--- type: Addressed product: PAN-OS version: 11.1.6 --- ## PAN-273215 Fixed an issue where a syntax error in the index generation script caused a high management plane CPU load after upgrading. ## PAN-271913 Fixed an issue on firewalls in high availability (HA) configurations where, when using the Cloud Identity Engine (CIE), the firewall experienced consistent memory leaks on the active firewall, which caused unexpected failovers. ## PAN-270224 Fixed an issue where indices were not opened after a query. ## PAN-269539 Fixed an issue where whitespace was added before the timestamp in syslog logs forwarded from Panorama. ## PAN-269000 Fixed an issue where the firewall stopped responding due to a NULL pointer dereference when path monitoring failed. ## PAN-268951 Fixed a CPS counter query issue that caused SNMP polling timeouts on the firewall. ## PAN-268727 Fixed an issue where traffic was dropped when the accumulation proxy was enabled and header insertion modified packets. ## PAN-268474 Fixed an issue on the firewall where the PAN-DB URL Filtering license displayed as **Valid** even when the firewall did not have the license, which caused traffic to drop. ## PAN-268419 Fixed an issue where **Managed Devices > Summary** displayed incorrect subcolumns. ## PAN-268319 Fixed an issue where **Receive Time** and **Time Generated** were not visible as attributes in the **Filter Builder** for system logs and URL filtering logs. ## PAN-268229 Fixed an issue where the firewall stopped responding during session setup for ECMP hit-count updates. ## PAN-268228 Fixed an issue where Panorama administrators were unable to select **Edit Selection** when pushing changes to devices if they logged in using TACACS authentication. ## PAN-267934 Fixed an issue where commits remained at 98%, which resulted in the BGP connection flapping. ## PAN-267590 Fixed a lock usage error that caused the ikemgr process to stop responding. ## PAN-267348 Fixed an issue on the Panorama web interface where **WildFire Activity by File Type** in the ACC did not display the file type name. ## PAN-267321 Fixed an issue where packets were dropped when BFD inter-dataplane packet forwarding failed. ## PAN-267285 Fixed an issue where a port was able to be connected from outside the network. With this fix, the port is restricted to the local interface. ## PAN-267091 Fixed an issue on Panorama where Elasticsearch repeatedly restarted. ## PAN-266900 Fixed an issue on the Panorama web interface where you were unable to click **OK** after selecting an install package type and file from the dropdown and selecting a firewall. ## PAN-266639 Fixed an issue where administrators were unable to edit or add virtual router configurations when a filter was applied to the viewer. ## PAN-266581 Fixed an issue where a failed SSL connection to a syslog server resulted in a /tmp/srvr.crt.xxxxxx file not being removed, which caused index node (inode) exhaustion. ## PAN-266167 Fixed an issue where the **restart** option for IPSec tunnels was greyed out (**Network > IPSec Tunnels > IKE Info**). ## PAN-266003 Fixed an issue on the firewall where a configuration policy push caused both active and passive firewalls to go down when a high number of spyware profiles and vulnerability profiles were pushed to the dataplane. ## PAN-265621 Fixed an issue where the **restart** option for IPSec tunnels was greyed out when you attempted to restart the tunnel from **Network > IPSec Tunnels > IKE Info**. ## PAN-265399 Fixed an issue where DNS queries for uppercase internal domain (SRV record) timed out when DNS Security was enabled. ## PAN-265366 Fixed an issue where firewall experienced frequent reboots when ipv6 trafic is routed to explicit proxy, causing explicit proxy to crash. ## PAN-265160 Fixed an issue where the firewall created multiple connections to a syslog server and remained in the FINWAIT1 state, which caused logs to drop while being forwarded to the syslog server. ## PAN-264981 Fixed an issue on the Panorama web interface where it took longer than expected to edit Security policy rules. ## PAN-264883 ```caveat PA-7080 appliances with LPCs only ``` Fixed an issue where syslog forwarding over TCP stopped after upgrading. ## PAN-264678 Fixed an issue where **Preview Changes** did not display configuration changes in **Commit and push** > **Push Scope**. ## PAN-264662 Fixed an issue where HTTP POST requests were blocked for URLs that had the **block-continue** category configured. ## PAN-263843 ```caveat VM-Series firewalls only ``` Fixed an issue where the firewall received no-license packet buffers instead of memory based packet buffer numbers. ## PAN-263208 ```caveat PA-5440 and PA-5445 firewalls only ``` Fixed an issue where interrupts were generated at a certain packet rate, and dataplane processes missed heartbeats, which caused the dataplane to go down. ## PAN-263012 Fixed an issue where commits failed from a Panorama appliance with a default master key to a firewall with a master key configured and a VM Information source configured. ## PAN-262973 Fixed an issue where changes made by a custom role Panorama administrator did not display in the push scope for other custom role administrators when a full commit was performed. ## PAN-262540 Fixed an issue where application traffic transactions that reused TCP ports did not work with decryption. ## PAN-262511 Fixed an issue on firewalls in HA configurations where OSPF neighbors were not established after an HA failover. ## PAN-260796 Fixed an issue where servers were not accessible through an active SSL GlobalProtect VPN tunnel until a new connection was established or the session was cleared on the firewall. ## PAN-260604 Fixed an issue where the firewall displayed inaccurate throughput utilization stats in NetFlow analyzer tools. ## PAN-260417 Fixed an issue on Panorama where UpdateLicDB was triggered every few minutes when firewalls with PAYG licenses were onboarded. ## PAN-257736 ```caveat PA-5450 firewalls only ``` Fixed an issue where traffic to benign applications was impacted by holding TCP sequential segments for MLC inspection and not releasing the full chain after a benign verdict was received. ## PAN-256552 Fixed an issue where the logrcvr stopped responding, which caused the firewall to restart. ## PAN-255747 Fixed an issue on the firewall where CLI commands returned Server error: op command for client dagger timed out as client is not available. ## PAN-255653 Fixed an HA failover issue where, when Management Processing Card (MPC) or Base Card (BC) failures occurred, the HA link went down, which caused fpp-down events on one firewall. ## PAN-253485 ```caveat Firewalls in active/passive HA configurations only ``` Fixed an issue where dataplane packet capture filter configuration failed on the active firewall with the error op command for client dagger timed out as client is not available. ## PAN-252669 Fixed an issue where the ikemgr process stopped responding with a SIGSEGV error. ## PAN-251973 Fixed an issue where the firewall did not detect evasions due to TCP checksum offloading not being enabled. ## PAN-249581 Fixed an issue where stale BGP routes were advertised to peers even when they were not present in the local RIB table. ## PAN-249384 Fixed an issue on Panorama where configuration locks were observed during a partial rulebase commit. ## PAN-243920 Fixed an issue where the firewall name was truncated in the logs when the name used more than 31 characters. ## PAN-233197 Fixed an issue where the CLI command to set the FEC parameter for the front panel ports was not supported on platforms supporting 25G and 100G.