Files
firewallissues/reference/PAN-OS/addressed/11.1.6-h6.html
T

648 lines
19 KiB
HTML

<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-282022</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed the support limitation for the Panorama M-600 and M-700
appliances.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-281885</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when exporting and importing CSV files, the hash
values of pre-shared key variables set at template and template stack
levels changed inconsistently, which resulted in both variables
displaying the same hash value.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-281269</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-5220, PA-5250, and PA-5420 firewalls</tt>) Fixed
an issue where the firewall management server memory usage
continuously increased.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-281264</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>routed</a
>
process memory usage continuously increased when Advanced Routing was
enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-280505</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the web interface did not display a message to
commit prior changes before attempting a partial configuration load.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-280243</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall lost the pre-shared key
configuration assigned from a PSK variable when an unrelated device
group configuration was loaded.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279336</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the CLI did not display a message to commit prior
changes before loading a partial configuration.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279176</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the configuration audit displayed inaccurate
information after partially loading the configuration via the CLI,
which caused the audit to flag the configuration as deleted or
changed.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-279065</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall sent logs with
<span class="ph uicontrol">connection succeeded</span> to the syslog
server every time a connection was established, which resulted in
excessive logs.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-278296</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the system MAC address of the aggregate interface
was the same on the active firewall and the passive firewall after an
upgrade.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-277762</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
unexpected failovers occurred on firewalls running PAN-OS 11.2.2-h2.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-277631</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>logrcvr</a
>
process discarded logs due to a full queue.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-275718</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama stopped forwarding logs to a Syslog
server after upgrading to PAN-OS 11.1.5-h1.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-275713</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>dscd</a
>
process stopped responding when
<span class="ph uicontrol">Endpoint Serial Number</span> was enabled,
which resulted in the
<span class="ph uicontrol">Active Directory</span> returning a list of
serial numbers for a specific firewall from the Cloud Identity Engine.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-275077</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where DNS Security intermittently logs malicious domain
URLs as Alert instead of taking a Sinkhole action, even when
configured to Sinkhole malicious DNS domains.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-274750</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the detailed log view in Panorama did not display
all packet details for traffic logs received from the cloud.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273694</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted due to an out-of-bounds
memory access that occurred as a result of the SIP content length
value being split across packets.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273453</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where restarting the firewall did not initiate an
autocommit job, which caused the firewall to stop responding and the
HA interface to go down.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272746</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-440 firewalls only</tt>) Fixed an issue where
the firewall entered an unstable state after committing changes or
onboarding to Panorama.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272171</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dropped the AAAA DNS server response
and caused delays in traffic from Ubuntu or Linux clients when DNS
Security was enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271498</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>PA-7000 Series firewalls, PA-5200 firewalls, and PA-5400f firewalls
in FIPS mode only</tt
>) Fixed an issue where decrypted traffic repeatedly failed and
frequent reboots were required.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271351</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-0116"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-0116</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270193</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama management server changed its
certificate authority (CA) unexpectedly, which caused managed
firewalls to disconnect.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269052</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic was blocked by a URL filtering profile
even though the Security policy rule did not have a URL filtering
profile configured.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268629</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic did not match the correct security policy
when using an application-filter that references a cloud application.
This occurred when a high number of cloud applications were attached
with a custom tag.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267518</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where WildFire submission logs incorrectly reported
allowed malicious samples even when they were blocked by threat
prevention profiles.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-266695</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a cyclic nested address group
configuration caused the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process to stop responding after a commit.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-262063</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not display the converted
configurations before a commit and reboot, and the commit failed when
attempting to migrate from MS to FRR mode.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261825</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic was dropped when Data Loss Prevention or
Advanced URL Filtering were enabled. This occurred when the payload
size was greater than 3.5 KB.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261739</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls in Microsoft Azure environments only</tt
>) Fixed an issue where the firewall displayed 0 for the physical port
counters read from MAC.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261597</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph uicontrol">all_pktproc</span> process stopped
responding, which caused the firewall to become unavailable.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-261312</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a commit for a policy and configuration dump
overlapped, which resulted in a null pointer exception.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260059</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where
<span class="ph uicontrol">Device Telemetry Regions</span> did not
show up with the latest content due to content files not being parsed
for the region list when Telemetry was turned off.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259767</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where GlobalProtect users were unable to connect when
the option
<span class="ph uicontrol"
>Block sessions if the certificate was not issued to the
authenticating device</span
>
was enabled in the certificate profile.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-258743</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, when you attempted to select a redistribution
profile when creating a BGP Redistribute policy rule, the firewall
displayed an empty dropdown.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-258680</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where, when you removed Security profile
groups from a Security policy rule via the CLI and committed the
change, the Security policy rule was deleted.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-257183</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dropped DNS traffic when using DNS
Security.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-256904</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall inconsistently blocked URLs due to
intermittent URL category misidentification.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-253127</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where, after upgrading to PAN-OS 11.0.2-h3, the
hardware pool DFLT became highly utilized, and the packet buffer
gradually increased.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-251724</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where users matched incorrect Security policy rules
with a HIP profile.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-235733</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the displayed NTP information was incorrect if
the DNS servers timed out.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-234993</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where CPU base gateway auto-scaling failed, which
caused performance issues.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-233868</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall took an incorrect action for
overlapping custom and edl-url-categories in a policy rule.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-212889</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where different threat names were used when
querying a threat under
<span class="ph uicontrol">Threat Monitor</span> (<span
class="ph uicontrol"
>Monitor &gt; App Scope</span
>) and the ACC. This resulted in the ACC displaying no data after
clicking a threat name in
<span class="ph uicontrol">Threat Monitor</span> and filtering it in
the global filters.
</div>
</td>
</tr>
</tbody>
</table>