PAN-OS 11.1.10-h32 Addressed Issues
Focus
Focus

PAN-OS 11.1.10-h32 Addressed Issues

Table of Contents

PAN-OS 11.1.10-h32 Addressed Issues

Lists the addressed issues in PAN-OS 11.1.10-h32.
The following table lists the addressed issues in PAN-OS 11.1.10-h32.
Issue ID
Description
PAN-331387
Fixed an issue where IPsec tunnels frequently went down due to high process memory utilization. With this fix, the system process now manages memory correctly, preventing tunnel instability.
PAN-330196
Fixed an issue where the firewall unexpectedly terminated operations and rebooted due to an internal software error.
PAN-328770
Fixed an issue where BGP Graceful Restart (GR) capability continued to be advertised to BGP peers after GR was disabled on a Logical Router configured with the Advanced Routing Engine, which caused peers to incorrectly believe the firewall supported GR. With this fix, disabling BGP GR on a Logical Router correctly removes the capability from BGP Open messages.
PAN-325496
(KVM VM-Series firewalls only) Fixed an issue where ARP entries were incomplete after an upgrade to an affected release.
PAN-324336
Fixed an issue where GlobalProtect iOS users were unable to connect due to the firewall incorrectly reporting that the maximum number of users was exceeded, even when the actual number of active users was below the configured limit.
PAN-323974
Fixed an issue where you were unable to add logging drives to the firewall, and validation errors occurred when pushing configurations from Panorama.
PAN-321937
Fixed an issue where an expired SD-WAN license caused SD-WAN tunnels to become unavailable, which resulted in traffic interruptions. With this fix, the device provides logs and commit messages about expired licenses.
PAN-321204
Fixed an issue where FTP-DATA sessions did not match the installed predict session, which led to session termination in HA configurations.
PAN-319343
(Prisma Access Gateways only) Fixed an issue where the global management plane stopped responding, which caused SSH and HTML disconnections, HIP database lookup failures, and significantly slower SCM commits. This occurred when egress IP allow listing was enabled in SCM and changes were made to EDLs.
PAN-314873
Fixed an issue where the firewall intermittently stopped forwarding traffic to the internet.
PAN-312685
Fixed an issue where committing a scheduled configuration push on Panorama caused the configd process to stop responding unexpectedly.
PAN-311988
(Firewalls in FIPS mode only) Fixed decryption issues that occurred after an upgrade to an affected release.
To enable this fix, run the CLI command debug dataplane set ssl-decrypt low-memory-throttle enable.
PAN-310699
Fixed an issue where the firewall stripped the Authentication Key Identifier (AKID) from certificates using SSL decryption, which prevented clients from authenticating server certificates and resulted in decryption failures.
PAN-310476
(Firewalls in active/passive HA configurations only) Fixed an issue where CPLD did not power cycle the firewall after internal packet path monitoring failures occurred, and both firewalls instead became simultaneously non-functional after a reboot.
PAN-310263
(VM-Series firewalls only) Fixed an issue where enabling TLS1.3 in a decryption profile prevented access to websites.
PAN-307933
(Panorama appliances in Log Collector mode only) Fixed an issue where the log collectors became unstable for an extended period of time when receiving large amounts of traffic.
PAN-306225
Fixed an issue on the firewall where the sslmgr process memory utilization continually increased due to memory fragmentation.
PAN-301756
Fixed an issue where ACC logs displayed a discrepancy in SSL traffic information between Panorama and the firewall. With this fix, the SSL traffic information in ACC logs now aligns correctly.
PAN-299027
(Panorama virtual appliances in Management Mode only) Fixed an issue where a maximum configuration size of 120 was incorrectly enforced instead of 150 MB.
PAN-297880
Fixed an issue where WildFire Analysis reports failed to load, displaying a 500 Internal Server Error when the system attempted to retrieve reports for certain files. With this fix, WildFire Analysis reports load as expected.
PAN-282335
Fixed an issue where firewalls in a cluster experienced approximately 50% packet loss on IPSec NATT tunnels when tunnel acceleration was enabled.
PAN-248913
Fixed an issue where the Elasticsearch client certificate was not auto renewed, which caused it to enter a Red state, and logs were not displayed in Panorama.