PAN-OS 11.1.13-h12 Addressed Issues
Focus
Focus

PAN-OS 11.1.13-h12 Addressed Issues

Table of Contents


PAN-OS 11.1.13-h12 Addressed Issues

Lists the addressed issues in PAN-OS 11.1.13-h12.
The following table lists the addressed issues in PAN-OS 11.1.13-h12.
Issue ID
Description
PAN-333894
Fixed an issue where communication with Microsoft Azure services was disrupted, which resulted in application outages. This occurred when firewalls dropped SYN-ACK packets that were part of a SYN-ACK cookie mechanism activated by Azure's DDoS mitigation. With this fix, firewalls now maintain connectivity during such traffic events.
PAN-332608
Fixed an issue where firewalls intermittently disconnected from SLS. With this fix, firewalls maintained a stable connection to SLS.
PAN-332247
Fixed an issue where the proxy generated HTTP 503 errors for multiple URLs, which prevented users from connecting to servers. With this fix, the proxy now functions as expected.
PAN-329612
Fixed an issue where multicast routing entries for certain IPTV streams were not correctly installed or populated with necessary interface information, which prevented the proper forwarding of multicast traffic. With this fix, multicast traffic now forwards as expected.
PAN-325151
Fixed an issue where a system log was not generated when the proxy reached its session limit.
PAN-323485
Fixed an issue where multicast radio RTP based traffic was dropped after an upgrade when the firewall performed Cloud Inline inspection, which led to an exceeded session queue for Cloud Threat Detection.
PAN-313218
Added the following CLI commands to address QoS packet drops due to bursty traffic:
  • debug dataplane set qos-setting qos-param qlimit 300
  • debug dataplane set qos-setting qos-param red low 50 high 90
To utilize this fix, change the parameters, disable QoS, commit changes, enable QOS, and then re-commit changes.
PAN-312844
Fixed an issue where a TLSv1.3 handshake did not complete when SSL Forward Proxy was enabled. This occurred when a large ClientHello message was split across multiple TCP segments and the final segment contained only one byte.
PAN-307481
Fixed a commit failure issue that occurred after migrating from Legacy to Advanced routing on firewalls where an OSPF authentication profile was configured to use a 16-character MD5 key with key-ID 10.
PAN-291706
Fixed an issue where the software tag descriptor was always at 100, which led to resource unavailability errors and prevented users from obtaining DHCP IP addresses.
PAN-283774
Fixed an issue where the firewall placed UDP sessions into a Discard state when a DNS Sinkhole/Block action occurred, which prevented subsequent DNS requests from reusing the same session and caused DNS-related outages.
PAN-264508
Fixed an issue where Cloud Identity Engine did not fetch user-mapping details for XML API users. This occurred when the firewall learned the same IP-user mapping multiple times within a short period. With this fix, the Cloud Identity Engine now accurately fetches these user-mapping details.