--- type: Addressed product: PAN-OS version: 11.1.13-h8 --- ## PAN-321340 ```caveat Firewalls in FIPS mode only ``` Fixed an issue where GlobalProtect unexpectedly prompted for RADIUS authentication instead of client certificate authentication due to an OSCP validation error and subsequent CRL verification failure, which led to certificates being marked as invalid. ## PAN-320598 Fixed an issue where internal and external DNS names did not resolve when connected to a GlobalProtect gateway. ## PAN-319288 Fixed an issue where a DPC in Slot 4 restarted repeatedly, which caused internal path monitoring failures and a failover event. ## PAN-318580 Fixed an issue where processes restarted and the firewall unexpectedly rebooted when you configured a Security policy rule with **Source Device > quarantine**. ## PAN-317755 Fixed an issue on Panorama where selective push operations failed when plugin configurations included access-domain or log-collector references. ## PAN-316556 Fixed an issue where a race condition between the session ager and packet processing resulted in memory corruption and caused the pan_task process to stop responding, which resulted in the firewall becoming unresponsive ## PAN-316120 Fixed an issue where, after Advanced Routing was enabled, the firewall advertised routes to internal BGP neighbors with the original external BGP next-hop address. ## PAN-315337 Fixed an issue where GlobalProtect throughput was reduced after an upgrade. ## PAN-315314 Fixed an issue where, when a push operation from Panorama to the firewall failed, accounting logs stopped forwarding. ## PAN-315160 ```caveat PA-7500 firewalls only ``` Fixed an issue where internal path monitoring logs incorrectly reported internal path monitoring failures when they did not occur. ## PAN-314752 Fixed an issue on Panorama where, after removing a scheduled configuration push, Panorama still initiated the push at its previously scheduled time. ## PAN-314623 ```caveat Firewalls in active/passive HA configurations only ``` Fixed an issue where, after a failover, routing information within OSPF protocol was not correctly translated or propagated, which affected network path convergence and FRR capabilities. ## PAN-314385 ```caveat Firewalls in active/passive HA clusters only ``` Fixed an issue where high dataplane CPU usage occurred and traffic offloading decreased when a failover occurred from the active firewall to the passive firewall, and then back to the active firewall. ## PAN-313827 Fixed an issue where a memory leak occurred related to the reportd process when custom reports were run via API. ## PAN-313700 Fixed an issue where an unexpected reboot occurred when Inline Cloud Analysis was enabled in an Anti-Spyware and Vulnerability profile. ## PAN-313606 Fixed an issue where Panorama pushed commits took longer than expected to complete without displaying an error message when committing due to slow cloud-app compilation. ## PAN-313443 Fixed an issue where firewalls acting as an accumulation proxy sent a server hello with an earlier TCP timestamp value than a preceding ACK packet, which prevented successful session establishment. This occurred when the client hello messages were split across multiple network segments. To use this fix, run the CLI command debug dataplane set ssl-decrypt accumulate-client-hello ts-relay yes. ## PAN-313036 Fixed an issue where the firewall dataplane continuously accumulated packets in the ctd_pkt_queue and packet buffers, which caused resource exhaustion and prematurely terminated sessions. ## PAN-311658 Fixed an issue where the reportd process stopped responding, which caused the firewall to reboot. ## PAN-311098 Fixed an issue where firewalls entered a nonfunctional state due to L7 running out of resources due to a high volume of traffic. ## PAN-309853 ```caveat Firewalls with FIPS-CC enabled only ``` Fixed an issue where, when attempting to make changes to the GlobalProtect portal, an error message was displayed and configuration updates failed. ## PAN-308775 ```caveat Firewalls in active/passive configurations only ``` Fixed an issue where NTP status intermittently showed as rejected on the active firewall, which prevented the firewalls from synchronizing time. ## PAN-308668 Fixed an issue on Prisma Access Remote Network firewalls where high CPU utilization caused slowness and command timeouts. ## PAN-308444 Fixed an issue where pushing multiple policy rules failed when the policy rules contained a large number of dynamic address object groups or user groups. ## PAN-297819 Fixed an issue where the firewall was unable to send device telemetry files to Cortex Data Lake due to the firewall receiving an invalid upload token. ## PAN-295082 Fixed an issue on the Panorama web interface where you were unable to delete or change a logical router for tunnel, SD-WAN, VLAN, or loopback interfaces under a template. ## PAN-293142 Fixed an issue where firewall components became unresponsive during sustained operation. ## PAN-289460 Fixed an issue where the timestamp value in SNMPv3 trap headers was incorrect. To use this fix, run the CLI command debug log-receiver enginetime-from-snmptime yes. ## PAN-282335 Fixed an issue where firewalls in a cluster experienced approximately 50% packet loss on IPSec NATT tunnels when tunnel acceleration was enabled. ## PAN-240066 Fixed a duplicate MAC address issue where an ethernet interface sent out Gratuitous ARP (GARP) messages for an IP address that was not configured on it. ## PAN-213491 Fixed an issue where the management CPU was high, which caused the web interface to be slower than expected.