Files
firewallissues/reference/PAN-OS/addressed/11.1.6-h1.html
T

876 lines
25 KiB
HTML

<table class="table colsep rowsep table-striped">
<!--cq:include script="../../common/tablestack.jsp" /-->
<colgroup>
<col style="width: 25%" />
<col style="width: 75%" />
</colgroup>
<thead class="thead">
<tr class="row rowsep">
<th class="entry">
<div class="p"><b class="ph b">Issue ID</b></div>
</th>
<th class="entry">
<div class="p"><b class="ph b">Description</b></div>
</th>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-278088</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">show system resources follow</span> CLI
command was not available.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-276546</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a session lost the PBF rule mapping after a
configuration change or commit.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273994</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-0111"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-0111</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273971</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-0108"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-0108</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273300</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where upgrading to PAN-OS 11.0.4-h2 failed
with a validation error.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273278</b></div>
</td>
<td class="entry relcol">
<div class="p">
A fix was made to address
<a
class="xref"
href="https://security.paloaltonetworks.com/CVE-2025-0109"
title=""
data-scope="external"
data-format="html"
data-type=""
target="_blank"
>CVE-2025-0109</a
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273245</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in HA configurations only</tt>) Fixed an
issue where upgrading an HA firewall pair from PAN-OS 10.2.11-h1 to
PAN-OS 11.1.5 caused the firewalls to enter a nonfunctional loop due
to repeated HA path monitoring failures.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273129</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where the
<span class="ph uicontrol">negate</span> option was visible when you
clicked on the rule name, but not when you viewed the target options
from the <span class="ph uicontrol">rulebase</span> attribute.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273085</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the web interface where you were unable to edit or
create policy rules.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273026</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic logs did not display correctly when
filters were applied.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-273021</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where 25G port links did not come up due to a change in
the handling of 25G DAC modules.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272959</b></div>
</td>
<td class="entry relcol">
Fixed an issue where the firewall generated BGP update packets larger
than 1500 bytes when the interface MTU was 1500 bytes and jumbo frames
were enabled globally.
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272849</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where log forwarding to a UDP syslog server stopped
when an unreachable TCP syslog server was configured and applied.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272538</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding during a commit-all validation when there
were uncommitted changes and
<span class="ph systemoutput">share-unused-objects-with-devices</span>
was set to off.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-272006</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall did not trigger a kernel core dump
as a large core when the CPLD (Complex Programmable Logic Device) sent
a Non-Maskable Interrupt (NMI) to the CPU.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271926</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where TLS 1.3 decryption failed with a bad record MAC
error when the firewall was configured to decrypt and inspect TLS
traffic.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271912</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>configd</a
>
process stopped responding when filtering in the configuration audit
window after upgrading to PAN-OS 11.1.3.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271613</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where configuration pushes from Panorama to the
firewall failed due to an OOXML commit error.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-271314</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where pushing changes to a prefix list used for BGP
from Panorama affected OSPF routes.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270607</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Firewalls in active/passive HA configurations only</tt
>) Fixed an issue where OSPF failed to establish after a failover from
the active firewall to the passive firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270549</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where some TLS connections were not handled correctly,
which led to instability in the dataplane.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-270471</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">Firewalls in active/active configurations only</tt
>) Fixed an issue where the firewall did not detect configuration
changes when only the interface of an IKE gateway was changed, which
caused IPSec tunnels to not come up after migrating the IKE gateway IP
address from a subinterface to a physical interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269956</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_pktproc</a
>
process stopped responding, which caused internal path monitor
failures.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269899</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama web interface was slower than
expected when querying for device tags.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269737</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the followig critical error displayed repeatedly:
<span class="ph systemoutput">/mnt/cdrom is mounted as Read-Only</span
>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269731</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not display logs from firewalls
after upgrading to PAN-OS 10.2.11 on devices due to Elasticsearch (ES)
getting restarted continuously.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269499</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall stopped responding when receiving a
high number of logs.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-269106</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the
<span class="ph systemoutput">wifclient</span> might crash during
server cert verification for MICA gRPC connections and cause the
dataplane to restart when using a cloud-based ML detection engine
(MICA). On certain platforms, this caused the firewall to reboot
periodically.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268972</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama was slower than expected when using a
high number of device group tags in a non-shared context.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268815</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue that caused the firewall to reboot due to the
<span class="ph systemoutput">wifclient</span> exiting multiple times
when using IoT Security.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-268465</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue with firewalls in active/passive HA configurations
where the the total user count in the registered users was different
between the active and passive firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267781</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama did not display the
<span class="ph uicontrol">Source Dynamic Address Group</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267762</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>Panorama virtual appliances in Management-Only mode</tt
>) Fixed a issue where the maximum configuration size was lower than
expected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267671</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall rebooted unexpectedly due to the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>all_task process</a
>
restarting with an OOM condition due to a memory leak on the
<a
class="term"
href="#"
title=""
data-scope=""
data-format="dita"
data-type=""
target="_self"
>reportd</a
>
process.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267662</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall experienced a memory out-of-bounds
access when the firewall was configured with SD-WAN and the SD-WAN
plugin was loading, which caused the firewall to stop responding and
drop VPN tunnels.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-267097</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the replay database size increased significantly
due to local and special configurations not being purged after
commits.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-266354</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Hybrid-SWG explicit proxy connections failed when
the number of destination domains exceeded 1024.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-265745</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall displayed incorrect MAC receive
error counters for VMWare devices hosted in ESXi.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-265219</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">VM-Series firewalls only</tt>) Fixed an issue where
GRE traffic did not work properly.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-265179</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where a kernel race condition caused the firewall to
reboot with a kernel panic.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-264423</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall sent a 503 response when a client
connected to a web server when the firewall was configured as a web
proxy and authentication bypass for Kerberos was enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-262946</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on the firewall where logging in via the CLI or web
interface did not work due to increased memory usage.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-262383</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall was unable to decompress the HTTP2
header, which caused the session to be classified as unknown-tcp
instead of web-browsing.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260461</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where traffic logs showed a non-zero destination port
number on ICMP echo sessions through the firewall.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260290</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue for fixed model licenses to support new content size
requirements by reducing the total sessions supported to be equivalent
to their flex memory counterpart.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260235</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall sent Threat logs and URL logs to an
external syslog server without Security profile settings when Enhanced
Application Logging was enabled.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-260149</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the management plane DNS cache size was lower
than expected.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-259078</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where WildFire Analysis reports were not generated and
the following error message was displayed:
<span class="ph systemoutput">Error 500: Internal Server Error</span>.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-258149</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall dropped the SYN-ACK when using the
TCP Fast Open option.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-255323</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt">PA-7050 firewalls only</tt>) Fixed an issue where
the Network Processing Card (NPC), Data Processing Card (DPC), and Log
forwarding Card (LFC) remained in a starting state after an unexpected
power cycle.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-254904</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where a core file was generated by
/usr/local/bin/logd during a restart.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-254293</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where an explicit proxy caused intermittent SSL
handshake failures to SAP applications accessing public URLs.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-252381</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the Panorama web interface was slower than
expected when opening interfaces, virtual routers, and zones in a
template or template stack.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-251484</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall web interface displayed incorrect
PPPoE configuration options under the subinterface of an Aggregate
Ethernet interface.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-250585</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where the firewall CPU use increased after upgrading
from PAN-OS 10.2.4-h4 to PAN-OS 10.2.8 due to a change in system
resource reporting by the REST API.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-248508</b></div>
</td>
<td class="entry relcol">
<div class="p">
(<tt class="ph tt"
>VM-Series firewalls on Amazon Web Services (AWS) environments
only</tt
>) Fixed an issue where the firewall did not perform MSS clamping when
GWLB endpoints were mapped to static subinterfaces.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-246699</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on Panorama where
<span class="ph uicontrol">Rule Usage</span> and
<span class="ph uicontrol">Apps Seen</span> under Security policy
rules stopped incrementing.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-233647</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where Panorama management servers generated duplicate
configuration logs.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-233581</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue on firewalls in active/active HA configurations where
SYN+ACK packets of asymmetric TCP sessions were dropped because of a
session synchronization issue.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-224152</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue where device tags for devices in a child device group
were not available in the parent shared device group.
</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p"><b class="ph b">PAN-216054</b></div>
</td>
<td class="entry relcol">
<div class="p">
Fixed an issue that caused the firewall's fan speed to increase while
it was idle.
</div>
</td>
</tr>
</tbody>
</table>