--- type: Addressed product: PAN-OS version: 11.1.6-h10 --- ## PAN-286897 Fixed an issue where the pan_task process stopped responding when the firewall attempted to forward files to the WildFire public cloud, which caused the dataplane to experience heartbeat failures. ## PAN-285590 ```caveat VM-Series firewalls on Amazon Web Services (AWS) GWLB environments only ``` Fixed an issue where the firewall CPU usage reached 100% after upgrading to PAN-OS 11.1.6-h1. ## PAN-284066 Fixed an issue where, after an upgrade, the SNMP polled values for IF-MIB::ifInErrors displayed a high number of errors that did not match the values in the CLI show interface command. ## PAN-283789 ```caveat Firewalls in HA configurations only ``` Fixed an issue where, after an upgrade, the mac receive error counter in receive incoming errors increased, which resulted in SNMP alerts. ## PAN-283467 ```caveat PA-3400 Series firewalls only ``` Fixed an issue where the firewall unexpectedly rebooted and entered maintenance mode due to a ctd-agent out-of-memory (OOM) condition. This occurred during advanced services load testing and a high volume of IoT EAL log forwarding. ## PAN-282640 Fixed an issue where custom reports showed incomplete data when exported in CSV format from Panorama. ## PAN-280477 Fixed an issue on the web interface were you were unable to scroll up or down to view source zones in a NAT policy rule. ## PAN-280335 Fixed an issue with an SNMPv3 EngineBoots value discrepancy that prevented to SNMP server from logging. ## PAN-273614 Fixed an issue where packets were dropped initially when a SYN cookie with activation threshold 0 was enabled. ## PAN-272605 Fixed an issue where the firewall did not display VPC endpoints when there was a large amount of VPC endpoints to interface mappings. ## PAN-271560 Fixed an issue where DNS requests to malware sites were not blocked as expected, and the dns-security-categories log-level and action displayed default values instead of unavailable. ## PAN-271152 ```caveat PA-7000 Series firewalls in HA configurations only ``` Fixed an issue where the firewall failed over into a non-functional state, and the LFC LED was blinking on the passive firewall. ## PAN-270849 Fixed a memory leak issue related to the configd process that occurred when running consecutive commits for multiple days. ## PAN-269193 Fixed an issue where the firewall redirected the user to the first application instead of the portal page with a list of applications when multiple applications were configured for GlobalProtect clientless VPN along with any user match. ## PAN-269139 ```caveat Firewalls with DPDK enabled in Azure, GCP, AWS, and KVM environments only ``` Fixed an issue where, after an upgrade to PAN-OS 11.1.4, the mac receive error counter increased without an error even though traffic was not impacted. ## PAN-264982 ```caveat VM-Series firewalls on KVM only ``` Fixed an issue where the firewall entered maintenance mode after an auto-commit when sending an ARP packet through the loopback interface using an IPv6 address. ## PAN-264477 Fixed an issue where the firewall did not start Elasticsearch after a commit if Elasticsearch was not previously enabled and started. ## PAN-261429 Fixed an issue where the show auth radius-require-msg-authentic command CLI displayed no output. ## PAN-254524 Fixed an issue on Panorama where, when the Commit and Push button was clicked during a selective Commit and Push operation, the window stopped responding, which caused the operation to be delayed. ## PAN-284116 Fixed an issue where mTLS decryption bypass did not work when the decryption profile was configured with the maximum TLS version as TLS 1.3. ## PAN-281882 Fixed an issue where OSPF redistributed connected routes beyond the intended loopback IP address. ## PAN-280698 Fixed an issue where the firewall removed the TCP timestamp from client hello messages that did not fit in a single packet, which resulted in connection issues. ## PAN-280532 Fixed an issue where, after disabling and re-enabling the external syslog server, the TCP session was not resumed, which caused all logs that were forwarded to the syslog server to be dropped. ## PAN-279621 Fixed an issue where processes stopped responding when HTTPS Forward traffic was run. ## PAN-278981 Fixed an issue where DNS domain resolutions experienced intermittent delays due to the firewall not connecting to the DNS Security cloud. ## PAN-262373 Fixed an issue where the error message Failed to reload config files displayed in the system logs even when device telemetry was not enabled. ## PAN-277417 Fixed an memory leak issue related to TLS inbound decryption. ## PAN-274806 ```caveat PA-5250 firewalls only ``` Fixed an issue where IPv6 pings experienced a high number of dropped packets when forwarded to another dataplane, which resulted in ping failures. This occurred when initiating a ping to the link local address of the firewall and the packet drop percentage depended on the number of dataplanes. ## PAN-274569 Fixed an issue where the QSPF transceiver interface displayed an incorrect range figure on the temperature alarm. ## PAN-274496 Fixed an issue where the root partition reached 100% which caused the system to become non-functional and failover even when aggressive cleaning was enabled. ## PAN-273422 Fixed an issue where traffic failed when Inline cloud analysis (Advanced Threat Prevention) was enabled in the Anti-Spyware profile with the action set to anything other than allow or alert and the maximum latency condition was reached. ## PAN-272812 Fixed an issue where SNMP monitoring of tunnel interfaces displayed zero values for received bytes and packets. ## PAN-271700 Fixed an issue where User-ID connections were lost after an HA failover. ## PAN-271184 Fixed an issue where Device Telemetry failed due to an issue with the encoding of characters in the log file path. ## PAN-271151 Fixed an issue where the GlobalProtect client did not automatically initiate a Kerberos SSO connection after logging in to Windows. ## PAN-270379 Fixed an issue where socket files created in the /tmp directory were not cleared. ## PAN-270192 Fixed an issue where Panorama did not display the management IP address of devices onboarded via ZTP. ## PAN-268705 Fixed an intermittent issue where the firewall failed to process FTP traffic after upgrading to PAN-OS 10.1.14. ## PAN-267707 Fixed an issue where BFD sessions did not come up even when BGP peering was established. ## PAN-267001 Fixed an issue where multicast streams were unstable with ECMP and dropped every 30 seconds. ## PAN-266704 Fixed an issue where filtering BGP routes by peer name in Advanced Routing Engine (ARE) did not display the correct routes. ## PAN-266574 Fixed an issue where users were unable connect to the portal due to Certificate Revocation List (CRL) checks due to the downloaded CRL file being expired, which caused the CRL cache to be bypassed. ## PAN-266312 Fixed an issue where BFD sessions took longer than expected to establish after an HA failover due to BGP. ## PAN-261999 ```caveat VM-Series firewalls in Microsoft Azure environments only ``` Fixed an issue where enabling flow basic on firewalls caused ARP entries to be removed on both firewalls. ## PAN-261570 ```caveat Firewalls in active/active HA configurations only ``` Fixed an issue where packet loss occurred when dataport was used for HA3 for asymmetrically routed traffic during commits and a virtual wire was configured. ## PAN-260229 Fixed an issue where HA path monitoring using VWire did not work as expected after a reboot. ## PAN-257442 A fix was made to address CVE-2025-0123. ## PAN-245064 ```caveat Multi-vsys firewalls only ``` Fixed an issue where commits failed on the firewall after selecting Export or push device config bundle on Panorama and a force push was required.