PAN-OS 11.1.4-h9 Addressed Issues
Table of Contents
Expand All
|
Collapse All
Next-Generation Firewall Docs
-
PAN-OS 11.1 & Later
- PAN-OS 11.1 & Later
- PAN-OS 11.0 (EoL)
- PAN-OS 10.2
- PAN-OS 10.1
- PAN-OS 10.0 (EoL)
- PAN-OS 9.1 (EoL)
- Cloud Management of NGFWs
-
- Management Interfaces
-
- Launch the Web Interface
- Use the Administrator Login Activity Indicators to Detect Account Misuse
- Manage and Monitor Administrative Tasks
- Commit, Validate, and Preview Firewall Configuration Changes
- Commit Selective Configuration Changes
- Export Configuration Table Data
- Use Global Find to Search the Firewall or Panorama Management Server
- Manage Locks for Restricting Configuration Changes
-
-
- Define Access to the Web Interface Tabs
- Provide Granular Access to the Monitor Tab
- Provide Granular Access to the Policy Tab
- Provide Granular Access to the Objects Tab
- Provide Granular Access to the Network Tab
- Provide Granular Access to the Device Tab
- Define User Privacy Settings in the Admin Role Profile
- Restrict Administrator Access to Commit and Validate Functions
- Provide Granular Access to Global Settings
- Provide Granular Access to the Panorama Tab
- Provide Granular Access to Operations Settings
- Panorama Web Interface Access Privileges
-
- Reset the Firewall to Factory Default Settings
-
- Plan Your Authentication Deployment
- Pre-Logon for SAML Authentication
- Configure SAML Authentication
- Configure Kerberos Single Sign-On
- Configure Kerberos Server Authentication
- Configure TACACS+ Authentication
- Configure TACACS Accounting
- Configure RADIUS Authentication
- Configure LDAP Authentication
- Configure Local Database Authentication
- Configure an Authentication Profile and Sequence
- Test Authentication Server Connectivity
- Troubleshoot Authentication Issues
-
- Keys and Certificates
- Default Trusted Certificate Authorities (CAs)
- Certificate Deployment
- Configure the Master Key
- Export a Certificate and Private Key
- Configure a Certificate Profile
- Configure an SSL/TLS Service Profile
- Configure an SSH Service Profile
- Replace the Certificate for Inbound Management Traffic
- Configure the Key Size for SSL Forward Proxy Server Certificates
-
- HA Overview
-
- Prerequisites for Active/Active HA
- Configure Active/Active HA
-
- Use Case: Configure Active/Active HA with Route-Based Redundancy
- Use Case: Configure Active/Active HA with Floating IP Addresses
- Use Case: Configure Active/Active HA with ARP Load-Sharing
- Use Case: Configure Active/Active HA with Floating IP Address Bound to Active-Primary Firewall
- Use Case: Configure Active/Active HA with Source DIPP NAT Using Floating IP Addresses
- Use Case: Configure Separate Source NAT IP Address Pools for Active/Active HA Firewalls
- Use Case: Configure Active/Active HA for ARP Load-Sharing with Destination NAT
- Use Case: Configure Active/Active HA for ARP Load-Sharing with Destination NAT in Layer 3
- HA Clustering Overview
- HA Clustering Best Practices and Provisioning
- Configure HA Clustering
- Refresh HA1 SSH Keys and Configure Key Options
- HA Firewall States
- Reference: HA Synchronization
-
- Use the Dashboard
- Monitor Applications and Threats
- Monitor Block List
-
- Report Types
- View Reports
- Configure the Expiration Period and Run Time for Reports
- Disable Predefined Reports
- Custom Reports
- Generate Custom Reports
- Generate the SaaS Application Usage Report
- Manage PDF Summary Reports
- Generate User/Group Activity Reports
- Manage Report Groups
- Schedule Reports for Email Delivery
- Manage Report Storage Capacity
- View Policy Rule Usage
- Use External Services for Monitoring
- Configure Log Forwarding
- Configure Email Alerts
-
- Configure Syslog Monitoring
-
- Traffic Log Fields
- Threat Log Fields
- URL Filtering Log Fields
- Data Filtering Log Fields
- HIP Match Log Fields
- GlobalProtect Log Fields
- IP-Tag Log Fields
- User-ID Log Fields
- Decryption Log Fields
- Tunnel Inspection Log Fields
- SCTP Log Fields
- Authentication Log Fields
- Config Log Fields
- System Log Fields
- Correlated Events Log Fields
- GTP Log Fields
- Audit Log Fields
- Syslog Severity
- Custom Log/Event Format
- Escape Sequences
- Forward Logs to an HTTP/S Destination
- Firewall Interface Identifiers in SNMP Managers and NetFlow Collectors
- Monitor Transceivers
-
- User-ID Overview
- Enable User-ID
- Map Users to Groups
- Enable User- and Group-Based Policy
- Enable Policy for Users with Multiple Accounts
- Verify the User-ID Configuration
-
- App-ID Overview
- App-ID and HTTP/2 Inspection
- Manage Custom or Unknown Applications
- Safely Enable Applications on Default Ports
- Applications with Implicit Support
-
- Prepare to Deploy App-ID Cloud Engine
- Enable or Disable the App-ID Cloud Engine
- App-ID Cloud Engine Processing and Policy Usage
- New App Viewer (Policy Optimizer)
- Add Apps to an Application Filter with Policy Optimizer
- Add Apps to an Application Group with Policy Optimizer
- Add Apps Directly to a Rule with Policy Optimizer
- Replace an RMA Firewall (ACE)
- Impact of License Expiration or Disabling ACE
- Commit Failure Due to Cloud Content Rollback
- Troubleshoot App-ID Cloud Engine
- Application Level Gateways
- Disable the SIP Application-level Gateway (ALG)
- Maintain Custom Timeouts for Data Center Applications
-
- Policy Types
- Policy Objects
- Track Rules Within a Rulebase
- Enforce Policy Rule Description, Tag, and Audit Comment
- Move or Clone a Policy Rule or Object to a Different Virtual System
-
- External Dynamic List
- Built-in External Dynamic Lists
- Configure the Firewall to Access an External Dynamic List
- Retrieve an External Dynamic List from the Web Server
- View External Dynamic List Entries
- Exclude Entries from an External Dynamic List
- Enforce Policy on an External Dynamic List
- Find External Dynamic Lists That Failed Authentication
- Disable Authentication for an External Dynamic List
- Register IP Addresses and Tags Dynamically
- Use Dynamic User Groups in Policy
- Use Auto-Tagging to Automate Security Actions
- CLI Commands for Dynamic IP Addresses and Tags
- Application Override Policy
- Test Policy Rules
-
- Network Segmentation Using Zones
- How Do Zones Protect the Network?
-
PAN-OS 11.1 & Later
- PAN-OS 11.1 & Later
- PAN-OS 11.0 (EoL)
- PAN-OS 10.2
- PAN-OS 10.1
-
- Tap Interfaces
-
- Layer 2 and Layer 3 Packets over a Virtual Wire
- Port Speeds of Virtual Wire Interfaces
- LLDP over a Virtual Wire
- Aggregated Interfaces for a Virtual Wire
- Virtual Wire Support of High Availability
- Zone Protection for a Virtual Wire Interface
- VLAN-Tagged Traffic
- Virtual Wire Subinterfaces
- Configure Virtual Wires
- Configure a PPPoE Client on a Subinterface
- Configure an IPv6 PPPoE Client
- Configure an Aggregate Interface Group
- Configure Bonjour Reflector for Network Segmentation
- Use Interface Management Profiles to Restrict Access
-
- DHCP Overview
- Firewall as a DHCP Server and Client
- Firewall as a DHCPv6 Client
- DHCP Messages
- Dynamic IPv6 Addressing on the Management Interface
- Configure an Interface as a DHCP Server
- Configure an Interface as a DHCPv4 Client
- Configure an Interface as a DHCPv6 Client with Prefix Delegation
- Configure the Management Interface as a DHCP Client
- Configure the Management Interface for Dynamic IPv6 Address Assignment
- Configure an Interface as a DHCP Relay Agent
-
- DNS Overview
- DNS Proxy Object
- DNS Server Profile
- Multi-Tenant DNS Deployments
- Configure a DNS Proxy Object
- Configure a DNS Server Profile
- Use Case 1: Firewall Requires DNS Resolution
- Use Case 2: ISP Tenant Uses DNS Proxy to Handle DNS Resolution for Security Policies, Reporting, and Services within its Virtual System
- Use Case 3: Firewall Acts as DNS Proxy Between Client and Server
- DNS Proxy Rule and FQDN Matching
-
- NAT Rule Capacities
- Dynamic IP and Port NAT Oversubscription
- Dataplane NAT Memory Statistics
-
- Translate Internal Client IP Addresses to Your Public IP Address (Source DIPP NAT)
- Create a Source NAT Rule with Persistent DIPP
- PAN-OS
- Strata Cloud Manager
- Enable Clients on the Internal Network to Access your Public Servers (Destination U-Turn NAT)
- Enable Bi-Directional Address Translation for Your Public-Facing Servers (Static Source NAT)
- Configure Destination NAT with DNS Rewrite
- Configure Destination NAT Using Dynamic IP Addresses
- Modify the Oversubscription Rate for DIPP NAT
- Reserve Dynamic IP NAT Addresses
- Disable NAT for a Specific Host or Interface
-
- Network Packet Broker Overview
- How Network Packet Broker Works
- Prepare to Deploy Network Packet Broker
- Configure Transparent Bridge Security Chains
- Configure Routed Layer 3 Security Chains
- Network Packet Broker HA Support
- User Interface Changes for Network Packet Broker
- Limitations of Network Packet Broker
- Troubleshoot Network Packet Broker
-
- Enable Advanced Routing
- Logical Router Overview
- Configure a Logical Router
- Create a Static Route
- Configure BGP on an Advanced Routing Engine
- Create BGP Routing Profiles
- Create Filters for the Advanced Routing Engine
- Configure OSPFv2 on an Advanced Routing Engine
- Create OSPF Routing Profiles
- Configure OSPFv3 on an Advanced Routing Engine
- Create OSPFv3 Routing Profiles
- Configure RIPv2 on an Advanced Routing Engine
- Create RIPv2 Routing Profiles
- Create BFD Profiles
- Configure IPv4 Multicast
- Configure MSDP
- Create Multicast Routing Profiles
- Create an IPv4 MRoute
-
-
PAN-OS 11.1
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 11.0 (EoL)
- PAN-OS 10.2
- PAN-OS 10.1
- PAN-OS 10.0 (EoL)
- PAN-OS 9.1 (EoL)
- PAN-OS 9.0 (EoL)
- PAN-OS 8.1 (EoL)
- Cloud Management and AIOps for NGFW
-
- Networking Features
- Decryption Features
- Certificate Management Features
- Management Features
- Panorama Features
- Mobile Infrastructure Security Features
- SD-WAN Features
- Zone Protection Features
- GlobalProtect Features
- IoT Security Features
- Virtualization Features
- Authentication Features
- Advanced WildFire Features
- Hardware Features
-
- PAN-OS 11.1.2 Known Issues
- PAN-OS 11.1.2-h16 Addressed Issues
- PAN-OS 11.1.2-h15 Addressed Issues
- PAN-OS 11.1.2-h14 Addressed Issues
- PAN-OS 11.1.2-h12 Addressed Issues
- PAN-OS 11.1.2-h9 Addressed Issues
- PAN-OS 11.1.2-h4 Addressed Issues
- PAN-OS 11.1.2-h3 Addressed Issues
- PAN-OS 11.1.2-h1 Addressed Issues
- PAN-OS 11.1.2 Addressed Issues
PAN-OS 11.1.4-h9 Addressed Issues
PAN-OS 11.1.4-h9 addressed issues.
Issue ID
|
Description
|
---|---|
PAN-273215
|
Fixed an issue where a syntax error in the index generation script
caused a high management plane CPU load after upgrading.
|
PAN-271912
|
Fixed an issue on Panorama where the *configd* process stopped
responding when filtering in the configuration audit window after
upgrading to PAN-OS 11.1.3.
|
PAN-271613
|
Fixed an issue where configuration pushes from Panorama to the
firewall failed due to an OOXML commit error.
|
PAN-271314
|
Fixed an issue where pushing changes to a prefix list used for BGP
from Panorama affected OSPF routes.
|
PAN-270224
|
Fixed an issue where indices were not opened after a query.
|
PAN-269956
|
Fixed an issue where the all_pktproc process stopped
responding, which caused internal path monitor failures.
|
PAN-269899
|
Fixed an issue where the Panorama web interface was slower than
expected when querying for device tags.
|
PAN-269673
|
Fixed an issue where ElasticSearch was not set up after an
upgrade.
|
PAN-269000
|
Fixed an issue where the firewall stopped responding due to a NULL
pointer dereference when path monitoring failed.
|
PAN-268972
|
Fixed an issue where Panorama was slower than expected when using a
high number of device group tags in a non-shared context.
|
PAN-268501
|
Fixed an issue where the firewall was unable to generate a TSF file
due to a full root partition.
|
PAN-266639
|
Fixed an issue where administrators were unable to edit or add
virtual router configurations when a filter was applied to the
viewer.
|
PAN-266114
|
Fixed an issue where, when a new set of URL logs came in, the content
of the earlier URL and traffic logs were lost.
|
PAN-265973
|
Fixed an issue where administrator sessions were logged out with an
ERR_CONNECTION_REFUSED error on the
browser.
|
PAN-265742
|
Fixed an issue on the Panorama web interface where the
OK button on the GlobalProtect gateway
configuration dialog box was not clickable.
|
PAN-265219
|
(VM-Series firewalls only) Fixed an issue where GRE traffic
did not work properly.
|
PAN-264871
|
Fixed an issue on Panorama where the configd process
stopped responding when viewing IP addresses on dynamic address
groups with a large number of IP addresses.
|
PAN-264249
|
Fixed an issue on the firewall where SNMP queries timed out when
using SNMP.
|
PAN-263973
|
Fixed an issue where log collectors had a low incoming log rate.
|
PAN-263287
|
The PAN-COMMON-MIB.my file was updated to support new object
identifiers (OID) to poll interface use via SNMP with table
identifiers.
|
PAN-263208
|
(PA-5440 and PA-5445 firewalls only) Fixed an issue where
interrupts were generated at a certain packet rate, and dataplane
processes missed heartbeats, which caused the dataplane to go
down.
|
PAN-263017
|
Fixed an issue where the firewall was unable to mount a disk
partition due to a corrupted filesystem.
|
PAN-261485
|
Fixed an issue where the firewall dropped the Real Time Transport
Protocol (RTP) session for the second SIP call on Persistent-DIPP
connections when the source port of the client device was reset.
|
PAN-260604
|
Fixed an issue where the firewall displayed inaccurate throughput
utilization stats in NetFlow analyzer tools.
|
PAN-260512
|
Fixed an issue where accessing the IP address of the device address
group objects from the user interface caused the
configd process to stop responding.
|
PAN-260461
|
Fixed an issue where traffic logs showed a non-zero destination port
number on ICMP echo sessions through the firewall.
|
PAN-260417
|
Fixed an issue on Panorama where
UpdateLicDB was triggered every few
minutes when firewalls with PAYG licenses were onboarded.
|
PAN-260235
|
Fixed an issue where the firewall sent Threat logs and URL logs to an
external syslog server without Security profile settings when
Enhanced Application Logging was enabled.
|
PAN-259910
|
Fixed an issue where the firewall reported the same value over
consecutive SNMP polls when asynchronous mode was enabled.
|
PAN-259881
|
Fixed an issue on Panorama where traffic log details were not
displayed under detailed log view.
|
PAN-259802
|
(Panorama appliances in high availability (HA) clusters
only) Fixed an issue where, after replacing a secondary
Panorama appliance in a Panorama HA cluster, the ElasticSearch
cluster was unable to establish SSL tunnels due to
SSLHandshakeException errors.
|
PAN-259078
|
Fixed an issue where WildFire Analysis reports were not generated and
the following error message was displayed: Error 500:
Internal Server Error.
|
PAN-258799
|
Fixed an issue where, when updating a Security Policy
Policy Optimizer, the web interface
stopped responding.
|
PAN-257961
|
Fixed an issue on Panorama where Test Security Policy
Match failed when the From or
To zone fields were populated.
|
PAN-255915
|
Fixed an issue where a memory leak in the sslmgr process
caused the firewall to restart.
|
PAN-254904
|
Fixed an issue on Panorama where a core file was generated by
/usr/local/bin/logd during a restart.
|
PAN-254577
|
Fixed an issue where a core file was created on the Log Forwarding
Card (LFC) due to a third-party software issue.
|
PAN-253829
|
Fixed an issue where the CLI command show running
security-policy timed out when the Security
policy was large.
|
PAN-252381
|
Fixed an issue where the Panorama web interface was slower than
expected when opening interfaces, virtual routers, and zones in a
template or template stack.
|
PAN-250394
|
Fixed an issue where a large amount of group data caused
serialization errors and prevented synchronization.
|
PAN-249581
|
Fixed an issue where stale BGP routes were advertised to peers even
when they were not present in the local RIB table.
|
PAN-246699
|
Fixed an issue on Panorama where the Rule
Usage and Apps Seen under
Security policy rules stopped incrementing.
|
PAN-246567
|
Fixed an issue where a firewall with a copper SFP transceiver
(PAN-SFP-CG) flapped during a commit.
|
PAN-242331
|
Fixed an issue where Prisma Access remote network firewalls
intermittently created incorrect user-to-IP-address mappings.
|
PAN-241004
|
Fixed an issue where DNS Proxy dropped client requests of the type
ns for a root domain.
|
PAN-235808
|
(Panorama appliances in Log Collector mode only) Fixed an
issue where an unnamed core file was generated after a reboot.
|
PAN-233197
|
Fixed an issue where the CLI command to set the FEC parameter for the
front panel ports was not supported on platforms supporting 25G and
100G.
|