--- type: Addressed product: PAN-OS version: 9.1.17 source: common-crawl crawl: CC-MAIN-2026-12 --- ## PAN-237935 Extended the offline PAN-DB, Panorama, and WildFire certificates which were previously set to expire on September 2, 2024. ## PAN-228043 Fixed an issue on firewalls on active/active HA configurations where packets dropped during commit operations when forwarding traffic via an HA3 link when an aggregate ethernet interface or data interface was used as an HA3 link. ## PAN-223317 Fixed an issue where SSL traffic failed with the error message: Error: General TLS protocol error. ## PAN-221637 Fixed an issue where User ID logs for logout events displayed incorrect factor completion times. ## PAN-218404 Fixed an issue where ikemgr stopped responding due to receiving CREATE_CHILD messages with a malformed SA payload. ## PAN-217681 Fixed an issue caused by out of order TCP segments where the TCP retransmission failed when the TCP segment had the FIN flag and the TCP data was truncated. ## PAN-215576 Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032. ## PAN-210883 Fixed an issue where SSL proxy traffic was dropped when DoS Zone protection was enabled. ## PAN-207003 Fixed an issue where the logrcvr process netflow buffer was not reset which resulted in duplicate netflow records. ## PAN-202593 Fixed an issue where expanding Global Find results displayed only the top level and second level of a searched item. ## PAN-199557 Fixed an issue on Panorama where virtual memory usage exceeded the set limit, which caused the configd process to restart. ## PAN-198372 Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended. ## PAN-198174 Fixed an issue where, when viewing traffic or threat logs from the **Application Command Center** (ACC) or **Monitor** tabs, performing a reverse DNS lookup caused the dnsproxy process to restart if DNS server settings were not configured. ## PAN-197935 Fixed an intermittent issue where XML API IP address tag registration failed on firewalls in a multivsys environment. ## PAN-197426 Fixed an issue on Panorama where, when attempting to view the **Monitor** page, the error message **invalid term** was displayed. ## PAN-196956 Fixed an issue where URL filtering logs did not display matching entries when filtered by device name. ## PAN-192431 Fixed an issue where unmanaged tags were set to NULL, which caused unmanaged devices to match the HIP rule for managed devices. As a result, you were unable to distinguish between managed and unmanaged devices. ## PAN-191867 Fixed an issue where CPU stalls resulted in a slot restart. ## PAN-190903 Fixed an issue where MAC addresses in threat capture were swapped between the source MAC and destination MAC addresses. ## PAN-189182 Fixed an issue where the change summary didn't work after upgrading the Panorama appliance. ## PAN-184630 Fixed an issue where TLS clients, such as those using OpenSSL 3.0, enforced the TLS renegotiation extension (RFC 5746). ## PAN-160633 ```caveat PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls only ``` Fixed an issue where the dataplane restarted repeatedly due to an internal path monitoring failures until a power cycle.