|
PAN-290803
|
(VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where firewall failed to bootstrap with a custom
image, and VM-Series plugin information was not displayed in the
system information.
|
|
PAN-290542
|
Fixed an issue where the
all_task
process stopped responding when an additional header logging HTTP
header was split across 2 packets.
|
|
PAN-290239
|
(PA-455 firewalls in active/passive high availability (HA)
configurations only) Fixed an issue where, after an upgrade, the TCP session for syslog
forwarding did not resume after the syslog server service was disabled
and then re-enabled, which caused logs to be dropped. This occurred
when the syslog server was down for more than 16 minutes.
|
|
PAN-289102
|
(PA-7500 Series, PA-5410, PA-5420, PA-5430, PA-5440, PA-5445,
PA-3400 Series, PA-1400 Series, PA-400 Series, VM-Series, and
CN-Series firewalls only) Fixed a race condition issue related to predict processing, which
resulted in a dataplane restart and traffic loss.
|
|
PAN-288930
|
Fixed an issue where traffic from cloud applications intermittently
matched an incorrect
cloud-apps policy rule when ACE
(App-ID Cloud Engine) was enabled.
|
|
PAN-287818
|
Fixed an issue where sessions timed out sooner than expected due to
the
pan_proxy_accumulation_restore_timeout
not initiating when the accumulation
session_init failed.
|
|
PAN-286897
|
Fixed an issue where the
pan_task
process stopped responding when the firewall attempted to forward
files to the WildFire public cloud, which caused the dataplane to
experience heartbeat failures.
|
|
PAN-286857
|
Fixed an issue where only failed Kerberos authentication events were
logged in auth.log, and
successful authentication events were not logged.
|
|
PAN-286848
|
Fixed an issue where ECMP incorrectly balanced sessions across links
based on the configured metric, which led to an imbalance in traffic
distribution and resulted in traffic assignment shifting
disproportionately to routes with lower metrics.
|
|
PAN-286825
|
Fixed an issue where GlobalProtect User-ID mappings were lost after 5
minutes, which caused users to not match User-ID source-based policy
rules. This occurred due to a mismatch between the GlobalProtect
gateway connection settings and the device behavior and when the
inactivity-logout setting was
deleted and set to a different value.
|
|
PAN-285894
|
Fixed an issue where the
all_task
process stopped responding, which caused the firewall to reboot
unexpectedly, and traffic failures occurred.
|
|
PAN-285651
|
(Panorama appliances in active/passive HA configurations on
Microsoft Azure environments only) Fixed an issue on Panorama that caused firewalls to disconnect
unexpectedly.
|
|
PAN-285597
|
Fixed an issue where a
routed
process memory leak occurred when advanced routing was enabled.
|
|
PAN-285590
|
(VM-Series firewalls on Amazon Web Services (AWS) GWLB environments
only) Fixed an issue where the firewall CPU usage reached 100% after
upgrading to PAN-OS 11.1.6-h1.
|
|
PAN-284117
|
( Panorama appliances in Log Collector mode only) Fixed an issue where the
vm_agent
process restarted after an upgrade.
|
|
PAN-284066
|
Fixed an issue where, after an upgrade, the SNMP polled values for
IF-MIB::ifInErrors displayed a
high number of errors that did not match the values in the CLI show
interface command.
|
|
PAN-283813
|
Fixed an issue on Panorama where the web interface performance was
slower than usual when retrieving read-only configurations from
Panorama.
|
|
PAN-283789
|
(Firewalls in HA configurations only) Fixed an
issue where, after an upgrade, the
mac receive error counter in
receive incoming errors increased,
which resulted in SNMP alerts.
|
|
PAN-283644
|
(Prisma Access only) Fixed an issue where URL
log ingestion decreased after an upgrade, and secondary connections
were lost.
|
|
PAN-283331
|
Fixed an issue where selective pushes to managed devices failed when
the User ID Master Device was
configured.
|
|
PAN-282697
|
Fixed an issue where traffic was delayed significantly when it used
No Authentication Explicit Proxy and
matched a decryption policy rule.
|
|
PAN-282640
|
Fixed an issue where custom reports showed incomplete data when
exported in CSV format from Panorama.
|
|
PAN-282394
|
Fixed an issue where a firewall was only able to display a maximum of
14 permitted IP addresses from a Panorama Template Variable.
|
|
PAN-282391
|
(Panorama appliances and Log Collectors only)
Fixed an issue where a VLD memory leak caused increased memory use,
which resulted in OOM errors.
|
|
PAN-282359
|
Fixed an issue where the Panorama web interface was slower than
expected.
|
|
PAN-282240
|
Fixed an issue where, when attempting to modify an Anti-Spyware
profile via the web interface under a shared location, clicking the
OK button displayed a console
exception error.
|
|
PAN-281885
|
Fixed an issue where, when exporting and importing CSV files, the hash
values of pre-shared key variables set at template and template stack
levels changed inconsistently, which resulted in both variables
displaying the same hash value.
|
|
PAN-281882
|
Fixed an issue where OSPF redistributed connected routes beyond the
intended loopback IP address.
|
|
PAN-281649
|
Fixed an issue where the index size limit was incorrectly calculated
and indices rolled over earlier than expected, which resulted in high
memory and OOM errors.
|
|
PAN-281540
|
Fixed an issue where the
logd
process repeatedly restarted when the SD-WAN site name was over 31
characters and contained certain XML escape characters.
|
|
PAN-281509
|
(Panorama appliances only) Fixed an issue where
log exports were slower than expected or failed when filtering logs
after an upgrade, which resulted in timeouts or delays in displaying
logs on the web interface.
|
|
PAN-281269
|
(PA-5420 firewalls) Fixed an issue where the
firewall management server memory usage continuously increased.
|
|
PAN-281264
|
Fixed an issue where the
routed
process memory usage continuously increased when Advanced Routing was
enabled.
|
|
PAN-280942
|
Fixed an issue where the
logrcvr
process stopped responding.
|
|
PAN-280698
|
Fixed an issue where the firewall removed the TCP timestamp from
client hello messages that did not fit in a single packet, which
resulted in connection issues.
|
|
PAN-280532
|
Fixed an issue where, after disabling and re-enabling the external
syslog server, the TCP session was not resumed, which caused all logs
that were forwarded to the syslog server to be dropped.
|
|
PAN-280505
|
Fixed an issue where the web interface did not display a message to
commit prior changes before attempting a partial configuration load.
|
|
PAN-280477
|
Fixed an issue on the web interface were you were unable to scroll up
or down to view source zones in a NAT policy rule.
|
|
PAN-280335
|
Fixed an issue with an SNMPv3 EngineBoots value discrepancy that
prevented to SNMP server from logging.
|
|
PAN-280243
|
Fixed an issue where the firewall lost the pre-shared key
configuration assigned from a PSK variable when an unrelated device
group configuration was loaded.
|
|
PAN-279691
|
(Firewalls in active/passive HA configurations only) Fixed an issue where the firewall didn't synchronize IPSec SAs
(security associations) to the passive firewall if the tunnel was not
initially established by the active firewall.
|
|
PAN-279500
|
Fixed an issue where TLS connections failed to establish in asymmetric
routing environments if the firewall did not see server-to-client
(s2c) packets of the TLS handshake.
To use this fix, run the following CLI command:
debug dataplane set ssl-decrypt accumulate-client-hello
asym-disable yes.
|
|
PAN-279495
|
Fixed an issue where accessing a URL from the browser returned the
error message
ERR_RESPONSE_HEADERS_TRUNCATED
when the firewall was configured with TLS 1.3.
|
|
PAN-279400
|
Fixed an issue where, when
Restrict Certificate Extensions was
enabled on decryption profiles, the basic constraints extension was
overwritten incorrectly.
|
|
PAN-279336
|
Fixed an issue where the CLI did not display a message to commit prior
changes before loading a partial configuration.
|
|
PAN-279176
|
Fixed an issue where the configuration audit displayed inaccurate
information after partially loading the configuration via the CLI,
which caused the audit to flag the configuration as deleted or
changed.
|
|
PAN-279065
|
Fixed an issue where the firewall sent logs with
connection succeeded to the syslog
server every time a connection was established, which resulted in
excessive logs.
|
|
PAN-278981
|
Fixed an issue where DNS domain resolutions experienced intermittent
delays due to the firewall not connecting to the DNS Security cloud.
To use this fix, enable DNS monitoring on the dataplane via the CLI
command
debug dnsproxyd enable-rtsig-health-monitor yes.
To show the current setting, run the CLI command
debug dnsproxyd enable-rtsig-health-monitor show. If the
cfg.general.dns-rtsig-monitor-interval
shows a non-zero value, DNS monitoring is enabled.
|
|
PAN-278812
|
Fixed an issue where authentication to GlobalProtect failed with the
error message
User not in allowed list.
|
|
PAN-278461
|
(Firewalls deployed in Amazon Web Services (AWS) environments
only) Fixed an issue where DNS Security retransmit packets were not
re-encapsulated into Geneve, which caused DNS requests that were
initiated from the firewall to be returned to AWS GWLB.
|
|
PAN-278190
|
Fixed an issue on Panorama where a scheduled report with SLS data had
an invalid translated-query.
|
|
PAN-278150
|
Fixed an issue where the firewall removed the Authentication Key
Identifier (AKID) from the certificate during SSL decryption, which
caused Python 3.13 to fail with a certificate verification error.
|
|
PAN-277808
|
Fixed an issue where the
eproxy. process stopped responding when running a long duration test using
IXload with hybrid SWG SAML authentication bypass for HTTPS payloads,
which caused the proxy to become unreachable.
|
|
PAN-277631
|
Fixed an issue where the
logrcvr
process discarded logs due to a full queue.
|
|
PAN-277464
|
Fixed an issue with intermittent access and slower than expected
loading times when accessing websites. This occurred when Anti-Spyware
inline cloud analysis was enabled and the
SSL Command and Control action was
not either allow or
alert and server hello packets were
out of order.
|
|
PAN-277234
|
Fixed an issue where a device group import resulted in a Security
policy rule being created with
Application set to
none.
|
|
PAN-277147
|
Fixed an issue where daily scheduled reports were not generated and
emailed.
|
|
PAN-276920
|
Fixed an issue where web-advertisement traffic was not immediately
blocked which resulted in pages loading indefinitely.
|
|
PAN-276678
|
Fixed an issue where Panorama became unresponsive while performing a
dynamic address update without a lock.
|
|
PAN-276276
|
(PA-450 firewalls only) Fixed an issue where,
after an upgrade, data that was excluded using the query builder in a
custom report was still visible in the report, and the logs displayed
errors related to invalid threat names being queried.
|
|
PAN-276062
|
Fixed an issue where importing a firewall with a large number of
address objects into Panorama did not work and remained at 99%
completion.
|
|
PAN-275754
|
Added support for bootstrapping Panorama virtual appliances on ESXi.
|
|
PAN-275718
|
Fixed an issue where Panorama stopped forwarding logs to a syslog
server after upgrading to PAN-OS 11.1.5-h1.
|
|
PAN-275713
|
Fixed an issue where the
dscd
process stopped responding when
Endpoint Serial Number was enabled,
which resulted in the **Active Directory* returning a list of serial
numbers for a specific firewall from the Cloud Identity Engine.
|
|
PAN-275133
|
Fixed an issue where HTTP 503 server errors occurred while browsing
websites due to slow Secure Web Gateway (SWG) bypass rule lookup.
|
|
PAN-275077
|
Fixed an issue where DNS Security intermittently logs malicious domain
URLs as Alert instead of taking a Sinkhole action, even when
configured to Sinkhole malicious DNS domains.
|
|
PAN-275047
|
(VM-Series firewalls only) Fixed an issue
where, after an upgrade, the firewall was unable to send logs to the
Strata Logging Service (SLS) when using a specific proxy server, and
the SSL connection status displayed as failed when attempting to
forward logs through the web proxy.
|
|
PAN-274806
|
(PA-5250 firewalls only) Fixed an issue where
IPv6 pings experienced a high number of dropped packets when forwarded
to another dataplane, which resulted in ping failures. This occurred
when initiating a ping to the link local address of the firewall and
the packet drop percentage depended on the number of dataplanes.
|
|
PAN-274797
|
Fixed an issue where a DPC on slot 3 failed intermittently due to the
pktlog_forwarding process
restarting, which resulted in an unexpected HA failover.
|
|
PAN-274750
|
Fixed an issue where the detailed log view in Panorama did not display
all packet details for traffic logs received from the cloud.
|
|
PAN-274726
|
Fixed an issue where Wildfire signature generation was enabled on all
nodes in a cluster instead of only the active node.
|
|
PAN-274697
|
Fixed an issue where push operations from Panorama failed on passive
firewalls when an application was removed from a Security policy rule
and the policy rule was referenced in a device group.
|
|
PAN-274671
|
Fixed an issue where empty traffic
logdb folders were generated for
each day even when trafcfic logs were not received by the
logrcvr
process.
|
|
PAN-274569
|
Fixed an issue where the QSPF transceiver interface displayed an
incorrect range figure on the temperature alarm.
|
|
PAN-274496
|
Fixed an issue where the root partition reached 100% which caused the
system to become non-functional and failover even when aggressive
cleaning was enabled.
|
|
PAN-274146
|
Fixed an issue where the firewall rebooted continuously after
upgrading to PAN-OS 11.1.5-h1 when a tunnel session was established in
a Gateway Load Balancing (GWLB) scenario and no data packet was
associated with the packet.
|
|
PAN-273964
|
Fixed an issue where SNMP scans to a firewall timed out after
upgrading to a PAN-OS 10.2 release.
|
|
PAN-273694
|
Fixed an issue where the firewall rebooted due to an out-of-bounds
memory access that occurred as a result of the SIP content length
value being split across packets.
|
|
PAN-273614
|
Fixed an issue where packets were dropped initially when a SYN cookie
with activation threshold 0 was enabled.
|
|
PAN-273597
|
Fixed an issue where logs in the cloud database displayed in the
Not-Resolved category but not in the
local database.
|
|
PAN-273453
|
Fixed an issue where restarting the firewall did not initiate an
autocommit job, which caused the firewall to stop responding and the
HA interface to go down.
|
|
PAN-273277
|
Fixed an issue where GlobalProtect clients on macOS devices were
prompted to enter their username and password for Kerberos SSO
authentication.
|
|
PAN-273153
|
Fixed an issue where the Panorama web interface was slower than
expected due to excessive polling of the
MonitorDirect.getTasks API by the
Task Manager.
|
|
PAN-273141
|
Fixed an issue where GlobalProtect clients experienced slow file
transfer download throughput when passing through an IPSec tunnel.
|
|
PAN-272812
|
Fixed an issue where SNMP monitoring of tunnel interfaces displayed
zero values for received bytes and packets.
|
|
PAN-272746
|
(PA-440 firewalls only) Fixed an issue where
the firewall entered an unstable state after committing changes or
onboarding to Panorama.
|
|
PAN-272605
|
Fixed an issue where the firewall did not display VPC endpoints when
there was a large amount of VPC endpoints to interface mappings.
|
|
PAN-272539
|
(Panorama appliances on Microsoft Azure environments only) Fixed an issue where user to IP address mapping was missing for
some users connected to specific Prisma Access gateways, which caused
the collection layer Azure firewall to not form the mapping.
|
|
PAN-272395
|
Fixed an issue where informational logs caused the
distributord
process log file to be frequently overwritten.
|
|
PAN-272175
|
Fixed an issue where session rematch caused ACE cloud application
traffic to match the wrong policy.
|
|
PAN-271700
|
Fixed an issue where User-ID connections were lost after an HA
failover.
|
|
PAN-271560
|
Fixed an issue where DNS requests to malware sites were not blocked as
expected, and the
dns-security-categories log-level
and action displayed default values instead of
unavailable.
|
|
PAN-271498
|
(PA-7000 Series firewalls, PA-5200 firewalls, and PA-5400f firewalls
in FIPS mode only) Fixed an issue where decrypted traffic repeatedly failed and
frequent reboots were required.
|
|
PAN-271425
|
(Firewalls in active/active HA configurations only) Fixed an issue with SSL inbound decryption on firewalls on a vwire
setup with asymmetric routing.
To use this fix, enter the CLI command
set system setting ssl-decrypt ha-vwire-mac-learn global yes
on both firewalls in an HA pair.
|
|
PAN-271184
|
Fixed an issue where Device Telemetry failed due to an issue with the
encoding of characters in the log file path.
|
|
PAN-271175
|
Fixed an issue where the
all_task
process stopped responding with a SIGABRT.
|
|
PAN-271151
|
Fixed an issue where the GlobalProtect client did not automatically
initiate a Kerberos SSO connection after logging in to Windows.
|
|
PAN-270849
|
Fixed a memory leak issue related to the
configd
process that occurred when running consecutive commits for multiple
days.
|
|
PAN-270744
|
Fixed an issue where API calls to Panorama failed with the error
Server error : Timed out while getting config lock. Please try
again.
|
|
PAN-270379
|
Fixed an issue where socket files created in the /tmp directory were
not cleared.
|
|
PAN-270193
|
Fixed an issue where the Panorama management server changed its
certificate authority (CA) unexpectedly, which caused managed
firewalls to disconnect.
|
|
PAN-270192
|
Fixed an issue where Panorama did not display the management IP
address of devices onboarded via ZTP.
|
|
PAN-269700
|
Fixed an issue where commits to service connection firewalls from
Panorama failed.
|
|
PAN-269677
|
Fixed an issue where Panorama did not check for a NULL pointer when
querying logs, which caused logs to not display on the web interface.
|
|
PAN-269624
|
Fixed an issue where GlobalProtect clients failed to connect with the
error message
The device or feature requires a GlobalProtect subscription
license.
|
|
PAN-269193
|
Fixed an issue where the firewall redirected the user to the first
application instead of the portal page with a list of applications
when multiple applications were configured for GlobalProtect
clientless VPN along with any user match.
|
|
PAN-269139
|
(Firewalls with DPDK enabled in Azure, GCP, AWS, and KVM
environments only) Fixed an issue where, after an upgrade to PAN-OS 11.1.4, the
mac receive error counter increased
without an error even though traffic was not impacted.
|
|
PAN-268708
|
Fixed an issue where PDF summary and email reports displayed IPv6
addresses instead of IPv4 addresses.
|
|
PAN-268614
|
Fixed an issue on the web interface where, when all rules were
highlighted when a read-only admin user clicked the
Highlight Unused Rules checkbox.
|
|
PAN-268489
|
Fixed a Threat log PCAP ID overwrapping issue.
|
|
PAN-268465
|
Fixed an issue with firewalls in active/passive HA configurations
where the total user count in the registered users was different
between the active and passive firewall.
|
|
PAN-268279
|
Fixed an issue where autocommits failed if the management IPv6 gateway
was the same as the dataplane interface IP address.
|
|
PAN-267759
|
Fixed an issue where Prisma Access gateway downloads were slower than
expected.
|
|
PAN-267518
|
Fixed an issue where WildFire submission logs incorrectly reported
allowed malicious samples even when they were blocked by threat
prevention profiles.
|
|
PAN-266427
|
Fixed an issue on the firewall where, when a high number of SD-WAN
branch sites or interfaces were not connected, SD-WAN processes and
tund
processes stopped responding due to a high probing rate.
|
|
PAN-266116
|
Fixed an issue where URLs did not work due to certificate revocation
list (CRL) requests failing.
|
|
PAN-265900
|
Fixed an issue where the firewall stopped responding due to a
tund
process or SD-WAN process restart.
|
|
PAN-265791
|
Fixed an issue where the
all_task process stopped
responding, which caused the dataplane to go down.
|
|
PAN-264982
|
(VM-Series firewalls on Kernel-based Virtual Machine (KVM) only) Fixed an issue where the firewall entered maintenance mode after an
auto-commit when sending an ARP packet through the loopback interface
using an IPv6 address.
|
|
PAN-264708
|
Fixed an issue where a selective push was blocked when a configuration
load was done.
|
|
PAN-262729
|
( Panorama appliances only) Fixed an issue where
the
configd
process experienced continuous high CPU utilization and repeatedly
restarted.
|
|
PAN-262373
|
Fixed an issue where the error message
Failed to reload config files
displayed in the system logs even when device telemetry was not
enabled.
|
|
PAN-262372
|
Fixed an issue where the firewall generated the error message
Successfully generating a new set of config files
in the system logs even when device telemetry was not enabled.
|
|
PAN-262063
|
Fixed an issue where the firewall did not display the converted
configurations before a commit and reboot, and the commit failed when
attempting to migrate from MS to FRR mode.
|
|
PAN-261597
|
Fixed an issue where the
all_pktproc
process stopped responding, which caused the firewall to become
unavailable.
|
|
PAN-261312
|
Fixed an issue where a commit for a policy and configuration dump
overlapped, which resulted in a null pointer exception.
|
|
PAN-261074
|
Fixed an issue where the firewall delayed video file transfers over
SMB when Exclude Video Traffic from
the Tunnel feature was enabled and no applications were added to the
list.
|
|
PAN-260229
|
Fixed an issue where HA path monitoring using VWire did not work as
expected after a reboot.
|
|
PAN-259727
|
(Panorama appliances in HA configurations only)
Fixed an issue where Panorama became unresponsive and displayed a 504
gateway timeout error when accessing the web interface or the CLI.
|
|
PAN-259610
|
Fixed an issue where Wildfire content installation failed for WF-500B
clusters when deployed from Panorama using the deployment schedule.
|
|
PAN-258743
|
Fixed an issue where, when you attempted to select a redistribution
profile when creating a BGP Redistribute policy rule, the firewall
displayed an empty dropdown.
|
|
PAN-258166
|
(PA-220 firewalls only) Fixed an issue where
the root partition frequently reached 100%.
|
|
PAN-258162
|
(Panorama appliances on AWS environments only
Fixed an issue where IP addresses were not retrieved in Dynamic
Address Groups when multiple AND operators were configured.
|
|
PAN-257183
|
Fixed an issue where the firewall dropped DNS traffic when using DNS
Security.
|
|
PAN-256904
|
Fixed an issue where the firewall inconsistently blocked URLs due to
intermittent URL category misidentification.
|
|
PAN-256867
|
Fixed an issue where the
logrcvr
process stopped responding while processing session logs for
forwarding to the LFC.
|
|
PAN-255759
|
Fixed an issue where the firewall was unable to match HIP data with
the correct anti-malware object for Windows Defender.
|
|
PAN-254904
|
Fixed an issue on Panorama where a core file was generated by
/usr/local/bin/logd during a restart.
|
|
PAN-254524
|
Fixed an issue on Panorama where, when the
Commit and Push button was clicked
during a selective
Commit and Push operation, the
window stopped responding, which caused the operation to be delayed.
|
|
PAN-253127
|
Fixed an issue where, after upgrading to PAN-OS 11.0.2-h3, the
hardware pool DFLT became highly utilized, and the packet buffer
gradually increased.
|
|
PAN-251715
|
Fixed an issue where the firewall closed the SSL connection to the
user ID agent.
|
|
PAN-243235
|
Fixed an issue where Panorama stopped responding and rebooted
repeatedly after an upgrade.
|
|
PAN-193285
|
Fixed an issue where the policy optimizer feature did not add entries
back to the mongodb database
after removing them during an upgrade or downgrade.
|