Files

24 KiB

type, product, version
type product version
Addressed PAN-OS 11.2.7

PAN-290803

VM-Series firewalls on Microsoft Azure environments only

Fixed an issue where firewall failed to bootstrap with a custom image, and VM-Series plugin information was not displayed in the system information.

PAN-290542

Fixed an issue where the all_task process stopped responding when an additional header logging HTTP header was split across 2 packets.

PAN-290239

PA-455 firewalls in active/passive high availability (HA) configurations only

Fixed an issue where, after an upgrade, the TCP session for syslog forwarding did not resume after the syslog server service was disabled and then re-enabled, which caused logs to be dropped. This occurred when the syslog server was down for more than 16 minutes.

PAN-289102

PA-7500 Series, PA-5410, PA-5420, PA-5430, PA-5440, PA-5445, PA-3400 Series, PA-1400 Series, PA-400 Series, VM-Series, and CN-Series firewalls only

Fixed a race condition issue related to predict processing, which resulted in a dataplane restart and traffic loss.

PAN-288930

Fixed an issue where traffic from cloud applications intermittently matched an incorrect cloud-apps policy rule when ACE (App-ID Cloud Engine) was enabled.

PAN-287818

Fixed an issue where sessions timed out sooner than expected due to the pan_proxy_accumulation_restore_timeout not initiating when the accumulation session_init failed.

PAN-286897

Fixed an issue where the pan_task process stopped responding when the firewall attempted to forward files to the WildFire public cloud, which caused the dataplane to experience heartbeat failures.

PAN-286857

Fixed an issue where only failed Kerberos authentication events were logged in auth.log, and successful authentication events were not logged.

PAN-286848

Fixed an issue where ECMP incorrectly balanced sessions across links based on the configured metric, which led to an imbalance in traffic distribution and resulted in traffic assignment shifting disproportionately to routes with lower metrics.

PAN-286825

Fixed an issue where GlobalProtect User-ID mappings were lost after 5 minutes, which caused users to not match User-ID source-based policy rules. This occurred due to a mismatch between the GlobalProtect gateway connection settings and the device behavior and when the inactivity-logout setting was deleted and set to a different value.

PAN-285894

Fixed an issue where the all_task process stopped responding, which caused the firewall to reboot unexpectedly, and traffic failures occurred.

PAN-285651

Panorama appliances in active/passive HA configurations on Microsoft Azure environments only

Fixed an issue on Panorama that caused firewalls to disconnect unexpectedly.

PAN-285597

Fixed an issue where a routed process memory leak occurred when advanced routing was enabled.

PAN-285590

VM-Series firewalls on Amazon Web Services (AWS) GWLB environments only

Fixed an issue where the firewall CPU usage reached 100% after upgrading to PAN-OS 11.1.6-h1.

PAN-284117

Panorama appliances in Log Collector mode only

Fixed an issue where the vm_agent process restarted after an upgrade.

PAN-284066

Fixed an issue where, after an upgrade, the SNMP polled values for IF-MIB::ifInErrors displayed a high number of errors that did not match the values in the CLI show interface command.

PAN-283813

Fixed an issue on Panorama where the web interface performance was slower than usual when retrieving read-only configurations from Panorama.

PAN-283789

Firewalls in HA configurations only

Fixed an issue where, after an upgrade, the mac receive error counter in receive incoming errors increased, which resulted in SNMP alerts.

PAN-283644

Prisma Access only

Fixed an issue where URL log ingestion decreased after an upgrade, and secondary connections were lost.

PAN-283331

Fixed an issue where selective pushes to managed devices failed when the User ID Master Device was configured.

PAN-282697

Fixed an issue where traffic was delayed significantly when it used No Authentication Explicit Proxy and matched a decryption policy rule.

PAN-282640

Fixed an issue where custom reports showed incomplete data when exported in CSV format from Panorama.

PAN-282394

Fixed an issue where a firewall was only able to display a maximum of 14 permitted IP addresses from a Panorama Template Variable.

PAN-282391

Panorama appliances and Log Collectors only

Fixed an issue where a VLD memory leak caused increased memory use, which resulted in OOM errors.

PAN-282359

Fixed an issue where the Panorama web interface was slower than expected.

PAN-282240

Fixed an issue where, when attempting to modify an Anti-Spyware profile via the web interface under a shared location, clicking the OK button displayed a console exception error.

PAN-281885

Fixed an issue where, when exporting and importing CSV files, the hash values of pre-shared key variables set at template and template stack levels changed inconsistently, which resulted in both variables displaying the same hash value.

PAN-281882

Fixed an issue where OSPF redistributed connected routes beyond the intended loopback IP address.

PAN-281649

Fixed an issue where the index size limit was incorrectly calculated and indices rolled over earlier than expected, which resulted in high memory and OOM errors.

PAN-281540

Fixed an issue where the logd process repeatedly restarted when the SD-WAN site name was over 31 characters and contained certain XML escape characters.

PAN-281509

Panorama appliances only

Fixed an issue where log exports were slower than expected or failed when filtering logs after an upgrade, which resulted in timeouts or delays in displaying logs on the web interface.

PAN-281269

PA-5420 firewalls

Fixed an issue where the firewall management server memory usage continuously increased.

PAN-281264

Fixed an issue where the routed process memory usage continuously increased when Advanced Routing was enabled.

PAN-280942

Fixed an issue where the logrcvr process stopped responding.

PAN-280698

Fixed an issue where the firewall removed the TCP timestamp from client hello messages that did not fit in a single packet, which resulted in connection issues.

PAN-280532

Fixed an issue where, after disabling and re-enabling the external syslog server, the TCP session was not resumed, which caused all logs that were forwarded to the syslog server to be dropped.

PAN-280505

Fixed an issue where the web interface did not display a message to commit prior changes before attempting a partial configuration load.

PAN-280477

Fixed an issue on the web interface were you were unable to scroll up or down to view source zones in a NAT policy rule.

PAN-280335

Fixed an issue with an SNMPv3 EngineBoots value discrepancy that prevented to SNMP server from logging.

PAN-280243

Fixed an issue where the firewall lost the pre-shared key configuration assigned from a PSK variable when an unrelated device group configuration was loaded.

PAN-279691

Firewalls in active/passive HA configurations only

Fixed an issue where the firewall didn't synchronize IPSec SAs (security associations) to the passive firewall if the tunnel was not initially established by the active firewall.

PAN-279500

Fixed an issue where TLS connections failed to establish in asymmetric routing environments if the firewall did not see server-to-client (s2c) packets of the TLS handshake.

To use this fix, run the following CLI command: debug dataplane set ssl-decrypt accumulate-client-hello asym-disable yes.

PAN-279495

Fixed an issue where accessing a URL from the browser returned the error message ERR_RESPONSE_HEADERS_TRUNCATED when the firewall was configured with TLS 1.3.

PAN-279400

Fixed an issue where, when Restrict Certificate Extensions was enabled on decryption profiles, the basic constraints extension was overwritten incorrectly.

PAN-279336

Fixed an issue where the CLI did not display a message to commit prior changes before loading a partial configuration.

PAN-279176

Fixed an issue where the configuration audit displayed inaccurate information after partially loading the configuration via the CLI, which caused the audit to flag the configuration as deleted or changed.

PAN-279065

Fixed an issue where the firewall sent logs with connection succeeded to the syslog server every time a connection was established, which resulted in excessive logs.

PAN-278981

Fixed an issue where DNS domain resolutions experienced intermittent delays due to the firewall not connecting to the DNS Security cloud.

To use this fix, enable DNS monitoring on the dataplane via the CLI command debug dnsproxyd enable-rtsig-health-monitor yes.

To show the current setting, run the CLI command debug dnsproxyd enable-rtsig-health-monitor show. If the cfg.general.dns-rtsig-monitor-interval shows a non-zero value, DNS monitoring is enabled.

PAN-278812

Fixed an issue where authentication to GlobalProtect failed with the error message User not in allowed list.

PAN-278461

Firewalls deployed in Amazon Web Services (AWS) environments only

Fixed an issue where DNS Security retransmit packets were not re-encapsulated into Geneve, which caused DNS requests that were initiated from the firewall to be returned to AWS GWLB.

PAN-278190

Fixed an issue on Panorama where a scheduled report with SLS data had an invalid translated-query.

PAN-278150

Fixed an issue where the firewall removed the Authentication Key Identifier (AKID) from the certificate during SSL decryption, which caused Python 3.13 to fail with a certificate verification error.

PAN-277808

Fixed an issue where the eproxy. process stopped responding when running a long duration test using IXload with hybrid SWG SAML authentication bypass for HTTPS payloads, which caused the proxy to become unreachable.

PAN-277631

Fixed an issue where the logrcvr process discarded logs due to a full queue.

PAN-277464

Fixed an issue with intermittent access and slower than expected loading times when accessing websites. This occurred when Anti-Spyware inline cloud analysis was enabled and the SSL Command and Control action was not either allow or alert and server hello packets were out of order.

PAN-277234

Fixed an issue where a device group import resulted in a Security policy rule being created with Application set to none.

PAN-277147

Fixed an issue where daily scheduled reports were not generated and emailed.

PAN-276920

Fixed an issue where web-advertisement traffic was not immediately blocked which resulted in pages loading indefinitely.

PAN-276678

Fixed an issue where Panorama became unresponsive while performing a dynamic address update without a lock.

PAN-276276

PA-450 firewalls only

Fixed an issue where, after an upgrade, data that was excluded using the query builder in a custom report was still visible in the report, and the logs displayed errors related to invalid threat names being queried.

PAN-276062

Fixed an issue where importing a firewall with a large number of address objects into Panorama did not work and remained at 99% completion.

PAN-275754

Added support for bootstrapping Panorama virtual appliances on ESXi.

PAN-275718

Fixed an issue where Panorama stopped forwarding logs to a syslog server after upgrading to PAN-OS 11.1.5-h1.

PAN-275713

Fixed an issue where the dscd process stopped responding when Endpoint Serial Number was enabled, which resulted in the *Active Directory returning a list of serial numbers for a specific firewall from the Cloud Identity Engine.

PAN-275133

Fixed an issue where HTTP 503 server errors occurred while browsing websites due to slow Secure Web Gateway (SWG) bypass rule lookup.

PAN-275077

Fixed an issue where DNS Security intermittently logs malicious domain URLs as Alert instead of taking a Sinkhole action, even when configured to Sinkhole malicious DNS domains.

PAN-275047

VM-Series firewalls only

Fixed an issue where, after an upgrade, the firewall was unable to send logs to the Strata Logging Service (SLS) when using a specific proxy server, and the SSL connection status displayed as failed when attempting to forward logs through the web proxy.

PAN-274806

PA-5250 firewalls only

Fixed an issue where IPv6 pings experienced a high number of dropped packets when forwarded to another dataplane, which resulted in ping failures. This occurred when initiating a ping to the link local address of the firewall and the packet drop percentage depended on the number of dataplanes.

PAN-274797

Fixed an issue where a DPC on slot 3 failed intermittently due to the pktlog_forwarding process restarting, which resulted in an unexpected HA failover.

PAN-274750

Fixed an issue where the detailed log view in Panorama did not display all packet details for traffic logs received from the cloud.

PAN-274726

Fixed an issue where Wildfire signature generation was enabled on all nodes in a cluster instead of only the active node.

PAN-274697

Fixed an issue where push operations from Panorama failed on passive firewalls when an application was removed from a Security policy rule and the policy rule was referenced in a device group.

PAN-274671

Fixed an issue where empty traffic logdb folders were generated for each day even when trafcfic logs were not received by the logrcvr process.

PAN-274569

Fixed an issue where the QSPF transceiver interface displayed an incorrect range figure on the temperature alarm.

PAN-274496

Fixed an issue where the root partition reached 100% which caused the system to become non-functional and failover even when aggressive cleaning was enabled.

PAN-274146

Fixed an issue where the firewall rebooted continuously after upgrading to PAN-OS 11.1.5-h1 when a tunnel session was established in a Gateway Load Balancing (GWLB) scenario and no data packet was associated with the packet.

PAN-273964

Fixed an issue where SNMP scans to a firewall timed out after upgrading to a PAN-OS 10.2 release.

PAN-273694

Fixed an issue where the firewall rebooted due to an out-of-bounds memory access that occurred as a result of the SIP content length value being split across packets.

PAN-273614

Fixed an issue where packets were dropped initially when a SYN cookie with activation threshold 0 was enabled.

PAN-273597

Fixed an issue where logs in the cloud database displayed in the Not-Resolved category but not in the local database.

PAN-273453

Fixed an issue where restarting the firewall did not initiate an autocommit job, which caused the firewall to stop responding and the HA interface to go down.

PAN-273277

Fixed an issue where GlobalProtect clients on macOS devices were prompted to enter their username and password for Kerberos SSO authentication.

PAN-273153

Fixed an issue where the Panorama web interface was slower than expected due to excessive polling of the MonitorDirect.getTasks API by the Task Manager.

PAN-273141

Fixed an issue where GlobalProtect clients experienced slow file transfer download throughput when passing through an IPSec tunnel.

PAN-272812

Fixed an issue where SNMP monitoring of tunnel interfaces displayed zero values for received bytes and packets.

PAN-272746

PA-440 firewalls only

Fixed an issue where the firewall entered an unstable state after committing changes or onboarding to Panorama.

PAN-272605

Fixed an issue where the firewall did not display VPC endpoints when there was a large amount of VPC endpoints to interface mappings.

PAN-272539

Panorama appliances on Microsoft Azure environments only

Fixed an issue where user to IP address mapping was missing for some users connected to specific Prisma Access gateways, which caused the collection layer Azure firewall to not form the mapping.

PAN-272395

Fixed an issue where informational logs caused the distributord process log file to be frequently overwritten.

PAN-272175

Fixed an issue where session rematch caused ACE cloud application traffic to match the wrong policy.

PAN-271700

Fixed an issue where User-ID connections were lost after an HA failover.

PAN-271560

Fixed an issue where DNS requests to malware sites were not blocked as expected, and the dns-security-categories log-level and action displayed default values instead of unavailable.

PAN-271498

PA-7000 Series firewalls, PA-5200 firewalls, and PA-5400f firewalls in FIPS mode only

Fixed an issue where decrypted traffic repeatedly failed and frequent reboots were required.

PAN-271425

Firewalls in active/active HA configurations only

Fixed an issue with SSL inbound decryption on firewalls on a vwire setup with asymmetric routing.

To use this fix, enter the CLI command set system setting ssl-decrypt ha-vwire-mac-learn global yes on both firewalls in an HA pair.

PAN-271184

Fixed an issue where Device Telemetry failed due to an issue with the encoding of characters in the log file path.

PAN-271175

Fixed an issue where the all_task process stopped responding with a SIGABRT.

PAN-271151

Fixed an issue where the GlobalProtect client did not automatically initiate a Kerberos SSO connection after logging in to Windows.

PAN-270849

Fixed a memory leak issue related to the configd process that occurred when running consecutive commits for multiple days.

PAN-270744

Fixed an issue where API calls to Panorama failed with the error Server error : Timed out while getting config lock. Please try again.

PAN-270379

Fixed an issue where socket files created in the /tmp directory were not cleared.

PAN-270193

Fixed an issue where the Panorama management server changed its certificate authority (CA) unexpectedly, which caused managed firewalls to disconnect.

PAN-270192

Fixed an issue where Panorama did not display the management IP address of devices onboarded via ZTP.

PAN-269700

Fixed an issue where commits to service connection firewalls from Panorama failed.

PAN-269677

Fixed an issue where Panorama did not check for a NULL pointer when querying logs, which caused logs to not display on the web interface.

PAN-269624

Fixed an issue where GlobalProtect clients failed to connect with the error message The device or feature requires a GlobalProtect subscription license.

PAN-269193

Fixed an issue where the firewall redirected the user to the first application instead of the portal page with a list of applications when multiple applications were configured for GlobalProtect clientless VPN along with any user match.

PAN-269139

Firewalls with DPDK enabled in Azure, GCP, AWS, and KVM environments only

Fixed an issue where, after an upgrade to PAN-OS 11.1.4, the mac receive error counter increased without an error even though traffic was not impacted.

PAN-268708

Fixed an issue where PDF summary and email reports displayed IPv6 addresses instead of IPv4 addresses.

PAN-268614

Fixed an issue on the web interface where, when all rules were highlighted when a read-only admin user clicked the Highlight Unused Rules checkbox.

PAN-268489

Fixed a Threat log PCAP ID overwrapping issue.

PAN-268465

Fixed an issue with firewalls in active/passive HA configurations where the total user count in the registered users was different between the active and passive firewall.

PAN-268279

Fixed an issue where autocommits failed if the management IPv6 gateway was the same as the dataplane interface IP address.

PAN-267759

Fixed an issue where Prisma Access gateway downloads were slower than expected.

PAN-267518

Fixed an issue where WildFire submission logs incorrectly reported allowed malicious samples even when they were blocked by threat prevention profiles.

PAN-266427

Fixed an issue on the firewall where, when a high number of SD-WAN branch sites or interfaces were not connected, SD-WAN processes and tund processes stopped responding due to a high probing rate.

PAN-266116

Fixed an issue where URLs did not work due to certificate revocation list (CRL) requests failing.

PAN-265900

Fixed an issue where the firewall stopped responding due to a tund process or SD-WAN process restart.

PAN-265791

Fixed an issue where the all_task process stopped responding, which caused the dataplane to go down.

PAN-264982

VM-Series firewalls on Kernel-based Virtual Machine (KVM) only

Fixed an issue where the firewall entered maintenance mode after an auto-commit when sending an ARP packet through the loopback interface using an IPv6 address.

PAN-264708

Fixed an issue where a selective push was blocked when a configuration load was done.

PAN-262729

Panorama appliances only

Fixed an issue where the configd process experienced continuous high CPU utilization and repeatedly restarted.

PAN-262373

Fixed an issue where the error message Failed to reload config files displayed in the system logs even when device telemetry was not enabled.

PAN-262372

Fixed an issue where the firewall generated the error message Successfully generating a new set of config files in the system logs even when device telemetry was not enabled.

PAN-262063

Fixed an issue where the firewall did not display the converted configurations before a commit and reboot, and the commit failed when attempting to migrate from MS to FRR mode.

PAN-261597

Fixed an issue where the all_pktproc process stopped responding, which caused the firewall to become unavailable.

PAN-261312

Fixed an issue where a commit for a policy and configuration dump overlapped, which resulted in a null pointer exception.

PAN-261074

Fixed an issue where the firewall delayed video file transfers over SMB when Exclude Video Traffic from the Tunnel feature was enabled and no applications were added to the list.

PAN-260229

Fixed an issue where HA path monitoring using VWire did not work as expected after a reboot.

PAN-259727

Panorama appliances in HA configurations only

Fixed an issue where Panorama became unresponsive and displayed a 504 gateway timeout error when accessing the web interface or the CLI.

PAN-259610

Fixed an issue where Wildfire content installation failed for WF-500B clusters when deployed from Panorama using the deployment schedule.

PAN-258743

Fixed an issue where, when you attempted to select a redistribution profile when creating a BGP Redistribute policy rule, the firewall displayed an empty dropdown.

PAN-258166

PA-220 firewalls only

Fixed an issue where the root partition frequently reached 100%.

PAN-258162

Panorama appliances on AWS environments only

( Fixed an issue where IP addresses were not retrieved in Dynamic Address Groups when multiple AND operators were configured.

PAN-257183

Fixed an issue where the firewall dropped DNS traffic when using DNS Security.

PAN-256904

Fixed an issue where the firewall inconsistently blocked URLs due to intermittent URL category misidentification.

PAN-256867

Fixed an issue where the logrcvr process stopped responding while processing session logs for forwarding to the LFC.

PAN-255759

Fixed an issue where the firewall was unable to match HIP data with the correct anti-malware object for Windows Defender.

PAN-254904

Fixed an issue on Panorama where a core file was generated by /usr/local/bin/logd during a restart.

PAN-254524

Fixed an issue on Panorama where, when the Commit and Push button was clicked during a selective Commit and Push operation, the window stopped responding, which caused the operation to be delayed.

PAN-253127

Fixed an issue where, after upgrading to PAN-OS 11.0.2-h3, the hardware pool DFLT became highly utilized, and the packet buffer gradually increased.

PAN-251715

Fixed an issue where the firewall closed the SSL connection to the user ID agent.

PAN-243235

Fixed an issue where Panorama stopped responding and rebooted repeatedly after an upgrade.

PAN-193285

Fixed an issue where the policy optimizer feature did not add entries back to the mongodb database after removing them during an upgrade or downgrade.