Files
firewallissues/web/data/issues/PAN-OS/addressed/11.2.4-h12.md
T

5.3 KiB

type, product, version
type product version
Addressed PAN-OS 11.2.4-h12

PAN-296519

Fixed an issue where a stream receiving a reconnect signal with an associated error in Wifclient caused the entire pool to close, which resulted in a complete disconnection.

PAN-295560

Fixed an issue where, after upgrading Panorama and Log Collectors, tunnel logs were not visible in Panorama or Splunk even though traffic and threat logs were received.

PAN-293673

Fixed an issue where the firewall stopped all tasks due to an OOM condition caused by a scheduled log export using FTP to an external FTP server.

PAN-292229

Fixed an issue where Panorama was unable to retrieve userid logs from the firewall for subscribed user-ip-mappings after Panorama was rebooted.

PAN-292202

Fixed an issue where the system logs repeatedly displayed the alert Clearing snmpd.log due to log overflow due to the SNMP counters rolling over.

PAN-291716

Fixed an issue where PA-460 firewalls experienced out-of-memory (OOM) conditions, leading to device crashes and reboots.

PAN-291631

VM-Series firewalls only

Fixed an issue where the firewall frequently rebooted.

PAN-291288

Fixed an issue where the firewall rebooted unexpectedly due to a pan_task process restart related to page allocation failures.

PAN-291094

Fixed an issue the firewall experienced packet descriptor on chip and buffer spikes, which led to dropped traffic due to an unidentified traffic pattern.

PAN-291067

Fixed an issue where the devsrvr process periodically exceeded its virtual memory limit and restarted, which led to intermittent outages.

PAN-290542

Fixed an issue where the all_task process stopped responding when an additional header logging HTTP header was split across 2 packets.

PAN-290449

Fixed an issue where, when multiple scheduled vulnerability reports were sent in the same email, only the first attached report was displayed.

PAN-287818

Fixed an issue where sessions timed out sooner than expected due to the pan_proxy_accumulation_restore_timeout not initiating when the accumulation session_init failed.

PAN-287803

Fixed an issue where, after upgrading firewalls to PAN-OS 11.1.6-h1, certain websites weren't accessible when the accumulation proxy was enabled. The proxy did not use the same DF bit state as the original traffic, causing it to be fragmented and dropped elsewhere in the network.

PAN-287782

Fixed an issue where firewalls configured in vwire mode modified DSCP values from AF11 to CS0 on traffic passing through the firewall, even when QoS policy rules and DSCP rewrite settings were not configured.

PAN-287622

Fixed an issue where IPv6 traffic was affected after upgrading the firewall to PAN-OS 11.1.6-h4 and later versions. With SSL decryption enabled and a decryption policy configured for the traffic, the firewall dropped packets due to receiving a Packet Too Big ICMP message. This occurred because the PathMTU information update was incorrect for the TCB (pan-server) when the firewall was acting as a server. Additionally, the flow label under the IPv6 header was set to zero while the packet was being transmitted out of the firewall.

PAN-287601

Fixed an issue on Panorama where commits took longer than expected.

PAN-287423

Fixed an issue where content loading issues occurred on IPv6 websites due to the firewall incorrectly setting the IPv6 header flow label to 0.

PAN-286299

Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the Network and Device tabs became read-only.

PAN-285285

Fixed an issue where commits remained at 98% completion when static route configuration cleanup was in progress.

PAN-286231

Fixed an issue where a simultaneous selective push from Panorama to multiple firewalls with different base configurations resulted in configuration corruption, which caused the firewall to go down.

PAN-280698

Fixed an issue where the firewall removed the TCP timestamp from client hello messages that did not fit in a single packet, which resulted in connection issues.

PAN-279706

M-600 appliances only

Fixed an issue where Panorama did not update all panreplay database entries after performing a commit and full push to all devices.

PAN-276484

Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (Device Deployment > Licenses) due to the inability to perform batch-license refreshes.

PAN-273453

Fixed an issue where restarting the firewall did not initiate an autocommit job, which caused the firewall to stop responding and the HA interface to go down.

PAN-273300

Fixed an issue on Panorama where upgrading to PAN-OS 11.0.4-h2 failed with a validation error.

PAN-265044

Fixed an issue where the default software packet buffer size for the Advanced Header Learning (AHL) feature was excessively large, which led to inefficient use of software packet buffers.

PAN-260015

Fixed an issue on the firewall where enabling Inline Cloud Analysis features might cause the firewall to unexpectedly reboot, due to an issue related to loopback data handling.