127206
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
## PAN-123277
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
## PAN-123040
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules dont display. A workaround exists for this issue. Please contact Support for information about the workaround.
## PAN-120440
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
## PAN-120303
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
- Modify the PAN-DB Server IP address on the managed firewall.
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
2. **Commit** your changes.
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
4. **Commit** your changes.
- Restart the firewall (devsrvr) process.
1. Log in to the firewall CLI.
2. Restart the devsrvr process: `debug software restart process device-server`
## PAN-118065
```caveat
M-Series Panorama management servers in Management Only mode
```
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
## PAN-116017
```caveat
Google Cloud Platform (GCP) only
```
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
## PAN-115816
```caveat
Microsoft Azure only
```
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
**Workaround:** Reboot the firewall.
## PAN-114495
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
## PAN-112694
```caveat
Firewalls with multiple virtual systems only
```
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
## PAN-112456
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
## PAN-111928
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
## PAN-111866
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
**Workaround:** Perform one of the following tasks.
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
- Manually select the devices that belong to the modified device group and template configurations.
## PAN-111729
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
## PAN-111670
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
## PAN-111251
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
## PAN-110794
DGA-based threats shown in the firewall threat log display the same name for all such instances.
## PAN-109759
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
## PAN-109526
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
## PAN-106675
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
## PAN-104780
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
## PAN-103276
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
## PAN-101688
```caveat
Panorama plugins
```
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
## PAN-101537
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
**Workaround:** Specify the vsys in the query string:
`admin>` `set system target-vsys <vsys-name>`
`admin>` `show log <log-type> direction equal <direction> query equal vsys eq <vsys-name> <dst> | <src> in <object-name>`
## PAN-98520
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
## PAN-97757
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
## PAN-97524
```caveat
Panorama management server only
```
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
## PAN-96985
The `request shutdown system` command does not shut down the Panorama management server.
## PAN-96960
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
## PAN-96446
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
## PAN-95773
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
## PAN-95511
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
## PAN-95028
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
## PAN-94846
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
## PAN-94093
HTTP Header Insertion does not work when jumbo frames are received out of order.
## PAN-93968
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
## PAN-93607
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesnt list the SCTP Protection profile in its drop-down list of available profiles.
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
## PAN-93532
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
## PAN-93193
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
- Switch to the firewall **Context** on the Panorama management server.
- Commit changes when a dynamic update is being installed.
- Generate a custom report when a dynamic update is being installed.
- Generate custom reports during a commit.
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
## PAN-91802
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
## PAN-83610
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
## PAN-83236
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
## PAN-83215
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
## PAN-81521
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
## PAN-77125
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode dont close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
## PAN-75457
```caveat
PAN-OS 8.0.1 and later releases
```
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
## PAN-73530
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
## PAN-73401
```caveat
PAN-OS 8.0.1 and later releases
```
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
**Workaround:** There are three possible workarounds to sync the controller nodes:
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
- Configure a worker list on the cluster controller:
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
or
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
Both commands result in Panorama reporting that the controller nodes are in sync.
## PAN-71329
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
## PAN-70906
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
## PAN-69505
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
## PAN-41558
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
## PAN-40079
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
## PAN-39636
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
## PAN-38255
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
## PAN-31832
The following issues apply when configuring a firewall to use a hardware security module (HSM):
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
@@ -0,0 +1,517 @@
---
type: Known
product: PAN-OS
version: 9.1.1
source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## PLUG-380
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
## PAN-223365
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
`admin``request restart system`
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
## PAN-199557
On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive.
**Workaround:** Manually reboot the `Active` Panorama HA peer.
## PAN-197341
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
For example:
1. You create a parent device group `DG-A` and a child device group `DG-B`.
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
## PAN-178194
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
## PAN-157240
When a firewall has hardware offloading turned on and OSPF enabled, if ECMP is enabled or disabled for a virtual router during a configuration commit, OSPF sessions may get stuck in Exchange Start state.
**Workaround:** Disable OSPF when enabling or disabling ECMP, and then re-enable OSPF in the next commit.
## PAN-154247
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
**Workaround:** Log out and back in to the Panorama web interface.
## PAN-153803
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
## PAN-151198
On the Panorama management server, read-only Panorama administrators (**Panorama** > **Administrators**) can load managed firewall configuration Backups (**Panorama** > **Managed Devices** > **Summary**).
## PAN-146573
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
## PAN-140084
```caveat
This issue is now resolved. See PAN-OS 9.1.5 Addressed Issues.
```
There is an issue where the default Dynamic IP and Port (DIPP) NAT oversubscription rate is set to 2.
## PAN-136763
On the Panorama management server, managed firewalls display as `disconnected` when installing a PAN-OS software update (**Panorama** > **Device Deployment** > **Software**) but display as `connected` when you view your managed firewalls Summary (**Panorama** > **Managed Devices** > **Summary**) and from the CLI.
**Workaround:** Log out and log back in to the Panorama web interface.
## PAN-136701
```caveat
PA-7000b Series firewalls only
```
Packets for new sessions drop when handling predict sessions.
**Workaround:** (PAN-OS 9.1.3 and later versions only) Use the following CLi commands to bypass this issue:
- `set session hwpredict disable yes`
- `show session hwpredict status`
## PAN-135260
```caveat
PA-7000 Series firewalls only
```
There is an intermittent issue where the dataplane process (all_pktproc_X) on a Network Processing Card (NPC) restarts unexpectedly when processing IPSec tunnel traffic. This issue can occur on any NPC card in any slot.
## PAN-134456
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
**Workaround:** Use a destination-based service route for the SNMP trap server.
## PAN-134053
ACC does not filter WildFire logs from Dynamic User Groups.
## PAN-130550
```caveat
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
```
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
## PAN-127813
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches dont communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
## PAN-127550
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
## PAN-127474
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
## PAN-127206
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
## PAN-124956
```caveat
This issue is now resolved. See PAN-OS 9.1.11 Addressed Issues.
```
There is an issue where VM-Series firewalls do not support packet buffer protection.
## PAN-123277
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
## PAN-123040
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules dont display. A workaround exists for this issue. Please contact Support for information about the workaround.
## PAN-120440
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
## PAN-120423
```caveat
This issue is now resolved. See PAN-OS 9.1.9 Addressed Issues.
```
PAN-OS 9.1.0 does not support the XML API for GlobalProtect logs.
## PAN-120303
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
- Modify the PAN-DB Server IP address on the managed firewall.
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
2. **Commit** your changes.
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
4. **Commit** your changes.
- Restart the firewall (devsrvr) process.
1. Log in to the firewall CLI.
2. Restart the devsrvr process: `debug software restart process device-server`
## PAN-118065
```caveat
M-Series Panorama management servers in Management Only mode
```
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
## PAN-116017
```caveat
Google Cloud Platform (GCP) only
```
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
## PAN-115816
```caveat
Microsoft Azure only
```
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
**Workaround:** Reboot the firewall.
## PAN-114495
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
## PAN-112694
```caveat
Firewalls with multiple virtual systems only
```
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
## PAN-112456
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
## PAN-111928
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
## PAN-111866
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
**Workaround:** Perform one of the following tasks.
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
- Manually select the devices that belong to the modified device group and template configurations.
## PAN-111729
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
## PAN-111670
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
## PAN-111251
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
## PAN-110794
DGA-based threats shown in the firewall threat log display the same name for all such instances.
## PAN-109759
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
## PAN-109526
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
## PAN-106675
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
## PAN-104780
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
## PAN-103276
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
## PAN-103018
```caveat
Panorama plugins
```
When you use the AND/OR boolean operators to define the match criteria for Dynamic Address Groups on Panorama, the boolean operators do not function properly. The member IP addresses are not included in the address group as expected.
## PAN-101688
```caveat
Panorama plugins
```
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
## PAN-101537
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
**Workaround:** Specify the vsys in the query string:
`admin>` `set system target-vsys <vsys-name>`
`admin>` `show log <log-type> direction equal <direction> query equal vsys eq <vsys-name> <dst> | <src> in <object-name>`
## PAN-98520
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
## PAN-97757
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
## PAN-97524
```caveat
Panorama management server only
```
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
## PAN-96985
The `request shutdown system` command does not shut down the Panorama management server.
## PAN-96960
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
## PAN-96446
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
## PAN-95773
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
## PAN-95511
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
## PAN-95028
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
## PAN-94846
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
## PAN-94093
HTTP Header Insertion does not work when jumbo frames are received out of order.
## PAN-93968
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
## PAN-93607
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesnt list the SCTP Protection profile in its drop-down list of available profiles.
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
## PAN-93532
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
## PAN-93193
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
- Switch to the firewall **Context** on the Panorama management server.
- Commit changes when a dynamic update is being installed.
- Generate a custom report when a dynamic update is being installed.
- Generate custom reports during a commit.
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
## PAN-91802
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
## PAN-83610
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
## PAN-83236
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
## PAN-83215
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
## PAN-81521
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
## PAN-77125
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode dont close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
## PAN-75457
```caveat
PAN-OS 8.0.1 and later releases
```
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
## PAN-73530
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
## PAN-73401
```caveat
PAN-OS 8.0.1 and later releases
```
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
**Workaround:** There are three possible workarounds to sync the controller nodes:
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
- Configure a worker list on the cluster controller:
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
or
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
Both commands result in Panorama reporting that the controller nodes are in sync.
## PAN-71329
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
## PAN-70906
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
## PAN-69505
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
## PAN-41558
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
## PAN-40079
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
## PAN-39636
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
## PAN-38255
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
## PAN-31832
The following issues apply when configuring a firewall to use a hardware security module (HSM):
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
@@ -0,0 +1,515 @@
---
type: Known
product: PAN-OS
version: 9.1.2
source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## PLUG-380
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
## PAN-223365
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
`admin``request restart system`
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
## PAN-199557
On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive.
**Workaround:** Manually reboot the `Active` Panorama HA peer.
## PAN-197341
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
For example:
1. You create a parent device group `DG-A` and a child device group `DG-B`.
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
## PAN-178194
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
## PAN-154247
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
**Workaround:** Log out and back in to the Panorama web interface.
## PAN-153803
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
## PAN-151909
```caveat
This issue is now resolved. See PAN-OS 9.1.10 Addressed Issues.
```
On the Panorama management server, Preview Changes (**Commit** > **Commit to Panorama**) incorrectly displays an existing route as Added and the new route as an existing route in the Candidate Configuration when you configure a new virtual router route (**Network** > **Virtual Router**).
## PAN-146573
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
## PAN-144889
```caveat
PAN-OS 9.1.2-h1 and later releases only
```
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
## PAN-144073
On the Panorama management server, hub and branch firewall latency, jitter, and packet loss data is not updated when monitoring SD-WAN link performance (**Panorama** > **SD-WAN** > **Monitoring**).
## PAN-140084
```caveat
This issue is now resolved. See PAN-OS 9.1.5 Addressed Issues.
```
There is an issue where the default Dynamic IP and Port (DIPP) NAT oversubscription rate is set to 2.
## PAN-136701
```caveat
PA-7000b Series firewalls only
```
Packets for new sessions drop when handling predict sessions.
**Workaround:** (PAN-OS 9.1.3 and later versions only) Use the following CLi commands to bypass this issue:
- `set session hwpredict disable yes`
- `show session hwpredict status`
## PAN-134456
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
**Workaround:** Use a destination-based service route for the SNMP trap server.
## PAN-134053
ACC does not filter WildFire logs from Dynamic User Groups.
## PAN-130550
```caveat
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
```
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
## PAN-127813
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches dont communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
## PAN-127550
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
## PAN-127474
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
## PAN-127206
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
## PAN-124956
```caveat
This issue is now resolved. See PAN-OS 9.1.11 Addressed Issues.
```
There is an issue where VM-Series firewalls do not support packet buffer protection.
## PAN-123277
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
## PAN-123040
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules dont display. A workaround exists for this issue. Please contact Support for information about the workaround.
## PAN-120440
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
## PAN-120423
```caveat
This issue is now resolved. See PAN-OS 9.1.9 Addressed Issues.
```
PAN-OS 9.1.0 does not support the XML API for GlobalProtect logs.
## PAN-120303
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
- Modify the PAN-DB Server IP address on the managed firewall.
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
2. **Commit** your changes.
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
4. **Commit** your changes.
- Restart the firewall (devsrvr) process.
1. Log in to the firewall CLI.
2. Restart the devsrvr process: `debug software restart process device-server`
## PAN-118065
```caveat
M-Series Panorama management servers in Management Only mode
```
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
## PAN-116017
```caveat
Google Cloud Platform (GCP) only
```
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
## PAN-115816
```caveat
Microsoft Azure only
```
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
**Workaround:** Reboot the firewall.
## PAN-114495
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
## PAN-112694
```caveat
Firewalls with multiple virtual systems only
```
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
## PAN-112456
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
## PAN-111928
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
## PAN-111866
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
**Workaround:** Perform one of the following tasks.
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
- Manually select the devices that belong to the modified device group and template configurations.
## PAN-111729
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
## PAN-111670
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
## PAN-111251
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
## PAN-110794
DGA-based threats shown in the firewall threat log display the same name for all such instances.
## PAN-109759
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
## PAN-109526
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
## PAN-106675
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
## PAN-104780
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
## PAN-103276
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
## PAN-103018
```caveat
Panorama plugins
```
When you use the AND/OR boolean operators to define the match criteria for Dynamic Address Groups on Panorama, the boolean operators do not function properly. The member IP addresses are not included in the address group as expected.
## PAN-101688
```caveat
Panorama plugins
```
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
## PAN-101537
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
**Workaround:** Specify the vsys in the query string:
`admin>` `set system target-vsys <vsys-name>`
`admin>` `show log <log-type> direction equal <direction> query equal vsys eq <vsys-name> <dst> | <src> in <object-name>`
## PAN-98520
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
## PAN-97757
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
## PAN-97524
```caveat
Panorama management server only
```
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
## PAN-96985
The `request shutdown system` command does not shut down the Panorama management server.
## PAN-96960
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
## PAN-96446
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
## PAN-95773
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
## PAN-95511
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
## PAN-95028
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
## PAN-94846
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
## PAN-94093
HTTP Header Insertion does not work when jumbo frames are received out of order.
## PAN-93968
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
## PAN-93607
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesnt list the SCTP Protection profile in its drop-down list of available profiles.
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
## PAN-93532
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
## PAN-93193
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
- Switch to the firewall **Context** on the Panorama management server.
- Commit changes when a dynamic update is being installed.
- Generate a custom report when a dynamic update is being installed.
- Generate custom reports during a commit.
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
## PAN-91802
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
## PAN-83610
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
## PAN-83236
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
## PAN-83215
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
## PAN-81521
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
## PAN-77125
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode dont close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
## PAN-75457
```caveat
PAN-OS 8.0.1 and later releases
```
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
## PAN-73530
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
## PAN-73401
```caveat
PAN-OS 8.0.1 and later releases
```
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
**Workaround:** There are three possible workarounds to sync the controller nodes:
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
- Configure a worker list on the cluster controller:
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
or
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
Both commands result in Panorama reporting that the controller nodes are in sync.
## PAN-71329
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
## PAN-70906
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
## PAN-69505
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
## PAN-41558
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
## PAN-40079
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
## PAN-39636
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
## PAN-38255
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
## PAN-31832
The following issues apply when configuring a firewall to use a hardware security module (HSM):
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
@@ -0,0 +1,551 @@
---
type: Known
product: PAN-OS
version: 9.1.3
source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## PLUG-380
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
## PAN-223365
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
`admin``request restart system`
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
## PAN-199557
On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive.
**Workaround:** Manually reboot the `Active` Panorama HA peer.
## PAN-197341
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
For example:
1. You create a parent device group `DG-A` and a child device group `DG-B`.
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
## PAN-178194
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
## PAN-154266
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
## PAN-154247
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
**Workaround:** Log out and back in to the Panorama web interface.
## PAN-153803
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
## PAN-151909
```caveat
This issue is now resolved. See PAN-OS 9.1.10 Addressed Issues.
```
On the Panorama management server, Preview Changes (**Commit** > **Commit to Panorama**) incorrectly displays an existing route as Added and the new route as an existing route in the Candidate Configuration when you configure a new virtual router route (**Network** > **Virtual Router**).
## PAN-150172
```caveat
This issue is now resolved. See PAN-OS 9.1.3-h1 Addressed Issues.
```
Dataplane processes restart when attempting to access websites that have the `NotBefore` attribute less than or equal to Unix Epoch Time in the server certificate with forward proxy enabled.
## PAN-149913
On the firewall CLI, the `show system info` command displays the management IP address of the firewall as the Ethernet1/1 interface IP address.
On the Panorama management server, the IPv4 address (**Panorama** > **Managed Devices** > **Summary**) displays the Ethernet1/1 interface IP address.
## PAN-146573
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
## PAN-146485
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
## PAN-144889
```caveat
PAN-OS 9.1.2-h1 and later releases only
```
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
## PAN-140959
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
## PAN-140084
```caveat
This issue is now resolved. See PAN-OS 9.1.5 Addressed Issues.
```
There is an issue where the default Dynamic IP and Port (DIPP) NAT oversubscription rate is set to 2.
## PAN-136701
```caveat
PA-7000b Series firewalls only
```
Packets for new sessions drop when handling predict sessions.
**Workaround:** Use the following CLi commands to bypass this issue:
- `set session hwpredict disable yes`
- `show session hwpredict status`
## PAN-134456
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
**Workaround:** Use a destination-based service route for the SNMP trap server.
## PAN-134053
ACC does not filter WildFire logs from Dynamic User Groups.
## PAN-130550
```caveat
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
```
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
## PAN-127813
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches dont communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
## PAN-127550
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
## PAN-127474
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
## PAN-127206
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
## PAN-124956
```caveat
This issue is now resolved. See PAN-OS 9.1.11 Addressed Issues.
```
There is an issue where VM-Series firewalls do not support packet buffer protection.
## PAN-123277
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
## PAN-123040
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules dont display. A workaround exists for this issue. Please contact Support for information about the workaround.
## PAN-121484
```caveat
This issue is now resolved. See PAN-OS 9.1.6 Addressed Issues.
```
The dataplane sends positive acknowledgments to predict-status checks from FPP when the corresponding predict is deleted, which causes SIP and RTSP applications to perform less than the expected achievable performance.
## PAN-120440
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
## PAN-120423
```caveat
This issue is now resolved. See PAN-OS 9.1.9 Addressed Issues.
```
PAN-OS 9.1.0 does not support the XML API for GlobalProtect logs.
## PAN-120303
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
- Modify the PAN-DB Server IP address on the managed firewall.
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
2. **Commit** your changes.
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
4. **Commit** your changes.
- Restart the firewall (devsrvr) process.
1. Log in to the firewall CLI.
2. Restart the devsrvr process: `debug software restart process device-server`
## PAN-118065
```caveat
M-Series Panorama management servers in Management Only mode
```
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
## PAN-116017
```caveat
Google Cloud Platform (GCP) only
```
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
## PAN-115816
```caveat
Microsoft Azure only
```
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
**Workaround:** Reboot the firewall.
## PAN-114495
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
## PAN-112694
```caveat
Firewalls with multiple virtual systems only
```
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
## PAN-112456
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
## PAN-111928
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
## PAN-111866
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
**Workaround:** Perform one of the following tasks.
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
- Manually select the devices that belong to the modified device group and template configurations.
## PAN-111729
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
## PAN-111670
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
## PAN-111251
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
## PAN-110794
DGA-based threats shown in the firewall threat log display the same name for all such instances.
## PAN-109759
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
## PAN-109526
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
## PAN-106675
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
## PAN-104780
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
## PAN-103276
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
## PAN-103018
```caveat
Panorama plugins
```
When you use the AND/OR boolean operators to define the match criteria for Dynamic Address Groups on Panorama, the boolean operators do not function properly. The member IP addresses are not included in the address group as expected.
## PAN-101688
```caveat
Panorama plugins
```
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
## PAN-101537
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
**Workaround:** Specify the vsys in the query string:
`admin>` `set system target-vsys <vsys-name>`
`admin>` `show log <log-type> direction equal <direction> query equal vsys eq <vsys-name> <dst> | <src> in <object-name>`
## PAN-98520
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
## PAN-97757
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
## PAN-97524
```caveat
Panorama management server only
```
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
## PAN-96985
The `request shutdown system` command does not shut down the Panorama management server.
## PAN-96960
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
## PAN-96446
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
## PAN-95773
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
## PAN-95511
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
## PAN-95028
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
## PAN-94846
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
## PAN-94093
HTTP Header Insertion does not work when jumbo frames are received out of order.
## PAN-93968
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
## PAN-93607
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesnt list the SCTP Protection profile in its drop-down list of available profiles.
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
## PAN-93532
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
## PAN-93193
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
- Switch to the firewall **Context** on the Panorama management server.
- Commit changes when a dynamic update is being installed.
- Generate a custom report when a dynamic update is being installed.
- Generate custom reports during a commit.
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
## PAN-91802
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
## PAN-83610
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
## PAN-83236
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
## PAN-83215
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
## PAN-81521
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
## PAN-77125
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode dont close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
## PAN-75457
```caveat
PAN-OS 8.0.1 and later releases
```
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
## PAN-73530
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
## PAN-73401
```caveat
PAN-OS 8.0.1 and later releases
```
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
**Workaround:** There are three possible workarounds to sync the controller nodes:
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
- Configure a worker list on the cluster controller:
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
or
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
Both commands result in Panorama reporting that the controller nodes are in sync.
## PAN-71329
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
## PAN-70906
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
## PAN-69505
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
## PAN-41558
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
## PAN-40079
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
## PAN-39636
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
## PAN-38255
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
## PAN-31832
The following issues apply when configuring a firewall to use a hardware security module (HSM):
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
@@ -0,0 +1,529 @@
---
type: Known
product: PAN-OS
version: 9.1.5
source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## PLUG-380
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
## PAN-223365
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
`admin``request restart system`
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
## PAN-199557
On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive.
**Workaround:** Manually reboot the `Active` Panorama HA peer.
## PAN-197341
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
For example:
1. You create a parent device group `DG-A` and a child device group `DG-B`.
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
## PAN-178194
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
## PAN-154266
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
## PAN-154247
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
**Workaround:** Log out and back in to the Panorama web interface.
## PAN-153803
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
## PAN-151909
```caveat
This issue is now resolved. See PAN-OS 9.1.10 Addressed Issues.
```
On the Panorama management server, Preview Changes (**Commit** > **Commit to Panorama**) incorrectly displays an existing route as Added and the new route as an existing route in the Candidate Configuration when you configure a new virtual router route (**Network** > **Virtual Router**).
## PAN-148359
```caveat
This issue is now resolved. See PAN-OS 9.1.8 Addressed Issues.
```
SD-WAN server-to-client symmetric return does not function correctly under certain circumstances, and the issue can also affect path selection of parent/child applications, such as FTP.
## PAN-146573
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
## PAN-146485
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
## PAN-144889
```caveat
PAN-OS 9.1.2-h1 and later releases only
```
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
## PAN-140959
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
## PAN-136701
```caveat
PA-7000b Series firewalls only
```
Packets for new sessions drop when handling predict sessions.
**Workaround:** Use the following CLi commands to bypass this issue:
- `set session hwpredict disable yes`
- `show session hwpredict status`
## PAN-134456
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
**Workaround:** Use a destination-based service route for the SNMP trap server.
## PAN-134053
ACC does not filter WildFire logs from Dynamic User Groups.
## PAN-130550
```caveat
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
```
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
## PAN-127813
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches dont communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
## PAN-127550
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
## PAN-127474
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
## PAN-127206
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
## PAN-124956
```caveat
This issue is now resolved. See PAN-OS 9.1.11 Addressed Issues.
```
There is an issue where VM-Series firewalls do not support packet buffer protection.
## PAN-123277
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
## PAN-123040
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules dont display. A workaround exists for this issue. Please contact Support for information about the workaround.
## PAN-121484
```caveat
This issue is now resolved. See PAN-OS 9.1.6 Addressed Issues.
```
The dataplane sends positive acknowledgments to predict-status checks from FPP when the corresponding predict is deleted, which causes SIP and RTSP applications to perform less than the expected achievable performance.
## PAN-120440
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
## PAN-120423
```caveat
This issue is now resolved. See PAN-OS 9.1.9 Addressed Issues.
```
PAN-OS 9.1.0 does not support the XML API for GlobalProtect logs.
## PAN-120303
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
- Modify the PAN-DB Server IP address on the managed firewall.
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
2. **Commit** your changes.
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
4. **Commit** your changes.
- Restart the firewall (devsrvr) process.
1. Log in to the firewall CLI.
2. Restart the devsrvr process: `debug software restart process device-server`
## PAN-118065
```caveat
M-Series Panorama management servers in Management Only mode
```
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
## PAN-116017
```caveat
Google Cloud Platform (GCP) only
```
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
## PAN-115816
```caveat
Microsoft Azure only
```
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
**Workaround:** Reboot the firewall.
## PAN-114495
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
## PAN-112694
```caveat
Firewalls with multiple virtual systems only
```
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
## PAN-112456
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
## PAN-111928
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
## PAN-111866
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
**Workaround:** Perform one of the following tasks.
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
- Manually select the devices that belong to the modified device group and template configurations.
## PAN-111729
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
## PAN-111670
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
## PAN-111251
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
## PAN-110794
DGA-based threats shown in the firewall threat log display the same name for all such instances.
## PAN-109759
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
## PAN-109526
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
## PAN-106675
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
## PAN-104780
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
## PAN-103276
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
## PAN-101688
```caveat
Panorama plugins
```
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
## PAN-101537
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
**Workaround:** Specify the vsys in the query string:
`admin>` `set system target-vsys <vsys-name>`
`admin>` `show log <log-type> direction equal <direction> query equal vsys eq <vsys-name> <dst> | <src> in <object-name>`
## PAN-98520
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
## PAN-97757
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
## PAN-97524
```caveat
Panorama management server only
```
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
## PAN-96985
The `request shutdown system` command does not shut down the Panorama management server.
## PAN-96960
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
## PAN-96446
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
## PAN-95773
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
## PAN-95511
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
## PAN-95028
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
## PAN-94846
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
## PAN-94093
HTTP Header Insertion does not work when jumbo frames are received out of order.
## PAN-93968
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
## PAN-93607
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesnt list the SCTP Protection profile in its drop-down list of available profiles.
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
## PAN-93532
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
## PAN-93193
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
- Switch to the firewall **Context** on the Panorama management server.
- Commit changes when a dynamic update is being installed.
- Generate a custom report when a dynamic update is being installed.
- Generate custom reports during a commit.
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
## PAN-91802
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
## PAN-83610
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
## PAN-83236
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
## PAN-83215
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
## PAN-81521
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
## PAN-77125
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode dont close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
## PAN-75457
```caveat
PAN-OS 8.0.1 and later releases
```
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
## PAN-73530
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
## PAN-73401
```caveat
PAN-OS 8.0.1 and later releases
```
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
**Workaround:** There are three possible workarounds to sync the controller nodes:
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
- Configure a worker list on the cluster controller:
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
or
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
Both commands result in Panorama reporting that the controller nodes are in sync.
## PAN-71329
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
## PAN-70906
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
## PAN-69505
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
## PAN-41558
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
## PAN-40079
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
## PAN-39636
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
## PAN-38255
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
## PAN-31832
The following issues apply when configuring a firewall to use a hardware security module (HSM):
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
@@ -0,0 +1,537 @@
---
type: Known
product: PAN-OS
version: 9.1.6
source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## PLUG-380
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
## PAN-223365
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
`admin``request restart system`
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
## PAN-199557
On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive.
**Workaround:** Manually reboot the `Active` Panorama HA peer.
## PAN-197341
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
For example:
1. You create a parent device group `DG-A` and a child device group `DG-B`.
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
## PAN-178194
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
## PAN-162748
```caveat
This issue is now resolved. See PAN-OS 9.1.9 Addressed Issues.
```
GlobalProtect clients in systems with umlaut diacritics in the serial number are unable to log in to the GlobalProtect gateway.
## PAN-160633
```caveat
PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls only
```
The dataplane restarts repeatedly due to internal path monitoring failures until a power cycle.
## PAN-154266
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
## PAN-154247
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
**Workaround:** Log out and back in to the Panorama web interface.
## PAN-153803
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
## PAN-151909
```caveat
This issue is now resolved. See PAN-OS 9.1.10 Addressed Issues.
```
On the Panorama management server, Preview Changes (**Commit** > **Commit to Panorama**) incorrectly displays an existing route as Added and the new route as an existing route in the Candidate Configuration when you configure a new virtual router route (**Network** > **Virtual Router**).
## PAN-148359
```caveat
This issue is now resolved. See PAN-OS 9.1.8 Addressed Issues.
```
SD-WAN server-to-client symmetric return does not function correctly under certain circumstances, and the issue can also affect path selection of parent/child applications, such as FTP.
## PAN-146573
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
## PAN-146485
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
## PAN-144889
```caveat
PAN-OS 9.1.2-h1 and later releases only
```
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
## PAN-140959
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
## PAN-136701
```caveat
PA-7000b Series firewalls only
```
Packets for new sessions drop when handling predict sessions.
**Workaround:** Use the following CLi commands to bypass this issue:
- `set session hwpredict disable yes`
- `show session hwpredict status`
## PAN-134456
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
**Workaround:** Use a destination-based service route for the SNMP trap server.
## PAN-134053
ACC does not filter WildFire logs from Dynamic User Groups.
## PAN-130550
```caveat
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
```
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
## PAN-127813
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches dont communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
## PAN-127550
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
## PAN-127474
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
## PAN-127206
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
## PAN-124956
```caveat
This issue is now resolved. See PAN-OS 9.1.11 Addressed Issues.
```
There is an issue where VM-Series firewalls do not support packet buffer protection.
## PAN-123277
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
## PAN-123040
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules dont display. A workaround exists for this issue. Please contact Support for information about the workaround.
## PAN-120440
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
## PAN-120423
```caveat
This issue is now resolved. See PAN-OS 9.1.9 Addressed Issues.
```
PAN-OS 9.1.0 does not support the XML API for GlobalProtect logs.
## PAN-120303
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
- Modify the PAN-DB Server IP address on the managed firewall.
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
2. **Commit** your changes.
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
4. **Commit** your changes.
- Restart the firewall (devsrvr) process.
1. Log in to the firewall CLI.
2. Restart the devsrvr process: `debug software restart process device-server`
## PAN-118065
```caveat
M-Series Panorama management servers in Management Only mode
```
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
## PAN-116017
```caveat
Google Cloud Platform (GCP) only
```
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
## PAN-115816
```caveat
Microsoft Azure only
```
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
**Workaround:** Reboot the firewall.
## PAN-114495
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
## PAN-112694
```caveat
Firewalls with multiple virtual systems only
```
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
## PAN-112456
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
## PAN-111928
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
## PAN-111866
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
**Workaround:** Perform one of the following tasks.
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
- Manually select the devices that belong to the modified device group and template configurations.
## PAN-111729
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
## PAN-111670
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
## PAN-111251
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
## PAN-110794
DGA-based threats shown in the firewall threat log display the same name for all such instances.
## PAN-109759
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
## PAN-109526
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
## PAN-106675
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
## PAN-104780
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
## PAN-103276
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
## PAN-101688
```caveat
Panorama plugins
```
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
## PAN-101537
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
**Workaround:** Specify the vsys in the query string:
`admin>` `set system target-vsys <vsys-name>`
`admin>` `show log <log-type> direction equal <direction> query equal vsys eq <vsys-name> <dst> | <src> in <object-name>`
## PAN-98520
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
## PAN-97757
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
## PAN-97524
```caveat
Panorama management server only
```
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
## PAN-96985
The `request shutdown system` command does not shut down the Panorama management server.
## PAN-96960
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
## PAN-96446
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
## PAN-95773
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
## PAN-95511
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
## PAN-95028
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
## PAN-94846
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
## PAN-94093
HTTP Header Insertion does not work when jumbo frames are received out of order.
## PAN-93968
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
## PAN-93607
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesnt list the SCTP Protection profile in its drop-down list of available profiles.
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
## PAN-93532
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
## PAN-93193
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
- Switch to the firewall **Context** on the Panorama management server.
- Commit changes when a dynamic update is being installed.
- Generate a custom report when a dynamic update is being installed.
- Generate custom reports during a commit.
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
## PAN-91802
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
## PAN-83610
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
## PAN-83236
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
## PAN-83215
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
## PAN-81521
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
## PAN-77125
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode dont close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
## PAN-75457
```caveat
PAN-OS 8.0.1 and later releases
```
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
## PAN-73530
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
## PAN-73401
```caveat
PAN-OS 8.0.1 and later releases
```
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
**Workaround:** There are three possible workarounds to sync the controller nodes:
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
- Configure a worker list on the cluster controller:
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
or
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
Both commands result in Panorama reporting that the controller nodes are in sync.
## PAN-71329
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
## PAN-70906
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
## PAN-69505
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
## PAN-41558
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
## PAN-40079
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
## PAN-39636
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
## PAN-38255
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
## PAN-31832
The following issues apply when configuring a firewall to use a hardware security module (HSM):
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
@@ -0,0 +1,541 @@
---
type: Known
product: PAN-OS
version: 9.1.7
source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## PLUG-380
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
## PAN-223365
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
`admin``request restart system`
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
## PAN-199557
On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive.
**Workaround:** Manually reboot the `Active` Panorama HA peer.
## PAN-197341
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
For example:
1. You create a parent device group `DG-A` and a child device group `DG-B`.
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
## PAN-178194
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
## PAN-162748
```caveat
This issue is now resolved. See PAN-OS 9.1.9 Addressed Issues.
```
GlobalProtect clients in systems with umlaut diacritics in the serial number are unable to log in to the GlobalProtect gateway.
## PAN-161121
```caveat
This issue is now resolved. See PAN-OS 9.1.8 Addressed Issues.
```
On the Panorama management server, invalid reference errors occur when attempting to delete an address object (**Objects** > **Addresses**) after removing the address object reference from an address group (**Objects** > **Address Groups**) resulting in you being unable commit and push the configuration to managed firewalls.
**Workaround:** Log in to the [Panorama CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli.html) and restart `configd`.
`admin>``debug software restart process configd`
## PAN-154266
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
## PAN-154247
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
**Workaround:** Log out and back in to the Panorama web interface.
## PAN-153803
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
## PAN-151909
```caveat
This issue is now resolved. See PAN-OS 9.1.10 Addressed Issues.
```
On the Panorama management server, Preview Changes (**Commit** > **Commit to Panorama**) incorrectly displays an existing route as Added and the new route as an existing route in the Candidate Configuration when you configure a new virtual router route (**Network** > **Virtual Router**).
## PAN-148359
```caveat
This issue is now resolved. See PAN-OS 9.1.8 Addressed Issues.
```
SD-WAN server-to-client symmetric return does not function correctly under certain circumstances, and the issue can also affect path selection of parent/child applications, such as FTP.
## PAN-146573
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
## PAN-146485
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
## PAN-144889
```caveat
PAN-OS 9.1.2-h1 and later releases only
```
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
## PAN-140959
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
## PAN-136701
```caveat
PA-7000b Series firewalls only
```
Packets for new sessions drop when handling predict sessions.
**Workaround:** Use the following CLi commands to bypass this issue:
- `set session hwpredict disable yes`
- `show session hwpredict status`
## PAN-134456
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
**Workaround:** Use a destination-based service route for the SNMP trap server.
## PAN-134053
ACC does not filter WildFire logs from Dynamic User Groups.
## PAN-130550
```caveat
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
```
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
## PAN-127813
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches dont communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
## PAN-127550
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
## PAN-127474
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
## PAN-127206
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
## PAN-124956
```caveat
This issue is now resolved. See PAN-OS 9.1.11 Addressed Issues.
```
There is an issue where VM-Series firewalls do not support packet buffer protection.
## PAN-123277
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
## PAN-123040
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules dont display. A workaround exists for this issue. Please contact Support for information about the workaround.
## PAN-120440
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
## PAN-120423
```caveat
This issue is now resolved. See PAN-OS 9.1.9 Addressed Issues.
```
PAN-OS 9.1.0 does not support the XML API for GlobalProtect logs.
## PAN-120303
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
- Modify the PAN-DB Server IP address on the managed firewall.
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
2. **Commit** your changes.
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
4. **Commit** your changes.
- Restart the firewall (devsrvr) process.
1. Log in to the firewall CLI.
2. Restart the devsrvr process: `debug software restart process device-server`
## PAN-118065
```caveat
M-Series Panorama management servers in Management Only mode
```
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
## PAN-116017
```caveat
Google Cloud Platform (GCP) only
```
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
## PAN-115816
```caveat
Microsoft Azure only
```
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
**Workaround:** Reboot the firewall.
## PAN-114495
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
## PAN-112694
```caveat
Firewalls with multiple virtual systems only
```
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
## PAN-112456
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
## PAN-111928
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
## PAN-111866
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
**Workaround:** Perform one of the following tasks.
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
- Manually select the devices that belong to the modified device group and template configurations.
## PAN-111729
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
## PAN-111670
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
## PAN-111251
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
## PAN-110794
DGA-based threats shown in the firewall threat log display the same name for all such instances.
## PAN-109759
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
## PAN-109526
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
## PAN-106675
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
## PAN-104780
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
## PAN-103276
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
## PAN-101688
```caveat
Panorama plugins
```
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
## PAN-101537
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
**Workaround:** Specify the vsys in the query string:
`admin>` `set system target-vsys <vsys-name>`
`admin>` `show log <log-type> direction equal <direction> query equal vsys eq <vsys-name> <dst> | <src> in <object-name>`
## PAN-98520
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
## PAN-97757
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
## PAN-97524
```caveat
Panorama management server only
```
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
## PAN-96985
The `request shutdown system` command does not shut down the Panorama management server.
## PAN-96960
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
## PAN-96446
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
## PAN-95773
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
## PAN-95511
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
## PAN-95028
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
## PAN-94846
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
## PAN-94093
HTTP Header Insertion does not work when jumbo frames are received out of order.
## PAN-93968
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
## PAN-93607
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesnt list the SCTP Protection profile in its drop-down list of available profiles.
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
## PAN-93532
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
## PAN-93193
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
- Switch to the firewall **Context** on the Panorama management server.
- Commit changes when a dynamic update is being installed.
- Generate a custom report when a dynamic update is being installed.
- Generate custom reports during a commit.
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
## PAN-91802
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
## PAN-83610
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
## PAN-83236
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
## PAN-83215
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
## PAN-81521
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
## PAN-77125
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode dont close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
## PAN-75457
```caveat
PAN-OS 8.0.1 and later releases
```
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
## PAN-73530
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
## PAN-73401
```caveat
PAN-OS 8.0.1 and later releases
```
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
**Workaround:** There are three possible workarounds to sync the controller nodes:
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
- Configure a worker list on the cluster controller:
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
or
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
Both commands result in Panorama reporting that the controller nodes are in sync.
## PAN-71329
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
## PAN-70906
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
## PAN-69505
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
## PAN-41558
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
## PAN-40079
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
## PAN-39636
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
## PAN-38255
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
## PAN-31832
The following issues apply when configuring a firewall to use a hardware security module (HSM):
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
@@ -0,0 +1,521 @@
---
type: Known
product: PAN-OS
version: 9.1.8
source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## PLUG-380
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
## PAN-223365
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
`admin``request restart system`
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
## PAN-199557
On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive.
**Workaround:** Manually reboot the `Active` Panorama HA peer.
## PAN-197341
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
For example:
1. You create a parent device group `DG-A` and a child device group `DG-B`.
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
## PAN-178194
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
## PAN-162748
```caveat
This issue is now resolved. See PAN-OS 9.1.9 Addressed Issues.
```
GlobalProtect clients in systems with umlaut diacritics in the serial number are unable to log in to the GlobalProtect gateway.
## PAN-154266
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
## PAN-154247
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
**Workaround:** Log out and back in to the Panorama web interface.
## PAN-153803
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
## PAN-151909
```caveat
This issue is now resolved. See PAN-OS 9.1.10 Addressed Issues.
```
On the Panorama management server, Preview Changes (**Commit** > **Commit to Panorama**) incorrectly displays an existing route as Added and the new route as an existing route in the Candidate Configuration when you configure a new virtual router route (**Network** > **Virtual Router**).
## PAN-146573
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
## PAN-146485
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
## PAN-144889
```caveat
PAN-OS 9.1.2-h1 and later releases only
```
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
## PAN-140959
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
## PAN-136701
```caveat
PA-7000b Series firewalls only
```
Packets for new sessions drop when handling predict sessions.
**Workaround:** Use the following CLi commands to bypass this issue:
- `set session hwpredict disable yes`
- `show session hwpredict status`
## PAN-134456
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
**Workaround:** Use a destination-based service route for the SNMP trap server.
## PAN-134053
ACC does not filter WildFire logs from Dynamic User Groups.
## PAN-130550
```caveat
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
```
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
## PAN-127813
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches dont communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
## PAN-127550
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
## PAN-127474
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
## PAN-127206
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
## PAN-124956
```caveat
This issue is now resolved. See PAN-OS 9.1.11 Addressed Issues.
```
There is an issue where VM-Series firewalls do not support packet buffer protection.
## PAN-123277
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
## PAN-123040
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules dont display. A workaround exists for this issue. Please contact Support for information about the workaround.
## PAN-120440
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
## PAN-120423
```caveat
This issue is now resolved. See PAN-OS 9.1.9 Addressed Issues.
```
PAN-OS 9.1.0 does not support the XML API for GlobalProtect logs.
## PAN-120303
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
- Modify the PAN-DB Server IP address on the managed firewall.
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
2. **Commit** your changes.
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
4. **Commit** your changes.
- Restart the firewall (devsrvr) process.
1. Log in to the firewall CLI.
2. Restart the devsrvr process: `debug software restart process device-server`
## PAN-118065
```caveat
M-Series Panorama management servers in Management Only mode
```
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
## PAN-116017
```caveat
Google Cloud Platform (GCP) only
```
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
## PAN-115816
```caveat
Microsoft Azure only
```
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
**Workaround:** Reboot the firewall.
## PAN-114495
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
## PAN-112694
```caveat
Firewalls with multiple virtual systems only
```
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
## PAN-112456
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
## PAN-111928
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
## PAN-111866
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
**Workaround:** Perform one of the following tasks.
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
- Manually select the devices that belong to the modified device group and template configurations.
## PAN-111729
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
## PAN-111670
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
## PAN-111251
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
## PAN-110794
DGA-based threats shown in the firewall threat log display the same name for all such instances.
## PAN-109759
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
## PAN-109526
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
## PAN-106675
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
## PAN-104780
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
## PAN-103276
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
## PAN-101688
```caveat
Panorama plugins
```
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
## PAN-101537
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
**Workaround:** Specify the vsys in the query string:
`admin>` `set system target-vsys <vsys-name>`
`admin>` `show log <log-type> direction equal <direction> query equal vsys eq <vsys-name> <dst> | <src> in <object-name>`
## PAN-98520
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
## PAN-97757
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
## PAN-97524
```caveat
Panorama management server only
```
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
## PAN-96985
The `request shutdown system` command does not shut down the Panorama management server.
## PAN-96960
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
## PAN-96446
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
## PAN-95773
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
## PAN-95511
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
## PAN-95028
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
## PAN-94846
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
## PAN-94093
HTTP Header Insertion does not work when jumbo frames are received out of order.
## PAN-93968
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
## PAN-93607
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesnt list the SCTP Protection profile in its drop-down list of available profiles.
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
## PAN-93532
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
## PAN-93193
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
- Switch to the firewall **Context** on the Panorama management server.
- Commit changes when a dynamic update is being installed.
- Generate a custom report when a dynamic update is being installed.
- Generate custom reports during a commit.
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
## PAN-91802
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
## PAN-83610
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
## PAN-83236
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
## PAN-83215
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
## PAN-81521
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
## PAN-77125
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode dont close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
## PAN-75457
```caveat
PAN-OS 8.0.1 and later releases
```
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
## PAN-73530
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
## PAN-73401
```caveat
PAN-OS 8.0.1 and later releases
```
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
**Workaround:** There are three possible workarounds to sync the controller nodes:
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
- Configure a worker list on the cluster controller:
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
or
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
Both commands result in Panorama reporting that the controller nodes are in sync.
## PAN-71329
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
## PAN-70906
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
## PAN-69505
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
## PAN-41558
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
## PAN-40079
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
## PAN-39636
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
## PAN-38255
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
## PAN-31832
The following issues apply when configuring a firewall to use a hardware security module (HSM):
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.
@@ -0,0 +1,513 @@
---
type: Known
product: PAN-OS
version: 9.1.9
source: common-crawl
crawl: CC-MAIN-2026-12
---
## BLANK-000000
Upgrading Panorama with a local Log Collector and Dedicated Log Collectors to PAN-OS 8.1 or a later PAN-OS release can take up to six hours to complete due to significant infrastructure changes. Ensure uninterrupted power to all appliances throughout the upgrade process.
## BLANK-000000
A critical System log is generated on the VM-Series firewall if the minimum memory requirement for the model is not available.
- When the memory allocated is less than 4.5GB, you cannot upgrade the firewall. The following error message displays: `Failed to install 9.0.0 with the following error: VM-50 in 9.0.0 requires 5.5GB memory, VM-50 Lite requires 4.5GB memory.Please configure this VM with enough memory before upgrading.`
- If the memory allocation is more than 4.5GB but less that the licensed capacity requirement for the model, it will default to the capacity associated with the VM-50.
The System log message `System capacity adjusted to VM-50 capacity due to insufficient memory for VM-<xxx> license`, indicates that you must allocate the additional memory required for licensed capacity for the firewall model.
## PLUG-380
When you rename a device group, template, or template stack in Panorama that is part of a VMware NSX service definition, the new name is not reflected in NSX Manager. Therefore, any ESXi hosts that you add to a vSphere cluster are not added to the correct device group, template, or template stack and your Security policy is not pushed to VM-Series firewalls that you deploy after you rename those objects. There is no impact to existing VM-Series firewalls.
## PAN-223365
The Panorama management server is unable to query any logs if the ElasticSearch health status for any Log Collector (**Panorama** > **Managed Collector** is degraded.
**Workaround:** [Log in to the Log Collector CLI](https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/set-up-panorama/access-and-navigate-panorama-management-interfaces/log-in-to-the-panorama-cli) and reboot.
`admin``request restart system`
Alternatively, you can contact [Palo Alto Networks Customer Support](https://support.paloaltonetworks.com/Support/Index) to restart the ElasticSearch process without rebooting the Log Collector.
## PAN-199557
On M-600 appliances in an Active/Passive high availability (HA) configuration, the `configd` process restarts due to a memory leak on the `Active` Panorama HA peer. This causes the Panorama web interface and CLI to become unresponsive.
**Workaround:** Manually reboot the `Active` Panorama HA peer.
## PAN-197341
On the Panorama management server, if you create multiple device group **Objects** with the same name in the Shared device group and any additional device groups (**Panorama** > **Device Groups**) under the same device group hierarchy that are used in one or more **Policies**, renaming the object with a shared name in any device group causes the object name to change in the policies where it is used. This issue applies only to device group objects that can be referenced in a Security policy rule.
For example:
1. You create a parent device group `DG-A` and a child device group `DG-B`.
2. You create address objects called `AddressObjA` in the `Shared`, `DG-A` and `DG-B` device groups and add `AddressObjA` to a Security policy rule under `DG-A` and `DG-B`.
3. Later, you change the `AddressObjA` name in the `Shared` device group to `AddressObjB`.
Changing the name of the address object in the `Shared` device group causes the references in the Policy rule to use the renamed `Shared` object instead of the device group object.
## PAN-178194
Firewalls licensed for Advanced URL Filtering generate a message indicating that a **License required for URL filtering to function** is unavailable displays at the bottom of the UI, due to a PAN-OS UI issue. This error does not affect the operation of Advanced URL Filtering or URL Filtering.
## PAN-162748
```caveat
This issue is now resolved. See PAN-OS 9.1.9 Addressed Issues.
```
GlobalProtect clients in systems with umlaut diacritics in the serial number are unable to log in to the GlobalProtect gateway.
## PAN-154266
When an application matches an SD-WAN policy and some sessions for the same application do not match an SD-WAN policy, the SD-WAN Monitoring—Traffic Characteristics screen displays the Links Used information with an SD-WAN policy and a null policy. Sessions that do not have an SD-WAN policy ID are filtered from Links Used.
**Workaround**: If you want to see session logs that include a default selection, create a catch-all SD-WAN policy rule and place it last in the list of SD-WAN policies.
## PAN-154247
On the Panorama management server, context switching to and from the managed firewall web interface may cause the Panorama administrator to be logged out.
**Workaround:** Log out and back in to the Panorama web interface.
## PAN-153803
On the Panorama management server, scheduled email PDF reports (**Monitor** > **PDF Reports**) fail if a GIF image is used in the header or footer.
## PAN-151909
```caveat
This issue is now resolved. See PAN-OS 9.1.10 Addressed Issues.
```
On the Panorama management server, Preview Changes (**Commit** > **Commit to Panorama**) incorrectly displays an existing route as Added and the new route as an existing route in the Candidate Configuration when you configure a new virtual router route (**Network** > **Virtual Router**).
## PAN-146573
PA-7000 series firewalls configured with a large number of interfaces experience impacted performance and possible timeouts when performing SNMP queries.
## PAN-146485
On the Panorama management server, adding, deleting, or modifying the upstream NAT configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the branch template stack as `out of sync`.
Additionally, adding, deleting, or modifying the BGP configuration (**Panorama** > **SD-WAN** > **Devices**) does not display the hub and branch template stacks as `out of sync`. For example, modifying the BGP configuration on the branch firewall does not cause the hub template stack to display as `out of sync`, nor does modifying the BGP configuration on the hub firewall cause the branch template stack as `out of sync`.
**Workaround:** After performing a configuration change, **Commit and Push** the configuration changes to all hub and branch firewalls in the VPN cluster containing the firewall with the modified configuration.
## PAN-144889
```caveat
PAN-OS 9.1.2-h1 and later releases only
```
On the Panorama management server, adding, deleting, or modifying the original subnet IP, or adding a new subnet after you successfully configure a tunnel IP subnet, for the SD-WAN 1.0.2 plugin does not display the managed firewall templates (**Panorama** > **Managed Devices** > **Summary**) as `Out of Sync`.
**Workaround**: When modifying the original subnet IP, or adding a new subnet, push the template configuration changes to your managed firewalls and **Force Template Values** (**Commit** > **Push to Devices** > **Edit Selections**).
## PAN-136701
```caveat
PA-7000b Series firewalls only
```
Packets for new sessions drop when handling predict sessions.
**Workaround:** Use the following CLi commands to bypass this issue:
- `set session hwpredict disable yes`
- `show session hwpredict status`
## PAN-140959
The Panorama management server allows you to downgrade Zero Touch Provisioning (ZTP) firewalls to PAN-OS 9.1.2 and earlier releases where ZTP functionality is not supported.
## PAN-134456
SNMP traps configured to use the dataplane port in service routes are still sent using the management interface.
**Workaround:** Use a destination-based service route for the SNMP trap server.
## PAN-134053
ACC does not filter WildFire logs from Dynamic User Groups.
## PAN-130550
```caveat
PA-3200 Series, PA-5220, PA-5250, PA-5260, and PA-7000 Series firewalls
```
For traffic between virtual systems (inter-vsys traffic), the firewall cannot perform source NAT using dynamic IP (DIP) address translation.
**Workaround:** Use source NAT with Dynamic IP and Port (DIPP) translation on inter-vsys traffic.
## PAN-127813
In the current release, SD-WAN auto-provisioning configures hubs and branches in a hub and spoke model, where branches dont communicate with each other. Expected branch routes are for generic prefixes, which can be configured in the hub and advertised to all branches. Branches with unique prefixes are not published up to the hub.
**Workaround:** Add any specific prefixes for branches to the hub advertise-list configuration.
## PAN-127550
Panorama supports only incremental additions for CSV imports when the SD-WAN plugin is enabled. Delete devices manually in the web interface or CLI.
## PAN-127474
When you configure a Server Profile, the custom log format for GlobalProtect logs is missing.
## PAN-127206
If you use the CLI to enable the cleartext option for the Include Username in HTTP Header Insertion Entries feature, the authentication request to the firewall may become unresponsive or time out.
## PAN-124956
```caveat
This issue is now resolved. See PAN-OS 9.1.11 Addressed Issues.
```
There is an issue where VM-Series firewalls do not support packet buffer protection.
## PAN-123277
Dynamic tags from other sources are accessible using the CLI but do not display on the Panorama web interface.
## PAN-123040
When you try to view network QoS statistics on an SD-WAN branch or hub, the QoS statistics and the hit count for the QoS rules dont display. A workaround exists for this issue. Please contact Support for information about the workaround.
## PAN-120440
There is an issue on M-500 Panorama management servers where any ethernet interface with an IPv6 address having Private PAN-DB-URL connectivity only supports the following format: `2001:DB9:85A3:0:0:8A2E:370:2`.
## PAN-120303
There is an issue where the firewall remains connected to the PAN-DB-URL server through the old management IP address on the M-500 Panorama management server, even when you configured the Eth1/1 interface.
**Workaround:** Update the PAN-DB-URL IP address on the firewall using one of the methods below.
- Modify the PAN-DB Server IP address on the managed firewall.
1. On the web interface, delete the **PAN-DB Server** IP address (**Device** > **Setup** > **Content ID** > **URL Filtering** settings).
2. **Commit** your changes.
3. Add the new M-500 Eth1/1 IP PAN-DB IP address.
4. **Commit** your changes.
- Restart the firewall (devsrvr) process.
1. Log in to the firewall CLI.
2. Restart the devsrvr process: `debug software restart process device-server`
## PAN-118065
```caveat
M-Series Panorama management servers in Management Only mode
```
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the `show interface all` command in the CLI after you commit.
**Workaround:** Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
## PAN-116017
```caveat
Google Cloud Platform (GCP) only
```
The firewall does not accept the DNS value from the initial configuration (init-cfg) file when you bootstrap the firewall.
**Workaround:** Add DNS value as part of the bootstrap.xml in the bootstrap folder and complete the bootstrap process.
## PAN-115816
```caveat
Microsoft Azure only
```
There is an intermittent issue where an Ethernet (eth1) interface does not come up when you first boot up the firewall.
**Workaround:** Reboot the firewall.
## PAN-114495
Alibaba Cloud runs on a KVM hypervisor and supports two Virtio modes: DPDK (default) and MMAP. If you deploy a VM-Series firewall running PAN-OS 9.0 in DPDK packet mode and you then switch to MMAP packet mode, the VM-Series firewall duplicates packets that originate from or terminate on the firewall. As an example, if a load balancer or a server behind the firewall pings the VM-Series firewall after you switch from DPDK packet mode to MMAP packet mode, the firewall duplicates the ping packets.
Throughput traffic is not duplicated if you deploy the VM-Series firewall using MMAP packet mode.
## PAN-112694
```caveat
Firewalls with multiple virtual systems only
```
If you configure dynamic DNS (DDNS) on a new interface (associated with vsys1 or another virtual system) and you then create a **New** Certificate Profile from the drop-down, you must set the location for the Certificate Profile to Shared. If you configure DDNS on an existing interface and then create a new Certificate Profile, we also recommend that you choose the Shared location instead of a specific virtual system. Alternatively, you can select a preexisting certificate profile instead of creating a new one.
## PAN-112456
You can temporarily submit a change request for a URL Category with more than two suggested categories. However, we support only two suggested categories so add no more than two suggested categories to a change request until we address this issue. If you submit more than two suggested categories, we will use only the first two categories you enter.
## PAN-111928
Invalid configuration errors are not displayed as expected when you revert a Panorama management server configuration.
**Workaround:** After you revert the Panorama configuration, **Commit** (**Commit** > **Commit to Panorama**) the reverted configuration to display the invalid configuration errors.
## PAN-111866
The push scope selection on the Panorama web interface displays incorrectly even though the commit scope displays as expected. This issue occurs when one administrator makes configuration changes to separate device groups or templates that affect multiple firewalls and a different administrator attempts to push those changes.
**Workaround:** Perform one of the following tasks.
- Initiate a **Commit to Panorama** operation followed by a **Push to Devices** operation for the modified device group and template configurations.
- Manually select the devices that belong to the modified device group and template configurations.
## PAN-111729
If you disable DPDK mode and enable it again, you must immediately reboot the firewall.
## PAN-111670
Tagged VLAN traffic fails when sent through an SR-IOV adapter.
## PAN-111251
Using the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule has no effect.
## PAN-110794
DGA-based threats shown in the firewall threat log display the same name for all such instances.
## PAN-109759
The firewall does not generate a notification for the GlobalProtect client when the firewall denies an unencrypted TLS session due to an authentication policy match.
## PAN-109526
The system log does not correctly display the URL for CRL files; instead, the URLs are displayed with encoded characters.
## PAN-106675
After upgrading the Panorama management server to PAN-OS 8.1 or a later release, predefined reports do not display a list of top attackers.
**Workaround:** Create new threat summary reports (**Monitor** > **PDF Reports** > **Manage PDF Summary**) containing the top attackers to mimic the predefined reports.
## PAN-104780
If you configure a HIP object to match only when a connecting endpoint is managed (**Objects** > **GlobalProtect** > **HIP Objects** > **<hip-object>** > **General** > **Managed**), iOS and Android endpoints that are managed by AirWatch are unable to successfully match the HIP object and the HIP report incorrectly indicates that these endpoints are not managed. This issue occurs because GlobalProtect gateways cannot correctly identify the managed status of these endpoints.
Additionally, iOS endpoints that are managed by AirWatch are unable to match HIP objects based on the endpoint serial number because GlobalProtect gateways cannot identify the serial numbers of these endpoints; these serial numbers do not appear in the HIP report.
## PAN-103276
Adding a disk to a virtual appliance running Panorama 8.1 or a later release on VMware ESXi 6.5 update1 causes the Panorama virtual appliance and host web client to become unresponsive.
**Workaround:** Upgrade the ESXi host to ESXi 6.5 update2 and add the disk again.
## PAN-101688
```caveat
Panorama plugins
```
The IP address-to-tag mapping information registered on a firewall or virtual system is not deleted when you remove the firewall or virtual system from a Device Group.
**Workaround:** Log in to the CLI on the firewall and enter the following command to unregister the IP address-to-tag mappings: `debug object registered-ip clear all`.
## PAN-101537
After you configure and push address and address group objects in Shared and vsys-specific device groups from the Panorama management server to managed firewalls, executing the `show log <log-type> direction equal <direction> <dst> | <src> in <object-name>` command on a managed firewall only returns address and address group objects pushed form the Shared device group.
**Workaround:** Specify the vsys in the query string:
`admin>` `set system target-vsys <vsys-name>`
`admin>` `show log <log-type> direction equal <direction> query equal vsys eq <vsys-name> <dst> | <src> in <object-name>`
## PAN-98520
When booting or rebooting a PA-7000 Series Firewall with the SMC-B installed, the BIOS console output displays attempts to connect to the card's controller in the System Memory Speed section. The messages can be ignored.
## PAN-97757
GlobalProtect authentication fails with an `Invalid username/password` error (because the user is not found in **Allow List**) after you enable GlobalProtect authentication cookies and add a RADIUS group to the **Allow List** of the authentication profile used to authenticate to GlobalProtect.
**Workaround:** Disable GlobalProtect authentication cookies. Alternatively, disable (clear) **Retrieve user group from RADIUS** in the authentication profile and configure group mapping from Active Directory (AD) through LDAP.
## PAN-97524
```caveat
Panorama management server only
```
The Security Zone and Virtual System columns (**Network** tab) display `None` after a Device Group and Template administrator with read-only privileges performs a context switch.
## PAN-96985
The `request shutdown system` command does not shut down the Panorama management server.
## PAN-96960
You cannot restart or shutdown a Panorama on KVM from the Virtual-manager console or virsch CLI.
## PAN-96446
A firewall that is not included in a Collector Group fails to generate a system log if logs are dropped when forwarded to a Panorama management server that is running in Management Only mode.
## PAN-95773
On VM-Series firewalls that have Data Plane Development Kit (DPDK) enabled and that use the i40e network interface card (NIC), the `show session info` CLI command displays an inaccurate throughput and packet rate.
**Workaround:** Disable DPDK by running the `set system setting dpdk-pkt-io off` CLI command.
## PAN-95511
The name for an address object, address group, or an external dynamic list must be unique. Duplicate names for these objects can result in unexpected behavior when you reference the object in a policy rule.
## PAN-95028
For administrator accounts that you created in PAN-OS 8.0.8 and earlier releases, the firewall does not apply password profile settings (**Device** > **Password Profiles**) until after you upgrade to PAN-OS 8.0.9 or a later release and then only after you modify the account passwords. (Administrator accounts that you create in PAN-OS 8.0.9 or a later release do not require you to change the passwords to apply password profile settings.)
## PAN-94846
When DPDK is enabled on the VM-Series firewall with i40e virtual function (VF) driver, the VF does not detect the link status of the physical link. The VF link status remains up, regardless of changes to the physical link state.
## PAN-94093
HTTP Header Insertion does not work when jumbo frames are received out of order.
## PAN-93968
The firewall and Panorama web interfaces display vulnerability threat IDs that are not available in PAN-OS 9.0 releases (**Objects** > **Security Profiles** > **Vulnerability Protection** > **<profile>** > **Exceptions**). To confirm whether a particular threat ID is available in your release, monitor the release notes for each new Applications and Threats content update or check the Palo Alto Networks [Threat Vault](https://threatvault.paloaltonetworks.com) to see the minimum PAN-OS release version for a threat signature.
## PAN-93607
When you configure a VM-500 firewall with an SCTP Protection profile (**Objects** > **Security Profiles** > **SCTP Protection**) and you try to add the profile to an existing Security Profile Group (**Objects** > **Security Profile Groups**), the Security Profile Group doesnt list the SCTP Protection profile in its drop-down list of available profiles.
**Workaround:** Create a new Security Profile Group and select the SCTP Protection profile from there.
## PAN-93532
When you configure a firewall running PAN-OS 9.0 as an nCipher HSM client, the web interface on the firewall displays the nCipher server status as Not Authenticated, even though the HSM state is up (**Device** > **Setup** > **HSM**).
## PAN-93193
The memory-optimized VM-50 Lite intermittently performs slowly and stops processing traffic when memory utilization is critically high. To prevent this issue, make sure that you do not:
- Switch to the firewall **Context** on the Panorama management server.
- Commit changes when a dynamic update is being installed.
- Generate a custom report when a dynamic update is being installed.
- Generate custom reports during a commit.
**Workaround:** When the firewall performs slowly, or you see a critical System log for memory utilization, wait for 5 minutes and then manually reboot the firewall.
Use the Task Manager to verify that you are not performing memory intensive tasks such as installing dynamic updates, committing changes or generating reports, at the same time, on the firewall.
## PAN-91802
On a VM-Series firewall, the **clear session all** CLI command does not clear GTP sessions.
## PAN-83610
In rare cases, a PA-5200 Series firewall (with an FE100 network processor) that has session offload enabled (default) incorrectly resets the UDP checksum of outgoing UDP packets.
**Workaround:** In PAN-OS 8.0.6 and later releases, you can persistently disable session offload for only UDP traffic using the `set session udp-off load no` CLI command.
## PAN-83236
The VM-Series firewall on Google Compute Platform does not publish firewall metrics to Google Stack Monitoring when you manually configure a DNS server IP address (**Device** > **Setup** > **Services**).
**Workaround:** The VM-Series firewall on Google Cloud Platform must use the DNS server that Google provides.
## PAN-83215
SSL decryption based on ECDSA certificates does not work when you import the ECDSA private keys onto an nCipher nShield hardware security module (HSM).
## PAN-81521
Endpoints failed to authenticate to GlobalProtect through Kerberos when you specify an FQDN instead of an IP address in the Kerberos server profile (**Device** > **Server Profiles** > **Kerberos**).
**Workaround:** Replace the FQDN with the IP address in the Kerberos server profile.
## PAN-77125
PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls configured in tap mode dont close offloaded sessions after processing the associated traffic; the sessions remain open until they time out.
**Workaround:** Configure the firewalls in virtual wire mode instead of tap mode, or disable session offloading by running the `set session off load no` CLI command.
## PAN-75457
```caveat
PAN-OS 8.0.1 and later releases
```
In WildFire appliance clusters that have three or more nodes, the Panorama management server does not support changing node roles. In a three-node cluster for example, you cannot use Panorama to configure the worker node as a controller node by adding the HA and cluster controller configurations, configure an existing controller node as a worker node by removing the HA configuration, and then commit and push the configuration. Attempts to change cluster node roles from Panorama results in a validation error—the commit fails and the cluster becomes unresponsive.
## PAN-73530
The firewall does not generate a packet capture (pcap) when a Data Filtering profile blocks files.
## PAN-73401
```caveat
PAN-OS 8.0.1 and later releases
```
When you import a two-node WildFire appliance cluster into the Panorama management server, the controller nodes report their state as out-of-sync if either of the following conditions exist:
- You did not configure a worker list to add at least one worker node to the cluster. (In a two-node cluster, both nodes are controller nodes configured as an HA pair. Adding a worker node would make the cluster a three-node cluster.)
- You did not configure a service advertisement (either by enabling or not enabling advertising DNS service on the controller nodes).
**Workaround:** There are three possible workarounds to sync the controller nodes:
- After you import the two-node cluster into Panorama, push the configuration from Panorama to the cluster. After the push succeeds, Panorama reports that the controller nodes are in sync.
- Configure a worker list on the cluster controller:
admin@wf500(active-controller)# `set deviceconfig cluster mode controller worker-list <worker-ip-address>`
(`<worker-ip-address>` is the IP address of the worker node you are adding to the cluster.) This creates a three-node cluster. After you import the cluster into Panorama, Panorama reports that the controller nodes are in sync. When you want the cluster to have only two nodes, use a different workaround.
- Configure service advertisement on the local CLI of the cluster controller and then import the configuration into Panorama. The service advertisement can advertise that DNS is or is not enabled.
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled yes`
or
admin@wf500(active-controller)# `set deviceconfig cluster mode controller service-advertisement dns-service enabled no`
Both commands result in Panorama reporting that the controller nodes are in sync.
## PAN-71329
Local users and user groups in the Shared location (all virtual systems) are not available to be part of the user-to-application mapping for GlobalProtect Clientless VPN applications (**Network** > **GlobalProtect** > **Portals** > **<portal>** > **Clientless VPN** > **Applications**).
**Workaround:** Create users and user groups in specific virtual systems on firewalls that have multiple virtual systems. For single virtual systems (like VM-Series firewalls), users and user groups are created under Shared and are not configurable for Clientless VPN applications.
## PAN-70906
If the PAN-OS web interface and the GlobalProtect portal are enabled on the same IP address, then when a user logs out of the GlobalProtect portal, the administrative user is also logged out from the PAN-OS web interface.
**Workaround:** Use the IP address to access the PAN-OS web interface and an FQDN to access the GlobalProtect portal.
## PAN-69505
When viewing an external dynamic list that requires client authentication and you **Test Source URL**, the firewall fails to indicate whether it can reach the external dynamic list server and returns a URL access error (**Objects** > **External Dynamic Lists**).
## PAN-41558
When you use a firewall loopback interface as a GlobalProtect gateway interface, traffic is not routed correctly for third-party IPSec clients, such as strongSwan.
**Workaround:** Use a physical firewall interface instead of a loopback firewall interface as the GlobalProtect gateway interface for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.
## PAN-40079
The VM-Series firewall on KVM, for all supported Linux distributions, does not support the Broadcom network adapters for PCI pass-through functionality.
## PAN-39636
Regardless of the **Time Frame** you specify for a scheduled custom report on a Panorama M-Series appliance, the earliest possible start date for the report data is effectively the date when you configured the report (**Monitor** > **Manage Custom Reports**). For example, if you configure the report on the 15th of the month and set the **Time Frame** to **Last 30 Days**, the report that Panorama generates on the 16th will include only data from the 15th onward. This issue applies only to scheduled reports; on-demand reports include all data within the specified **Time Frame**.
**Workaround:** To generate an on-demand report, click **Run Now** when you configure the custom report.
## PAN-38255
When you perform a factory reset on a Panorama virtual appliance and configure the serial number, logging does not work until you reboot Panorama or execute the `debug software restart process management-server` CLI command.
## PAN-31832
The following issues apply when configuring a firewall to use a hardware security module (HSM):
- **nCipher nShield Connect**—The firewall requires at least four minutes to detect that an HSM was disconnected, causing SSL functionality to be unavailable during the delay.
- **SafeNet Network**—When losing connectivity to either or both HSMs in an HA configuration, the display of information from the `show high-availability state` and `show hsm info` commands are blocked for 20 seconds.