Files
firewallissues/web/data/issues/PAN-OS/addressed/11.1.6-h29.md
T
2026-04-15 15:02:12 -05:00

5.2 KiB

type, product, version
type product version
Addressed PAN-OS 11.1.6-h29

PAN-316911

VM-Series firewalls on Amazon Web Services (AWS) environments only

Fixed an issue where a newly bootstrapped firewall required a management server restart, relicensing, or license push from Panorama to invoke the device certificate.

PAN-314061

Fixed an issue where traffic was disrupted during IPSec rekey operations due to a 2 second delay in sending the DELETE message for the previous Security Association (SA) to the peer gateway after a new SA was negotiated.

PAN-313850

PA-1400 Series firewalls in HA configurations only

Fixed an issue where a split-brain condition occurred and HA1/HA2 links went down while upgrading when the HA configuration used dataplane interfaces for HA1 and a combination of HSCI and Ethernet interfaces for HA2.

PAN-313623

Fixed an issue where the /opt/pancfg/mgmt/ssl/private/ directory on Palo Alto Networks devices with TPM support became 100% utilized due to an accumulation of undeleted .pub_pem files. This occurred because executing the show device-certificate status CLI command initiated a process that generated these files but failed to remove them, which prevented the fetching of new device certificates.

PAN-312706

Fixed an issue where the firewalls restarted due to a function lacking a NULL-pointer sanity check.

PAN-311250

Panorama appliances and Log Collectors only

Fixed an issue where logs from multiple devices were not visible on Panorama even though the Elasticsearch health status on the dedicated Log Collectors appeared green.

PAN-309300

Fixed an issue where management plane system resources configuration size exceeded 28 MB for over 4 hours, and the following error message was displayed: Configuration size reaching device capacity limit.

PAN-308786

(Panorama appliances only) Fixed an issue where traffic log queries using the device_name filter returned no results, and complex log queries that included negation operators produced incorrect outputs.

PAN-308654

Fixed an issue where the Elasticsearch Close Indices process closed more indices than expected and dropped the number of open shards below the minimum of 800 per Elasticsearch instance. This occurred because the process did not correctly account for the number of Elasticsearch instances when calculating the maximum number of allowed open shards.

PAN-308507

Panorama managed firewalls only

Fixed an issue where the firewall intermittently failed to maintain active log forwarding streams to Cortex Data Lake even when duplicate logging and enhanced application logging were enabled.

PAN-306555

Fixed an issue where the firewall stopped responding, which led to service outages.

PAN-304718

Fixed an issue where OSPF and BGP outages occurred due to an all_task process restart during clientless VPN content rewrite processing.

PAN-304696

Fixed an issue where the Cloud User-ID connection timed out because the firewall took too long to process the OCSP response.

PAN-298945

Fixed an issue where OSCP HTTP POST requests were not formatted correctly, which caused failures with strict responders.

PAN-298617

Optimized the commit workflow to reduce the size of the effective configuration, resulting in lower memory consumption.

PAN-297005

Fixed an issue where exporting custom reports resulted in empty CSV files.

PAN-296694

Fixed an issue where the firewall rebooted due to the useridd process repeatedly restarting during an IP-port data type writes to the redis from multiple sources such as TSA or XML in a scale environment.

PAN-296202

Firewalls in active/active HA configurations only

Added a log enhancement to capture an issue where, when a commit operation was in progress, newly deployed IP address tags that used the XML API were not immediately reflected in address group resolution, which delayed IP address mapping to address groups and caused traffic to be incorrectly allowed or denied.

PAN-291067

Fixed an issue where the devsrvr process periodically exceeded its virtual memory limit and restarted, which led to intermittent outages.

PAN-290157

Fixed an issue on Panorama where the configd process stopped responding when filtering in the Config Audit window, which caused Panorama to restart unexpectedly.

PAN-288175

Addressed a stack buffer overflow memory leak under plugin management code path.

PAN-287584

Fixed an issue on the web interface where the address object pop up window only displayed a maximum of four address objects in the policy rule even after expanding the window.

PAN-278688

Fixed an issue where DNS Security threat logs were not displayed on the firewall when packet capture was enabled and the domain name length was 62 characters.

PAN-273158

PA-7000 Series firewalls only

Fixed an issue where an incorrect ASIC configuration caused silent packet drops or application slowness when receiving a mix of jumbo and non-jumbo packets.

PAN-271643

Fixed an issue where, when a commit job ID was higher than 65535, the XML API truncated the ID to a 16-bit unsigned integer due to an incorrect type case during printing, which resulted in an incorrect job ID being reported compared to the CLI output for the same commit.