From f5bf9648f6ba5507d224aae325634559e91a8fc5 Mon Sep 17 00:00:00 2001 From: Aaron Axvig Date: Wed, 15 Apr 2026 14:25:08 -0500 Subject: [PATCH] Added remaining PAN-OS 11.1 reference files --- reference/PAN-OS/addressed/11.1.0-h1.html | 36 + reference/PAN-OS/addressed/11.1.0-h2.html | 103 + reference/PAN-OS/addressed/11.1.0-h3.html | 41 + reference/PAN-OS/addressed/11.1.0-h4.html | 61 + reference/PAN-OS/addressed/11.1.0.html | 280 ++ reference/PAN-OS/addressed/11.1.1-h1.html | 41 + reference/PAN-OS/addressed/11.1.1-h2.html | 61 + reference/PAN-OS/addressed/11.1.1.html | 242 ++ reference/PAN-OS/addressed/11.1.2-h1.html | 73 + reference/PAN-OS/addressed/11.1.2-h12.html | 181 + reference/PAN-OS/addressed/11.1.2-h14.html | 157 + reference/PAN-OS/addressed/11.1.2-h15.html | 61 + reference/PAN-OS/addressed/11.1.2-h16.html | 245 ++ reference/PAN-OS/addressed/11.1.2-h18.html | 95 + reference/PAN-OS/addressed/11.1.2-h3.html | 84 + reference/PAN-OS/addressed/11.1.2-h4.html | 430 ++ reference/PAN-OS/addressed/11.1.2-h9.html | 288 ++ reference/PAN-OS/addressed/11.1.2.html | 284 ++ reference/PAN-OS/addressed/11.1.3-h1.html | 45 + reference/PAN-OS/addressed/11.1.3-h10.html | 281 ++ reference/PAN-OS/addressed/11.1.3-h11.html | 61 + reference/PAN-OS/addressed/11.1.3-h13.html | 237 ++ reference/PAN-OS/addressed/11.1.3-h2.html | 115 + reference/PAN-OS/addressed/11.1.3-h4.html | 166 + reference/PAN-OS/addressed/11.1.3-h6.html | 133 + reference/PAN-OS/addressed/11.1.3.html | 2038 +++++++++ reference/PAN-OS/addressed/11.1.4-h1.html | 167 + reference/PAN-OS/addressed/11.1.4-h13.html | 1005 +++++ reference/PAN-OS/addressed/11.1.4-h15.html | 174 + reference/PAN-OS/addressed/11.1.4-h16.html | 32 + reference/PAN-OS/addressed/11.1.4-h17.html | 383 ++ reference/PAN-OS/addressed/11.1.4-h18.html | 200 + reference/PAN-OS/addressed/11.1.4-h25.html | 261 ++ reference/PAN-OS/addressed/11.1.4-h27.html | 165 + reference/PAN-OS/addressed/11.1.4-h4.html | 797 ++++ reference/PAN-OS/addressed/11.1.4-h7.html | 359 ++ reference/PAN-OS/addressed/11.1.4-h9.html | 646 +++ reference/PAN-OS/addressed/11.1.4.html | 271 ++ reference/PAN-OS/addressed/11.1.5-h1.html | 61 + reference/PAN-OS/addressed/11.1.5.html | 4495 ++++++++++++++++++++ reference/PAN-OS/addressed/11.1.8.html | 3580 ++++++++++++++++ reference/PAN-OS/addressed/11.1.9.html | 945 ++++ reference/urls.json | 84 +- 43 files changed, 19422 insertions(+), 42 deletions(-) create mode 100644 reference/PAN-OS/addressed/11.1.0-h1.html create mode 100644 reference/PAN-OS/addressed/11.1.0-h2.html create mode 100644 reference/PAN-OS/addressed/11.1.0-h3.html create mode 100644 reference/PAN-OS/addressed/11.1.0-h4.html create mode 100644 reference/PAN-OS/addressed/11.1.0.html create mode 100644 reference/PAN-OS/addressed/11.1.1-h1.html create mode 100644 reference/PAN-OS/addressed/11.1.1-h2.html create mode 100644 reference/PAN-OS/addressed/11.1.1.html create mode 100644 reference/PAN-OS/addressed/11.1.2-h1.html create mode 100644 reference/PAN-OS/addressed/11.1.2-h12.html create mode 100644 reference/PAN-OS/addressed/11.1.2-h14.html create mode 100644 reference/PAN-OS/addressed/11.1.2-h15.html create mode 100644 reference/PAN-OS/addressed/11.1.2-h16.html create mode 100644 reference/PAN-OS/addressed/11.1.2-h18.html create mode 100644 reference/PAN-OS/addressed/11.1.2-h3.html create mode 100644 reference/PAN-OS/addressed/11.1.2-h4.html create mode 100644 reference/PAN-OS/addressed/11.1.2-h9.html create mode 100644 reference/PAN-OS/addressed/11.1.2.html create mode 100644 reference/PAN-OS/addressed/11.1.3-h1.html create mode 100644 reference/PAN-OS/addressed/11.1.3-h10.html create mode 100644 reference/PAN-OS/addressed/11.1.3-h11.html create mode 100644 reference/PAN-OS/addressed/11.1.3-h13.html create mode 100644 reference/PAN-OS/addressed/11.1.3-h2.html create mode 100644 reference/PAN-OS/addressed/11.1.3-h4.html create mode 100644 reference/PAN-OS/addressed/11.1.3-h6.html create mode 100644 reference/PAN-OS/addressed/11.1.3.html create mode 100644 reference/PAN-OS/addressed/11.1.4-h1.html create mode 100644 reference/PAN-OS/addressed/11.1.4-h13.html create mode 100644 reference/PAN-OS/addressed/11.1.4-h15.html create mode 100644 reference/PAN-OS/addressed/11.1.4-h16.html create mode 100644 reference/PAN-OS/addressed/11.1.4-h17.html create mode 100644 reference/PAN-OS/addressed/11.1.4-h18.html create mode 100644 reference/PAN-OS/addressed/11.1.4-h25.html create mode 100644 reference/PAN-OS/addressed/11.1.4-h27.html create mode 100644 reference/PAN-OS/addressed/11.1.4-h4.html create mode 100644 reference/PAN-OS/addressed/11.1.4-h7.html create mode 100644 reference/PAN-OS/addressed/11.1.4-h9.html create mode 100644 reference/PAN-OS/addressed/11.1.4.html create mode 100644 reference/PAN-OS/addressed/11.1.5-h1.html create mode 100644 reference/PAN-OS/addressed/11.1.5.html create mode 100644 reference/PAN-OS/addressed/11.1.8.html create mode 100644 reference/PAN-OS/addressed/11.1.9.html diff --git a/reference/PAN-OS/addressed/11.1.0-h1.html b/reference/PAN-OS/addressed/11.1.0-h1.html new file mode 100644 index 0000000..aea4660 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.0-h1.html @@ -0,0 +1,36 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-237871
+
+
+ (WF-500 appliances and PAN-DB private cloud deployments only) Fixed an issue where the + root-cert was set to expire on + December 31, 2023. With this fix, the expiration date has been + extended. +
+
diff --git a/reference/PAN-OS/addressed/11.1.0-h2.html b/reference/PAN-OS/addressed/11.1.0-h2.html new file mode 100644 index 0000000..e9865b3 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.0-h2.html @@ -0,0 +1,103 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-238792
+
+
+ Fixed the following device certificate issues: +
    +
  • + The firewall was unable to automatically renew the device + certificate-Fetching device certificates failed incorrectly with + the error message + OTP is not valid. +
  • +
  • + Firewalls disconnected from + Strata Logging Service after renewing the + device certificate. +
  • +
  • + The device certificate was not correctly generated on the log + forwarding card (LFC). +
  • +
  • + WildFire cloud logs did not log thermite certificate usage status. +
  • +
+
+
+
PAN-237876
+
+
+ Extended the firewall Panorama root CA certificate which was + previously set to expire on April 7th, 2024. +
+
+
PAN-231771
+
+
+ Fixed an issue where the firewall issued /box/getserv/ requests with + PAN-OS 7.1.0 and did not take device certificates. +
+
+
PAN-227568
+
+
+ When a device certificate is installed, renewed, or removed, the + firewall will reconnect to the WildFire cloud to use the newest + certificate. +
+
+
PAN-215576
+
+
+ Fixed an issue where the + userID-Agent and + TS-Agent certificates were set to + expire on November 18, 2024. With this fix, the expiration date has + been extended to January 2032. +
+
diff --git a/reference/PAN-OS/addressed/11.1.0-h3.html b/reference/PAN-OS/addressed/11.1.0-h3.html new file mode 100644 index 0000000..fbf13b0 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.0-h3.html @@ -0,0 +1,41 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-252214
+
+
+ A fix was made to address + CVE-2024-3400. +
+
diff --git a/reference/PAN-OS/addressed/11.1.0-h4.html b/reference/PAN-OS/addressed/11.1.0-h4.html new file mode 100644 index 0000000..cfffc82 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.0-h4.html @@ -0,0 +1,61 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-272809
+
+
+ A fix was made to address + CVE-2024-0012 + (PAN-SA-2024-0015) and + CVE-2024-9474. +
+
diff --git a/reference/PAN-OS/addressed/11.1.0.html b/reference/PAN-OS/addressed/11.1.0.html new file mode 100644 index 0000000..2c157dd --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.0.html @@ -0,0 +1,280 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-233557
+
+
+ Fixed an issue where, after using Panorama to configure per policy + persistent DIPP, downgrading the firewall using Panorama and then + upgrading the firewall back to a later PAN-OS release, the global DIPP + configuration was not successfully converted b ack to the per policy + persistent DIPP rules. +
+
+
PAN-230359
+
+
+ Fixed an issue where SAML authentication failed with the error message + Failed to verify signature against certificate + when ds:KeyName was in the IdP + metadata. +
+
+
PAN-227639
+
+
+ Fixed an issue where the + ACC displayed an incorrect DNS-base + application traffic byte count. +
+
+
PAN-227376
+
+
+ Fixed an issue where a memory overrun caused the + all_task + process to stop responding. +
+
+
PAN-227368
+
+
+ Fixed an issue where GlobalProtect users could not connect the app to + a portal or gateway and GlobalProtect Clientless VPN users were unable + to access applications when authentication took longer than 20 + seconds. +
+
+
PAN-226418
+
+
+ A CLI command was added to address an issue where long-lived sessions + aged out even when there was ongoing traffic. +
+
+
PAN-226198
+
+
+ Fixed an issue on Panorama where the + configd + process repeatedly restarted when attempting to make configuration + changes. +
+
+
PAN-225920
+
+
+ Fixed an issue where duplicate predict sessions didn't release NAT + resources. +
+
+
PAN-225886
+
+
+ Fixed an issue where if you enabled explicit proxy mode for the web + proxy, intermittent errors and unexpected TCP reconnections may have + occurred. +
+
+
PAN-225169
+
+
+ Added a CLI command to view + Strata Logging Service queue usage. +
+
+
PAN-224772
+
+
+ Fixed a high memory usage issue with the + mongodb + process that caused an OOM condition. +
+
+
PAN-224145
+
+
+ Fixed an issue in multi-vsys environments where, when Panorama was on + a PAN-OS 10.2 release and the firewall was on a PAN-OS 10.1 release, + commits failed on the firewall when inbound inspection mode was + configured in the decryption policy rule. +
+
+
PAN-223457
+
+
+ Fixed an issue where, if the number of group queries exceeded the Okta + rate limit threshold, the firewall cleared the cache for the groups. +
+
+
PAN-221126
+
+
+ Fixed an issue where email server profiles (Device > Server Profiles > Email and Panorama > Server + Profiles > Email) to forward logs as email notifications were not forwarded in a + readable format. +
+
+
PAN-218555
+
+
+ Fixed an issue where the firewall did not receive dynamic address + updates pushed from Panorama during initial registration to Panorama. +
+
+
PAN-213931
+
+
+ Fixed an issue where the + logrcvr + process cache was not in sync with the mapping on the firewall. +
+
+
PAN-206913
+
+ Fixed an issue where, when DHCPv6 client was configured on firewalls in + active/passive HA configurations, releasing the IPv6 address from the + client released the IPv6 address from only the active firewall. +
diff --git a/reference/PAN-OS/addressed/11.1.1-h1.html b/reference/PAN-OS/addressed/11.1.1-h1.html new file mode 100644 index 0000000..fbf13b0 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.1-h1.html @@ -0,0 +1,41 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-252214
+
+
+ A fix was made to address + CVE-2024-3400. +
+
diff --git a/reference/PAN-OS/addressed/11.1.1-h2.html b/reference/PAN-OS/addressed/11.1.1-h2.html new file mode 100644 index 0000000..cfffc82 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.1-h2.html @@ -0,0 +1,61 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-272809
+
+
+ A fix was made to address + CVE-2024-0012 + (PAN-SA-2024-0015) and + CVE-2024-9474. +
+
diff --git a/reference/PAN-OS/addressed/11.1.1.html b/reference/PAN-OS/addressed/11.1.1.html new file mode 100644 index 0000000..0d86a85 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.1.html @@ -0,0 +1,242 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-239241
+
+ Extended the root certificate for WildFire appliances to December 31, + 2032. +
+
PAN-238792
+
+
+ Fixed the following device certificate issues: +
    +
  • + The firewall was unable to automatically renew the device + certificate-Fetching device certificates failed incorrectly with + the error message + OTP is not valid. +
  • +
  • + Firewalls disconnected from + Strata Logging Service after renewing the + device certificate. +
  • +
  • + The device certificate was not correctly generated on the log + forwarding card (LFC). +
  • +
  • + WildFire cloud logs did not log thermite certificate usage status. +
  • +
+
+
+
PAN-237935
+
+
+ Extended the offline PAN-DB, Panorama, and WildFire certificates which + were previously set to expire on September 2, 2024. +
+
+
PAN-237876
+
+ Extended the firewall Panorama root CA certificate which was previously + set to expire on April 7th, 2024. +
+
PAN-236605
+
+
+ Fixed an issue where the + configd + process stopped responding due to a deadlock related to + rule-hit-count. +
+
+
PAN-235385
+
+
Enhanced wifclient cloud connectivity redundancy.
+
+
PAN-234929
+
+
+ Fixed an issue where tabs in the + ACC such as + Network Activity + Threat Activity and + Blocked Activity did not display + data when you applied a Time filter + of Last 15 Minutes, + Last Hour, + Last 6 Hours, or + Last 12 Hours, and the data that was + displayed with the + Last 24 Hours filter was not + accurate. Reports that were run against summary logs also did not + display accurate results. +
+
+
PAN-233957
+
+
+ (PA-5450 firewalls only) Fixed an issue where + the NAT private pool was not used properly when enabling slot 6 DPC. +
+
+
PAN-233191
+
+
+ (PA-5450 firewalls only) Fixed an issue where + the Data Processing Card (DPC) restarted due to path monitor failure + after QSFP28 disconnected from the Network Processing Card (NPC). +
+
+
PAN-232358
+
+
+ (PA-5450 firewalls only) Fixed an issue where + the interface on QSFP28 ports did not go down when the Tx cable was + removed from the QSFP28 module. +
+
+
PAN-231771
+
+
+ Fixed an issue where the firewall issued /box/getserv/ requests with + PAN-OS 7.1.0 and did not take device certificates. +
+
+
PAN-231658
+
+
+ Fixed an issue where DNS resolution failed when interfaces were + configured as DHCP and a DNS server was provided via DHCP while also + statically configured with DNS servers. +
+
+
PAN-231194
+
+
+ Fixed an issue where the firewall was unable to clear hints from the + disk. +
+
+
PAN-227568
+
+
+ When a device certificate is installed, renewed, or removed, the + firewall will reconnect to the WildFire cloud to use the newest + certificate. +
+
+
PAN-215576
+
+
+ Fixed an issue where the + userID-Agent and + TS-Agent certificates were set to + expire on November 18, 2024. With this fix, the expiration date has + been extended to January 2032. +
+
diff --git a/reference/PAN-OS/addressed/11.1.2-h1.html b/reference/PAN-OS/addressed/11.1.2-h1.html new file mode 100644 index 0000000..7485fbf --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.2-h1.html @@ -0,0 +1,73 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-242879
+
+
+ Fixed an issue where the dataplane restarted when advanced features + such as Advanced Threat Protection, Advanced WildFire, and Advanced + URL Filtering hit max latency under inline mode. +
+
+
PAN-242634
+
+
+ (PA-1400 Series, PA-3400 Series, and PA-5400 Series firewalls + only) Fixed an issue where a large packet burst from the dataplane to the + management plane caused the DPDK kernel network interface to become + unresponsive. +
+
+
PAN-240166
+
+
+ Fixed an issue where, when explicit proxy was configured on the + firewall, websites loaded more slowly than expected or did not load + due to DNS using TCP. +
+
+
PAN-239279
+
+
+ Fixed an issue where the proxy did not accept new connections. +
+
diff --git a/reference/PAN-OS/addressed/11.1.2-h12.html b/reference/PAN-OS/addressed/11.1.2-h12.html new file mode 100644 index 0000000..c8eb71d --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.2-h12.html @@ -0,0 +1,181 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-264421
+
+
+ Fixed an issue on Panorama where + Push Scope did not populate + automatically after changing the device group configuration. +
+
+
PAN-263226
+
+
+ Fixed an issue where decryption based traffic failed on Explicit Proxy + nodes. +
+
+
PAN-262831
+
+
+ (PA-5450 firewalls only) Fixed an intermittent + issue where the + all_task + process stopped responding, which caused the firewall to restart. +
+
+
PAN-262593
+
+
+ Fixed an issue where traffic to websites failed on the Google Chrome + web browser on Secure Web Gateway (SWG) nodes. +
+
+
PAN-261991
+
+
+ Fixed an issue where traffic that did not match a decryption policy + rule, or matched a no-decrypt policy rule, failed when accumulation + proxy was enabled and a Zone Protection profile was configured with + syn-cookies enabled. +
+
+
PAN-261917
+
+
+ Fixed an issue where websites with a no-decrypt policy rule were + decrypted in traffic log when using a Google Chrome browser with PQC + enabled. +
+
+
PAN-259769
+
+
+ Fixed an issue where the GlobalProtect portal was not accessible via a + web browser and displayed the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-258736
+
+
+ Fixed an issue where policy rule configurations pushed from Panorama + were not reflected on the firewall if the rule had 63 characters. +
+
+
PAN-253213
+
+
+ Fixed an issue where the firewall sent HIP notifications every time it + received a HIP report instead of every two hours. +
+
+
PAN-252300
+
+
+ Fixed an issue where you were unable to select device groups in the + push scope for user accounts. +
+
+
PAN-245690
+
+
+ Fixed an issue where the + Managed Collectors health status on + Panorama displayed as empty. +
+
+
PAN-209574
+
+
+ Fixed an issue with HTTP/2 traffic where downloading large files did + not work when decryption was enabled. +
+
diff --git a/reference/PAN-OS/addressed/11.1.2-h14.html b/reference/PAN-OS/addressed/11.1.2-h14.html new file mode 100644 index 0000000..9c85d30 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.2-h14.html @@ -0,0 +1,157 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
PAN-262287 +
+ Fixed an issue where dereferencing a NULL pointer that occurred caused + pan_task + processes to stop responding. +
+
+
PAN-261673
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where, when Accelerated Networking was enabled, + traffic was dropped because of the + flow_parse_ip_hdr + counter related to an Nvidia driver issue. +
+
+
PAN-259151
+
+
+ Fixed an issue where unused objects were pushed to the firewall, which + caused configuration pushes to fail with the error + Number of address groups exceed platform capacity. +
+
+
PAN-259002
+
+
+ Fixed an issue where frequent external dynamic list updates caused the + configd + process to restart. +
+
+
PAN-257601
+
+
+ (PA-5450 firewalls only) Fixed an issue where + Networking Cards (NC) experienced an internal link fault which caused + path monitoring failure on the Dataplane Processing Card (DPC). +
+
+
PAN-257327
+
+
+ Fixed an issue where a failover event occurred unexpectedly on the + firewall. +
+
+
PAN-253626
+
+
+ Fixed an issue on Panorama where unused objects were pushed to the + firewall, which caused the push operations to intermittently fail. +
+
+
PAN-236191
+
+
+ Fixed an issue where the web interface performance was slower than + expected. +
+
+
PAN-222542
+
+
+ (PA-7000 Series firewalls only) Fixed an issue + where Log Forward Cards (LFC) were incorrectly identified as + distribution policies, which caused packet loss due to traffic, BFD, + and other control packets being forwarded to the LFC. +
+
diff --git a/reference/PAN-OS/addressed/11.1.2-h15.html b/reference/PAN-OS/addressed/11.1.2-h15.html new file mode 100644 index 0000000..cfffc82 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.2-h15.html @@ -0,0 +1,61 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-272809
+
+
+ A fix was made to address + CVE-2024-0012 + (PAN-SA-2024-0015) and + CVE-2024-9474. +
+
diff --git a/reference/PAN-OS/addressed/11.1.2-h16.html b/reference/PAN-OS/addressed/11.1.2-h16.html new file mode 100644 index 0000000..e58754c --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.2-h16.html @@ -0,0 +1,245 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-272809
+
+
+ A fix was made to address + CVE-2024-0012 + (PAN-SA-2024-0015) and + CVE-2024-9474. +
+
+
PAN-269000
+
+
+ Fixed an issue where the firewall stopped responding due to a NULL + pointer dereference when path monitoring failed. +
+
+
PAN-265785
+
+
+ Fixed an issue where the firewall rebooted due to a + sysd + variable being modified before it was created. +
+
+
PAN-265179
+
+
+ Fixed an issue where a kernel race condition caused the firewall to + reboot with a kernel panic. +
+
+
PAN-263973
+
+
+ Fixed an issue where log collectors had a low incoming log rate. +
+
+
PAN-263208
+
+
+ (PA-5440 and PA-5445 firewalls only) Fixed an + issue where interrupts were generated at a certain packet rate, and + dataplane processes missed heartbeats, which caused the dataplane to + go down. +
+
+
PAN-259881
+
+
+ Fixed an issue on Panorama where traffic log details were not + displayed under detailed log view. +
+
+
PAN-259351
+
+
+ A fix was made to address + CVE-2024-3393. +
+
+
PAN-256223
+
+
+ Fixed an issue where device telemetry log collection filled the root + partition. +
+
+
PAN-255747
+
+
+ Fixed an issue on the firewall where CLI commands returned + Server error: op command for client dagger timed out as client is + not available. +
+
+
PAN-253485
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where dataplane packet capture filter configuration + failed on the active firewall with the error + op command for client dagger timed out as client is not + available. +
+
+
PAN-249300
+
+
+ Fixed an issue where, when CUID was enabled, the CUID firewall pub + node was slower than expected when processing incoming traffic and + User-ID mapping redistribution between PAN-OS nodes was impacted. +
+
+
PAN-219805
+
+
+ Fixed an issue where the + reportd + process stopped responding due to a race condition. +
+
diff --git a/reference/PAN-OS/addressed/11.1.2-h18.html b/reference/PAN-OS/addressed/11.1.2-h18.html new file mode 100644 index 0000000..9633936 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.2-h18.html @@ -0,0 +1,95 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-279604
+
+
+ Fixed an issue where scheduled SaaS application usage reports were + generated incorrectly, and the login page was displayed instead of the + report content. +
+
+
PAN-273085
+
+
+ Fixed an issue on the web interface where you were unable to edit or + create policy rules. +
+
+
PAN-272006
+
+
+ Fixed an issue where the firewall did not trigger a kernel core dump + as a large core when the CPLD (Complex Programmable Logic Device) sent + a Non-Maskable Interrupt (NMI) to the CPU. +
+
+
PAN-271926
+
+
+ Fixed an issue where TLS 1.3 decryption failed with a bad record MAC + error when the firewall was configured to decrypt and inspect TLS + traffic. +
+
+
PAN-270549
+
+
+ Fixed an issue where some TLS connections were not handled correctly, + which led to instability in the dataplane. +
+
+
PAN-268727
+
+
+ Fixed an issue where traffic was dropped when the accumulation proxy + was enabled and header insertion modified packets. +
+
diff --git a/reference/PAN-OS/addressed/11.1.2-h3.html b/reference/PAN-OS/addressed/11.1.2-h3.html new file mode 100644 index 0000000..7b80365 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.2-h3.html @@ -0,0 +1,84 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-252214
+
+
+ A fix was made to address + CVE-2024-3400. +
+
+
PAN-246949
+
+
+ Fixed an issue where custom admin users were not able to click + OK in the push scope selection + window when device group or template were disabled under commit in the + admin roles. +
+
+
PAN-244013
+
+
+ Fixed an issue on the Panorama web interface where, when a new content + package was installed, new + Anti-Spyware Signatures and new + Vulnerability Signatures were not + visible in their respective profiles. +
+
+
PAN-243951
+
+
+ Fixed an issue on Panorama appliances in active/passive HA + configurations where managed devices displayed as out-of-sync on the + passive appliance when peer configuration changes were made to the + SD-WAN configuration on the active peer. +
+
diff --git a/reference/PAN-OS/addressed/11.1.2-h4.html b/reference/PAN-OS/addressed/11.1.2-h4.html new file mode 100644 index 0000000..6879dd5 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.2-h4.html @@ -0,0 +1,430 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-252214
+
+
+ A fix was made to address + CVE-2024-3400. +
+
+
PAN-251013
+
+
+ Fixed an issue on the web interface where the + Virtual Router and + Virtual System + configurations for the template incorrectly showed as + none. +
+
+
PAN-250686
+
+
+ Fixed an issue where selective push operations did not work when more + than one admin user simultaneously performed changes and partial + commits on Panorama. +
+
+
PAN-249931
+
+
+ Fixed an issue where configuration pushes from Panorama on PAN-OS + 11.1.1 to a firewall on a PAN-OS 10.2 release failed. +
+
+
PAN-249808
+
+
+ Fixed an issue where the + configd + process stopped responding when performing multi-device group pushes + via XML API. +
+
+
PAN-247403
+
+
+ (VM-Series firewalls only) Fixed an issue where + the push scope CLI command took longer than expected, which caused the + web interface to be slow. +
+
PAN-246960 +
+ Fixed an issue where firewalls failed to fetch content updates from + the Wildfire Private Cloud due to an + Unsupported protocol error. +
+
+
PAN-244894
+
+
+ Fixed an issue where turning off + mprelay + logging caused *mprelay* heartbeat failure. +
+
+
PAN-244622
+
+
+ Fixed an issue where FIB re-push did not work with Advanced Routing + enabled. +
+
+
PAN-244227
+
+
+ Fixed an issue where inconsistent FIB entries across the dataplane + were not detected. +
+
+
PAN-242309
+
+
+ Fixed an issue where a higher byte count (s2c) was observed for + DNS-Base application. +
+
+
PAN-242027
+
+
+ Fixed an issue where the + all-task + process repeatedly restarted during memory allocation failures. +
+
+
PAN-241141
+
+
+ Fixed an issue where creating more than one address object in the same + XML API request resulted in a commit error. +
+
+
PAN-240477
+
+
+ Fixed a temporary hardware issue that caused PAN-SFP-PLUS-CU-5M to not + be able to link up on PA-3400 and PA-1400 Series firewalls. +
+
+
PAN-240308
+
+
+ Fixed an issue where ElasticSearch did not work as expected when + raid-mounts were not fully ready after a reboot. +
+
+
PAN-239367
+
+
+ Fixed an issue on the firewall where a memory leak associated with the + logrcvr + process occurred. +
+
+
PAN-239354
+
+
+ Fixed an issue where DNS resolution was delayed when an Antispyware + policy rule was applied to both client to firewall and firewall to + internal DNS server legs of a connection. +
+
+
PAN-238643
+
+ Fixed an issue where a memory leak caused multiple processes to stop + responding when VM Information Sources was configured +
+
PAN-237537
+
+
+ Fixed an issue where, when deleting CTD entries, the + all_pktproc + process stopped responding which resulted in dataplane failure. +
+
+
PAN-237208
+
+
+ Fixed an issue where the + reportd + process stopped and the firewall rebooted. +
+
+
PAN-233789
+
+
+ Fixed an issue with push and commit and push operations where the user + was not correctly bound to the scope, which caused all device groups + to be selected for a selective push. +
+
+
PAN-233692
+
+
+ Fixed an issue on Panorama where the + configd + process stopped, which caused performance issues. +
+
+
PAN-233684
+
+ Fixed an issue on Panorama where + Push to Devices or + Commit and Push operations took longer + than expected on the web interface. +
+
PAN-231148
+
+
+ Fixed an issue where no DHCP option list was defined when using + GlobalProtect. +
+
+
PAN-230746
+
+
+ Fixed an issue on the web interface where device groups with a large + number of managed firewalls displayed the + Policy page more slowly than + expected. +
+
+
PAN-205482
+
+
+ Fixed an issue related to the + configd + process where Panorama displayed the error + Server not responding when editing + policies. +
+
diff --git a/reference/PAN-OS/addressed/11.1.2-h9.html b/reference/PAN-OS/addressed/11.1.2-h9.html new file mode 100644 index 0000000..d5dea3e --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.2-h9.html @@ -0,0 +1,288 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-258225
+
+
+ Fixed an issue on the Panorama web interface where Security policy + rules loaded more slowly than expected. +
+
+
PAN-257615
+
+
+ Fixed an issue on Panorama where logs did not display or displayed + intermittently on the web interface. +
+
+
PAN-256725
+
+
+ Fixed an issue on the Panorama interface where + Traffic and + Unified event details loaded more + slowly than expected. +
+
+
PAN-255868
+
+
+ (PA-3400 Series firewalls only) Fixed an issue + where the firewall entered maintenance mode after enabling kernel data + collection during the silent reboot. +
+
+
PAN-255266
+
+
+ Fixed an issue where you were unable to clone a template stack with + the Pre-Shared Key variable. +
+
+
PAN-254411
+
+
+ Fixed an issue where the + configd + process stopped responding, which caused + RR_CONNECTION_REFUSED error messages + to be displayed in admin sessions. +
+
+
PAN-253546
+
+
+ Fixed an issue where a TLS client hello was split into multiple + packets and arrived out of order, so the packets were dropped and the + session terminated. +
+
+
PAN-251563
+
+
+ Added CPLD enhancement to capture external power issues. +
+
+
PAN-247099
+
+
+ Fixed an issue where the firewall decrypted traffic unexpectedly when + the client hello was spread across multiple packets. +
+
+
PAN-246772
+
+
+ Fixed an issue on the firewall where the dataplane went down due to a + path monitor failure caused by an OOM condition related to the + pan_task + process. +
+
+
PAN-246059
+
+
+ Fixed an issue where forwarded logs were not visible on Panorama due + to the Elasticsearch service not starting when it encountered old and + unsupported indices. +
+
+
PAN-245428
+
+
+ Fixed an issue where FIB entries aged out and were incorrectly removed + after an HA failover event. +
+
+
PAN-244548
+
+
+ Fixed an issue where ECMP sessions changed destination MAC addresses + mid-session, which caused connections to be reset. +
+
+
PAN-243098
+
+
+ Fixed an issue with corrupted images when SSL decryption and Security + profiles were configured. +
+
+
PAN-240739
+
+
+ Fixed an issue where the ECMP FIB update on the dataplane didn't clear + the pending change flag, which caused the next non-ECMP FIB update to + miss the latest generation ID and age out after 5 minutes. +
+
+
PAN-240612
+
+
Fixed a kernel panic caused by a third-party issue.
+
+
PAN-240596
+
+
+ Fixed an issue where the + all_task + process stopped responding due to an invalid memory address. +
+
+
PAN-236133
+
+
+ Fixed an issue where SSL traffic was impacted when + SSL Command and Control detector for + Incline Cloud Analysis was set to + reset-both, reset-client, + reset-server, or + drop. +
+
+
PAN-234560
+
+
+ Fixed an issue where the daily summary report displayed IPv6 addresses + instead of IPv4 addresses. +
+
diff --git a/reference/PAN-OS/addressed/11.1.2.html b/reference/PAN-OS/addressed/11.1.2.html new file mode 100644 index 0000000..e06e330 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.2.html @@ -0,0 +1,284 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-242627
+
+
Fixed an issue where selective push did not work.
+
+
PAN-242561
+
+
+ Fixed an issue where GlobalProtect tunnels disconnected shortly after + being established when SSL was used as the transfer protocol. +
+
+
PAN-242519
+
+
+ Fixed an issue where scheduled email reports failed if the + @ + symbol before the mail client was missing. +
+
+
PAN-241504
+
+
+ Fixed an issue on the web interface where filtering logs under the + Monitor tab was slower than + expected. +
+
+
PAN-239769
+
+
+ Fixed an issue where object references in a rule were renamed, and a + selective revert of the changes with + Commit changes by me caused a + reference error. +
+
+
PAN-238769
+
+
+ (VM-Series firewalls in FIPS-CC mode only) + Fixed an issue where upgrading Panorama caused all locally created + Security policy rule actions to Deny. +
+
+
PAN-238586
+
+
+ Fixed an issue where DNS resolution failure from the LFC resulted in + WildFire public cloud connectivity failure. +
+
+
PAN-236120
+
+
+ Fixed an issue where the /opt/panlogs partition reached capacity due + to the logdb-quota for the User-ID log folder not being matched. +
+
+
PAN-235840
+
+
+ Fixed an issue where, after a configuration push from Panorama to + managed firewalls, the status displayed as + None and the push took longer than + expected. +
+
+
PAN-235585
+
+
+ Fixed an issue where, when custom signatures and predefined signatures + shared the same literal pattern part, the custom signature caused an + incorrect calculation for the length of the predefined signature, + which resulted in App-ID not detecting correctly. +
+
+
PAN-234279
+
+
+ Fixed an issue where the + ikemgr + process crashed due to an IKEv1 timing issue, which caused commits to + fail with the following error message: + Client ikemgr requesting last config in the middle of a + commit/validate, aborting current commit. +
+
+
PAN-230106
+
+
+ Fixed an issue where the firewall was unable to retrieve the most + current external dynamic list information from the server due to + hostname resolution failure. +
+
+
PAN-227397
+
+
+ Fixed an issue where selective pushes on Panorama removed a previously + pushed configuration from the firewalls. +
+
+
PAN-226785
+
+
+ Fixed an issue where accessing websites with HTTP to HTTPS redirect + failed via explicit proxy. +
+
+
PAN-225337
+
+
+ Fixed an issue on Panorama related to Shared configuration objects + where configuration pushes to multi-vsys firewalls failed. +
+
+
PAN-225203
+
+
+ Fixed an issue where the Log Forwarding Card (LFC) did not honor the + negotiated MSS on the logging connection. +
+
+
PAN-224954
+
+
+ Fixed an issue where, after upgrading and rebooting a Panorama + appliance in Panorama or Log Collector mode, managed firewalls + continuously disconnected. +
+
+
PAN-223259
+
+
+ Fixed an issue where selective pushes failed with the error message + Failed to generate selective push configuration. Unable to retrieve + last in-sync configuration for the device, either a push was never + done or version is too old. Please try a full push. +
+
+
PAN-216941
+
+
+ (Panorama appliances in Log Collector mode only) Fixed an issue where Panorama stopped processing and saving logs. +
+
diff --git a/reference/PAN-OS/addressed/11.1.3-h1.html b/reference/PAN-OS/addressed/11.1.3-h1.html new file mode 100644 index 0000000..b018cea --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.3-h1.html @@ -0,0 +1,45 @@ + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-256765
+
+
+ Fixed an issue where you were unable to push variables from Panorama + in service routes for non-cluster templates. +
+
+
PAN-255868
+
+
+ (PA-3400 Series firewalls only) Fixed an issue + where the firewall entered maintenance mode after enabling kernel data + collection during the silent reboot. +
+
diff --git a/reference/PAN-OS/addressed/11.1.3-h10.html b/reference/PAN-OS/addressed/11.1.3-h10.html new file mode 100644 index 0000000..0097294 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.3-h10.html @@ -0,0 +1,281 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-265336
+
+
+ (PA-800 Series, PA-3200 Series, PA-5200 Series, and PA-5450 + firewalls only) Fixed an issue where the copper ports flapped when generating a + technical support file or executing telemetry. +
+
+
PAN-265287
+
+
+ Fixed an issue where the firewall experienced a packet buffer leak in + the dataplane of the network processing card (NPC) when processing + certain net messages. +
+
+
PAN-265287
+
+
+ Fixed an issue where the firewall experienced a packet buffer leak in + the dataplane of the NPC when processing certain net messages. +
+
+
PAN-263973
+
+
+ Fixed an issue where log collectors had a low incoming log rate. +
+
+
PAN-262287
+
+
+ Fixed an issue where dereferencing a NULL pointer that occurred caused + pan_task + processes to stop responding. +
+
+
PAN-261485
+
+
+ Fixed an issue where the firewall dropped the Real Time Transport + Protocol (RTP) session for the second SIP call on Persistent-DIPP + connections when the source port of the client device was reset. +
+
+
PAN-259733
+
+
+ Fixed an issue where a custom report was not deleted on Panorama when + expected. +
+
+
PAN-259151
+
+
+ Fixed an issue where unused objects were pushed to the firewall, which + caused configuration pushes to fail with the error + Number of address groups exceed platform capacity. +
+
+
PAN-257912
+
+
+ Fixed an issue where the firewall stopped responding when it received + RADIUS traffic and user equipment (UE) traffic at the same time on an + NPC. +
+
+
PAN-257615
+
+
+ Fixed an issue on Panorama where logs did not display or displayed + intermittently on the web interface. +
+
+
PAN-257601
+
+
+ (PA-5450 firewalls only) Fixed an issue where + Networking Cards (NC) experienced an internal link fault which caused + path monitoring failure on the Dataplane Processing Card (DPC). +
+
+
PAN-257327
+
+
+ (PA-5440 firewalls only) Fixed an issue where a + failover event occurred unexpectedly on the firewall. +
+
+
PAN-256725
+
+
+ Fixed an issue on the Panorama interface where + Traffic and + Unified event details loaded more + slowly than expected. +
+
+
PAN-254794
+
+
+ Fixed an issue where the Panorama management server stopped + responding. +
+
+
PAN-253626
+
+
+ Fixed an issue on Panorama where unused objects were pushed to the + firewall, which caused the push operations to intermittently fail. +
+
+
PAN-250394
+
+
+ Fixed an issue where a large amount of group data caused serialization + errors and prevented synchronization. +
+
+
PAN-246708
+
+
+ Fixed an issue where the firewall stopped responding when the + all_pktproc + repeatedly restarted. +
+
+
PAN-243098
+
+
+ Fixed an issue with corrupted images when SSL decryption and Security + profiles were configured. +
+
+
PAN-222542
+
+
+ (PA-7000 Series firewalls only) Fixed an issue + where Log Forward Cards (LFC) were incorrectly identified as + distribution policies, which caused packet loss due to traffic, BFD, + and other control packets being forwarded to the LFC. +
+
diff --git a/reference/PAN-OS/addressed/11.1.3-h11.html b/reference/PAN-OS/addressed/11.1.3-h11.html new file mode 100644 index 0000000..cfffc82 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.3-h11.html @@ -0,0 +1,61 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-272809
+
+
+ A fix was made to address + CVE-2024-0012 + (PAN-SA-2024-0015) and + CVE-2024-9474. +
+
diff --git a/reference/PAN-OS/addressed/11.1.3-h13.html b/reference/PAN-OS/addressed/11.1.3-h13.html new file mode 100644 index 0000000..8cf5e62 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.3-h13.html @@ -0,0 +1,237 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-272809
+
+
+ A fix was made to address + CVE-2024-0012 + (PAN-SA-2024-0015) and + CVE-2024-9474. +
+
+
PAN-269000
+
+
+ Fixed an issue where the firewall stopped responding due to a NULL + pointer dereference when path monitoring failed. +
+
+
PAN-265785
+
+
+ Fixed an issue where the firewall rebooted due to a + sysd + variable being modified before it was created. +
+
+
PAN-263208
+
+
+ (PA-5440 and PA-5445 firewalls only) Fixed an + issue where interrupts were generated at a certain packet rate, and + dataplane processes missed heartbeats, which caused the dataplane to + go down. +
+
+
PAN-260604
+
+
+ Fixed an issue where the firewall displayed inaccurate throughput + utilization stats in NetFlow analyzer tools. +
+
+
PAN-259881
+
+
+ Fixed an issue on Panorama where traffic log details were not + displayed under detailed log view. +
+
+
PAN-259351
+
+
+ A fix was made to address + CVE-2024-3393. +
+
+
PAN-258799
+
+
+ Fixed an issue where, when updating a Security Policy + Policy Optimizer, the web interface + stopped responding. +
+
+
PAN-256223
+
+
+ Fixed an issue where device telemetry log collection filled the root + partition. +
+
+
PAN-255915
+
+
+ Fixed an issue where a memory leak in the + sslmgr + process caused the firewall to restart. +
+
+
PAN-254826
+
+
+ Fixed an issue where the firewall stopped responding when processing + traffic. +
+
+
PAN-254794
+
+
+ Fixed an issue where the Panorama management server stopped + responding. +
+
+
PAN-254577
+
+
+ Fixed an issue where a core file was created on the Log Forwarding + Card (LFC) due to a third-party software issue. +
+
diff --git a/reference/PAN-OS/addressed/11.1.3-h2.html b/reference/PAN-OS/addressed/11.1.3-h2.html new file mode 100644 index 0000000..de745db --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.3-h2.html @@ -0,0 +1,115 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-259733
+
+
+ Fixed an issue where a custom report was not deleted on Panorama when + expected. +
+
+
PAN-259473
+
+
+ (PA-5450 firewalls only) Fixed an issue where + the chassis shut down when FAN1 was removed. +
+
+
PAN-254411
+
+
+ Fixed an issue where the + configd + process stopped responding, which caused + ERR_CONNECTION_REFUSED error messages to be + displayed in admin sessions. +
+
+
PAN-253546
+
+
+ Fixed an issue where a TLS client hello was split into multiple + packets and arrived out of order, so the packets were dropped and the + session terminated. +
+
+
PAN-249814
+
+
+ Fixed an issue where multiple + all_task + processes stopped responding, which caused the dataplane to fail. +
+
+
PAN-247099
+
+
+ Fixed an issue where the firewall decrypted traffic unexpectedly when + the client hello was spread across multiple packets. +
+
diff --git a/reference/PAN-OS/addressed/11.1.3-h4.html b/reference/PAN-OS/addressed/11.1.3-h4.html new file mode 100644 index 0000000..40a1110 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.3-h4.html @@ -0,0 +1,166 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-259480
+
+
+ Fixed an issue where the + varrcvr + process stopped responding after running out of memory due to how the + process queued and dequeued files for WildFire file forwarding when a + WildFire Analysis Security profile was enabled. +
+
+
PAN-257925
+
+
+ (CN-Series firewalls only) Fixed an issue where + the CLI command + show system setting ctd state did + not work as expected. +
+
+
PAN-257615
+
+
+ Fixed an issue on Panorama where logs did not display or displayed + intermittently on the web interface. +
+
+
PAN-257462
+
+
+ Fixed an issue related to the + varrcvr + process where the management plane CPU was higher than expected during + WildFire updates. +
+
+
PAN-256385
+
+
+ (CN-Series firewalls only) Fixed an issue where + communication was broken between the management plane and the + dataplane when anti-spyware profiles were configured in a Security + policy rule. +
+
+
PAN-254373
+
+
+ Fixed an issue where the firewall did not handle error code 500 + responses from the WildFire cloud correctly. +
+
+
PAN-251639
+
+
+ Fixed an issue where an out-of-memory condition occurred due to a + memory leak related to the + varrvcr + process when a WildFire Analysis security profile was enabled. +
+
+
PAN-248148
+
+
Jumbo frame feature support is enabled.
+
+
PAN-225213
+
+
+ Fixed an issue where + Push All Changes displayed changes + that were already committed in the push scope for another device group + after performing a selective commit and selective push to the first + device group. +
+
diff --git a/reference/PAN-OS/addressed/11.1.3-h6.html b/reference/PAN-OS/addressed/11.1.3-h6.html new file mode 100644 index 0000000..c93235d --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.3-h6.html @@ -0,0 +1,133 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-263226
+
+
+ Fixed an issue where decryption based traffic failed on Explicit Proxy + nodes. +
+
+
PAN-262593
+
+
+ Fixed an issue where traffic to websites failed on the Google Chrome + web browser on Secure Web Gateway (SWG) nodes. +
+
+
PAN-261991
+
+
+ Fixed an issue where traffic that did not match a decryption policy + rule, or matched a no-decrypt policy rule, failed when accumulation + proxy was enabled and a Zone Protection profile was configured with + syn-cookies enabled. +
+
+
PAN-261917
+
+
+ Fixed an issue where websites with a no-decrypt policy rule were + decrypted in traffic log when using a Google Chrome browser with PQC + enabled. +
+
+
PAN-259769
+
+
+ Fixed an issue where the GlobalProtect portal was not accessible via a + web browser and displayed the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-257957
+
+
+ (Firewalls and Panorama appliances in FIPS-CC mode only) Fixed an issue where the + authd + process restarted if RADIUS PAP/CHAP authentication was used. +
+
+
PAN-242331
+
+
+ Fixed an issue where Prisma Access remote network firewalls + intermittently created incorrect user-to-IP-address mappings. +
+
+
PAN-232214
+
+
+ Fixed an issue where GlobalProtect clients remained in the connecting + state during portal pre-login when Kerberos single sign-on (SSO) was + enabled. +
+
diff --git a/reference/PAN-OS/addressed/11.1.3.html b/reference/PAN-OS/addressed/11.1.3.html new file mode 100644 index 0000000..9527b5c --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.3.html @@ -0,0 +1,2038 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-251013
+
+
+ Fixed an issue on the web interface where the + Virtual Router and + Virtual System + configurations for the template incorrectly showed as + none. +
+
+
PAN-250686
+
+
+ Fixed an issue where selective push operations did not work when more + than one admin user simultaneously performed changes and partial + commits on Panorama. +
+
+
PAN-249808
+
+
+ Fixed an issue where the + configd + process stopped responding when performing multi-device group pushes + via XML API. +
+
+
PAN-249597
+
+
+ Fixed an issue where the Policy page + on the Panorama web interface was slower than expected when a device + group had a large number of managed devices. +
+
+
PAN-249019
+
+
+ Fixed an issue where the + all_pktproc + process stopped responding, which caused the firewall to become + unresponsive. +
+
+
PAN-248748
+
+
+ Fixed an issue that caused the dataplane to stop responding when + running a packet diagnostic with Jumbo frames enabled. +
+
+
PAN-248105
+
+
+ Fixed an issue where the GlobalProtect SSL VPN tunnel immediately + disconnected due to a keep-alive timeout. +
+
+
PAN-247403
+
+
+ (Panorama virtual appliances only) Fixed an + issue where the push scope CLI command took longer than expected, + which caused the web interface to be slow. +
+
+
PAN-246707
+
+
+ Fixed an issue where failover was not triggered when multiple + processes stopped responding. +
+
+
PAN-246420
+
+
+ (PA-5450 Series firewalls only) Fixed an issue + where the firewall rebooted unexpectedly during an upgrade. +
+
+
PAN-246215
+
+
+ Fixed an issue where the sleep time for a suspended + pan_task + process caused configuration and policy updates to be blocked. +
+
+
PAN-245701
+
+
+ Fixed an issue where the returned values to SNMP requests for data + port statistics were incorrect. +
+
+
PAN-245690
+
+
+ Fixed an issue where the Managed Collectors health status on Panorama + displayed as empty. +
+
+
PAN-245428
+
+
+ Fixed an issue where FIB entries aged out and were incorrectly removed + after an HA failover event. +
+
+
PAN-245387
+
+
+ Fixed an issue where selective push failed intermittently due to + schema validation or bad encryption errors. +
+
+
PAN-245041
+
+
+ Fixed an issue where the WF-500 appliance returned an error verdict + for every sample in FIPS mode. +
+
+
PAN-244907
+
+
+ (PA-3400, PA-5400, and PA-1400 Series firewalls only) Fixed an issue where virtual wire ports did not go down when moving + from an active state to a suspended state. +
+
+
PAN-244894
+
+
+ Fixed an issue where turning off + mprelay + logging caused + mprelay + heartbeat failure. +
+
+
PAN-244836
+
+
+ A knob was introduced to toggle the default behavior of BGP in the + Advanced Routing stack to not suppress duplicate updates. By default, + the prefix updates are suppressed for optimization. +
+
+
PAN-244648
+
+
+ Fixed an issue where, when FIPS was enabled in maintenance mode, the + firewall rebooted and returned to maintenance mode. +
+
+
PAN-244625
+
+
+ (VM-Series firewalls only) Fixed an issue where + incorrect virtual MAC addresses were used in interfaces. +
+
+
PAN-244622
+
+
+ Fixed an issue where FIB re-push did not work with Advanced Routing + enabled. +
+
+
PAN-244548
+
+
+ Fixed an issue where ECMP sessions changed destination MAC addresses + mid-session, which caused connections to be reset. +
+
+
PAN-244493
+
+
+ Fixed a memory limitation with mapping subinterfaces to VPCE endpoints + for GCP IPS, Amazon Web Services (AWS) integration with GWLB, and NSX + service chain mapping. +
+
+
PAN-244227
+
+
+ Fixed an issue where inconsistent FIB entries across the dataplane + were not detected. +
+
+
PAN-244013
+
+
+ Fixed an issue where the web interface did not display newly added + Anti-Spyware signatures or Vulnerability Signatures. +
+
+
PAN-243463
+
+
+ Fixed an issue where high Enhanced Application Log traffic used excess + system resources and caused processes to not work. +
+
+
PAN-242027
+
+
+ Fixed an issue where the + all-task + process repeatedly restarted during memory allocation failures. +
+
+
PAN-241548
+
+
+ Fixed an issue where the firewall stopped responding when switching + from endpoint authentication bypass to endpoint Kerberos + authentication with SWG-proxy traffic. +
+
+
PAN-241230
+
+
+ Fixed an issue where the SNMP get request status value for Panorama + connections was incorrect. +
+
+
PAN-241164
+
+
+ (PA-410 firewalls only) Fixed an issue where + system and configuration logs sent from the firewall to Panorama + contained the serial number field instead of the firewall device name. +
+
+
PAN-241141
+
+
+ Fixed an issue where creating more than one address object in the same + XML API request resulted in a commit error. +
+
+
PAN-241041
+
+
+ Fixed an issue where, after upgrading to 11.1.0, exporting CSV files + for template stack variables or template variables resulted in an + empty file. +
+
+
PAN-241018
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed a Dataplane Development Kit (DPDK) issue where interfaces + remained in a link-down stage after an Azure hot plug event. +
+
+
PAN-240993
+
+
+ Fixed an issue where you were unable to revert a sort in task manager + in the admin column. +
+
+
PAN-240786
+
+
+ Fixed an issue on firewalls in HA configurations where VXLAN sessions + were allocated, but not installed or freed, which resulted in a + constant high session table usage that was not synced between the + firewalls. This resulted in a session count mismatch. +
+
+
PAN-240618
+
+
+ Fixed an issue where configuration commits were successful even when + dynamic peer IKE gateways configured on the same interface and IP + address that did not have the same IKE crypto profile. +
+
+
PAN-240612
+
+
Fixed a kernel panic caused by a third-party issue
+
+
PAN-240596
+
+
+ Fixed an issue where + all_task + stopped responding due to an invalid memory address. +
+
+
PAN-240477
+
+
+ Fixed a temporary hardware issue that caused PAN-SFP-PLUS-CU-5M to not + be able to link up on PA-3400 and PA-1400 Series firewalls. +
+
+
PAN-240368
+
+
+ Fixed an issue where authentication portal redirection for HTTPS + websites did not work when + Enhanced Handling of SSL/TLS Handshakes for Decrypted Traffic + was enabled. +
+
+
PAN-240347
+
+
+ Fixed an issue with the web interface where the + Dashboard and a + Device Group policy rule took longer + than expected to load. +
+
+
PAN-240308
+
+
+ Fixed an issue where ElasticSearch did not work as expected when + raid-mounts were not fully ready after a reboot. +
+
+
PAN-240251
+
+
+ Fixed an issue where the + vldmgr + process incorrectly restarted during an Elasticsearch restart. +
+
+
PAN-239776
+
+
+ Fixed an issue where Panorama went into maintenance mode due to a + GlobalProtect quota configuration that was under the minimum required + quota. +
+
+
PAN-239722
+
+
+ Fixed an issue where SNMP scans to the firewall took longer than + expected and intermittently timed out. +
+
+
PAN-239662
+
+
+ Fixed an issue where the NSSA default route from the firewall was not + generated to advertise even though the backbone area default route was + advertised during a graceful restart. +
+
+
PAN-239367
+
+
+ Fixed an issue on the firewall where a memory leak associated with the + logrcvr + process occurred. +
+
+
PAN-239354
+
+
+ Fixed an issue where DNS resolution was delayed when an antispyware + policy rule was applied to both client to firewall and firewall to + internal DNS server legs of a connection. +
+
+
PAN-239337
+
+
+ Fixed an issue where the log_index was suspended and corrupted BDX + files flooded the index_log. +
+
+
PAN-239256
+
+
+ Fixed an issue where ARP entries were unable to be completed for + subinterfaces with SNAT configured. +
+
+
PAN-239255
+
+
+ Fixed an issue where the firewall did not update the ARP cache timeout + value after modifying the + arp-cache-timeout setting. +
+
+
PAN-238996
+
+
+ Fixed an issue where commits did not complete and remained in a + pending state due to a race condition. With this fix, the commit will + fail after 60 seconds and not remain in a pending state. +
+
+
PAN-238643
+
+
+ Fixed an issue where a memory leak caused multiple processes to stop + responding when VM Information Sources was configured. +
+
+
PAN-238625
+
+
+ Fixed an issue where, when the physical interface went down, the + SD-WAN Ethernet connection state still showed + UP/path-monitor due to the Active + URL SaaS monitor connection state remaining UP/path-monitor. +
+
+
PAN-238621
+
+
+ Fixed an issue where the HA3 link status remained down when updating + the HA3 interface configuration when the AE interface was up. +
+
+
PAN-238562
+
+
+ Fixed an issue where log collectors stopped responding when gathering + reports from Panorama. +
+
+
PAN-238508
+
+
+ Fixed an issue where the + routed + process created excessive logs in the log file. +
+
+
PAN-237678
+
+
+ Fixed an issue with firewalls in active/passive HA configurations + where the passive firewall displayed the error message + Unable to read QSFP Module ID + when the passive link state was set to shutdown. +
+
+
PAN-237537
+
+
+ Fixed an issue where, when deleting CTD entries, the + all_pktproc + process stopped responding which resulted in dataplane failure. +
+
+
PAN-237478
+
+
+ Fixed an issue where the traffic log displayed 0 bytes for denied + sessions. +
+
+
PAN-237454
+
+
+ Fixed an issue where Panorama stopped redistributing IP + address-to-username mappings when packet loss occurred between the + distributor and the client. +
+
+
PAN-237369
+
+
+ (PA-1420 firewalls only) Fixed an issue where + the + all_task + process stopped responding, which caused the firewall to become + unresponsive. +
+
+
PAN-237246
+
+
+ Fixed an issue where the + all_pktproc + process repeatedly restarted, which caused the firewall to go into a + nonfunctional state. +
+
+
PAN-236802
+
+
+ Fixed an issue on firewalls in HA configurations where unexpected + failovers occurred. +
+
+
PAN-236261
+
+
+ Fixed an issue where a proxy server was used for External Dynamic List + communication even when the dataplane interface was configured through + service routes. +
+
+
PAN-236244
+
+
+ Fixed an issue where you were unable to select Authentication Profiles + via the web interface. +
+
+
PAN-236233
+
+
+ Fixed an issue where SNMP reports displayed incorrect values for SSL + Proxy sessions and SSL Proxy utilization. +
+
+
PAN-235737
+
+
+ Fixed an issue where the + brdagent + process stopped responding due to a sudden increase in logging to the + bcm.log. +
+
+
PAN-235628
+
+
+ Fixed an issue where you were not prompted for login credentials when + you disconnected and connected back to the GlobalProtect portal when + SAML authentication was selected along with Single Sign-On (SSO) and + Single Log Out (SLO). +
+
+
PAN-235557
+
+
+ Fixed an issue where uploads from tunnels, including GlobalProtect, + were slower than expected when the inner and outer sessions were on + different dataplanes. +
+
+
PAN-235476
+
+
+ Fixed an issue where threat logs from different Security zones were + aggregated into one log. +
+
+
PAN-235168
+
+
+ Fixed an issue where disk space became full even after clearing old + logs and content images. +
+
+
PAN-235081
+
+
+ (VM-Series firewalls only) Fixed an issue where + the firewall sent packets to its own interface after configuring + NAT64. +
+
+
PAN-234596
+
+
+ Fixed an issue on firewalls in active/passive HA configurations where + the passive firewall incorrectly became active after a reboot. +
+
+
PAN-234459
+
+
+ Fixed an issue with the firewall web interface where local SSL + decryption exclusion cache entries were not visible. +
+
+
PAN-234290
+
+
+ Fixed an issue where the firewall displayed incorrect interface + transfer rates when running the CLI command + show system state filter-pretty sys.s1.px + with a filter. +
+
+
PAN-234169
+
+
+ Fixed an issue where downloading files failed or was slower than + expected due to malware scanning even when the session was matched to + a Security policy rule with no Anti-Virus profile attached. +
+
+
PAN-234031
+
+
+ Fixed an issue on multi-core firewalls where the firewall displayed + packets out of order when capturing packets on the transmit stage. +
+
+
PAN-233833
+
+
+ Fixed an issue where enabling Jumbo frames resulted in software packet + buffer depletion. +
+
+
PAN-233789
+
+
+ Fixed an issue with Push and + Commit and Push operations where the + user was not correctly bound to the scope, which caused all device + groups to be selected for a selective push. +
+
+
PAN-233692
+
+
+ Fixed an issue on Panorama where the + configd + process stopped, which caused performance issues. +
+
+
PAN-233684
+
+
+ Fixed an issue on Panorama where + Push to Devices or + Commit and Push operations took + longer than expected on the web interface. +
+
+
PAN-233603
+
+
+ (CN-Series firewalls only) Fixed an issue where + slot information was not correct after a + slotd + process restart on the management pod. +
+
+
PAN-233541
+
+
+ Fixed an issue where device group and template administrators with + access to a specific virtual system were able to see logs for all + virtual systems via Context Switch. +
+
+
PAN-233517
+
+
+ Fixed an issue on Panorama where managed device templates and device + groups took longer than expected to display in the + Push to Devices window. +
+
+
PAN-233463
+
+
+ Fixed an issue where the X-Forwarded-For (XFF) IP addressed value was + not displayed in traffic logs. +
+
+
PAN-233207
+
+
+ Fixed an issue where the + configd + process stopped responding when a partial configuration revert + operation was performed. +
+
+
PAN-233039
+
+
+ Fixed an issue where GENEVE encapsulated packets coming from a GFE + Proxy mapped to an incorrect Security policy rule. +
+
+
PAN-232953
+
+
+ Fixed an issue where you were able to cancel the same commit + repeatedly, which displayed the error message + Cannot stop job <job> at this time. +
+
+
PAN-232368
+
+
+ Fixed an issue where commits failed with the error message + Error: Max. user groups used in policy 1389 exceed capacity + (1000). +
+
+
PAN-232250
+
+
+ Fixed an issue where, when SSH service profiles for management access + were set to None, the reported + output was incorrect. +
+
+
PAN-231802
+
+
+ Fixed an issue where an Advanced Routing BGP session flapped with + commits when BGP peer authentication was enabled. +
+
+
PAN-231552
+
+
+ Fixed an issue where traffic returning from a third-party Security + chain was dropped. +
+
+
PAN-231507
+
+
+ (PA-1400 Series firewalls only) Fixed an issue + where, when an HSCI interface was used as an HA2 interface, HA2 + packets were intermittently dropped on the passive firewall, which + caused the HA2 connection to flap due to missing HA2 keepalive + messages. +
+
+
PAN-231480
+
+
+ Fixed an issue where the firewall CLI output for GlobalProtect log + quota settings did not match the settings configured on the Panorama + web interface. +
+
+
PAN-231439
+
+
+ Fixed an issue where, when a VoIP call using dynamic IP and NAT was + put on hold, the audio became one-way due to early termination of NAT + ports. +
+
+
PAN-231395
+
+
+ Fixed an intermittent issue where the OCSP query failed. +
+
+
PAN-231148
+
+
+ Fixed an issue where no DHCP option list was defined when using + GlobalProtect. +
+
+
PAN-230813
+
+
+ Fixed an issue where flex memory leak caused decryption failure and + commit failure with the error message + Error preparing global objects failed to handle + CONFIG_UPDATE_START. +
+
+
PAN-230746
+
+
+ Fixed an issue on the web interface where device groups with a large + number of managed firewalls displayed the + Policy page more slowly than + expected. +
+
+
PAN-230656
+
+
+ (Firewalls in HA configurations only) Fixed an + issue where a split brain condition occurred on both firewalls after + booting up any firewall, and an HA switchover occurred after booting + up a firewall with a higher HA priority even when no preemptive option + was enabled on the firewall. +
+
+
PAN-230377
+
+
+ Fixed an issue where FEC support was not enabled by default for + PAN-25G-SFP28-LR modules. +
+
+
PAN-230372
+
+
+ Fixed an issue where OCSP queries did not work after upgrading to a + PAN-OS 11.0 release. +
+
+
PAN-230039
+
+
+ Fixed an issue where migrating from an Enterprise License Agreement + (ELA) to a Flexible VM-Series License failed with a deactivation error + message. +
+
+
PAN-229985
+
+
+ (VM-Series firewalls in Amazon Web Services (AWS) only) Fixed an issue where, when Gateway Load Balancer (GWLB) overlay + routing was enabled, GWLB packets re-encapsulated with the incorrect + flow cookie in the GENEVE header when transmitting the response back + to GWLB. +
+
+
PAN-229874
+
+
+ Fixed an issue where the firewall was unable to form OSPFv3 adjacency + when using an ESP authentication profile. +
+
+
PAN-229873
+
+
+ (PA-7050 firewalls only) Fixed an issue related + to + brdagent + process errors. +
+
+
PAN-229315
+
+
+ Fixed an issue where Octets in NetFlow records were always reported to + be 0 despite having a non-zero packet count. +
+
+
PAN-229069
+
+
+ Fixed an issue where clientless VPN portal users were unable to access + clientless applications due to an SSL renegotiation being triggered. +
+
+
PAN-228457
+
+
+ (PA-7000 firewalls only) Fixed an issue where + the GTP logs forwarded from the firewall to the log collector did not + include the pcap. +
+
+
PAN-228442
+
+
+ Fixed an issue on firewalls in active/passive HA configurations where + sessions did not fail over from the active firewall to the passive + firewall when upgrading PAN-OS. +
+
+
PAN-228323
+
+
+ Fixed an issue where a large number of Panorama management server + cookies were created in the Redis database when the Cloud-Service + plugin sent an authentication request every second, and logging in to + or using Panorama was slower than expected. +
+
+
PAN-227973
+
+
+ Fixed an issue where commits failed after renaming an address object + or object group with a selective commit. +
+
+
PAN-227939
+
+
+ Fixed an issue where the + all_task + process stopped responding due to high wifclient memory usage, which + caused the firewall to reboot. +
+
+
PAN-227887
+
+
+ Fixed an issue where IP address checksums were calculated incorrectly. +
+
+
PAN-227510
+
+
+ Fixed an issue where the error message + Failed to establish GRPC connection to UrlCat service: failed to + start grpc connection + was displayed in the system log when the Advanced URL Filtering + license was applied but not configured. +
+
+
PAN-227064
+
+
+ Fixed an issue with high availability (HA) sync failure when + performing a partial commit after creating a Security policy via REST + API. +
+
+
PAN-226489
+
+
+ Fixed an issue where Panorama was unable to push scheduled dynamic + updates to firewalls with the error message + Failed to add deploy job. Too many (30) deploy jobs pending for + device. +
+
+
PAN-225090
+
+
+ Fixed an issue on Panorama where + Commit and Push was grayed out when + making changes to a template or device group. +
+
+
PAN-225064
+
+
+ Fixed an issue where Panorama stopped responding and entered a + non-functional state after moving multiple Security policy rules at + the same time from one device group to another device group. +
+
+
PAN-224938
+
+
+ Fixed an issue where the CLI command settings for + set system setting logging max-log-rate + did not persist after a + mgmtsrvr + process restart. +
+
+
PAN-224584
+
+ Fixed an issue on Panorama where generating UAR reports for 30 days or + more was slower than expected, and reports showed the same logs + repeatedly in a loop. +
+
PAN-224424
+
+
+ (PA-3440 firewalls only) Fixed an issue where + you were unable to set the link speed as 25Gbps from the drop-down in + the template for Ethernet ports 1/23 through 1/26. +
+
+
PAN-224060
+
+
+ (PA-220 Series firewalls only) Fixed an issue + where multiple dataplane processes stopped responding after an + upgrade. +
+
+
PAN-223365
+
+
+ Fixed an issue where Panorama was unable to query any logs if the + Elasticsearch health status for any log collector was degraded. +
+
+
PAN-223172
+
+
+ Fixed an issue on Panorama where host IDs manually added to the device + quarantine list were unexpectedly removed. +
+
+
PAN-222188
+
+
+ A CLI command was introduced to address an issue where SNMP monitoring + performance was slower than expected, which resulted in + snmpwalk timeouts. +
+
+
PAN-222002
+
+
+ Fixed an issue where content updates failed with the error message + Unable to get key pancontent-8.0.pass from cryptod. Error -9. +
+
+
PAN-220931
+
+
+ (Panorama appliances in FIPS-CC mode only) + Fixed an issue where scheduled email reports did not contain PDF + attachments. +
+
+
PAN-219805
+
+
+ Fixed an issue where the + reportd + process stopped responding due to a race condition. +
+
+
PAN-219113
+
+
+ Fixed an issue where, when a port on the NPC was configured for log + forwarding, the ingress traffic on the card was sent for processing to + the LPC, and the LPC card was reloaded when the ingress volume of + traffic was high. +
+
+
PAN-217619
+
+
+ Fixed an issue where supported Bi-DI transceivers were not recognized + which caused ports to not come up. +
+
+
PAN-217307
+
+
+ Fixed an issue where the + log-start and + log-end policy rule filters did + not return reliable results when set to + no or + yes. +
+
+
PAN-217241
+
+
+ Fixed an issue where predict session conversion failed for RTP and + RTCP traffic. +
+
+
PAN-209574
+
+
+ Fixed an issue with HTTP/2 traffic where downloading large files did + not work when decryption was enabled. +
+
+
PAN-205482
+
+
+ Fixed an issue related to the + configd + process where Panorama displayed the error + Server not responding when editing + policies. +
+
+
PAN-199141
+
+
+ Fixed an issue where renaming a device group and then performing a + partial commit led to the device group hierarchy being incorrectly + changed. +
+
+
PAN-196395
+
+
+ (PA-5450 firewalls only) Fixed an issue where + the firewall accepted 12 aggregate ethernet interfaces, but you were + unable to configure interfaces 9-12 via the web interface. +
+
+
PAN-174454
+
+
+ Fixed an issue where the firewall did not fetch group and user + membership due to the Okta sync domain not matching the active Cloud + Identity Engine domain. +
+
diff --git a/reference/PAN-OS/addressed/11.1.4-h1.html b/reference/PAN-OS/addressed/11.1.4-h1.html new file mode 100644 index 0000000..b1cbd94 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.4-h1.html @@ -0,0 +1,167 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-245690
+
+
+ Fixed an issue where the + Managed Collectors health status on + Panorama displayed as empty. +
+
+
PAN-259733
+
+
+ Fixed an issue where a custom report was not deleted on Panorama when + expected. +
+
+
PAN-259480
+
+
+ Fixed an issue where the + varrcvr + process stopped responding after running out of memory due to how the + process queued and dequeued files for WildFire file forwarding when a + WildFire Analysis Security profile was enabled. +
+
+
PAN-257615
+
+
+ Fixed an issue on Panorama where logs did not display or displayed + intermittently on the web interface. +
+
+
PAN-257462
+
+
+ Fixed an issue related to the + varrcvr + process where the management plane CPU was higher than expected during + WildFire updates. +
+
+
PAN-257028
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where firewalls entered a non-functional state and + displayed the error message + Dataplane down: path monitor failure during the fail-over. +
+
+
PAN-255711
+
+
+ Fixed an issue where the firewall displayed a malformed request error + when selecting a custom format and clicking + OK on the configuration window due + to the log type + Correlation incorrectly being + displayed (Device > Log Setting - Correlation > Syslog Server Profile + > Custom Log Format > Correlation). +
+
+
PAN-254373
+
+
+ Fixed an issue where the firewall did not handle error code 500 + responses from the WildFire cloud correctly. +
+
+
PAN-225213
+
+
+ Fixed an issue where + Push All Changes displayed changes + that were already committed in the push scope for another device group + after performing a selective commit and selective push to the first + device group. +
+
diff --git a/reference/PAN-OS/addressed/11.1.4-h13.html b/reference/PAN-OS/addressed/11.1.4-h13.html new file mode 100644 index 0000000..e3c3421 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.4-h13.html @@ -0,0 +1,1005 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-279604
+
+
+ Fixed an issue where scheduled SaaS application usage reports were + generated incorrectly, and the login page was displayed instead of the + report content. +
+
+
PAN-278088
+
+
+ Fixed an issue where the + show system resources follow CLI + command was not available. +
+
+
PAN-274791
+
+
+ Fixed an issue where the firewall rebooted when Shared Pool Type 32 + was depleted and traffic matched advanced features. +
+
+
PAN-274592
+
+
+ (Firewalls in HA configurations only) Fixed an + issue where the firewall did not fail over when the active firewall + experienced data plane issues. +
+
+
PAN-273994
+
+
+ A fix was made to address + CVE-2025-0111. +
+
+
PAN-273971
+
+ A fix was made to address + CVE-2025-0108. +
+
PAN-273278
+
+ A fix was made to address + CVE-2025-0109. +
+
PAN-273129
+
+
+ Fixed an issue on the web interface where the + negate option was visible when you + clicked on the rule name, but not when you viewed the target options + from the rulebase attribute. +
+
+
PAN-273085
+
+
+ Fixed an issue on the web interface where you were unable to edit or + create policy rules. +
+
+
PAN-273026
+
+
+ Fixed an issue where traffic logs did not display correctly when + filters were applied. +
+
+
PAN-273019
+
+
+ Fixed an intermittent issue where SSL decryption failed. +
+
+
PAN-272959
+
+
+ Fixed an issue where the firewall generated BGP update packets larger + than 1500 bytes when the interface MTU was 1500 bytes and jumbo frames + were enabled globally. +
+
+
PAN-272006
+
+
+ Fixed an issue where the firewall did not trigger a kernel core dump + as a large core when the CPLD (Complex Programmable Logic Device) sent + a Non-Maskable Interrupt (NMI) to the CPU. +
+
+
PAN-271937
+
+
+ (PA-5450 firewalls only) Fixed an issue where + the + logrcvr + process stopped responding when processing logs from a large number of + sources. +
+
+
PAN-271926
+
+
+ Fixed an issue where TLS 1.3 decryption failed with a bad record MAC + error when the firewall was configured to decrypt and inspect TLS + traffic. +
+
+
PAN-270549
+
+
+ Fixed an issue where some TLS connections were not handled correctly, + which led to instability in the dataplane. +
+
+
PAN-270471
+
+
+ (Firewalls in active/active configurations only) Fixed an issue where the firewall did not detect configuration + changes when only the interface of an IKE gateway was changed, which + caused IPSec tunnels to not come up after migrating the IKE gateway IP + address from a subinterface to a physical interface. +
+
+
PAN-270077
+
+
+ (VM-Series firewalls in Amazon Web Services (AWS) environments + only) Fixed an issue template values were missing in newly spun firewalls + in auto scale deployments without an explicit push with forced + template values from Panorama. +
+
+
PAN-269731
+
+
+ Fixed an issue where Panorama did not display logs from firewalls + after upgrading to PAN-OS 10.2.11 on devices due to Elasticsearch (ES) + getting restarted continuously. +
+
+
PAN-269539
+
+
+ Fixed an issue where whitespace was added before the timestamp in + syslog logs forwarded from Panorama. +
+
+
PAN-269499
+
+
+ Fixed an issue where the firewall stopped responding when receiving a + high number of logs. +
+
+
PAN-269106
+
+
+ Fixed issue where the + wifclient restarted and multiple + processes stopped responding. +
+
+
PAN-268909
+
+
+ Fixed an issue where IP address tags were removed from firewalls after + a management server or + useridd + process restart. This occurred when a Panorama serial-number based + configuration was used for User-ID redistribution. +
+
+
PAN-268815
+
+
+ Fixed an issue where the firewall entered a non-functional state due + to duplicate entries in the shared memory. +
+
+
PAN-268727
+
+
+ Fixed an issue where traffic was dropped when the accumulation proxy + was enabled and header insertion modified packets. +
+
+
PAN-267781
+
+
+ Fixed an issue where Panorama did not display the Source Dynamic + Address Group. +
+
+
PAN-267762
+
+
+ (Panorama virtual appliances in Management-Only mode) Fixed a issue where the maximum configuration size was lower than + expected. +
+
+
PAN-267671
+
+ Fixed an issue where the firewall rebooted unexpectedly due to the + all_task + process restarting with an OOM condition due to a memory leak on the + reportd + process. +
+
PAN-267430
+
+
+ Fixed an issue where Panorama was unable to return logs for queries + that were longer than 64,000 characters. +
+
+
PAN-267097
+
+
+ Fixed an issue where the replay database size increased significantly + due to local and special configurations not being purged after + commits. +
+
+
PAN-266581
+
+
+ Fixed an issue where a failed SSL connection to a syslog server + resulted in a + /tmp/srvr.crt.xxxxxx file not + being removed, which caused index node (inode) exhaustion. +
+
+
PAN-266559
+
+
+ Fixed an issue where partial commits failed when objects that were + referenced in a high number of Security policy rules were renamed. +
+
+
PAN-266354
+
+
+ Fixed an issue where Hybrid-SWG explicit proxy connections failed when + the number of destination domains exceeded 1024. +
+
+
PAN-265745
+
+
+ Fixed an issue where the firewall displayed incorrect MAC receive + error counters for VMWare devices hosted in ESXi. +
+
+
PAN-265179
+
+
+ Fixed an issue where a kernel race condition caused the firewall to + reboot with a kernel panic. +
+
+
PAN-265160
+
+
+ Fixed an issue where the firewall created multiple connections to a + syslog server and remained in the FINWAIT1 state, which caused logs to + drop while being forwarded to the syslog server. +
+
+
PAN-264369
+
+
+ Fixed an issue where the + 7 Day Threat Report was empty in the + scheduled reports sent via email. +
+
+
PAN-263291
+
+
+ Fixed an issue where Microsoft Outlook did not work as expected when + the GlobalProtect clientless VPN was configured. +
+
+
PAN-262627
+
+
+ Fixed an issue where the firewall rebooted into maintenance mode due + to a service failure in the + configd + process. +
+
+
PAN-262383
+
+
+ Fixed an issue where the firewall was unable to decompress the HTTP2 + header, which caused the session to be classified as unknown-tcp + instead of web-browsing. +
+
+
PAN-262254
+
+
+ Fixed an issue where the firewall experienced an OOM condition and the + useridd + process stopped responding, which caused the firewall to drop + interfaces from their respective aggregate groups. +
+
+
PAN-261998
+
+
+ Fixed an issue where the firewall configuration process restarted + during an External Dynamic List refresh or a commit and push + operation. +
+
+
PAN-260290
+
+
+ Fixed an issue for fixed model licenses to support new content size + requirements by reducing the total sessions supported to be equivalent + to their flex memory counterpart +
+
+
PAN-260149
+
+
+ Fixed an issue where the management plane DNS cache size was lower + than expected. +
+
+
PAN-259055
+
+
+ Fixed an issue where the firewall stopped responding when receiving + SNMPv3 traps. +
+
+
PAN-258996
+
+
+ Fixed an issue where the firewall displayed the SFP ports as + PowerDown when the SFP + transceiver was removed and reinserted or the port was shut down and + brought back up on the peer device. +
+
+
PAN-257390
+
+
+ (PA-5250 firewalls only) Fixed an issue where + the + logrcvr + process stopped responding due to a segmentation fault. +
+
+
PAN-256669
+
+
+ Fixed an issue where the memory usage reported by SNMP did not match + the memory usage reported by the top command. +
+
+
PAN-255773
+
+
+ Fixed an issue where errors related to applications in + Content-preview caused commit + failures. +
+
+
PAN-255747
+
+
+ Fixed an issue on the firewall where CLI commands returned + Server error: op command for client dagger timed out as client is + not available. +
+
+
PAN-255653
+
+
+ Fixed an HA failover issue where, when Management Processing Card + (MPC) or Base Card (BC) failures occurred, the HA link went down, + which caused fpp-down events on one firewall. +
+
+
PAN-253485
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where dataplane packet capture filter configuration + failed on the active firewall with the error + op command for client dagger timed out as client is not + available. +
+
+
PAN-252669
+
+
+ Fixed an issue where the + ikemgr + process stopped responding with a SIGSEGV error. +
+
+
PAN-252036
+
+
+ Fixed an issue where, when the GlobalProtect portal was not + configured, accessing the GlobalProtect gateway still loaded a portal + malformed page. +
+
+
PAN-252224
+
+
+ Fixed an issue where Panorama did not forward logs to a syslog server + over an SSL connection using CRL as a revocation verification method. +
+
+
PAN-250585
+
+
+ Fixed an issue where the firewall CPU use increased after upgrading + from PAN-OS 10.2.4-h4 to PAN-OS 10.2.8 due to a change in system + resource reporting by the REST API. +
+
+
PAN-246209
+
+
+ Fixed an issue where IPSec VPN tunnels went down after receiving a + DHCP server message that the DHCP client cleared the IP address on the + interface. +
+
+
PAN-242739
+
+
+ Fixed an issue on the firewall where the dataplane repeatedly + restarted. +
+
+
PAN-240225
+
+
+ Fixed an issue where authentication failed on web-based GlobalProtect + portal. +
+
+
PAN-238594
+
+
+ Fixed an issue where the firewall rebooted when a QSFP28 cable was + removed from the port while the port was passing traffic. +
+
+
PAN-232833
+
+
+ Fixed an issue where the following error message displayed for IoT + trial licenses: + IoT Security license is required for the feature to function. +
+
+
PAN-232550
+
+
+ Fixed an issue where SNMPv3 authentication failed when using SHA-512 + Auth protocol. +
+
+
PAN-225228
+
+
+ Fixed an issue where filtering threat logs using any value under + THREAT ID/NAME displayed the error + Invalid term. +
+
+
PAN-218873
+
+
+ Fixed an issue where a HIP mask was reused when an existing IP address + user mapping was updated by a new IP address user mapping that had a + different username but the same IP address. +
+
+
PAN-216054
+
+
+ Fixed an issue that caused the firewall's fan speed to increase while + it was idle. +
+
+
PAN-214430
+
+
+ Fixed an issue where some commands did not have executable + permissions. +
+
+
PAN-212197
+
+
+ Fixed an issue where you were able to create local administrator + usernames that contained only numbers. +
+
+
PAN-207972
+
+
+ Fixed an issue on the web interface where the BGP routing table did + not display advertised routes. +
+
+
PAN-193285
+
+
+ Fixed an issue where the policy optimizer feature did not add entries + back to the mongodb database + after removing them during an upgrade or downgrade. +
+
diff --git a/reference/PAN-OS/addressed/11.1.4-h15.html b/reference/PAN-OS/addressed/11.1.4-h15.html new file mode 100644 index 0000000..3647858 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.4-h15.html @@ -0,0 +1,174 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-282236
+
+ Fixed an issue where large IPv6 packets were reassembled on the firewall + when the packets arrived fragmented over an IPv4 tunnel. +
+
PAN-280471
+
+
+ Fixed an issue where navigating + PanoramaMonitorLogs + was slower than expected. +
+
+
PAN-279746
+
+
+ Fixed an issue where SMTP packets were not sent out when the Client + Hello arrived at the firewall in multiple out-of-order segments and + the traffic was not subject to SSL decryption. +
+
+
PAN-279191
+
+
+ Fixed an issue where a GlobalProtect gateway stopped responding when + handling HTTP/1.1 traffic with web inspection enabled. +
+
+
PAN-278684
+
+
+ (PA-445 firewalls only) Fixed an issue where + the firewall did not properly power cycle during a reboot. +
+
+
PAN-275905
+
+
+ Fixed an issue where the Panorama web interface was slower than + expected and Elasticsearch CPU usage was high. +
+
+
PAN-275032
+
+
+ Fixed an issue where the Elasticsearch cluster certificate (CC) status + displayed with a past expiration date, which caused all shards to be + unassigned. +
+
+
PAN-273141
+
+
+ Fixed an issue where GlobalProtect clients experienced slow file + transfer download throughput when passing through an IPSec tunnel. +
+
+
PAN-272085
+
+
+ Fixed an issue where the firewall might crash and reboot when DoH is + enabled for DNS Security and multiple DoH transactions are sent in a + single HTTP/1 connection. +
+
+
PAN-270744
+
+
+ Fixed an issue where API calls to Panorama failed with the error + Server error : Timed out while getting config lock. Please try + again. +
+
+
PAN-268279
+
+
+ Fixed an issue where autocommits failed if the management IPv6 gateway + was the same as the dataplane interface IP address. +
+
+
PAN-242130
+
+
+ Fixed an issue where the firewall displayed the speed and duplex of + its dataplane interfaces as + Unknown even though the link was up. +
+
diff --git a/reference/PAN-OS/addressed/11.1.4-h16.html b/reference/PAN-OS/addressed/11.1.4-h16.html new file mode 100644 index 0000000..048f19a --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.4-h16.html @@ -0,0 +1,32 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-282022
+
+
+ Fixed the support limitation for the Panorama M-600 and M-700 + appliances. +
+
diff --git a/reference/PAN-OS/addressed/11.1.4-h17.html b/reference/PAN-OS/addressed/11.1.4-h17.html new file mode 100644 index 0000000..e03a5e0 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.4-h17.html @@ -0,0 +1,383 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-282022
+
+
+ Fixed the support limitation for the Panorama M-600 and M-700 + appliances. +
+
+
PAN-281885
+
+
+ Fixed an issue where, when exporting and importing CSV files, the hash + values of pre-shared key variables set at template and template stack + levels changed inconsistently, which resulted in both variables + displaying the same hash value. +
+
+
PAN-280505
+
+
+ Fixed an issue where the web interface did not display a message to + commit prior changes before attempting a partial configuration load. +
+
+
PAN-280243
+
+
+ Fixed an issue where the firewall lost the pre-shared key + configuration assigned from a PSK variable when an unrelated device + group configuration was loaded. +
+
+
PAN-279336
+
+
+ Fixed an issue where the CLI did not display a message to commit prior + changes before loading a partial configuration. +
+
+
PAN-279176
+
+
+ Fixed an issue where the configuration audit displayed inaccurate + information after partially loading the configuration via the CLI, + which caused the audit to flag the configuration as deleted or + changed. +
+
+
PAN-277762
+
+
+ (VM-Series firewalls only) Fixed an issue where + unexpected failovers occurred on firewalls running PAN-OS 11.2.2-h2. +
+
+
PAN-275713
+
+
+ Fixed an issue where the + dscd + process stopped responding when + Endpoint Serial Number was enabled, + which resulted in the + Active Directory returning a list of + serial numbers for a specific firewall from the Cloud Identity Engine. +
+
+
PAN-275077
+
+
+ Fixed an issue where DNS Security intermittently logs malicious domain + URLs as Alert instead of taking a Sinkhole action, even when + configured to Sinkhole malicious DNS domains. +
+
+
PAN-274750
+
+
+ Fixed an issue where the detailed log view in Panorama did not display + all packet details for traffic logs received from the cloud. +
+
+
PAN-273694
+
+
+ Fixed an issue where the firewall rebooted due to an out-of-bounds + memory access that occurred as a result of the SIP content length + value being split across packets. +
+
+
PAN-272538
+
+
+ Fixed an issue where the + configd + process stopped responding during a commit-all validation when there + were uncommitted changes and + share-unused-objects-with-devices + was set to off. +
+
+
PAN-272171
+
+
+ Fixed an issue where the firewall dropped the AAAA DNS server response + and caused delays in traffic from Ubuntu or Linux clients when DNS + Security was enabled. +
+
+
PAN-270607
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where OSPF failed to establish after a failover from + the active firewall to the passive firewall. +
+
+
PAN-271351
+
+
+ A fix was made to address + CVE-2025-0116. +
+
+
PAN-267091
+
+
+ Fixed an issue on Panorama where Elasticsearch repeatedly restarted. +
+
+
PAN-264678
+
+
+ Fixed an issue where + Preview Changes did not display + configuration changes in + Commit and push > Push Scope. +
+
+
PAN-262511
+
+
+ Fixed an issue on firewalls in HA configurations where OSPF neighbors + were not established after an HA failover. +
+
+
PAN-261825
+
+
+ Fixed an issue where traffic was dropped when Data Loss Prevention or + Advanced URL Filtering were enabled. This occurred when the payload + size was greater than 3.5 KB. +
+
+
PAN-259706
+
+
+ Fixed an issue on Panorama where the web interface was slower than + expected or unresponsive when monitoring definitions were added in the + Kubernetes plugin. +
+
+
PAN-257183
+
+
+ Fixed an issue where the firewall dropped DNS traffic when using DNS + Security. +
+
+
PAN-254174
+
+
+ A fix was made to address + CVE-2025-0115. +
+
+
PAN-248762
+
+
+ Fixed an issue where, when the Advanced Routing Engine was configured + with OSPF, the firewall stopped responding when attempting to connect + to the neighbor while exchanging route maps. +
+
+
PAN-239201
+
+
+ Fixed an issue where partial commit or partial validation operations + failed for non-super user administrators with the error + <device-group-name> is invalid. meta data not found for dg + <device-group-name>. +
+
+
PAN-235733
+
+
+ Fixed an issue where the displayed NTP information was incorrect if + the DNS servers timed out. +
+
diff --git a/reference/PAN-OS/addressed/11.1.4-h18.html b/reference/PAN-OS/addressed/11.1.4-h18.html new file mode 100644 index 0000000..ad9ae29 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.4-h18.html @@ -0,0 +1,200 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-286255
+
+
+ Fixed an issue where, when the firewall received an unexpected + termination request for SSL sessions, the dataplane experienced a slow + buffer resource leak. +
+
+
PAN-282069
+
+
+ Fixed an issue on Panorama where Security policy rules were removed + from device groups when you cloned or edited Security policy rules + that used more than 63 characters. +
+
+
PAN-280942
+
+
+ Fixed an issue where the + logrcvr + process stopped responding. +
+
+
PAN-273949
+
+
+ Fixed an issue where the firewall generated the following error + message in the + snmpd + logs: + pan_get_keystr_from_cryptod(pan_snmpinterface.c:181): Key + X2F1dGhfa2V5 import from cryptod failed. +
+
+
PAN-271273
+
+
+ Fixed an issue where dynamic update downloads failed when + IPv6 firewalling was enabled on the + firewall and both IPv4 and IPv6 were configured on the management + interface. +
+
+
PAN-270193
+
+
+ Fixed an issue where the Panorama management server changed its + certificate authority (CA) unexpectedly, which caused managed + firewalls to disconnect. +
+
+
PAN-268614
+
+
+ Fixed an issue on the web interface where, when all rules were + highlighted when a read-only admin user clicked the + Highlight Unused Rules checkbox. +
+
+
PAN-265621
+
+
+ Fixed an issue where the + restart option for IPSec tunnels was + greyed out when you attempted to restart the tunnel from + NetworkIPSec TunnelsIKE Info. +
+
+
PAN-260300
+
+
+ (PA-5410, PA-5420, PA-5430, PA-5440 and PA-5445 firewalls only) Fixed an issue related to the + all_pktproc + process where DPC slot 3 stopped responding. +
+
+
PAN-259535
+
+
+ Fixed an issue where the firewall failed to boot up after running + power cycle tests due to + ehmon + process heartbeat failures. +
+
diff --git a/reference/PAN-OS/addressed/11.1.4-h25.html b/reference/PAN-OS/addressed/11.1.4-h25.html new file mode 100644 index 0000000..3087258 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.4-h25.html @@ -0,0 +1,261 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-292261
+
+
+ Fixed an issue where the firewall repeatedly reported an unreachable + syslog server as back online when + the server remained unavailable. This resulted in misleading + alternating connection status messages in the system logs. +
+
+
PAN-287423
+
+
+ Fixed an issue where content loading issues occurred on IPv6 websites + due to the firewall incorrectly setting the IPv6 header flow label to + 0. +
+
+
PAN-286255
+
+
+ Fixed an issue where, when the firewall received an unexpected + termination request for SSL sessions, the dataplane experienced a slow + buffer resource leak. +
+
+
PAN-282069
+
+
+ Fixed an issue on Panorama where Security policy rules were removed + from device groups when you cloned or edited Security policy rules + that used more than 63 characters. +
+
+
PAN-280942
+
+
+ Fixed an issue where the + logrcvr + process stopped responding. +
+
+
PAN-280698
+
+
+ Fixed an issue where the firewall removed the TCP timestamp from + client hello messages that did not fit in a single packet, which + resulted in connection issues. +
+
+
PAN-279901
+
+
+ An issue was fixed where the firewall dropped fragmented TLS + ClientHello packets, which blocked access to certain websites. This + occurred because the packets arrived truncated, in varying sizes and + orders, and the firewall's heuristics failed to handle them correctly. +
+
+ To enable this fix, run: + debug dataplane set ssl-decrypt accumulate-client-hello disjoined + yes. +
+
+
PAN-273949
+
+
+ Fixed an issue where the firewall generated the following error + message in the + snmpd + logs: + pan_get_keystr_from_cryptod(pan_snmpinterface.c:181): Key + X2F1dGhfa2V5 import from cryptod failed. +
+
+
PAN-271273
+
+
+ Fixed an issue where dynamic update downloads failed when + IPv6 firewalling was enabled on the + firewall and both IPv4 and IPv6 were configured on the management + interface. +
+
+
PAN-270193
+
+
+ Fixed an issue where the Panorama management server changed its + certificate authority (CA) unexpectedly, which caused managed + firewalls to disconnect. +
+
+
PAN-268614
+
+
+ Fixed an issue on the web interface where, when all rules were + highlighted when a read-only admin user clicked the + Highlight Unused Rules checkbox. +
+
+
PAN-265621
+
+
+ Fixed an issue where the + restart option for IPSec tunnels was + greyed out when you attempted to restart the tunnel from + NetworkIPSec TunnelsIKE Info. +
+
+
PAN-260300
+
+
+ (PA-5410, PA-5420, PA-5430, PA-5440 and PA-5445 firewalls only) Fixed an issue related to the + all_pktproc + process where DPC slot 3 stopped responding. +
+
+
PAN-259535
+
+
+ Fixed an issue where the firewall failed to boot up after running + power cycle tests due to + ehmon + process heartbeat failures. +
+
diff --git a/reference/PAN-OS/addressed/11.1.4-h27.html b/reference/PAN-OS/addressed/11.1.4-h27.html new file mode 100644 index 0000000..c4fce4c --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.4-h27.html @@ -0,0 +1,165 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-301801
+
+
+ Fixed an issue on Log Collectors where the Elasticsearch process + fluctuated intermittently between green and red states, which led to + interruptions in log collection. This issue occurred when the number + of shards exceeded the cluster's maximum supported threshold of + greater than 1000 shards per Elasticsearch instance. +
+
+
PAN-292159 and PAN-271216
+
+
+ A fix was made to address + CVE-2025-4615. +
+
+
PAN-291661
+
+
+ Fixed an issue on Panorama appliances and Log Collectors where, after + an upgrade, Elasticsearch intermittently entered into a Red state + before automatically recovering. +
+
+
PAN-286164
+
+
+ A fix was made to address + CVE-2025-4614. +
+
+
PAN-282093
+
+
+ Enhanced the CLI command + request legacy reset to delete + the legacy certificate files that were being used to connect with the + secondary Panorama appliance. +
+
+
PAN-278296
+
+
+ Fixed an issue where the system MAC address of the aggregate interface + was the same on the active firewall and the passive firewall after an + upgrade. +
+
+
PAN-272539
+
+
+ (Panorama appliances on Microsoft Azure environments only) Fixed an issue where user to IP address mapping was missing for + some users connected to specific Prisma Access gateways, which caused + the collection layer Azure firewall to not form the mapping. +
+
+
PAN-271221
+
+
+ A fix was made to address + CVE-2025-4615. +
+
+
PAN-251715
+
+
+ Fixed an issue where the firewall closed the SSL connection to the + user ID agent. +
+
diff --git a/reference/PAN-OS/addressed/11.1.4-h4.html b/reference/PAN-OS/addressed/11.1.4-h4.html new file mode 100644 index 0000000..6a218f3 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.4-h4.html @@ -0,0 +1,797 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-265963
+
+
+ Fixed an issue where the + escd + process caused a memory leak when session resiliency was enabled on + the firewall. +
+
+
PAN-265349
+
+
+ Fixed an issue where multiple segments of HTTP proxy connect messages + were not handled correctly by proxy. +
+
+
PAN-264421
+
+
+ Fixed an issue on Panorama where + Push Scope did not populate + automatically after changing the device group configuration. +
+
+
PAN-263987
+
+
+ Fixed an issue on the firewall where, when a NAT transversal IPSec + tunnel was terminated, and the NAT rule that was applied to the NAT-T + IPSec tunnel was on the same firewall, traffic flowing through the + tunnel was not correctly translated. +
+
+
PAN-263559
+
+
+ Fixed an issue where the dataplane stopped responding and the firewall + unexpectedly rebooted due to multiple process restarts. +
+
+
PAN-263226
+
+
+ Fixed an issue where, when SSL decryption was enabled and Client Hello + messages spanned multiple TCP segments, some SSL decrypted sessions + failed. +
+
+
PAN-262593
+
+
+ Fixed an issue where traffic to websites failed on the Google Chrome + web browser on Secure Web Gateway (SWG) nodes. +
+
+
PAN-262340
+
+
+ Fixed an issue where FQDN resolution failed for address objects, and + all FQDN traffic was denied by the interzone-default policy rule. +
+
+
PAN-262287
+
+
+ Fixed an issue where dereferencing a NULL pointer that occurred when + App-ID stopped responding caused the firewall to restart. +
+
+
PAN-261991
+
+
+ Fixed an issue where traffic that did not match a decryption policy + rule, or matched a no-decrypt policy rule, failed when accumulation + proxy was enabled and a Zone Protection profile was configured with + syn-cookies enabled. +
+
+
PAN-261917
+
+
+ Fixed an issue where websites with a no-decrypt policy rule were + decrypted in traffic log when using a Google Chrome browser with PQC + enabled. +
+
+
PAN-261909
+
+
+ Fixed an issue where the GlobalProtect client did not display the + dialog box for an MFA verification code. +
+
+
PAN-261489
+
+
+ Fixed an issue where an out-of-memory (OOM) condition caused a + firewall outage. +
+
+
PAN-261484
+
+
+ Fixed an issue on the firewall where DPDK allocated twice the amount + of memory as requested for pre-allocation. +
+
+
PAN-261001
+
+
+ Fixed an issue where GlobalProtect users were unable to switch + gateways after upgrading to GlobalProtect version 6.2.3. +
+
+
PAN-260974
+
+
+ Fixed an issue where the Cloud Identity Engine (CIE) user context did + not correctly redistribute user/IP address port mapping to on-premises + firewalls. +
+
+
PAN-259997
+
+
+ (PA-3410, PA-3420, and PA-3430 firewalls only) + Fixed an issue where the install failed when upgrading from PAN-OS + 10.2.3-h3 and later 10.2 releases to PAN-OS 10.2.10 due to the number + of configured vsys zones exceeding the zone limit in PAN-OS 10.2.10. +
+
+
PAN-259769
+
+
+ Fixed an issue where the GlobalProtect portal was not accessible via a + web browser and displayed the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-259151
+
+
+ Fixed an issue where unused objects were pushed to the firewall, which + caused configuration pushes to fail with the error + Number of address groups exceed platform capacity. +
+
+
PAN-258736
+
+
+ Fixed an issue where policy rule configurations pushed from Panorama + were not reflected on the firewall if the rule had 63 characters. +
+
+
PAN-258225
+
+
+ Fixed an issue on the Panorama web interface where Security policy + rules loaded more slowly than expected. +
+
+
PAN-257957
+
+
+ (Firewalls and Panorama appliances in FIPS-CC mode only) Fixed an issue where the authd process + restarted if RADIUS PAP/CHAP authentication was used. +
+
+
PAN-257925
+
+
+ (CN-Series firewalls only) Fixed an issue where + the CLI command + show system setting ctd state did + not work as expected. +
+
+
PAN-256725
+
+
+ Fixed an issue on the Panorama interface where + Traffic and + Unified event details loaded more + slowly than expected. +
+
+
PAN-256666
+
+
+ Fixed an issue where the configdprocess stopped + responding when Commit and Push operations were + performed on multiple device groups. +
+
+
PAN-256385
+
+
+ (CN-Series firewalls only) Fixed an issue where + communication was broken between the management plane and the + dataplane when anti-spyware profiles were configured in a Security + policy rule. +
+
+
PAN-256350
+
+
+ Fixed an issue where, when you cloned an admin role or an LDAP server + profile and then changed the name of the clone, the configuration + change was not reflected on the managed firewall after pushing the + configuration from Panorama. +
+
+
PAN-256320
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where GTP sessions remained as allocated sessions on + the passive firewall even when there were no active sessions. +
+
+
PAN-255930
+
+
+ Fixed an issue where persistent DIPP NAT entries were deleted even + when being used during an active session. +
+
+
PAN-255266
+
+
+ Fixed an issue where you were unable to clone a template stack with + the Pre-Shared Key variable. +
+
+
PAN-254826
+
+
+ Fixed an issue where the firewall stopped responding when processing + traffic. +
+
+
PAN-254671
+
+
+ Fixed an issue where excessive + Timed out while getting config lock + error messages were generated when making bulk changes via XML API. +
+
+
PAN-254423
+
+
+ Fixed an issue on Panorama where custom role-based admin users with + read only access were able to make changes to configurations. +
+
+
PAN-253626
+
+
+ Fixed an issue on Panorama where unused objects were pushed to the + firewall, which caused the push operations to intermittently fail. +
+
+
PAN-253213
+
+
+ Fixed an issue where the firewall sent HIP notifications every time it + received a HIP report instead of every two hours. +
+
+
PAN-252300
+
+
+ Fixed an issue where you were unable to select device groups in the + push scope for user accounts. +
+
+
PAN-251676
+
+
+ Fixed an issue on Panorama appliances in large-scale deployments where + configd + process core files consumed more space in the /opt/panlogs partition + than was available. +
+
+
PAN-251655
+
+
+ Fixed an issue where the firewall stopped forwarding files to the + WildFire cloud and a restart of the + varrcvr + process was required. +
+
+
PAN-250787
+
+
+ Fixed an issue where network issues between the firewall and the log + collector caused + logrcvr + process memory exhaustion. +
+
+
PAN-250419
+
+
+ Fixed an issue where XML API explorer inserted a plus (+) character in + the Xpath when a space was used in the object name. +
+
+
PAN-250062
+
+
+ Fixed an issue where device telemetry failed after upgrading due to + bundle generation failure. +
+
+
PAN-249266
+
+
+ Fixed an issue where the + config + process virtual memory was exceeded due to delays in post-commit + processing. +
+
+
PAN-249011
+
+
+ Fixed an issue where the firewall became unresponsive when committing + a configuration change with a large number of uncommitted changes in + the replay database. +
+
+
PAN-247099
+
+
+ Fixed an issue where the firewall decrypted traffic unexpectedly when + the client hello was spread across multiple packets. +
+
+
PAN-246304
+
+
+ Fixed an issue on Panorama where commits failed due to a timeout in + the + sysd + process during decryption. +
+
+
PAN-246220
+
+
+ Fixed an issue where a dynamic peer connection was rejected when using + an FQDN for the peer address. +
+
+
PAN-244039
+
+
+ (PA-5450 firewalls only) Fixed an issue where + the firewall dropped packets when attempting to reuse a TCP session. +
+
+
PAN-243098
+
+
+ Fixed an issue with corrupted images when SSL decryption and Security + profiles were configured. +
+
+
PAN-241781
+
+
+ Fixed an issue where partial commit and commit-all operations took + more time than expected to create the job ID. +
+
+
PAN-241044
+
+
+ Fixed an issue where traffic was denied by the interzone-default + policy rule when a Security policy rule with an FQDN destination was + configured. +
+
+
PAN-234560
+
+
+ Fixed an issue where the daily summary report displayed IPv6 addresses + instead of IPv4 addresses. +
+
+
PAN-233727
+
+
+ Fixed an issue on the web interface where the following error message + was incorrectly displayed for an IKE gateway with a valid + configuration: + ikev2->pq-ppk->negotiation-mode is invalid. +
+
+
PAN-237582
+
+
+ Fixed an issue where logs were intermittently missing on the log + collector due to missing aliases for some indices +
+
+
PAN-234094
+
+
+ Fixed an issue on Panorama where + Deploy Master Keyresulted in the error message + Failed to communicate with device due to a low connection timeout + value. +
+
+
PAN-232214
+
+
+ Fixed an issue where GlobalProtect clients remained in the connecting + state during portal pre-login when Kerberos single sign-on (SSO) was + enabled. +
+
+
PAN-230825
+
+
+ Fixed an issue where link flaps occurred on Panorama appliances in HA + configurations. +
+
diff --git a/reference/PAN-OS/addressed/11.1.4-h7.html b/reference/PAN-OS/addressed/11.1.4-h7.html new file mode 100644 index 0000000..bbf9b63 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.4-h7.html @@ -0,0 +1,359 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-272809
+
+
+ A fix was made to address + CVE-2024-0012 + (PAN-SA-2024-0015) and + CVE-2024-9474. +
+
+
PAN-268823
+
+
+ Fixed an issue where + MonitorLog Display + did not display all logs when you applied a filter. +
+
+
PAN-265785
+
+
+ Fixed an issue where the firewall rebooted due to a + sysd + variable being modified before it was created. +
+
+
PAN-264883
+
+
+ (PA-7080 appliances with LPCs only) Fixed an + issue where syslog forwarding over TCP stopped after upgrading. +
+
+
PAN-263369
+
+
+ Fixed an issue where commits from Panorama to Panorama virtual + appliances failed with the error message + Internal error during commit processing. Commit/Validate + failed + after upgrading Panorama. +
+
+
PAN-261673
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where, when Accelerated Networking was enabled, + traffic was dropped because of the + flow_parse_ip_hdr counter related + to an Nvidia driver issue. +
+
+
PAN-261371
+
+
+ (PA-5410 firewalls in active/passive high availability (HA) + configurations only) Fixed an issue where the + reportd + process restarted, which caused the firewall to reboot. +
+
+
PAN-261209
+
+
+ (Firewalls in active/active HA configuration only) Fixed an issue where the firewall displayed the HA2 status as down + when the HSCI port was used for both HA2 and HA3. +
+
+
PAN-260905
+
+
+ Fixed an issue where the HS: Fiber Port Eth1/2 did not come up on a + cold boot and remained in an incorrect state. +
+
+
PAN-260316
+
+
+ Fixed an issue where the + all_task + process stopped responding and the firewall rebooted. +
+
+
PAN-259351
+
+
+ A fix was made to address + CVE-2024-3393. +
+
+
PAN-259002
+
+
+ Fixed an issue where frequent external dynamic list updates caused the + configd + process to restart. +
+
+
PAN-257601
+
+
+ (PA-5450 firewalls only) Fixed an issue where + Networking Cards (NC) experienced an internal link fault which caused + path monitoring failure on the Dataplane Processing Card (DPC). +
+
+
PAN-257327
+
+
+ Fixed an issue where a failover event occurred unexpectedly on the + firewall. +
+
+
PAN-256223
+
+
+ Fixed an issue where device telemetry log collection filled the root + partition. +
+
+
PAN-254794
+
+
+ Fixed an issue where the Panorama management server stopped + responding. +
+
+
PAN-249384
+
+
+ Fixed an issue on Panorama where configuration locks were observed + during a partial rulebase commit. +
+
+
PAN-243240
+
+
+ Fixed an issue where the using QoS caused packet buffer utilization to + increase exponentially and the + PKI POOL DFLT pool depleted until + a reboot was performed. +
+
+
PAN-242479
+
+
+ Fixed an issue where a high number of packets caused high packet + descriptors on the firewall when handling EtherIP traffic. +
+
+
PAN-230893
+
+
+ Added a CLI command to address an issue where system lock files + blocked authentication. +
+
diff --git a/reference/PAN-OS/addressed/11.1.4-h9.html b/reference/PAN-OS/addressed/11.1.4-h9.html new file mode 100644 index 0000000..b763baf --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.4-h9.html @@ -0,0 +1,646 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-273215
+
+
+ Fixed an issue where a syntax error in the index generation script + caused a high management plane CPU load after upgrading. +
+
+
PAN-271912
+
+
+ Fixed an issue on Panorama where the *configd* process stopped + responding when filtering in the configuration audit window after + upgrading to PAN-OS 11.1.3. +
+
+
PAN-271613
+
+
+ Fixed an issue where configuration pushes from Panorama to the + firewall failed due to an OOXML commit error. +
+
+
PAN-271314
+
+
+ Fixed an issue where pushing changes to a prefix list used for BGP + from Panorama affected OSPF routes. +
+
+
PAN-270224
+
+
+ Fixed an issue where indices were not opened after a query. +
+
+
PAN-269956
+
+
+ Fixed an issue where the + all_pktproc + process stopped responding, which caused internal path monitor + failures. +
+
+
PAN-269899
+
+
+ Fixed an issue where the Panorama web interface was slower than + expected when querying for device tags. +
+
+
PAN-269673
+
+
+ Fixed an issue where ElasticSearch was not set up after an upgrade. +
+
+
PAN-269000
+
+
+ Fixed an issue where the firewall stopped responding due to a NULL + pointer dereference when path monitoring failed. +
+
+
PAN-268972
+
+
+ Fixed an issue where Panorama was slower than expected when using a + high number of device group tags in a non-shared context. +
+
+
PAN-268501
+
+
+ Fixed an issue where the firewall was unable to generate a TSF file + due to a full root partition. +
+
+
PAN-266639
+
+
+ Fixed an issue where administrators were unable to edit or add virtual + router configurations when a filter was applied to the viewer. +
+
+
PAN-266114
+
+
+ Fixed an issue where, when a new set of URL logs came in, the content + of the earlier URL and traffic logs were lost. +
+
+
PAN-265973
+
+
+ Fixed an issue where administrator sessions were logged out with an + ERR_CONNECTION_REFUSED error on + the browser. +
+
+
PAN-265742
+
+
+ Fixed an issue on the Panorama web interface where the + OK button on the GlobalProtect + gateway configuration dialog box was not clickable. +
+
+
PAN-265219
+
+
+ (VM-Series firewalls only) Fixed an issue where + GRE traffic did not work properly. +
+
+
PAN-264871
+
+
+ Fixed an issue on Panorama where the + configd + process stopped responding when viewing IP addresses on dynamic + address groups with a large number of IP addresses. +
+
+
PAN-264249
+
+
+ Fixed an issue on the firewall where SNMP queries timed out when using + SNMP. +
+
+
PAN-263973
+
+
+ Fixed an issue where log collectors had a low incoming log rate. +
+
+
PAN-263287
+
+
+ The PAN-COMMON-MIB.my file was updated to support new object + identifiers (OID) to poll interface use via SNMP with table + identifiers. +
+
+
PAN-263208
+
+
+ (PA-5440 and PA-5445 firewalls only) Fixed an + issue where interrupts were generated at a certain packet rate, and + dataplane processes missed heartbeats, which caused the dataplane to + go down. +
+
+
PAN-263017
+
+
+ Fixed an issue where the firewall was unable to mount a disk partition + due to a corrupted filesystem. +
+
+
PAN-261485
+
+
+ Fixed an issue where the firewall dropped the Real Time Transport + Protocol (RTP) session for the second SIP call on Persistent-DIPP + connections when the source port of the client device was reset. +
+
+
PAN-260604
+
+
+ Fixed an issue where the firewall displayed inaccurate throughput + utilization stats in NetFlow analyzer tools. +
+
+
PAN-260512
+
+
+ Fixed an issue where accessing the IP address of the device address + group objects from the user interface caused the + configd + process to stop responding. +
+
+
PAN-260461
+
+
+ Fixed an issue where traffic logs showed a non-zero destination port + number on ICMP echo sessions through the firewall. +
+
+
PAN-260417
+
+
+ Fixed an issue on Panorama where + UpdateLicDB was triggered every + few minutes when firewalls with PAYG licenses were onboarded. +
+
+
PAN-260235
+
+
+ Fixed an issue where the firewall sent Threat logs and URL logs to an + external syslog server without Security profile settings when Enhanced + Application Logging was enabled. +
+
+
PAN-259910
+
+
+ Fixed an issue where the firewall reported the same value over + consecutive SNMP polls when asynchronous mode was enabled. +
+
+
PAN-259881
+
+
+ Fixed an issue on Panorama where traffic log details were not + displayed under detailed log view. +
+
+
PAN-259802
+
+
+ (Panorama appliances in high availability (HA) clusters only) Fixed an issue where, after replacing a secondary Panorama + appliance in a Panorama HA cluster, the ElasticSearch cluster was + unable to establish SSL tunnels due to SSLHandshakeException errors. +
+
+
PAN-259078
+
+
+ Fixed an issue where WildFire Analysis reports were not generated and + the following error message was displayed: + Error 500: Internal Server Error. +
+
+
PAN-258799
+
+
+ Fixed an issue where, when updating a Security Policy + Policy Optimizer, the web interface + stopped responding. +
+
+
PAN-257961
+
+
+ Fixed an issue on Panorama where + Test Security Policy Match failed + when the From or + To zone fields were populated. +
+
+
PAN-255915
+
+
+ Fixed an issue where a memory leak in the + sslmgr + process caused the firewall to restart. +
+
+
PAN-254904
+
+
+ Fixed an issue on Panorama where a core file was generated by + /usr/local/bin/logd during a restart. +
+
+
PAN-254577
+
+
+ Fixed an issue where a core file was created on the Log Forwarding + Card (LFC) due to a third-party software issue. +
+
+
PAN-253829
+
+
+ Fixed an issue where the CLI command + show running security-policy + timed out when the Security policy was large. +
+
+
PAN-252381
+
+
+ Fixed an issue where the Panorama web interface was slower than + expected when opening interfaces, virtual routers, and zones in a + template or template stack. +
+
+
PAN-250394
+
+
+ Fixed an issue where a large amount of group data caused serialization + errors and prevented synchronization. +
+
+
PAN-249581
+
+
+ Fixed an issue where stale BGP routes were advertised to peers even + when they were not present in the local RIB table. +
+
+
PAN-246699
+
+
+ Fixed an issue on Panorama where the + Rule Usage and + Apps Seen under Security policy + rules stopped incrementing. +
+
+
PAN-246567
+
+
+ Fixed an issue where a firewall with a copper SFP transceiver + (PAN-SFP-CG) flapped during a commit. +
+
+
PAN-242331
+
+
+ Fixed an issue where Prisma Access remote network firewalls + intermittently created incorrect user-to-IP-address mappings. +
+
+
PAN-241004
+
+
+ Fixed an issue where DNS Proxy dropped client requests of the type + ns for a root domain. +
+
+
PAN-235808
+
+
+ (Panorama appliances in Log Collector mode only) Fixed an issue where an unnamed core file was generated after a + reboot. +
+
+
PAN-233197
+
+
+ Fixed an issue where the CLI command to set the FEC parameter for the + front panel ports was not supported on platforms supporting 25G and + 100G. +
+
diff --git a/reference/PAN-OS/addressed/11.1.4.html b/reference/PAN-OS/addressed/11.1.4.html new file mode 100644 index 0000000..83f4a7f --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.4.html @@ -0,0 +1,271 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-256181
+
+
+ Fixed an issue where the management interface and front panel port + interface statistics were not populated in asynchronous mode of SNMP + operations. +
+
+
PAN-255868
+
+
+ (PA-3400 Series firewalls only) Fixed an issue + where the firewall entered maintenance mode after enabling kernel data + collection during the silent reboot. +
+
+
PAN-253317
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where you were unable to log in to the firewall + after a private data reset. +
+
+
PAN-252517
+
+
+ Fixed an issue where SNMP failed to respond to multiple Object + Identifier (OID) queries in a single SNMP GET request. +
+
+
PAN-251639
+
+
+ Fixed an issue where an out of memory condition might occur due to a + memory leak in the + varrcvr + process when a Wildfire Analysis security profile is enabled. +
+
+
PAN-250597
+
+
+ Fixed an issue where Global Find for a Panorama pushed shared address + object displayed Others in the + results. +
+
+
PAN-250270
+
+
+ Fixed an issue where partial commits did not merge changes when the + complete rule base was updated with edit operations via XML API. +
+
+
PAN-249814
+
+
+ Fixed an issue where multiple + all_task + processes stopped responding, which caused the dataplane to fail. +
+
+
PAN-249292
+
+
+ (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where CPU usage was higher than expected after a + hotplug event when Accelerated Networking was enabled for the + management interface. +
+
+
PAN-245157
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the firewall restarted after an HA failover + when DPDK was enabled. +
+
+
PAN-245125
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where file descriptors were not closed due to + invalid configurations. +
+
+
PAN-244746
+
+
+ Fixed an issue where changes committed on Panorama were not reflected + on the firewall after a successful push. +
+
+
PAN-238183
+
+
+ Fixed an issue where Panorama displayed deviating device system logs + for non-connected interfaces. +
+
+
PAN-236497
+
+
+ Fixed an issue where the firewall was unable to purge expired GTP-U + sessions that remained as allocated sessions even after the TTL was + expired. +
+
+
PAN-234977
+
+
+ Fixed an issue where, when a Layer 2 interface that was a member of a + VLAN was down, all traffic transmitted over the VLAN was dropped. +
+
+
PAN-231642
+
+
+ Fixed an issue on the Panorama web interface where users that were + logged in through multiple sessions were able to see an active lock on + only one session. +
+
+
PAN-214773
+
+
+ Fixed an issue where RTP packets traversing inter-vsys were dropped on + the outgoing vsys. +
+
+
PAN-202095
+
+
+ Fixed an issue on the web interface where the language setting was not + retained. +
+
diff --git a/reference/PAN-OS/addressed/11.1.5-h1.html b/reference/PAN-OS/addressed/11.1.5-h1.html new file mode 100644 index 0000000..cfffc82 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.5-h1.html @@ -0,0 +1,61 @@ + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-272809
+
+
+ A fix was made to address + CVE-2024-0012 + (PAN-SA-2024-0015) and + CVE-2024-9474. +
+
diff --git a/reference/PAN-OS/addressed/11.1.5.html b/reference/PAN-OS/addressed/11.1.5.html new file mode 100644 index 0000000..1ca5845 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.5.html @@ -0,0 +1,4495 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-268823
+
+
+ Fixed an issue where + Monitor > Log Display did not + display all logs when you applied a filter. +
+
+
PAN-265963
+
+
+ Fixed an issue where the + escd + process caused a memory leak when session resiliency was enabled on + the firewall. +
+
+
PAN-265785
+
+
+ Fixed an issue where the firewall rebooted due to a + sysd + variable being modified before it was created. +
+
+
PAN-265462
+
+
+ Fixed an issue where you were unable to download PDFs when connected + via a Clientless VPN. +
+
+
PAN-265344
+
+
+ Fixed an issue where + Import GlobalProtect Client Package + did not work after clicking OK after + selecting a valid package under + Device > GlobalProtect Client > Upload). +
+
+
PAN-265287
+
+
+ Fixed an issue where the firewall experienced a packet buffer leak in + the dataplane of the network processing card (NPC) when processing + certain net messages. +
+
+
PAN-264806
+
+
+ (PA-3440 firewalls only) Fixed an issue where + the firewall was unable to validate or commit a configuration when it + was imported from another firewall model. +
+
+
PAN-264369
+
+
+ Fixed an issue where the + 7 Day Threat Report was empty in the + scheduled reports sent via email. +
+
+
PAN-264249
+
+
+ Fixed an issue on the firewall where SNMP queries timed out when using + SNMP. +
+
+
PAN-263987
+
+
+ Fixed an issue on the firewall where, when a NAT transversal IPSec + tunnel was terminated, and the NAT rule that was applied to the NAT-T + IPSec tunnel was on the same firewall, traffic flowing through the + tunnel was not correctly translated. +
+
+
PAN-263956
+
+
+ (PA-440 firewalls only) Fixed an issue where a + firewall running PAN-OS 11.1.2-h3 only displayed the + Auto option for the interface duplex + setting. +
+
+
PAN-263505
+
+
+ (PA-850 firewalls only) Fixed an issue where + the firewall stopped responding and rebooted after upgrading to PAN-OS + 11.1.4. +
+
+
PAN-263287
+
+
+ The PAN-COMMON-MIB.my file was updated to support new object + identifiers (OID) to poll interface use via SNMP with table + identifiers. +
+
+
PAN-263278
+
+
+ Fixed an issue where the management interface flapped when IPv6 was + disabled and DHCPv6 was enabled. +
+
+
PAN-263226
+
+
+ Fixed an issue where, when SSL decryption was enabled and Client Hello + messages spanned multiple TCP segments, some SSL decrypted sessions + failed. +
+
+
PAN-263164
+
+
+ Fixed an issue where Netflow User ID information was truncated to 31 + characters. +
+
+
PAN-262902
+
+
+ Fixed an issue on the web interface where cloning region objects did + not work. +
+
+
PAN-262593
+
+
+ Fixed an issue where traffic to websites failed on the Google Chrome + web browser on Secure Web Gateway (SWG) nodes. +
+
+
PAN-262415
+
+
+ Fixed an issue where a partial configuration load failed for + configuration files that contained + regenerate-hostkeys. +
+
+
PAN-262410
+
+
+ Fixed an issue where the + App Scope graph did not display for + all days when selecting + Last 60 days or + Last 90 days. +
+
+
PAN-262340
+
+
+ Fixed an issue where FQDN resolution failed for address objects, and + all FQDN traffic was denied by the interzone-default policy rule. +
+
+
PAN-262287
+
+
+ Fixed an issue where dereferencing a NULL pointer that occurred when + App-ID stopped responding caused the firewall to restart. +
+
+
PAN-262254
+
+
+ Fixed an issue where the firewall experienced an OOM condition and the + useridd + process stopped responding, which caused the firewall to drop + interfaces from their respective aggregate groups. +
+
+
PAN-261991
+
+
+ Fixed an issue where traffic that did not match a decryption policy + rule, or matched a no-decrypt policy rule, failed when accumulation + proxy was enabled and a Zone Protection profile was configured with + syn-cookies enabled. +
+
+
PAN-261935
+
+
+ Fixed an issue where the firewall unexpectedly rebooted when replacing + or inserting SFPs from an old firewall into a new RMA firewall. +
+
+
PAN-261831
+
+
+ (Firewalls in HA configuration only) Fixed an + issue where link-down events did not occur after an HA failover. +
+
+
PAN-261671
+
+
+ Fixed an issue where GlobalProtect clients randomly fell back to the + SSL tunnel as the gateway dropped the initial three keepalive packets. +
+
+
PAN-261639
+
+
+ Fixed an issue where the firewall incorrectly logged the XFF IP in + threat logs when a single HTTP header was used. +
+
+
PAN-261489
+
+
+ Fixed an issue where an out-of-memory (OOM) condition caused a + firewall outage. +
+
+
PAN-261485
+
+
+ Fixed an issue where the firewall dropped the Real Time Transport + Protocol (RTP) session for the second SIP call on Persistent-DIPP + connections when the source port of the client device was reset. +
+
+
PAN-261484
+
+
+ Fixed an issue on the firewall where DPDK allocated twice the amount + of memory as requested for pre-allocation. +
+
+
PAN-261371
+
+
+ (PA-5410 firewalls in active/passive HA configurations only) Fixed an issue where the + reportd + process restarted, which caused the firewall to reboot. +
+
+
PAN-261209
+
+
+ (Firewalls in active/active HA configuration only) Fixed an issue where the firewall displayed the HA2 status as down + when the HSCI port was used for both HA2 and HA3. +
+
+
PAN-261174
+
+
+ Fixed an issue on Panorama where importing a certificate for a + template stack configuration incorrectly prompted for a passphrase as + a required field. +
+
+
PAN-261028
+
+
+ Fixed an issue where the firewall did not autocommit after a reboot + when the cellular interface was configured as a local interface for + the IPSec Satellite and the IP address was allocated dynamically. +
+
+
PAN-261019
+
+
+ Fixed an issue where Evasive Empire C2 Traffic Detection generated + benign verdicts and max latency timeout logs simultaneously when the + MICA ATP action was configured as + reset-both. +
+
+
PAN-260974
+
+
+ Fixed an issue where the Cloud Identity Engine (CIE) user context did + not correctly redistribute user/IP address port mapping to on-premises + firewalls. +
+
+
PAN-260928
+
+
+ Fixed an issue where GlobalProtect failed to connect when using LDAP + authentication with machine certificates with the error message + You are not authorized to connect to GlobalProtect portal. +
+
+
PAN-260905
+
+
+ Fixed an issue where the HS: Fiber Port Eth1/2 did not come up on a + cold boot and remained in an incorrect state. +
+
+
PAN-260842
+
+
+ A CLI command was introduced to address an issue where TCP packets + were out of order. +
+
+
PAN-260633
+
+
+ Fixed an issue where the firewall did not send a client certificate + after a TLS Certificate Request when establishing a secure syslog + connection. +
+
+
PAN-260546
+
+
+ (PA-440 firewalls only) Fixed an issue where + the system clock reset to the epoch date and time after 8 to 12 weeks + of shelf life or no power. +
+
+
PAN-260512
+
+
+ Fixed an issue where accessing the IP address of the device address + group objects from the user interface caused the + configd + process to stop responding. +
+
+
PAN-260316
+
+
+ Fixed an issue where the + all_task + process stopped responding and the firewall rebooted. +
+
+
PAN-260218
+
+
+ Fixed an issue where BGP Aggregate Advertise filters did not work as + expected when the summary option was enabled, and only summarized + routes were advertised. +
+
+
PAN-260193
+
+
+ Fixed an issue where GlobalProtect on macOS clients did not connect + when using a client certificate and the X.509 policy was set to + Use System Default. +
+
+
PAN-260132
+
+
+ Fixed an issue where secondary IP addresses with a /32 prefix + configured on Layer 3 interfaces were not reachable in FRR mode. +
+
+
PAN-260114
+
+
+ Fixed an issue where the firewall generated a + devsrvr + core file when processes were restarted. +
+
+
PAN-259910
+
+
+ Fixed an issue where the firewall reported the same value over + consecutive SNMP polls when asynchronous mode was enabled. +
+
+
PAN-259883
+
+
+ Fixed an issue where the firewalls behind an Amazon Web Services (AWS) + Gateway Load Balancer (GWLB) stopped responding when processing GENEVE + packets with the reserved bit set. +
+
+
PAN-259881
+
+
+ Fixed an issue on Panorama where traffic log details were not + displayed under detailed log view. +
+
+
PAN-259802
+
+
+ (Panorama appliances in HA clusters only) Fixed + an issue where, after replacing a secondary Panorama appliance in a + Panorama HA cluster, the ElasticSearch cluster was unable to establish + SSL tunnels due to SSLHandshakeException errors. +
+
+
PAN-259769
+
+
+ Fixed an issue where the GlobalProtect portal was not accessible via a + web browser and displayed the error + ERR_EMPTY_RESPONSE. +
+
+
PAN-259706
+
+
+ Fixed an issue on Panorama where the web interface was slower than + expected or unresponsive when monitoring definitions were added in the + Kubernetes plugin. +
+
+
PAN-259535
+
+
+ Fixed an issue where the firewall failed to boot up after running + power cycle tests due to + ehmon + process heartbeat failures. +
+
+
PAN-259370
+
+
+ Fixed an issue on the web interface where + Correlation Log Detail > Match Evidence + did not populate. +
+
+
PAN-259351
+
+
+ A fix was made to address + CVE-2024-3393. +
+
+
PAN-259344
+
+
+ Fixed an issue where performing a configuration commit on a firewall + locally or from Panorama caused a memory leak related to the + configd + process and resulted in an OOM condition. +
+
+
PAN-259200
+
+
+ Fixed an issue where the firewall displayed truncated zone names in + the Block IP List log when a zone + name contained more than 14 characters. +
+
+
PAN-259151
+
+
+ Fixed an issue where unused objects were pushed to the firewall, which + caused configuration pushes to fail with the error + Number of address groups exceed platform capacity. +
+
+
PAN-259002
+
+
+ Fixed an issue where frequent external dynamic list updates caused the + configd + process to restart. +
+
+
PAN-258996
+
+
+ Fixed an issue where the firewall displayed the SFP ports as + PowerDown when the SFP + transceiver was removed and reinserted or the port was shut down and + brought back up on the peer device. +
+
+
PAN-258757
+
+
+ Fixed an issue on Panorama where upgrades failed with validation + errors. +
+
+
PAN-258734
+
+
+ Fixed an issue where virtual wire ports did not go down when moving + from an active state to a suspended state. +
+
+
PAN-258576
+
+
+ Fixed an issue on the Panorama web interface where products in HIP + objects were not displayed correctly. +
+
+
PAN-258442
+
+
+ Fixed an issue where changes made to the split tunnel configuration on + the Prisma Access gateway were not reflected on the GlobalProtect + client. +
+
+
PAN-258240
+
+
+ (Firewalls in HA configurations only) Fixed an + issue where HA path monitoring did not work as expected when using + vwire. +
+
+
PAN-258225
+
+
+ Fixed an issue on the Panorama web interface where Security policy + rules loaded more slowly than expected. +
+
+
PAN-258188
+
+
+ Fixed an issue on Panorama Template where the virtual wire + subinterface page did not display all fields and the + OK button did not work. +
+
+
PAN-258166
+
+
+ (PA-220 firewalls only) Fixed an issue where + the root partition frequently reached 100%. +
+
+
PAN-257961
+
+
+ Fixed an issue on Panorama where + Test Security Policy Match failed + when the From or + To zone fields were populated. +
+
+
PAN-257957
+
+
+ (Firewalls and Panorama appliances in FIPS-CC mode only) Fixed an issue where the + authd + process restarted if RADIUS PAP/CHAP authentication was used. +
+
+
PAN-257925
+
+
+ (CN-Series firewalls only) Fixed an issue where + the CLI command + show system setting ctd state did + not work as expected. +
+
+
PAN-257912
+
+
+ Fixed an issue where the firewall stopped responding when it received + RADIUS traffic and user equipment (UE) traffic at the same time on a + Network Processing Card (NPC) +
+
+
PAN-257747
+
+
+ Fixed an issue where the firewall incorrectly displayed the error + message + IoT Security license is required for feature to function + even when the firewall had a valid Enterprise IoT security license. +
+
+
PAN-257660
+
+
+ Fixed an issue where show commands were hidden for superusers in + read-only roles. +
+
+
PAN-257652
+
+
+ Fixed an issue where Internal Host Detection for IPv6 did not work + after upgrading to a PAN-OS 10.2 release. +
+
+
PAN-257638
+
+
+ Fixed an issue where the firewall dataplane stopped responding, which + caused BGP flaps between hubs and branches. +
+
+
PAN-257624
+
+
+ Fixed an issue where the firewall web interface was blank after + logging in. +
+
+
PAN-257619
+
+
+ Fixed an issue on Panorama where the + Task Manager took longer than + expected to display managed FW report tasks details when its empty +
+
+
PAN-257601
+
+
+ (PA-5450 firewalls only) Fixed an issue where + Networking Cards (NC) experienced an internal link fault which caused + path monitoring failure on the Dataplane Processing Card (DPC). +
+
+
PAN-257600
+
+
+ Fixed an issue where the firewall returned a 404 error for all sites + accessed through the clientless VPN portal. +
+
+
PAN-257432
+
+
+ Fixed an issue on Panorama where the + reportd + process stopped responding, which caused a log query issue. +
+
+
PAN-257390
+
+
+ (PA-5250 firewalls only) Fixed an issue where + the + logrcvr + process stopped responding due to a segmentation fault. +
+
+
PAN-257327
+
+
+ (PA-5440 firewalls only) Fixed an issue where a + failover event occurred unexpectedly on the firewall. +
+
+
PAN-257267
+
+
+ (VM-Series firewalls only) Fixed an issue where + observed warning message during commit completion & critical + system log when configuration size exceeded the maximum recommended + configuration size. +
+
+
PAN-257117
+
+
+ Fixed an issue where CSV or PDF exports of zones did not contain all + zones. +
+
+
PAN-257028
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where firewalls entered a non-functional state and + displayed the error message + Dataplane down: path monitor failure during the fail-over. +
+
+
PAN-257021
+
+
+ "Fixed an issue on the web interface where + Match Evidence log details for + Monitor > Correlated events did + not populate." +
+
+
PAN-256960
+
+
+ Fixed an issue where a custom portal login page was not displayed + correctly in the GlobalProtect portal when using a customized portal + landing page. +
+
+
PAN-256939
+
+
+ Fixed an issue on the firewall where disk space was low in + /opt/pancfg/, which caused + dynamic content installation to fail. +
+
+
PAN-256738
+
+
+ (VM-Series firewalls in HA configurations only) + Fixed an issue where BGP routes from the active firewall were lost + when the passive firewall was rebooted. +
+
+
PAN-256725
+
+
+ Fixed an issue on the Panorama interface where + Traffic and + Unified event details loaded more + slowly than expected. +
+
+
PAN-256669
+
+
+ Fixed an issue where the memory usage reported by SNMP did not match + the memory usage reported by the top command. +
+
+
PAN-256666
+
+
+ Fixed an issue where the + configd + process stopped responding when + Commit and Push operations were + performed on multiple device groups. +
+
+
PAN-256652
+
+
+ Fixed an issue where content updates were processed incorrectly, which + caused a mismatch between a Threat ID's signature and its + corresponding action. +
+
+
PAN-256518
+
+
+ Fixed an issue where Panorama was unable to push firmware updates to a + VM-Series firewall with a PAYG license. +
+
+
PAN-256449
+
+
+ Fixed an issue where DHCPv6 relay was not working in Advanced Routing + mode when the firewall was configured as a DHCP relay agent. +
+
+
PAN-256385
+
+
+ (CN-Series firewalls only) Fixed an issue where + communication was broken between the management plane and the + dataplane when anti-spyware profiles were configured in a Security + policy rule. +
+
+
PAN-256362
+
+
+ Fixed an issue in Panorama where shared address objects used in the + GlobalProtect configuration agents were not considered as used and not + pushed to Firewall that causes commit-all failure error +
+
+
PAN-256350
+
+
+ Fixed an issue where, when you cloned an admin role or an LDAP server + profile and then changed the name of the clone, the configuration + change was not reflected on the managed firewall after pushing the + configuration from Panorama. +
+
+
PAN-256327
+
+
+ (Panorama virtual appliances on Microsoft Azure environments + only) Fixed an issue where the + logd + process repeatedly restarted due to a buffer overflow when generating + a traffic summary from a traffic log. +
+
+
PAN-256249
+
+
+ Fixed an issue on the web interface that occurred when changing the + pre-shared key to a variable (Network > Network Profiles > IKE Gateways). +
+
+
PAN-256223
+
+
+ Fixed an issue where device telemetry log collection filled the root + partition. +
+
+
PAN-256115
+
+
+ Fixed an issue where, after replacing a Panorama appliance or log + collector, the secondary Panorama appliance or log collector displayed + a disconnected status for the + inter-log collector connection. +
+
+
PAN-256051
+
+
+ Fixed an issue on the firewall where enabling flow basic caused the + firewall to stop responding due to a + masterd + process restart. +
+
+
PAN-255930
+
+
+ Fixed an issue where persistent DIPP NAT entries were deleted even + when being used during an active session. +
+
+
PAN-255895
+
+
+ Fixed an issue where Panorama administrators with the + Panorama Administrator dynamic + administrator type were not able to create or modify BGP timer + profiles or BGP dampening profiles. +
+
+
PAN-255820
+
+
+ Fixed an issue where the WildFire signature generation check box in + Panorama did not register a change in the configuration. +
+
+
PAN-255773
+
+
+ Fixed an issue where errors related to applications in + Content-preview caused commit + failures. +
+
+
PAN-255711
+
+
+ Fixed an issue where the firewall displayed a malformed request error + when selecting a custom format and clicking + OK on the configuration window due + to the log type + Correlation incorrectly being + displayed (Device > Log Setting - Correlation > Syslog Server Profile + > Custom Log Format > Correlation). +
+
+
PAN-255660
+
+
+ (Firewalls in active/active HA configurations only) Fixed an issue where the path monitor displayed as up even when + routes to the destination IP address were removed. +
+
+
PAN-255579
+
+
+ (PA-7500 Series firewalls and Panorama appliances only) Fixed an issue where dataplane logs were displayed after a delay. +
+
+
PAN-255396
+
+
+ Fixed an issue where, when using serial number and IP address + authentication, and multiple gateways were configured, the portal + returned the last gateway in the list and disregarded the satellite + assignment by serial number. +
+
+
PAN-255391
+
+
+ Fixed an issue where the firewall was unable to filter logs using the + ISO 8601 timestamp format after upgrading to PAN-OS 11.0.4 or a later + release. +
+
+
PAN-255360
+
+
+ Fixed an issue where the firewall booted into maintenance mode when + there was no connectivity to the specified hardware security module + (HSM). +
+
+
PAN-255285
+
+
+ Fixed an issue where, when only the HSCI-A link was connected on + firewall cluster nodes, and the management interface went down, a + split brain condition occurred. +
+
+
PAN-255282
+
+
+ (PA-450 firewalls in HA configurations only) + Fixed an issue where the firewall remained in an active state and all + traffic stopped until a failover to the passive firewall was + performed. +
+
+
PAN-255252
+
+
+ Fixed an issue where Panorama administrators with the type Dynamic + were unable to create, modify, or delete BGP Dampening profiles. +
+
+
PAN-255163
+
+
+ (CN-Series firewalls only) Fixed an issue where + the system database key that stored the configuration status of the + dataplane pod was not updated frequently. +
+
+
PAN-255116
+
+
+ Fixed an issue where, when QoS was enabled, traffic on an NGFW cluster + node that went from an MC-LAG interface to a destination stopped when + a member of the MC-LAG went down. +
+
+
+ 254927 +
+
+
+ (PA-7500 Series firewalls only) Fixed an issue + where data packets sent to threat inspection processing on the + networking card caused the + pan_task + process to stop responding. +
+
+
PAN-254901
+
+
+ Fixed an issue where GlobalProtect user-to-IP address mapping was + removed even though the tunnel for the specific user was up and + traffic was being passed. +
+
+
PAN-254875
+
+
+ (PA-410 firewalls only) Fixed an issue where + the firewall rebooted unexpectedly due to multiple + all_task + process restarts. +
+
+
+ PAN-254827 +
+
+
+ Fixed an issue where, when you changed an IP address on a management + interface on an NGFW cluster node, commit-all operations did not push + the updated IP address. +
+
+
PAN-254826
+
+
+ Fixed an issue where the firewall stopped responding when processing + traffic. +
+
+
PAN-254797
+
+
+ (PA-5400 Series firewalls only) Fixed an issue + where you were unable to use SNMP polling o monitor the status of + power supply units. +
+
+
PAN-254704
+
+
+ (LSVPN Portal firewalls in active/passive HA configurations only) Fixed an issue where the satellite cookie key did not sync between + LSVPN portal HA firewalls, which resulted in re-authentication of + satellites with the portal during the event of HA failover. +
+
+
PAN-254671
+
+
+ Fixed an issue where excessive + Timed out while getting config lock + error messages were generated when making bulk changes via XML API. +
+
+
PAN-254629
+
+
+ Fixed an issue on the Management Processing Card where excessive logs + were generated for an error. +
+
+
PAN-254577
+
+
+ Fixed an issue where a core file was created on the Log Forwarding + Card due to a third-party software issue. +
+
+
PAN-254423
+
+
+ Fixed an issue on Panorama where custom role-based admin users with + read only access were able to make changes to configurations. +
+
+
PAN-254422
+
+
+ Fixed an issue where the firewall required a restart when an SD-WAN + policy rule was pushed from Panorama. +
+
+
PAN-254351
+
+
+ Fixed an issue where an NGFW cluster node remained in a suspended + state when GRE tunnel termination was used with keepalive enabled on + both ends. +
+
+
PAN-254301
+
+
+ Fixed an issue where GlobalProtect logs showed the public IPv4 address + in the private IPv4 address field for logs generated during + portal/gateway negotiation. +
+
+
PAN-254241
+
+
+ Fixed an issue where the firewall stopped responding due to a high + number of SD-WAN probes being sent. +
+
+
PAN-254181
+
+
+ (CN-Series firewalls only) Fixed an issue where + firewall pods and application pods repeatedly restarted. +
+
+
PAN-254124
+
+
+ (PA-7050 firewalls with DPC and 100G NPCs only) + Fixed an issue on the firewall where you were unable to change the + flow key type from tag to tuple. +
+
+
PAN-253829
+
+
+ Fixed an issue where the CLI command + show running security-policy + timed out when the Security policy was large. +
+
+
PAN-253819
+
+
+ Fixed an issue where a + User Activity Report was not + generated by Run Now or not emailed + through the Email Schedule when the + locale setting was not English. +
+
+
PAN-253626
+
+
+ Fixed an issue on Panorama where unused objects were pushed to the + firewall, which caused the push operations to intermittently fail. +
+
+
PAN-253584
+
+
+ Fixed an issue where ikemgr process unexpectedly stopped due to a + memory mapping in an incorrect location. +
+
+
PAN-253557
+
+
+ Fixed an issue where, after a cluster manager restart on the leader + node of an NGFW cluster, traffic stopped due to only the state machine + transitioning to unknown and not the leader. +
+
+
PAN-253452
+
+
+ Fixed an issue where GlobalProtect users were unable to connect to the + GlobalProtect gateway and received the error + Gateway does not exist. +
+
+
PAN-253466
+
+
+ Fixed an issue where, on NFGW cluster nodes, an expected packet buffer + leak occurred with FTP/SIP traffic over an extended period of time. +
+
+
PAN-253250
+
+
+ Fixed an issue where, when ASPath Prepend was configured, AS override + did not work. +
+
+
PAN-253085
+
+
+ Fixed an issue where the firewall restarted when the parsing of the + cross-pkt http origin header failed when processing a translator + website. +
+
+
PAN-252974
+
+
+ (PA-450 firewalls only) Fixed an issue where + specific routes were not advertised when BGP Aggregate was configured + with the advertise filter. +
+
+
PAN-252867
+
+
+ Fixed an issue where an incorrect memory reference in an IoT API + caused the wifclient process to + stop responding. +
+
+
PAN-252816
+
+
+ Fixed an issue where multiple SSHD process restarts triggered a + firewall reboot when the login banner and SSH host keys were updated + at the same time. +
+
+
PAN-252801
+
+
+ Fixed an issue where the LSVPN tunnel monitoring status displayed as + No data available after re-key + events. +
+
+
PAN-252411
+
+
+ Fixed an issue where, when log files were purged from the rollup + summary logs, the summary report still used the rollup summary data, + which resulted in the summary report displaying less data. +
+
+
PAN-252370
+
+
+ Fixed an issue where services with the reserved keyword + application-default were allowed. +
+
+
PAN-252270
+
+
+ Fixed an issue on the firewall where changes were incorrectly applied + after a reboot or a restart of the + configd + process. +
+
+
PAN-252224
+
+
+ Fixed an issue where Panorama did not forward logs to a syslog server + over an SSL connection using CRL as a revocation verification method. +
+
+
PAN-252161
+
+
+ Fixed an issue where the + gp_broker + process stopped responding. +
+
+
PAN-252131
+
+
+ (PA-5200 Series and PA-7000 Series firewalls only) Fixed an issue where an unsupported SFP caused the firewall to + restart. +
+
+
PAN-252036
+
+
+ Fixed an issue where, when the GlobalProtect portal was not + configured, accessing the GlobalProtect gateway still loaded a portal + malformed page. +
+
+
PAN-252029
+
+
+ Fixed an issue where the firewall stopped responding when processing + authentication requests. +
+
+
PAN-251929
+
+
+ Fixed an issue where inbound decryption did not work when FIPS self + tests were turned on. +
+
+
PAN-251732
+
+
+ Fixed an issue where Oracle traffic over generic routing encapsulation + (GRE) was dropped when the traffic passed through the firewall using + tunnel content inspection (TCI). +
+
+
PAN-251684
+
+
+ Fixed an issue where the LEDs for copper ports lighted up when SFP + links were up. +
+
+
PAN-251676
+
+
+ Fixed an issue on Panorama appliances in large-scale deployments where + configd + process core files consumed more space in the /opt/panlogs partition + than was available. +
+
+
PAN-251661
+
+
+ Fixed an issue where a memory overwrite occurred during HTTP/2 header + inflation. +
+
+
PAN-251656
+
+
+ Fixed an issue where enabling lockless QoS caused traffic disruptions. +
+
+
PAN-251501
+
+
+ Fixed an issue where, after a reboot, NGFW cluster nodes failed to + rejoin a cluster due to a timing issue. +
+
+
PAN-251372
+
+
+ Fixed an issue where a policy-based forwarding (PBF) did not work for + a server-to-client (S-C) flow when the source port was specified. +
+
+
PAN-251035
+
+
+ Fixed an issue where selective push operations did not push + certificate changes to the firewall. +
+
+
PAN-250948
+
+
+ Fixed an issues where GlobalProtect on Microsoft Windows devices did + not attempt CNAME resolution for sinkhole.paloaltonetworks.com. +
+
+
PAN-250909
+
+
+ Fixed an issue where, when creating a Security policy rule via the + CLI, validation was not implemented and the same object was able to be + referenced in the policy twice. +
+
+
PAN-250756
+
+
+ Fixed an issue where querying threat logs using the threat name, such + as generic:<site> did not + work. +
+
+
PAN-250716
+
+
+ Fixed an issue where + Panorama > Push to Devices + displayed device group and template entries that had been changed by + other administrators. +
+
+
PAN-250703
+
+
+ Fixed an issue where the task manager failed with a 504 error when a + large number of previous jobs or tasks were present. +
+
+
PAN-250530
+
+
+ Fixed an issue where management traffic routed via the dataplane was + being decrypted instead of bypassing the decryption lookup. +
+
+
PAN-250462
+
+
+ Fixed an issue where the session logout time for the firewall was + incorrect when viewing via context switch from Panorama. +
+
+
PAN-250455
+
+
+ Fixed an issue where GlobalProtect portal authentication incorrectly + timed out after 30 seconds when the timeout value was set to 1 minute. +
+
+
PAN-250443
+
+
+ (VM-Series firewalls only) Fixed an issue where + multiple processes exited due to an OOM condition and caused a network + outage. +
+
+
PAN-250419
+
+
+ Fixed an issue where XML API explorer inserted a plus (+) character in + the Xpath when a space was used in the object name. +
+
+
PAN-250405
+
+
+ (CN-Series firewalls only) Fixed an issue on + the firewall where + websrvr related messages + displayed repeatedly. +
+
+
PAN-250394
+
+
+ Fixed an issue where a large amount of group data caused serialization + errors and prevented synchronization. +
+
+
PAN-250311
+
+
+ Fixed an issue where the domain was not mapped when using certificate + profile authentication on GlobalProtect. +
+
+
PAN-250258
+
+
+ Fixed an issue on the firewall where the Certificate Name character + limit was 31 characters instead of 63 characters. +
+
+
PAN-250146
+
+
+ Fixed an issue on the web interface where templates incorrectly showed + that telemetry was enabled when it was not enabled. With this fix, the + telemetry setting is not displayed in the template on the web + interface. +
+
+
PAN-250127
+
+
+ Fixed an issue where commits failed with the error message + set is not allowed when + default originate was enabled with a + route map that included a set action. +
+
+
PAN-250062
+
+
+ Fixed an issue where device telemetry failed after upgrading due to + bundle generation failure. +
+
+
PAN-250043
+
+
+ Fixed an issue where, on an NGFW cluster node, operations failed when + QoS interfaces were configured with an egress max that exceeded 68,000 + Mbps. +
+
+
PAN-250021
+
+
+ Fixed an issue where + Change Summary and + Preview Changes displayed + inconsistent information when changing an admin user password. +
+
+
PAN-250005
+
+
+ Fixed an issue where the Advanced Routing migration script did not + migrate BGP import policy rules correctly when the policy rule was + configured with an exact match condition. +
+
+
PAN-249855
+
+
+ Fixed an issue where the firewall dropped the active source of the + Multicast source via MSDP when they were not received from the MSDP + peer firewall. +
+
+
PAN-249727
+
+
+ Fixed an issue where, on an NGFW cluster node, the + Custom/Pre-defined URL category was + not in the session flow data, which caused it to be excluded from the + promoted session after a failover. +
+
+
PAN-249548
+
+
+ Fixed an issue where the firewall stopped responding during a high + availability (HA) failover with continued traffic. +
+
+
PAN-249533
+
+
+ Fixed an issue where an internal error message was displayed when you + selected + Exclude video traffic from the tunnel (Windows and macOS + only). +
+
+
PAN-249404
+
+
+ Fixed an issue on the Panorama web interface where the commit lock for + a device group and template with the same name was not visible. +
+
+
PAN-249266
+
+
+ Fixed an issue where the + config + process virtual memory was exceeded due to delays in post-commit + processing. +
+
+
PAN-249194
+
+
+ Fixed an issue where SaaS quality profile probes were dropped on the + SD-WAN hub. +
+
+
PAN-249132
+
+
+ Fixed an issue on Panorama DG where the address group object created + with Disable Override property in + Parent DG was overridden by child DG via CLI. +
+
+
PAN-249072
+
+
+ Fixed an issue where content upgrade installation failed with the + error + Error: can't find cert <cert> when using cloud + interfaces. +
+
+
PAN-248945
+
+
+ Fixed an issue where commits failed when you committed a configuration + to advertise the default route (0.0.0.0/0) as a BGP network statement + (Advanced Routing > BGP settings). +
+
+
PAN-248841
+
+
+ Fixed an issue where the SSL response time was not displayed in the + GlobalProtect log. +
+
+
PAN-248762
+
+
+ Fixed an issue where, when the Advanced Routing Engine was configured + with OSPF, the firewall stopped responding when attempting to connect + to the neighbor while exchanging route maps. +
+
+
PAN-248618
+
+
+ Fixed an issue where the + show chassis inventory in the XML + API output did not include the chassis serial number. +
+
+
PAN-248542
+
+
+ Fixed an issue where the NPB policy type was missing from + configuration policy updates, which caused error messages to + incorrectly display in the system logs. +
+
+
PAN-248312
+
+
+ Fixed an issue where the firewall did not re-encapsulate the DNS + Security Sinkhole Domain Response into GENEVE when the firewall was + integrated with AWS Gateway Load Balancer (GWLB) and Cloud NGFW. +
+
+
PAN-248285
+
+
+ Fixed an issue where the firewall went into maintenance mode or + stopped responding. +
+
+
PAN-248211
+
+
+ Fixed an issue on Panorama where commits failed when Advanced Routing + was enabled. +
+
+
PAN-247857
+
+
+ (PA-7050 firewalls in HA configurations only) + Fixed an issue on the firewall where a dataplane process restarted + when updating the routing table. +
+
+
PAN-247754
+
+
+ Fixed an issue where successful + Commit and Push operations performed + by SAML authenticated users were not reflected on the firewall. +
+
+
PAN-247230
+
+
+ Fixed an issue where the syslog forwarding configuration did not + include the full path for Security policy rules. +
+
+
PAN-247190
+
+
+ (VM-Series firewalls only) Fixed an issue where + the firewall was unable to connect to Panorama after manually + uploading the license key. +
+
+
PAN-247052
+
+
+ Fixed an intermittent issue where the OSPF ABR option was disabled + when a static route was added. +
+
+
PAN-246803
+
+
+ Fixed an issue with failed pre-login cookies that caused GlobalProtect + portal configurations to show as empty. +
+
+
PAN-246567
+
+
+ Fixed an issue where a firewall with a copper SFP transceiver + (PAN-SFP-CG) flapped during a commit. +
+
+
PAN-246416
+
+
+ Fixed an issue where the firewall stopped responding when processing + specific HTTP response packets due to an incorrect offset calculation. +
+
+
PAN-246304
+
+
+ Fixed an issue on Panorama where commits failed due to a timeout in + the + sysd + process during decryption. +
+
+
PAN-246256
+
+
+ Fixed an issue where the firewall received the following error message + in the system logs after rebooting: + fail to read ncores: cfg.paltform.cores. +
+
+
PAN-246220
+
+
+ Fixed an issue where a dynamic peer connection was rejected when using + an FQDN for the peer address. +
+
+
PAN-246209
+
+
+ Fixed an issue where IPSec VPN tunnels went down after receiving a + DHCP server message that the DHCP client cleared the IP address on the + interface. +
+
+
PAN-245993
+
+
+ Fixed an issue where API calls to move the BGP export rules failed + with the error + The request could not be handled. +
+
+
PAN-245845
+
+
+ Fixed an issue where the firewall displayed a message that the license + was invalid even though all licenses were up to date. +
+
+
PAN-245682
+
+
+ Fixed an issue on Panorama where + Commit and Push progress displayed + over 100%. +
+
+
PAN-245545
+
+
+ Fixed an issue where, when you were connected to the VPN and enabled + the client accelerator, you were disconnected from the VPN. +
+
+
PAN-245058
+
+
+ Fixed an issue on the Panorama web interface where tagging a new user + failed the error message + Tags addition failed. +
+
+
PAN-244743
+
+
+ Fixed an issue where intermittent 500 errors occurred when making API + calls to the firewall. +
+
+
PAN-244708
+
+
+ Fixed an issue where the GlobalProtect VPN connection inactivity TTL + value became negative, which caused the VPN to disconnect when the + system time was changed back to the past time. +
+
+
PAN-244262
+
+
+ Fixed an issue where interface settings were not saved when the + template was overridden in the candidate configuration while enabling + DNS settings. +
+
+
PAN-244035
+
+
+ (PA-5220 firewalls only) Fixed an issue on the + web interface where the displayed dataplane CPU usage was up to 20% + less than the correct CPU usage. +
+
+
PAN-243969
+
+
+ Fixed an issue on Panorama managed firewalls where you were unable to + add a new Layer 3 interface to a template with a zone, VR, IP address, + and SD-WAN interface profile configured. +
+
+
PAN-243968
+
+
+ Fixed an issue where the correct portal agent configuration for + GlobalProtect was not matched. This occurred when CRL checks failed + due to unavailability. +
+
+
PAN-243957
+
+
+ Fixed an issue where the firewall TLS/SSL service profile exclusion + settings were not correctly applied on the captive portal. +
+
+
PAN-243908
+
+
+ Fixed an issue where custom object import for spyware got stuck on + uploading page and seen uploaded successfully after refreshing GUI + tab. +
+
+
PAN-243816
+
+
+ Fixed an issue where new users were unable to change their password + during the first login when the + Max session count was set to 1 and + Require Password Change on First Login + was enabled. +
+
+
PAN-243787
+
+
+ Fixed an issue where the CLI command + delete user-file ssh-known-hosts + did not remove the SSH host keys. +
+
+
PAN-243786
+
+
+ Fixed an issue on Panorama where custom GlobalProtect reports + displayed inaccurate values. +
+
+
PAN-243773
+
+
+ Fixed an issue where the DHCP server stopped responding with the error + IP address is already in use. +
+
+
PAN-243674
+
+
+ Fixed an issue where you were unable to configure NDP proxy with IPv6 + address /88 on a Layer 3 interface. +
+
+
PAN-243240
+
+
+ Fixed an issue where the using QoS caused packet buffer utilization to + increase exponentially and the + PKI POOL DFLT pool depleted until + a reboot was performed. +
+
+
PAN-243223
+
+
+ Fixed an issue where authentication to the GlobalProtect gateway + failed due to an invalid Satellite certificate. +
+
+
PAN-243190
+
+
+ Fixed an issue where the show commands for HSCI ports did not provide + information about optics and light levels. +
+
+
PAN-243123
+
+
+ Fixed an issue where SNMPv3 traps were not sent when using FQDN server + addresses. +
+
+
PAN-243098
+
+
+ Fixed an issue with corrupted images when SSL decryption and Security + profiles were configured. +
+
+
PAN-242960
+
+
+ Fixed an issue where the firewall did not honor the peer + Desired Minimum Tx Interval when in + a BFD INIT state. +
+
+
PAN-242958
+
+
+ Fixed an issue where the firewall intermittently logged + connect-agent-failure messages + for service connection instances due to bi-directional host ID + redistribution. +
+
+
PAN-242957
+
+
+ Fixed an issue where the + Rule usage columns of overridden + default policy rules on the Security policy page stopped responding. +
+
+
PAN-242826
+
+
+ Fixed an issue with the REST API syntax when creating a DHCP server + configuration for an existing subinterface. +
+
+
PAN-242739
+
+
+ Fixed an issue on the firewall where the dataplane repeatedly + restarted. +
+
+
PAN-242479
+
+
+ Fixed an issue where a high number of packets caused high packet + descriptors on the firewall when handling EtherIP traffic. +
+
+
PAN-242431
+
+
+ Fixed an issue where the BGP timer setting was in read-only mode for + custom admin users when Advanced Routing was enabled. +
+
+
PAN-242331
+
+
+ Fixed an issue where Prisma Access remote network firewalls + intermittently created incorrect user-to-IP-address mappings. +
+
+
PAN-242130
+
+
+ Fixed an issue where the firewall displayed the speed and duplex of + its dataplane interfaces as + Unknown even though the link was up. +
+
+
PAN-241871
+
+
+ Fixed an issue where the firewall was unable to create new IPSec + tunnels when the tunnel monitor flapped. +
+
+
PAN-241821
+
+
+ Fixed an issue where + Global Search did not show results + past the second level. +
+
+
PAN-241781
+
+
+ Fixed an issue where partial + commit and + commit-all operations took more + time than expected to create the job ID. +
+
+
PAN-241772
+
+
+ Fixed an issue where, when TLSv1.3 was used, an incorrect error + message invalid padding was + displayed instead of the expected error message + Invalid server certificate. +
+
+
PAN-241655
+
+
+ Fixed an issue where the firewall incorrectly categorized URLs as + phishing due to machine learning + analysis + MLAV + incorrectly marking the URLs as malicious. +
+
+
PAN-241536
+
+
+ Fixed an issue on Panorama where admin users with the Custom Panorama + Admin role were unable to add, edit, or delete route filters under + Routing Profiles +
+
+
PAN-241519
+
+
+ Fixed an issue where incorrect log filters were displayed under + unified logs. +
+
+
PAN-241295
+
+
+ Fixed an issue where Panorama pushed permitted IP address lists were + editable on the firewall. +
+
+
PAN-241044
+
+
+ Fixed an issue where traffic was denied by the interzone-default + policy rule when a Security policy rule with an FQDN destination was + configured. +
+
+
PAN-241004
+
+
+ Fixed an issue where DNS Proxy dropped client requests of the type + ns for a root domain. +
+
+
PAN-240990
+
+
+ Fixed an issue where + l3svc.py displayed incorrect + logs. +
+
+
PAN-240723
+
+
+ Fixed an issue where Threat logs were logged within a 5 second + interval instead of the exact detection time when the logging rate was + low. +
+
+
PAN-240225
+
+
+ Fixed an issue where authentication failed on web-based GlobalProtect + portal. +
+
+
PAN-239952
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where HA sync messages from the active firewall took + longer than expected to reach the passive firewall. +
+
+
PAN-239695
+
+
+ Fixed an issue where the firewall stopped responding due to an + internal server error when accessing certificates with the block + private key option enabled. +
+
+
PAN-239532
+
+
+ Fixed an issue where the firewall was unable to identify the URL + category in the session details. +
+
+
PAN-239409
+
+
+ Fixed an issue where the + lodash.js version installed on + the firewall was not accurately reflected in PanXML. +
+
+
PAN-239246
+
+
+ Fixed an issue where the CLI command + debug user-id dump hip-based-profile-database-entry + returned an incorrect value in the output for the + total size of hip reports. +
+
+
PAN-239201
+
+
+ Fixed an issue where partial commit or partial validation operations + failed for non-super user administrators with the error + <device-group-name> is invalid. meta data not found for dg + <device-group-name>. +
+
+
PAN-239165
+
+
+ Fixed an issue where adding an interface in a route filter resulted in + an OSPF LSA Type-5 packet check failure, which caused redistributed + routes to be removed. +
+
+
PAN-239143
+
+
+ Fixed an issue with accessing websites when URL filtering profiles + were configured with the + block-continue action and the server + used HTTP/2. +
+
+
PAN-239138
+
+
+ Fixed an issue where a decryption rule with the Log Successful TLS + handshakes option disabled still generated successful decryption logs. +
+
+
PAN-239036
+
+
+ Fixed an issue where the + configd + process stopped responding on Panorama due to an out-of-memory + condition. +
+
+
PAN-238813
+
+
+ Fixed an issue where the DNS proxy was unable to handle UDP DNS + replies with a length of over 512 bytes. +
+
+
PAN-238793
+
+
+ (Panorama virtual appliances in Microsoft Azure environments + only) Fixed an issue where a bootstrapped Panorama appliance did not + automatically retrieve the CDL license, which resulted in the firewall + not automatically sending logs to CDL. +
+
+
PAN-238741
+
+
+ Fixed an issue where, after a selective push of the configuration, a + parent device group object with multiple child device groups was not + shown in the device group's push scope. +
+
+
PAN-238303
+
+
+ (PA-5220 firewalls only) Fixed an issue where + multicast streaming did not recover when multicast traffic was + offloaded. +
+
+
PAN-238266
+
+
+ Fixed an issue where the default + lag-flow-key-type was different + between the dataplane and the forwarding engine. +
+
+
PAN-237582
+
+
+ Fixed an issue where logs were intermittently missing on the log + collector due to missing aliases for some indices. +
+
+
PAN-237109
+
+
+ Fixed an issue where the application page was not launched directly + after the login page when only one application was configured. +
+
+
PAN-236909
+
+
+ Fixed an issue where, when you committed the first configuration + change after booting up the firewall, the external dynamic list file + download failed until the list was refreshed. This occurred when the + configuration was pushed with a certificate profile. +
+
+
PAN-236830
+
+
+ Fixed an issue where traffic that was correctly detected on the + firewall as the threat category + DNS was detected on Panorama as the + threat category N/A. +
+
+
PAN-236574
+
+
+ Fixed an issue where User-ID traffic was incorrectly identified as SSL + application instead of + paloalto-userid-agent + application. +
+
+
PAN-236447
+
+
+ Fixed an issue where the firewall rebooted and the kernel log + displayed the following message: + + 0.000000] Linux version 4.18.0-240.1.1.27.pan.x86_64. +
+
+
PAN-236182
+
+
+ Fixed an issue where, when forward message processing received an + invalid payload with a message length of 0 in the buffer header, the + firewall rebooted unexpectedly. +
+
+
PAN-236059
+
+
+ Fixed an issue on firewalls in HA configuration where the IoT content + version was not synced from the active firewall to the passive + firewall. +
+
+
PAN-235808
+
+
+ (Panorama appliances in Log Collector mode only) Fixed an issue where an unnamed core file was generated after a + reboot. +
+
+
PAN-235529
+
+
+ Fixed an issue where the Active Directory IP-address-to-user mappings + were not updated on + Mappings & Tags on the Cloud + Identity Engine. +
+
+
PAN-235110
+
+
+ (PA-220 firewalls only) Fixed an issue where + the web interface did not load after an upgrade. +
+
+
PAN-234461
+
+
+ Fixed an issue where excess + distributord + process memory use caused processes to restart due to OOM conditions. +
+
+
PAN-234272
+
+
+ Fixed an issue where scheduled device group reports included data from + other device groups. +
+
+
PAN-234107
+
+
+ Fixed an issue where Smart Card authentication failed when the SAN + field contained additional details. +
+
+
PAN-234082
+
+
+ (Panorama virtual appliances only) Fixed an + issue where Saas reports were generated with a report period of 0 + days. +
+
+
PAN-233681
+
+
+ Fixed an issue where the + authd + process on Prisma Access firewalls stopped responding after receiving + the SIGUSR1 signal. +
+
+
PAN-232833
+
+
+ Fixed an issue where the following error message displayed for IoT + trial licenses: + IoT Security license is required for the feature to function. +
+
+
PAN-232792
+
+
+ Fixed an issue on the Panorama where the web interface did not display + the Scheduled Config Push page. +
+
+
PAN-232594
+
+
+ (Panorama managed CN-Series firewalls in HA configurations only) Fixed an issue where an error occurred while adding tags. +
+
+
PAN-232550
+
+
+ Fixed an issue where SNMPv3 authentication failed when using SHA-512 + Auth protocol. +
+
+
PAN-232263
+
+
+ (Panorama virtual appliances only) Fixed an + issue where multiple processes stopped responding due to a traffic + outage, which was caused by a corrupted content file. +
+
+
PAN-231065
+
+
+ Fixed an issue on Panorama where the CLI command + show applications list <Application-group/application + filters> device-group <name of device-group> + returned incomplete result. +
+
+
PAN-230934
+
+
+ Fixed an issue where HTTP/S, SSH, and PING were enabled on the AUX + port by default even when these administrative management services + were not enabled on the interface. +
+
+
PAN-230902
+
+
+ Fixed an issue on the Panorama web interface where you were unable to + configure L3 net-inspect rules for a template stack. +
+
+
PAN-230893
+
+
+ Added a CLI command to address an issue where system lock files + blocked authentication. +
+
+
PAN-230825
+
+
+ Fixed an issue where link flaps occurred on Panorama appliances in HA + configurations. +
+
+
PAN-228555
+
+
+ Fixed an issue where GlobalProtect logs returned no data when using + the filter + ( private_ip eq 0.0.0.0 ). +
+
+
PAN-227978
+
+
+ Fixed an issue where the web interface did not accurately list the + status of the port when NGFW clustering was enabled. +
+
+
PAN-226789
+
+
+ (VM-Series firewalls in Amazon Web Services (AWS) environments + only) Fixed an issue template values were missing in newly spun firewalls + in auto scale deployments without an explicit push with forced + template values from Panorama. +
+
+
PAN-226365
+
+
+ Fixed an issue with the output format of certificate issuer and + subject fields during certificate creation. +
+
+
PAN-226280
+
+
+ Fixed an issue where the + ConfigPushScheduler REST API + failed when the target device was a firewall with a non-default + management profile. +
+
+
PAN-226125
+
+
+ Fixed an issue where the + Management Interface Telnet Service + was disabled but the service was still allowed. +
+
+
PAN-225806
+
+
+ Fixed an issue where LACP packets did not reach the dataplane, which + caused the firewall to stop forwarding traffic. +
+
+
PAN-225228
+
+
+ Fixed an issue where filtering threat logs using any value under + THREAT ID/NAME displayed the error + Invalid term. +
+
+
PAN-224729
+
+
+ Fixed an issue where you were unable to create duplicate entries in + Advanced Routing AS path prepend the BGP filter route map. +
+
+
PAN-221096
+
+
+ Fixed an issue where IPSec transport mode failed when the firewall was + the initiator. +
+
+
PAN-218873
+
+
+ Fixed an issue where a HIP mask was reused when an existing IP address + user mapping was updated by a new IP address user mapping that had a + different username but the same IP address. +
+
+
PAN-215882
+
+
+ Fixed an issue where you were unable to connect to the GlobalProtect + gateway when the gateway was scaled up automatically. +
+
+
PAN-214430
+
+
+ Fixed an issue where some commands did not have executable + permissions. +
+
+
PAN-212197
+
+
+ Fixed an issue where you were able to create local administrator + usernames that contained only numbers. +
+
+
PAN-207972
+
+
+ Fixed an issue on the web interface where the BGP routing table did + not display advertised routes. +
+
+
PAN-202619
+
+
+ Fixed an issue where, when SPI values were different for static and + dynamic Satellite tunnel IP addresses during IPSec tunnel + renegotiation, traffic issues occurred between the satellite and the + gateway. +
+
+
PAN-197428
+
+
+ Fixed an issue where IKE negotiation with distinguished name + identification did not work. +
+
+
PAN-193285
+
+
+ Fixed an issue where the policy optimizer feature did not add entries + back to the mongodb database + after removing them during an upgrade or downgrade. +
+
+
PAN-192176
+
+
+ Fixed an issue where the management server access log file did not + rotate, which caused the root partition to become full and led to + system instability. +
+
+
PAN-164885
+
+
+ Fixed an issue on Panorama where + Commit and Push or + Push to Devices operations failed + when an external dynamic list was configured to check for updates + every 5 minutes due to the commit and external dynamic fetch processes + overlapping. +
+
+
PAN-76904
+
+
+ (PA-5410 firewalls only) Fixed an issue where + the management interface went down and an error message displayed in + the show interface management CLI + command output. +
+
diff --git a/reference/PAN-OS/addressed/11.1.8.html b/reference/PAN-OS/addressed/11.1.8.html new file mode 100644 index 0000000..af99333 --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.8.html @@ -0,0 +1,3580 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-284490
+
+
+ A fix was made to address + CVE-2025-2182. +
+
+
PAN-283493
+
+
+ Fixed an issue threat reports were empty when generated from Panorama, + but displayed correctly when generated from the firewall. +
+
+
PAN-282236
+
+
+ Fixed an issue where large IPv6 packets were reassembled incorrectly + on the firewall when the packets arrived fragmented over an IPv4 + tunnel. +
+
+
PAN-281540
+
+
+ Fixed an issue where the + logd + process repeatedly restarted when the SD-WAN site name was over 31 + characters and contained certain XML escape characters. +
+
+
PAN-280505
+
+
+ Fixed an issue where the web interface did not display a message to + commit prior changes before attempting a partial configuration load. +
+
+
PAN-280471
+
+
+ Fixed an issue where navigating + Panorama > Monitor > Logs was + slower than expected. +
+
+
PAN-280243
+
+
+ Fixed an issue where the firewall lost the pre-shared key + configuration assigned from a PSK variable when an unrelated device + group configuration was loaded. +
+
+
PAN-279983
+
+
+ (PA-1400 Series firewalls only) Fixed an issue + on the web interface where + Enable Bonjour Reflector was not + displayed (Network > Interfaces > Ethernet Interface). +
+
+
PAN-279746
+
+
+ Fixed an issue where SMTP packets were not sent out when the Client + Hello arrived at the firewall in multiple out-of-order segments and + the traffic was not subject to SSL decryption. +
+
+
PAN-279604
+
+
+ Fixed an issue where scheduled SaaS application usage reports were + generated incorrectly, and the login page was displayed instead of the + report content. +
+
+
PAN-279336
+
+
+ Fixed an issue where the CLI did not display a message to commit prior + changes before loading a partial configuration. +
+
+
PAN-279176
+
+
+ Fixed an issue where the configuration audit displayed inaccurate + information after partially loading the configuration via the CLI, + which caused the audit to flag the configuration as deleted or + changed. +
+
+
PAN-278684
+
+
+ (PA-445 firewalls only) Fixed an issue where + the firewall did not properly power cycle during a reboot. +
+
+
PAN-277751
+
+
+ Fixed an issue where a policy-based forwarding (PBF) rule with an + action of no-pbf and a service of + TCP-22 did not match traffic after upgrading to PAN-OS 11.1.5-h1. As a + result, traffic was matched by a lower rule with a service of + any and an action of + forward. +
+
+
PAN-277631
+
+
+ Fixed an issue where the + logrcvr + process discarded logs due to a full queue. +
+
+
PAN-277306
+
+
+ Fixed an issue where the XML API and REST API failed to run commands + with an error. +
+
+
PAN-276822
+
+
+ Fixed an issue where the packet buffer size increased significantly + when WildFire File Forwarding was continued after a threat detection + and then canceled. +
+
+
PAN-276795
+
+
+ Fixed an issue where the GlobalProtect client displayed an error + message when you clicked + Check Now and + Preferred Releases and + Base Releases were unchecked (Device > Software). +
+
+
PAN-276599
+
+
+ Fixed an issue where the password expiry prompt was not visible when + logging in via the web interface. +
+
+
PAN-276491
+
+
+ (Panorama virtual appliances only) Fixed an + issue where Panorama stopped responding when running reports. +
+
+
PAN-276352
+
+
+ Fixed an issue where multicast flows were dropped due to a missing + sysd + variable for maximum multicast routes. +
+
+
PAN-276062
+
+
+ Fixed an issue where importing a firewall with a large number of + address objects into Panorama did not work and remained at 99% + completion. +
+
+
PAN-275905
+
+
+ Fixed an issue where the Panorama web interface was slower than + expected and Elasticsearch CPU usage was high. +
+
+
PAN-275754
+
+
+ Added support for bootstrapping Panorama virtual appliances on ESXi. +
+
+
PAN-275718
+
+
+ Fixed an issue where Panorama stopped forwarding logs to a Syslog + server after upgrading to PAN-OS 11.1.5-h1. +
+
+
PAN-275653
+
+
+ Fixed an issue where the Log Collector service did not start on a new + Log Collector appliance added to a Log Collector group. As a result, + the new Log Collector appliance did not appear in the cluster and the + number of nodes in the cluster was incorrect. +
+
+
PAN-275077
+
+
+ Fixed an issue where DNS Security intermittently logs malicious domain + URLs as Alert instead of taking a Sinkhole action, even when + configured to Sinkhole malicious DNS domains. +
+
+
PAN-275032
+
+
+ (M-600 appliances only) Fixed an issue where + the Elasticsearch cluster certificate (CC) status displayed with a + past expiration date, which caused all shards to be unassigned. +
+
+
PAN-274791
+
+
+ Fixed an issue where the firewall might reboot when traffic matches + with certain Advanced features (such as Advanced Threat Prevention and + Advanced URL Filtering with properly configured URL + Filtering/Anti-Spyware/Vulnerability security profiles) and Shared + Pool Type 32 becomes depleted. +
+
+
PAN-274671
+
+
+ Fixed an issue where empty traffic + logdb folders were generated for + each day even when traffic logs were not received by the + logrcvr + process. +
+
+
PAN-274570
+
+
+ Fixed an issue where the + devsrvr + process restarted after a failed commit due to an invalid memory + access. +
+
+
PAN-274557
+
+
+ Fixed an issue on PA-5450 in FIPSCC mode where a firewall rebooted + into maintenance mode when it was manually rebooted from the web + interface. +
+
+
PAN-274292
+
+
+ (M-600 Appliances only) Fixed an issue where + the web interface was slow when logging in and filtering for policies + due to deep search operations taking longer than expected. +
+
+
PAN-274207
+
+
+ Fixed an issue where Global Search did not redirect correctly to + routing profiles when searching for their names. +
+
+
PAN-274146
+
+
+ Fixed an issue where the firewall rebooted continuously after + upgrading to PAN-OS 11.1.5-h1 when a tunnel session was established in + a Gateway Load Balancing (GWLB) scenario and no data packet was + associated with the packet. +
+
+
PAN-274038
+
+
+ Fixed an issue where you were unable to use the + s_encrypted field in custom reports + for the Panorama threat log database. +
+
+
PAN-273991
+
+
+ Fixed an issue where the transmit power for a cable that was used on + port 44 displayed as N/A. +
+
+
PAN-273963
+
+
+ Fixed an issue where GlobalProtect health information (HIP) did not + display the certificate key usage. +
+
+
PAN-273949
+
+
+ Fixed an issue where the firewall generated the following error + message in the + snmpd + logs: + pan_get_keystr_from_cryptod(pan_snmpinterface.c:181): Key + X2F1dGhfa2V5 import from cryptod failed. +
+
+
PAN-273727
+
+
+ Fixed an issue where the firewall skipped the DNS policy rule of a + domain external dynamic list (EDL) during an EDL refresh. +
+
+
PAN-273614
+
+
+ Fixed an issue where packets were dropped initially when a SYN cookie + with activation threshold 0 was enabled. +
+
+
PAN-273597
+
+
+ Fixed an issue where logs in the cloud database displayed in the + Not-Resolved category but not in the + local database. +
+
+
PAN-273589
+
+
+ Fixed an issue where firewalls configured with a VPN tunnel stopped + responding when a configuration update was applied. +
+
+
PAN-273453
+
+
+ Fixed an issue where restarting the firewall did not initiate an + autocommit job, which caused the firewall to stop responding and the + HA interface to go down. +
+
+
PAN-273277
+
+
+ Fixed an issue where GlobalProtect clients on macOS devices were + prompted to enter their username and password for Kerberos SSO + authentication. +
+
+
PAN-273153
+
+
+ Fixed an issue where the Panorama web interface was slower than + expected due to excessive polling of the + MonitorDirect.getTasks API by the + Task Manager. +
+
+
PAN-273019
+
+
+ Fixed an intermittent issue where SSL decryption failed. +
+
+
PAN-272998
+
+
+ Fixed an issue where commits from Panorama to VM-Series firewalls on + Microsoft Azure environments failed. +
+
+
PAN-272796
+
+
+ Fixed an issue where you were unable to export the GlobalProtect + client software version to the SCP server. +
+
+
PAN-272746
+
+
+ (PA-440 firewalls only) Fixed an issue where + the firewall entered an unstable state after committing changes or + onboarding to Panorama. +
+
+
PAN-272743
+
+
+ Fixed an issue where non-captive portal traffic was not visible under + Traffic Logs when the traffic was + denied by an authentication rule and the session was discarded. +
+
+
PAN-272726
+
+
+ Fixed an issue on the web interface where the + URL Filtering change category + feature did not work. +
+
+
PAN-272605
+
+
+ Fixed an issue where the firewall did not display VPC endpoints when + there was a large amount of VPC endpoints to interface mappings. +
+
+
PAN-272408
+
+
+ (PA-1420 firewalls only) Fixed an issue where + the firewall reported unsupported SFPs when PAN-SFPPLUS10GBASE-T SFPs + were used on ports Ethernet 1/21 and 1/22. +
+
+
PAN-272178
+
+
+ Fixed an issue where the firewall displayed packet buffers between 18 + and 19 even when there was little or no traffic. +
+
+
PAN-272172
+
+
+ Fixed an issue where + plugin_api_server could + experience a memory leak when using OpenConfig for telemetry. +
+
+
PAN-272171
+
+
+ Fixed an issue where the firewall dropped the AAAA DNS server response + and caused delays in traffic from Ubuntu or Linux clients when DNS + Security was enabled. +
+
+
PAN-272085
+
+
+ Fixed an issue where the firewall might crash and reboot when DoH is + enabled for DNS Security and multiple DoH transactions are sent in a + single HTTP/1 connection. +
+
+
PAN-271915
+
+
+ Fixed an issue where the push scope did not populate when attempting + to push a policy to a device group. +
+
+
PAN-271774
+
+
+ Fixed an issue where the firewall logs displayed the reason for data + filtering action as + FW Skipped: XXXX. +
+
+
PAN-271700
+
+
+ Fixed an issue where User-ID connections were lost after an HA + failover. +
+
+
PAN-271637
+
+
+ Fixed an issue where the firewall did not increase the metric of the + default route when redistributed into OSPF when the firewall was + configured as an NSSA ABR. +
+
+
PAN-271636
+
+
+ (PA-1400 and PA-3400 Series firewalls only) + Fixed an issue where the firewall displayed the error message + Failed to parse pbf policy when + you committed a configuration that included more than 8 Policy Based + Forwarding (PBF) rules with symmetric return enabled. +
+
+
PAN-271490
+
+
+ Fixed an issue on the firewall that caused the following error message + to be displayed: + frr_ns0: failed to stop child frr_ns0_ospf6d. +
+
+
PAN-271438
+
+
+ Fixed an issue where the firewall calculated available memory + incorrectly on CENTOS devices, which caused the firewall to display + high memory usage alerts even when sufficient memory was available. +
+
+
PAN-271436
+
+
+ A CLI counter was added to indicate a full suppression queue. +
+
+
PAN-271184
+
+
+ Fixed an issue where Device Telemetry failed due to an issue with the + encoding of characters in the log file path. +
+
+
PAN-271181
+
+
+ Fixed an issue where committing changes to Advanced Routing and + redistribution profiles failed while pushing the configuration from + SCM. +
+
+
PAN-271152
+
+
+ (7000-Series firewalls in HA configurations only) Fixed an issue where the firewall failed over into a non-functional + state, and the LFC LED was blinking on the passive firewall. +
+
+
PAN-270849
+
+
+ Fixed a memory leak issue related to the + configd + process that occurred when running consecutive commits for mulitple + days. +
+
+
PAN-270747
+
+
+ Fixed an issue where the + show system statistics application + CLI command failed. +
+
+
PAN-270744
+
+
+ Fixed an issue where API calls to Panorama failed with the error + Server error : Timed out while getting config lock. Please try + again. +
+
+
PAN-270651
+
+
+ Fixed an issue where the firewall didn't restart after applying an + air-gapped license if the firewall capacity was the same as the + license capacity. The additional character in subscription is tracked + fixed as IT issue. +
+
+
PAN-270569
+
+
+ Fixed an issue where the + userid + process stopped responding due to memory was being reset to NULL when + it was freed. +
+
+
PAN-270554
+
+
+ Fixed an issue where the GlobalProtect client (UWP) or metered hotspot + connections triggered TLS resumption fo GlobalProtect portal + authentication, which caused the portal authentication to fail with a + valid cert required error. +
+
+
PAN-270549
+
+
+ Fixed an issue where some TLS connections were not handled correctly, + which led to instability in the dataplane. +
+
+
PAN-270493
+
+
+ Fixed an issue where the + Low free buffer limit output was + not available. +
+
+
PAN-270248
+
+
+ Fixed an issue where the firewall failed to forward logs to a SNMP + trap server if the SNMP manager IP address was unable to be resolved. +
+
+
PAN-270193
+
+
+ Fixed an issue where the Panorama management server changed its + certificate authority (CA) unexpectedly, which caused managed + firewalls to disconnect. +
+
+
PAN-270068
+
+
+ Fixed an issue where the firewall attempted to connect to the AppID + cloud using gRPC even when App-ID Cloud Engine was disabled. +
+
+
PAN-269913
+
+
+ Fixed an issue threat reports were empty when generated from Panorama, + but displayed correctly when generated from the firewall. +
+
+
PAN-269716
+
+
+ Fixed an issue where half-closed TCP sessions did not refresh the + session timeout when continuously receiving data after setting the + cfg.session.tcp-no-refresh-fin-rst + option toTrue. +
+
+
PAN-269624
+
+
+ Fixed an issue where GlobalProtect clients failed to connect with the + error message + The device or feature requires a GlobalProtect subscription + license. +
+
+
PAN-269456
+
+
+ Fixed an issue where the firewall rebooted unexpectedly when + configuring the GlobalProtect portal and gateway from Panorama. +
+
+
PAN-269291
+
+
+ Fixed an issue where the scheduled report generation script did not + return debug information. +
+
+
PAN-269286
+
+
+ Fixed an issue where the firewall did not query for an AAAA record + when only IPv6 was enabled for the management interface. +
+
+
PAN-269264
+
+
+ Fixed an issue where the firewall did not send the client hello to the + server when the server hello message contained a certificate with a + common name of 0.0.0.0. +
+
+
PAN-269193
+
+
+ Fixed an issue where the firewall redirected the user to the first + application instead of the portal page with a list of applications + when multiple applications were configured for GlobalProtect + clientless VPN along with any user match. +
+
+
PAN-269191
+
+
+ (VM-Series firewalls only) Fixed an issue where + the aggressive clean-up threshold for disk space was set to 95% in + system monitor. +
+
+
PAN-269091
+
+
+ Fixed an issue where the + varrcvr + process stopped responding. +
+
+
PAN-269052
+
+
+ Fixed an issue where traffic was blocked by a URL filtering profile + even though the Security policy rule did not have a URL filtering + profile configured. +
+
+
PAN-269027
+
+
+ Fixed an issue related to external dynamic lists that caused commit + times on the firewall to be higher than expected. +
+
+
PAN-268909
+
+
+ Fixed an issue where IP address tags were removed from firewalls after + a management server or + useridd + process restart. This occurred when a Panorama serial-number based + configuration was used for User-ID redistribution. +
+
+
PAN-268800
+
+
+ Fixed an issue where a large number of logs caused the + logrcvr + process to stop responding. +
+
+
PAN-268708
+
+
+ Fixed an issue where PDF summary and email reports displayed IPv6 + addresses instead of IPv4 addresses. +
+
+
PAN-268707
+
+
+ Fixed an issue where the XML API call to clear rule hit count using + device group syntax failed with an error. +
+
+
PAN-268629
+
+
+ Fixed an issue where traffic did not match the correct security policy + when using an application-filter that references a cloud application. + This occurred when a high number of cloud applications were attached + with a custom tag. +
+
+
PAN-268606
+
+
+ Fixed an issue where GlobalProtect users with client certificates + received an authentication failure message without entering a password + and clicking connect or + login. +
+
+
PAN-268597
+
+
+ Fixed an issue where the firewall displayed 0 bytes received for + GlobalProtect SSL sessions in the traffic logs. +
+
+
PAN-268569
+
+
+ Fixed an issue where the web interface was slower than expected when + logging in and filtering for policies. +
+
+
PAN-268489
+
+
Fixed a Threat log PCAP ID overwrapping issue.
+
+
PAN-268425
+
+
+ Fixed an issue where the + execute show transceiver-detail all + XML API command returned an incorrect value for the low temperature + alarm threshold. +
+
+
PAN-268279
+
+
+ Fixed an issue where autocommits failed if the management IPv6 gateway + was the same as the dataplane interface IP address. +
+
+
PAN-268276
+
+
+ Fixed an issue where GlobalProtect clients intermittently failed to + connect to the gateway with the error message + could not connect to gateway. +
+
+
PAN-268168
+
+
+ Fixed an issue where uploading files that were 5GB or larger to Google + Drive or Youtube failed when a decryption policy rule for http2 was + enabled +
+
+
PAN-268127
+
+
+ Fixed an issue where tagging devices in Panorama did not work as + expected. +
+
+
PAN-268118
+
+
+ Fixed an issue on firewalls in active/passive HA configurations where, + after a failover, irrelevant routing FIB entries were seen in the + routing table on the newly active firewall. +
+
+
PAN-267912
+
+
+ Fixed an issue on the Panorama web interface where + Application and + Category was not able to be selected + under Test Policy Match. +
+
+
PAN-267660
+
+
+ Fixed an issue where UserID stopped working when the + show object registered user CLI + command was used with start-point and limit options. +
+
+
PAN-267650
+
+
+ Fixed an issue where the firewall did not detect the eth1/1 and eth1/2 + interfaces when you created a firewall on an ESXi 8 server. +
+
+
PAN-267614
+
+
+ Fixed an issue where the Panorama web interface was slower than + expected due to high CPU utilization on the + mongodb + process. +
+
+
PAN-267580
+
+
+ Fixed an issue where an External Dynamic List (EDL) IP address in an + unsupported format was recognized as valid on the firewall. +
+
+
PAN-267518
+
+
+ Fixed an issue where WildFire submission logs incorrectly reported + allowed malicious samples even when they were blocked by threat + prevention profiles. +
+
+
PAN-267426
+
+
+ (Firewalls in HA configuration only) Fixed an + issue where the + Network pre-negotiation enabled page + did not display on the firewall dashboard. +
+
+
PAN-267381
+
+
+ Fixed an issue where the firewall failed to upload a macOSX file if + the file had a MIME boundary. +
+
+
PAN-267235
+
+
+ Fixed an issue where the firewall did not send User-ID redistribution + messages to Panorama when the firewall had multiple virtual systems + configured and one of the virtual systems had a display name that was + the same as the existing vsys name. +
+
+
PAN-267128
+
+
+ Fixed an issue where the firewall dropped packets if the log rate + exceeded the configured maximum log rate. +
+
+
PAN-267045
+
+
+ Fixed an issue on the firewall where ICMP ping loss occurred after + installing a Network Processing Card (NPC) in slot 7. +
+
+
PAN-267001
+
+
+ Fixed an issue where multicast streams were unstable with ECMP and + dropped every 30 seconds. +
+
+
PAN-266905
+
+
+ Fixed an issue where sessions ended with the message + decrypt error in the logs for + traffic that matched a + no-decrypt policy. +
+
+
PAN-266800
+
+
+ (PA-800 firewalls in HA configurations only) + Fixed an issue where the Link LEDs for ethernet1/9 to ethernet1/12 did + not turn off after a failover. +
+
+
PAN-266704
+
+
+ Fixed an issue where filtering BGP routes by peer name in Advanced + Routing Engine (ARE) did not display the correct routes. +
+
+
PAN-266698
+
+
+ Fixed an issue where an email was able to be transferred to the + destination MTA even when the firewall detected a suspicious file with + a reset-bot action when it was encrypted by STARTTLS. +
+
+
PAN-266695
+
+
+ Fixed an issue on Panorama where a cyclic nested address group + configuration caused the + configd + process to stop responding after a commit. +
+
+
PAN-266688
+
+
+ Fixed an issue on the firewall where traffic matched a custom + signature even if the custom signature was removed from the + configuration. +
+
+
PAN-266653
+
+
+ Fixed an issue where unexpected path monitor failures caused the + firewall to stop responding. +
+
+
PAN-266574
+
+
+ Fixed an issue where users were unable connect to the portal due to + Certificate Revocation List (CRL) checks due to the downloaded CRL + file being expired, which caused the CRL cache to be bypassed. +
+
+
PAN-266559
+
+
+ Fixed an issue where partial commits failed when objects that were + referenced in a high number of Security policy rules were renamed. In + such cases below error would be seen in configd logs, "Limit printing + dirty xpaths in journal at count 3000" +
+
+ To overcome the 3000 xpaths change limit, use the command to set the + limit to a higher value and restart configd daemon. " debug + management-server max-ref-xpaths " +
+
+
PAN-266462
+
+
+ Fixed an issue where selective pushes did not work as expected when + the device group was renamed by a different admin user. +
+
+
PAN-266427
+
+
+ Fixed an issue on the firewall where, when a high number of SD-WAN + branch sites or interfaces were not connected, SD-WAN processes and + tund + processes stopped responding due to a high probing rate. +
+
+
PAN-266391
+
+
+ Fixed an issue where the number of hints values were not updated even + when there were no hint files on the system. +
+
+
PAN-266354
+
+
+ Fixed an issue where Hybrid-SWG explicit proxy connections failed when + the number of destination domains exceeded 1024. +
+
+
PAN-266312
+
+
+ Fixed an issue where BFD sessions took longer than expected to + establish after an HA failover due to BGP. +
+
+
PAN-266279
+
+
+ Fixed an issue on Panorama where the default version of IKE gateway + was not set to IKEv2 only mode, which caused VPN establishment issues + if the firewall recognized a new configuration as IKEv1. +
+
+
PAN-266116
+
+
+ Fixed an issue where URLs did not work due to certificate revocation + list (CRL) requests failing. +
+
+
PAN-265931
+
+
+ Added debug functionality in the + packet-diag + log to address an issue regarding policy rule matching. +
+
+
PAN-265926
+
+
+ (PA-3400 Series firewalls only) Fixed an issue + where the + all_task + process stopped responding, which caused the firewall to reboot. +
+
+
PAN-265916
+
+
+ Fixed an issue where double-clicking the login button returned the + error message + Login session expired. +
+
+
PAN-265900
+
+
+ Fixed an issue where the firewall stopped responding due to a + tund + process or SD-WAN process restart. +
+
+
PAN-265791
+
+
+ Fixed an issue where the + all_task process stopped + responding, which caused the dataplane to go down. +
+
+
PAN-265686
+
+
+ Fixed an issue where the GlobalProtect portal logged passwords in + cleartext. +
+
+
PAN-265434
+
+
+ Fixed an issue where the flow process restarted with the error message + SIGABRT __GI_raise __GI_abort __libc_message malloc_printer. +
+
+
PAN-265014
+
+
+ Fixed an issue where changes made to device groups with the same + prefix name were not visible in the commit scope. +
+
+
PAN-264912
+
+
+ Fixed an issue where the firewall did not shut down completely. +
+
+
PAN-264866
+
+
+ Fixed an issue on Panorama where you were unable to change the order + of traffic steering rules. +
+
+
PAN-264845
+
+
+ Fixed an issue where the Log Forwarding for Security Services feature + did not correctly filter policy rules with log forwarding profiles. +
+
+
PAN-264570
+
+
+ Fixed an issue where the maximum session limit for a vsys was + 4,194,290. +
+
+
PAN-264538
+
+
+ (VM-Series firewalls only) Fixed an issue where + the + all_task + process stopped responding and a reboot was required. +
+
+
PAN-264477
+
+
+ Fixed an issue where the firewall did not start Elasticsearch after a + commit if Elasticsearch was not previously enabled and started. +
+
+
PAN-264423
+
+
+ Fixed an issue where the firewall sent a 503 response when a client + connected to a web server when the firewall was configured as a web + proxy and authentication bypass for Kerberos was enabled. +
+
+
PAN-264289
+
+
+ Fixed an issue where the CLI and XML API values for the show system + environment command did not match. +
+
+
PAN-264246
+
+
+ Fixed an issue where the Authentication Portal did not work properly + with session cookies when the request to the portal contained the + header Sec-Fetch-Site=cross-site. +
+
+
PAN-264169
+
+
+ (PA-5400 Series firewalls only) Fixed an issue + where the firewall sent correlated event logs to the syslog server + using the management interface instead of the log interface. +
+
+
PAN-264053
+
+
+ Fixed an issue where the firewall stopped responding after the + all_task + process stopped responding. +
+
+
PAN-263749
+
+
+ Fixed an issue where disk space that was used by file descriptors was + not freed, which caused the root partition to become full and Panorama + to be inaccessible. +
+
+
PAN-263674
+
+
+ (VM-Series firewalls in HA configurations only) + Fixed an issue where the firewall rebooted due to multiple HA + failovers. +
+
+
PAN-263654
+
+
+ Fixed an issue where multiple DNS responses with different CNAME + values caused evasion false positive alerts. +
+
+
PAN-263544
+
+
+ Fixed an issue where management plane CPU usage increased after + upgrading when there was a full-mesh User-ID redistribution + configuration between multiple firewalls. +
+
+
PAN-263291
+
+
+ Fixed an issue where Microsoft Outlook did not work as expected when + the GlobalProtect clientless VPN was configured. +
+
+
PAN-263086
+
+
+ (PA-455 firewalls in HA configurations only) + Fixed an issue where the HA LED light on the front panel did not turn + on even when HA was enabled. +
+
+
PAN-263063
+
+
+ Enhanced debugging capability when the control network to DP0 was not + reliable when the J2C port was down. +
+
+
PAN-262819
+
+
+ (PA-3410, PA-3420, and PA-3430 firewalls only) + Fixed an issue where the maximum supported number of zones was 200. +
+
+
PAN-262782
+
+
+ Fixed an issue on the firewall where + cfg.developer.tasks had a default + configuration of True, which + capped dataplane CPU performance at 50% in production. +
+
+
PAN-262729
+
+
+ (Panorama appliances only) Fixed an issue where + the + configd + process experienced continuous high CPU utilization and repeatedly + restarted. +
+
+
PAN-262375
+
+
+ (Firewalls in active/active HA configurations only) Fixed an issue where non-tunneled internal GlobalProtect gateway + client information was not synced between firewall peers when using a + floating IP address. +
+
+
PAN-262373
+
+
+ Fixed an issue where the error message + Failed to reload config files + displayed in the system logs even when device telemetry was not + enabled. +
+
+
PAN-262372
+
+
+ Fixed an issue where the firewall generated the error message + Successfully generating a new set of config files + in the system logs even when device telemetry was not enabled. +
+
+
PAN-262278
+
+
+ Fixed an issue where the service route setting for HTTP was not + applied when the source interface IP address was set via an address + object, which caused HTTP traffic to be sent from the management + interface. +
+
+
PAN-262063
+
+
+ Fixed an issue where the firewall did not display the converted + configurations before a commit and reboot, and the commit failed when + attempting to migrate from MS to FRR mode. +
+
+
PAN-262040
+
+
+ Fixed an issue where the XML API key length exceeded the buffer size + when the API key lifetime was changed from the default value. +
+
+
PAN-261999
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where enabling flow basic on firewalls caused ARP + entries to be removed on both firewalls. +
+
+
PAN-261998
+
+
+ Fixed an issue where the firewall configuration process restarted + during an External Dynamic List refresh or a commit and push + operation. +
+
+
PAN-261997
+
+
+ Fixed an issue where the firewall displayed incorrect statistics for + mac_transmit_err and send_deffered on PA-440 appliances running PAN-OS + 10.1.9-h3. +
+
+
PAN-261936
+
+
+ Fixed an issue where WildFire submission logs were not displayed when + filtered by Sender Address. +
+
+
PAN-261825
+
+
+ Fixed an issue where traffic was dropped when Data Loss Prevention or + Advanced URL Filtering were enabled. This occurred when the payload + size was greater than 3.5 KB. +
+
+
PAN-261824
+
+
+ Fixed an issue where frequent + brdagent + errors occurred. +
+
+
PAN-261739
+
+
+ (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the firewall displayed 0 for the physical port + counters read from MAC. +
+
+
PAN-261677
+
+
+ Fixed an issue where multiple + smartctl + processes entered a d state due + to failure to read from the kernel partition, which resulted in high + CPU and management impact. +
+
+
PAN-261602
+
+
+ Fixed an issue where GlobalProtect Decryption logs were not forwarded + to Panorama. +
+
+
PAN-261597
+
+
+ Fixed an issue where the + all_pktproc + process stopped responding, which caused the firewall to become + unavailable. +
+
+
PAN-261570
+
+
+ (Firewalls in active/active HA configurations only) Fixed an issue where packet loss occurred when dataport was used + for HA3 for asymmetrically routed traffic during commits and a virtual + wire was configured . +
+
+
PAN-261429
+
+
+ Fixed an issue where the + show auth radius-require-msg-authentic + command CLI displayed no output. +
+
+
PAN-261390
+
+
+ Fixed an issue that caused the Panorama web interface to be slower + than expected due to disabling completion-cache by default. +
+
+
PAN-261312
+
+
+ Fixed an issue where a commit for a policy and configuration dump + overlapped, which resulted in a null pointer exception. +
+
+
PAN-261182
+
+
+ Fixed an issue where the firewall dropped a retransmitted SYN packet + when using the TCP Fast Open option. +
+
+
PAN-261074
+
+
+ Fixed an issue where the firewall delayed video file transfers over + SMB when Exclude Video Traffic from + the Tunnel feature was enabled and no applications were added to the + list. +
+
+
PAN-260879
+
+
+ Fixed an issue where the Panorama port 28270 did not adhere to the + restricted TLS version and ciphers set in the + Secure Communication Settings. +
+
+
PAN-260752
+
+
+ Fixed an issue where the firewall did not support TLSv1.3 in the + Clientless VPN, which caused the portal page to not load. +
+
+
PAN-260720
+
+
+ Fixed an issue where the + dsdc + process stopped responding after receiving an unexpected API return + value. +
+
+
PAN-260700
+
+
+ Fixed an issue where the firewall was unable to load application + metadata from the chunk files. This occurred when the application + metadata entry was larger than the buffer used to read it, which + resulted in an incomplete entry that caused commit failures. +
+
+
PAN-260564
+
+
+ Fixed an issue on firewalls in HA configurations where a network loop + was detected by switches after suspending HA on the active firewall. +
+
+
PAN-260358
+
+
+ Fixed an issue where the firewall did not include the NAS-ID and + NAS-IP attributes in the RADIUS Access-Request message when using + PEAP-MSCHAPv2 authentication. +
+
+
PAN-260300
+
+
+ (PA-5410, PA-5420, PA-5430, PA-5440 and PA-5445 firewalls only) Fixed an issue related to the + all_pktproc + process where DPC slot 3 stopped responding. +
+
+
PAN-260279
+
+
+ Fixed an issue where selective push operations failed with the error + message: + Failed to generate selective push configuration. Schema validation + failed. Please try a full push. +
+
+
PAN-260229
+
+
+ Fixed an issue where HA path monitoring using VWire did not work as + expected after a reboot. +
+
+
PAN-260186
+
+
+ Fixed an issue where Panorama pushed content to devices that did not + have a Threat Prevention license. +
+
+
PAN-260113
+
+
+ Fixed an issue where the web interface stopped responding when + configuring the GlobalProtect gateway when the language was set to + Japanese. +
+
+
PAN-260059
+
+
+ Fixed an issue where + Device Telemetry Regions did not + show up with the latest content due to content files not being parsed + for the region list when Telemetry was turned off. +
+
+
PAN-260003
+
+
+ Fixed an issue where commits failed when you set + Use Management interface for all and + MGMT was configured for + Data Services. +
+
+
PAN-259870
+
+
+ (PA-7000b firewalls only) Fixed an issue where + Luna Network Hardware Security Modules (HSM) did not work after an + upgrade or downgrade. +
+
+
PAN-259865
+
+
+ (VM-Series firewalls across all public and private clouds) Fixed an issue where the firewall experienced high dataplane CPU + usage when SSL Decryption was enabled. +
+
+
PAN-259767
+
+
+ Fixed an issue where GlobalProtect users were unable to connect when + the option + Block sessions if the certificate was not issued to the + authenticating device + was enabled in the certificate profile. +
+
+
PAN-259343
+
+
+ Fixed an issue on the Panorama web interface where the + Configuration tab did not accurately + display changes made to URL filtering profiles. +
+
+
PAN-259140
+
+
+ Fixed an issue where the + request wildfire registration channel public + API command failed with the error message + Method not found. +
+
+
PAN-259091
+
+
+ Fixed an issue where the CLI command + show user ip-user-mapping-mp all + displayed the total timeout value instead of the current timeout value + when the + set cli op-command-xml-output on + CLI command was used. +
+
+
PAN-258912
+
+
+ (PA-7000b firewalls only) Fixed an issue where + the firewall web interface displayed an incorrect HSM client version + when the client was upgraded to version 7.2.0.220. +
+
+
PAN-258743
+
+
+ Fixed an issue where, when you attempted to select a redistribution + profile when creating a BGP Redistribute policy rule, the firewall + displayed an empty dropdown. +
+
+
PAN-258680
+
+
+ Fixed an issue on Panorama where, when you removed Security profile + groups from a Security policy rule via the CLI and committed the + change, the Security policy rule was deleted. +
+
+
PAN-258570
+
+
+ Fixed an issue where the firewall might reboot unexpectedly due to the + varrcvr + process progressively using more memory when WildFire file forwarding + is handling PE files. +
+
+
PAN-257960
+
+
+ Fixed an issue where ICD's virtual memory continuously increased due + to an increase in unknown IP addresses, which resulted in high + management plane CPU utilization. +
+
+
PAN-257594
+
+
+ Added support for export and import of SC3 CA certificates on Panorama + appliances during RMA. +
+
+
PAN-257515
+
+
+ Fixed an issue where Possible Domain Fronting Detection for HTTP/2 + generated false positives. With this change, domain fronting is + limited to HTTP/1. +
+
+
PAN-257355
+
+
+ Fixed an issue where a false positive HTTP/TLS evasion alert was + generated when the domain had DNS load balance. +
+
+
PAN-257183
+
+
+ Fixed an issue where the firewall dropped DNS traffic when using DNS + Security. +
+
+
PAN-257070
+
+
+ Fixed an issue where querying URL filtering logs with the filter + (url_category_list contains 'artificial-intelligence' ) displayed both + the artificial-intelligence and the shopping categories. +
+
+
PAN-256904
+
+
+ Fixed an issue where the firewall inconsistently blocked URLs due to + intermittent URL category misidentification. +
+
+
PAN-256867
+
+
+ Fixed an issue where the + logrcvr + process stopped responding while processing session logs for + forwarding to the LFC. +
+
+
PAN-256670
+
+
+ Fixed an issue where scheduled email reports were sent without PDF + attachments if the firewall was in FIPS-CC mode. +
+
+
PAN-256560
+
+
+ Fixed an issue where exporting a + Custom Report to CSV format did not + display the full report if it contained non-ASCII characters. +
+
+
PAN-256138
+
+
+ (VM-Series firewalls only) Fixed an issue where + firewalls with a DNS server IP address received by DHCP from Amazon + Web Services (AWS) had a delay in resolving FQDNs after a reboot. +
+
+
PAN-255759
+
+
+ Fixed an issue where the firewall was unable to match HIP data with + the correct anti-malware object for Windows Defender. +
+
+
PAN-255619
+
+
+ Fixed an intermittent issue where file downloads from websites failed + when decrypting HTTP/2 traffic. +
+
+
PAN-255611
+
+
+ Fixed an issue on the firewall where newly added routes were not + automatically sorted based on subnets when added to a redistribution + profile. +
+
+
PAN-255441
+
+
+ Fixed an issue where BGP-ARE routes were not advertised due to a peer + route map filter. +
+
+
PAN-255294
+
+
+ (PA-3410 firewalls only) Fixed an issue with an + incorrectly open port. +
+
+
PAN-255190
+
+
+ Fixed an issue where the TCP timeout value was reflected incorrectly + when using application override for a custom application in TAP mode. +
+
+
PAN-255020
+
+
+ Fixed an issue where the Panorama web interface did not display the + push scope data for custom admin users when performing a partial + commit and push. +
+
+
PAN-254293
+
+
+ Fixed an issue where an explicit proxy caused intermittent SSL + handshake failures to SAP applications accessing public URLs. +
+
+
PAN-253921
+
+
+ Fixed an issue where the firewall displayed the following error + message: + critical userid registe 0 fail to integrate the update of + registered ip addresses since 2 seconds ago; critical system log + alerts observed. +
+
+
PAN-252978
+
+
+ (PA-3200 Series firewalls only) Fixed an issue + where interfaces running at 10 Gbps did not display the speed and + duplex information in the CLI or displayed only as + auto. +
+
+
PAN-252336
+
+
+ Fixed an issue where newly added devices or existing deleted devices + on the primary Panorama appliance were not updated on the secondary + Panorama appliance if the secondary Panorama appliance experienced an + HA sync commit failure. +
+
+
PAN-251724
+
+
+ Fixed an issue where users matched incorrect Security policy rules + with a HIP profile. +
+
+
PAN-251533
+
+
+ (PA-450 firewalls only) Fixed an issue on the + web interface where the DHCPv6 client was not available for VLAN + interfaces. +
+
+
PAN-251442
+
+
+ Fixed an issue where the firewall rebooted into maintenance mode if + the authentication process restarted repeatedly. +
+
+
PAN-250928
+
+
+ (PA-5450 firewalls in active/active HA configurations only) Fixed an issue where firewall traffic was silently dropped when + sent to the peer owner. +
+
+
PAN-250048
+
+
+ Fixed an issue where applications did not load via the Clientless VPN + portal when the portal was hosted on an L3 VLAN interface. +
+
+
PAN-249748
+
+
+ Fixed an issue where, when a dynamic address group with more than + 500,000 addresses was created, the firewall displayed the error + message + pan_cfg_addresses_from_xmlhash failed. +
+
+
PAN-247141
+
+
+ Fixed an issue where DNS traffic did not match the intended SD-WAN + policy rule when NAT was enabled. +
+
+
PAN-245683
+
+
+ Fixed an issue where committing a configuration change on a Panorama + managed firewall caused a short outage for GlobalProtect clients. +
+
+
PAN-243283
+
+
+ (PA-3400 Series firewalls only) Fixed an issue + where the firewall had a lower maximum number of Security profiles + than expected. +
+
+
PAN-242602
+
+
+ Fixed an issue where GlobalProtect clients experienced slow SMB-V3 + download throughput when passing through a Prisma IPSec tunnel and the + firewall and the SMB-V3 session owner dataplane was the same as the + IPSec-ESP tunnel on the multi-dataplane firewall. +
+
+
PAN-241953
+
+
+ Fixed an issue where the firewall did not have a heartbeat mechanism + for the + authd + process, which caused the firewall to become unresponsive if the + authd + process stopped responding. +
+
+
PAN-241474
+
+
+ (PA-5200 Series firewalls only) Fixed an issue + where the firewall did not increment the flow_parse_ip_cksm counter + when traffic with an IP address checksum error was received. +
+
+
PAN-240144
+
+
+ Fixed an issue where a multi-vsys firewall failed to authenticate to + GlobalProtect with a new group that had the same name (suffixed or + prefixed) as an existing group. +
+
+
PAN-237294
+
+
+ Fixed an issue where the interface rate counter intermittently went to + zero frequently. +
+
+
PAN-237106
+
+
+ Fixed an issue where LSVPN satellite certificates were generated with + serial numbers with over than 40 hex characters, which led to issues + with revoking or deleting the certificates. +
+
+
PAN-234993
+
+
+ Fixed an issue where CPU base gateway auto-scaling failed, which + caused performance issues. +
+
+
PAN-234411
+
+
+ Fixed an issue where the + authd + process stopped responding. +
+
+
PAN-233868
+
+
+ Fixed an issue where the firewall took an incorrect action for + overlapping custom and edl-url-categories in a policy rule. +
+
+
PAN-226184
+
+
+ Fixed an issue where push operations from Panorama were slow due to + the + rasmgr + process taking longer than expected. +
+
diff --git a/reference/PAN-OS/addressed/11.1.9.html b/reference/PAN-OS/addressed/11.1.9.html new file mode 100644 index 0000000..ac6f6ad --- /dev/null +++ b/reference/PAN-OS/addressed/11.1.9.html @@ -0,0 +1,945 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
Issue ID
+
+
Description
+
+
PAN-290996
+
+ This issue is now resolved. See PAN-OS 11.1.10-h1 Addressed Issues +
+
+
+ When performing an SNMP walk, the Connections Per Second (CPS) + counters incorrectly return a value of 0 for each virtual system + (VSYS), despite the firewall actively processing connections. +
+
+
PAN-286255
+
+
+ Fixed an issue where, when the firewall received an unexpected + termination request for SSL sessions, the dataplane experienced a slow + buffer resource leak. +
+
+
PAN-285941
+
+
+ Fixed an issue where high memory consumption occurred on the + logrcvr + process. +
+
+
PAN-284073
+
+
+ Fixed an issue on the firewall that caused commits to fail and the web + interface to become inaccessible. +
+
+
PAN-283954
+
+
+ Fixed an issue where the + configd + process stopped responding due to a circular reference between address + groups. +
+
+
PAN-283168
+
+
+ Fixed an issue related to syslog forwarding that caused the + logrcvr + process stopped responding. +
+
+
PAN-282697
+
+
+ Fixed an issue where traffic was delayed significantly when it used + No Authentication Explicit Proxy and + matched a decryption policy rule. +
+
+
PAN-282454
+
+
+ Fixed an issue where, when you added the + Virtual System Name column under + Unified Logs, the column did not + remain visible in the table if you closed and re-opened the tab. +
+
+
PAN-282391
+
+
+ Fixed an issue on Panorama where a memory leak occurred after cloning + a template, resulting in an increase in memory use, which caused OOM + errors. +
+
+
PAN-282359
+
+
+ Fixed an issue where the Panorama web interface was slower than + expected. +
+
+
PAN-282206
+
+
+ Fixed an issue where configuring Secure Web Gateway (SWG) in + no-auth mode led to latency when no + decryption policy rules or + No-decrypt policy rules were + present. +
+
+
PAN-282069
+
+
+ Fixed an issue on Panorama where Security policy rules were removed + from device groups when you cloned or edited Security policy rules + that used more than 63 characters. +
+
+
PAN-281885
+
+
+ Fixed an issue where, when exporting and importing CSV files, the hash + values of pre-shared key variables set at template and template stack + levels changed inconsistently, which resulted in both variables + displaying the same hash value. +
+
+
PAN-281882
+
+
+ Fixed an issue where OSPF was redistributing connected routes beyond + the intended loopback IP. +
+
+
PAN-281649
+
+
+ Fixed an issue where the index size limit was incorrectly calculated + and indices rolled over earlier than expected, which resulted in high + memory and OOM errors. +
+
+
PAN-281269
+
+
+ (PA-5220, PA-5250, and PA-5420 firewalls) Fixed + an issue where the firewall management server memory usage + continuously increased. +
+
+
PAN-280942
+
+
+ Fixed an issue where the + logrcvr + process stopped responding. +
+
+
PAN-280700
+
+
+ Fixed an Issue where commits failed with the error + invalid IPv6 x:x - must be global/link-local unicast + when the management IPv6 address had a specific value. +
+
+
PAN-280477
+
+
+ Fixed an issue on the web interface were you were unable to scroll up + or down to view source zones in a NAT policy rule. +
+
+
PAN-279691
+
+
+ (Firewalls in active/passive HA configurations only) Fixed an issue where the firewall didn't synchronize IPSec SAs + (security associations) to the passive firewall if the tunnel was not + initially established by the active firewall. +
+
+
PAN-279647
+
+
+ Fixed an issue where threat names were displayed differently on the + web interface and the exported CSV file. +
+
+
PAN-279621
+
+
+ Fixed an issue where processes stopped responding when HTTPS Forward + traffic was run. +
+
+
PAN-279400
+
+
+ Fixed an issue where, when + Restrict Certificate Extensions was + enabled on decryption profiles, the basic constraints extension was + overwritten incorrectly. +
+
+
PAN-279209
+
+
+ Fixed an issue where changes made to the management interface + permitted IP address list in a global template were not pushed to the + template stack or firewalls. +
+
+
PAN-279195
+
+
+ Fixed an issue on Panorama where + Device Health displayed the device + memory as 0%. +
+
+
PAN-279065
+
+
+ Fixed an issue where the firewall sent logs with + connection succeeded to the syslog + server every time a connection was established, which resulted in + excessive logs. +
+
+
PAN-278190
+
+
+ Fixed an issue on Panorama where a scheduled report with SLS data had + an invalid translated-query. +
+
+
PAN-277755
+
+
+ Fixed an issue that caused the + request system private-data-reset + CLI command to fail. +
+
+
PAN-277417
+
+
+ Fixed an memory leak issue related to TLS inbound decryption. +
+
+
PAN-277018
+
+
+ Fixed an issue where FTP data connections did not work for EPRT with + Source IP + Port translation enabled on the firewall. +
+
+
PAN-276862
+
+
+ Fixed an issue on Panorama where the + logd + process stopped responding unexpectedly. +
+
+
PAN-276616
+
+
+ Fixed an issue on the firewall where half-duplex settings on Ethernet + was not visible. +
+
+
PAN-276412
+
+
+ Fixed an issue where you were unable to download XML files from + Panorama > Summary > Backups. +
+
+
PAN-274907
+
+
+ Fixed an issue on Panorama where + Config Audit Commit Date displayed + the timestamp of the configuration edit instead of the commit time. +
+
+
PAN-274750
+
+
+ Fixed an issue where the detailed log view in Panorama did not display + all packet details for traffic logs received from the cloud. +
+
+
PAN-274726
+
+
+ Fixed an issue where Wildfire signature generation was enabled on all + nodes in a cluster instead of only the active node. +
+
+
PAN-274569
+
+
+ Fixed an issue where the QSPF transceiver interface displayed an + incorrect range figure on the temperature alarm. +
+
+
PAN-274314
+
+
+ (PA-1400 Series firewalls, PA-3400 Series firewalls, and PA-5400 + Series firewalls only) Fixed an issue where, when the + pan_task + process restarted, control plane packets were dropped, which could + impact LACP and pings to host interfaces. +
+
+
PAN-273870
+
+
+ Fixed an issue on the firewall where you were unable to local changes + that were made via the web interface. +
+
+
PAN-273422
+
+
+ Fixed an issue where traffic failed when Inline cloud analysis + (Advanced Threat Prevention) was enabled in the Anti-Spyware profile + with the action set to anything other than + allow or + alert and the maximum latency + condition was reached. +
+
+
PAN-273141
+
+
+ Fixed an issue where GlobalProtect clients experienced slow file + transfer download throughput when passing through an IPSec tunnel. +
+
+
PAN-271701
+
+
+ Fixed an issue where Advanced Services, App-ID Cloud Engine (ACE), and + Enhanced Application Log stopped working due to incorrect memory usage + accounting, which caused memory usage to remain at 99% after an + extended period of time. +
+
+
PAN-271498
+
+
+ (PA-7000 Series firewalls, PA-5200 firewalls, and PA-5400f firewalls + in FIPS mode only) Fixed an issue where decrypted traffic repeatedly failed and + frequent reboots were required. +
+
+
PAN-271273
+
+
+ Fixed an issue where dynamic update downloads failed when + IPv6 firewalling was enabled on the + firewall and both IPv4 and IPv6 were configured on the management + interface. +
+
+
PAN-271175
+
+
+ Fixed an issue where the + all_task + process stopped responding with a SIGABRT. +
+
+
PAN-271151
+
+
+ Fixed an issue where the GlobalProtect client did not automatically + initiate a Kerberos SSO connection after logging in to Windows. +
+
+
PAN-270192
+
+
+ Fixed an issue where Panorama did not display the management IP + address of devices onboard via ZTP. +
+
+
PAN-269404
+
+
+ Fixed an issue where the firewall did not reset the maximum latency + timer for hold mode. +
+
+
PAN-268705
+
+
+ Fixed an intermittent issue where the firewall failed to process FTP + traffic after upgrading to PAN-OS 10.1.14. +
+
+
PAN-268614
+
+
+ Fixed an issue on the web interface where, when all rules were + highlighted when a read-only admin user clicked the + Highlight Unused Rules checkbox. +
+
+
PAN-267936
+
+
+ Fixed an issue where commits failed with a validation error when you + changed the encryption level and re-encryption option on a Panorama + managed firewall. +
+
+
PAN-267444
+
+
+ Fixed an issue where large file downloads or uploads failed or + remained in an incomplete state when using DLP HTTP2 mirror mode. +
+
+
PAN-266589
+
+
+ Fixed an issue where the firewall was unable to generate a tech + support file when management server debug was disabled. +
+
+
PAN-263465
+
+
+ Fixed an issue where the + logrcvr + process stopped responding due to a memory leak and buffer overrun. +
+
+
PAN-263270
+
+
+ Fixed an issue where, after a commit was performed from Strata Cloud + Manager, the SD-WAN configuration containing BGP routes did not + display on the hub firewall. +
+
+
PAN-263052
+
+
+ Fixed an issue where the + request logdb migrate-to-panorama start end-time <start-time> + <type> + CLI command did not work as expected, and you were unable to resend + logs from a firewall to Panorama or a log collector. +
+
+
PAN-260015
+
+
+ Fixed an issue on the firewall where the dataplane restarted due to + insufficient allocation of memory buffers. +
+
+
PAN-259610
+
+
+ Fixed an issue where Wildfire content installation failed for WF-500B + clusters when deployed from Panorama using the deployment schedule. +
+
+
PAN-255914
+
+
+ (VM-Series firewalls on Amazon Web Services (AWS) environments + only) Fixed an issue where a newly bootstrapped firewall required a + management server restart, relicensing, or license push from Panorama + to invoke the device certificate. +
+
+
PAN-254524
+
+
+ Fixed an issue on Panorama where, when the + Commit and Push button was clicked + during a selective + Commit and Push operation, the + window stopped responding, which caused the operation to be delayed. +
+
+
PAN-253127
+
+
+ Fixed an issue where, after upgrading to PAN-OS 11.0.2-h3, the + hardware pool DFLT became highly utilized, and the packet buffer + gradually increased. +
+
+
PAN-249574
+
+
+ Fixed an issue where selective pushes failed due to a missing log + collector reference. +
+
+
PAN-245064
+
+
+ (Multi-vsys firewalls only) Fixed an issue + where commits failed on the firewall after selecting + Export or push device config bundle + on Panorama and a force push was required. +
+
+
PAN-238208
+
+
+ Fixed an issue where the firewall API returned inconsistent responses + to a failed call using a valid API key. With this fix, the firewall + returns the error + Session is invalid if the session is + not available for the cookie. +
+
diff --git a/reference/urls.json b/reference/urls.json index 6c49efd..aa91ff3 100644 --- a/reference/urls.json +++ b/reference/urls.json @@ -1,163 +1,163 @@ { "PAN-OS": { "11.1.0": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-0-known-and-addressed-issues/pan-os-11-1-0-addressed-issues", "known": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-0-known-and-addressed-issues/pan-os-11-1-0-known-issues" }, "11.1.0-h1": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-0-known-and-addressed-issues/pan-os-11-1-0-h1-addressed-issues", "known": "" }, "11.1.0-h2": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-0-known-and-addressed-issues/pan-os-11-1-0-h2-addressed-issues", "known": "" }, "11.1.0-h3": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-0-known-and-addressed-issues/pan-os-11-1-0-h3-addressed-issues", "known": "" }, "11.1.0-h4": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-0-known-and-addressed-issues/pan-os-11-1-0-h4-addressed-issues", "known": "" }, "11.1.1": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-1-known-and-addressed-issues/pan-os-11-1-1-addressed-issues", "known": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-1-known-and-addressed-issues/pan-os-11-1-1-known-issues" }, "11.1.1-h1": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-1-known-and-addressed-issues/pan-os-11-1-1-h1-addressed-issues", "known": "" }, "11.1.1-h2": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-1-known-and-addressed-issues/pan-os-11-1-1-h2-addressed-issues", "known": "" }, "11.1.2": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-2-known-and-addressed-issues/pan-os-11-1-2-addressed-issues", "known": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-2-known-and-addressed-issues/pan-os-11-1-2-known-issues" }, "11.1.2-h1": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-2-known-and-addressed-issues/pan-os-11-1-2-h1-addressed-issues", "known": "" }, "11.1.2-h3": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-2-known-and-addressed-issues/pan-os-11-1-2-h3-addressed-issues", "known": "" }, "11.1.2-h4": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-2-known-and-addressed-issues/pan-os-11-1-2-h4-addressed-issues", "known": "" }, "11.1.2-h9": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-2-known-and-addressed-issues/pan-os-11-1-2-h9-addressed-issues", "known": "" }, "11.1.2-h12": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-2-known-and-addressed-issues/pan-os-11-1-2-h12-addressed-issues", "known": "" }, "11.1.2-h14": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-2-known-and-addressed-issues/pan-os-11-1-2-h14-addressed-issues", "known": "" }, "11.1.2-h15": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-2-known-and-addressed-issues/pan-os-11-1-2-h15-addressed-issues", "known": "" }, "11.1.2-h16": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-2-known-and-addressed-issues/pan-os-11-1-2-h16-addressed-issues", "known": "" }, "11.1.2-h18": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-2-known-and-addressed-issues/pan-os-11-1-2-h18-addressed-issues", "known": "" }, "11.1.3": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-3-known-and-addressed-issues/pan-os-11-1-3-addressed-issues", "known": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-3-known-and-addressed-issues/pan-os-11-1-3-known-issues" }, "11.1.3-h1": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-3-known-and-addressed-issues/pan-os-11-1-3-h1-addressed-issues", "known": "" }, "11.1.3-h2": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-3-known-and-addressed-issues/pan-os-11-1-3-h2-addressed-issues", "known": "" }, "11.1.3-h4": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-3-known-and-addressed-issues/pan-os-11-1-3-h4-addressed-issues", "known": "" }, "11.1.3-h6": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-3-known-and-addressed-issues/pan-os-11-1-3-h6-addressed-issues", "known": "" }, "11.1.3-h10": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-3-known-and-addressed-issues/pan-os-11-1-3-h10-addressed-issues", "known": "" }, "11.1.3-h11": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-3-known-and-addressed-issues/pan-os-11-1-3-h11-addressed-issues", "known": "" }, "11.1.3-h13": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-3-known-and-addressed-issues/pan-os-11-1-3-h13-addressed-issues", "known": "" }, "11.1.4": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-4-known-and-addressed-issues/pan-os-11-1-4-addressed-issues", "known": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-4-known-and-addressed-issues/pan-os-11-1-4-known-issues" }, "11.1.4-h1": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-4-known-and-addressed-issues/pan-os-11-1-4-h1-addressed-issues", "known": "" }, "11.1.4-h4": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-4-known-and-addressed-issues/pan-os-11-1-4-h4-addressed-issues", "known": "" }, "11.1.4-h7": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-4-known-and-addressed-issues/pan-os-11-1-4-h7-addressed-issues", "known": "" }, "11.1.4-h9": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-4-known-and-addressed-issues/pan-os-11-1-4-h9-addressed-issues", "known": "" }, "11.1.4-h13": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-4-known-and-addressed-issues/pan-os-11-1-4-h13-addressed-issues", "known": "" }, "11.1.4-h15": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-4-known-and-addressed-issues/pan-os-11-1-4-h15-addressed-issues", "known": "" }, "11.1.4-h16": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-4-known-and-addressed-issues/pan-os-11-1-4-h16-addressed-issues", "known": "" }, "11.1.4-h17": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-4-known-and-addressed-issues/pan-os-11-1-4-h17-addressed-issues", "known": "" }, "11.1.4-h18": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-4-known-and-addressed-issues/pan-os-11-1-4-h18-addressed-issues", "known": "" }, "11.1.4-h25": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-4-known-and-addressed-issues/pan-os-11-1-4-h25-addressed-issues", "known": "" }, "11.1.4-h27": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-4-known-and-addressed-issues/pan-os-11-1-4-h27-addressed-issues", "known": "" }, "11.1.5": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-5-known-and-addressed-issues/pan-os-11-1-5-addressed-issues", "known": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-5-known-and-addressed-issues/pan-os-11-1-5-known-issues" }, "11.1.5-h1": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-5-known-and-addressed-issues/pan-os-11-1-5-h1-addressed-issues", "known": "" }, "11.1.6": { @@ -245,11 +245,11 @@ "known": "" }, "11.1.8": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-8-known-and-addressed-issues/pan-os-11-1-8-addressed-issues", "known": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-8-known-and-addressed-issues/pan-os-11-1-8-known-issues" }, "11.1.9": { - "addressed": "", + "addressed": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-9-known-and-addressed-issues/pan-os-11-1-9-addressed-issues", "known": "https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-9-known-and-addressed-issues/pan-os-11-1-9-known-issues" }, "11.1.10": {