PAN-OS 11.1.6-h23 Addressed Issues
Table of Contents
Expand All
|
Collapse All
Next-Generation Firewall Docs
-
-
-
-
-
-
-
- PAN-OS 12.1
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 11.0 (EoL)
- PAN-OS 10.2
- PAN-OS 10.1
- PAN-OS 10.0 (EoL)
- PAN-OS 9.1 (EoL)
- PAN-OS 9.0 (EoL)
- PAN-OS 8.1 (EoL)
-
- PAN-OS 12.1
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 10.2
- PAN-OS 10.1
PAN-OS 11.1.6-h23 Addressed Issues
PAN-OSĀ® 11.1.6-h23 addressed issues.
Issue ID | Description |
|---|---|
PAN-306502 | Fixed an issue where TLS connection failure occurred when traffic was over TLS1.2 or below, header insertion was enabled on the firewall, send TLS handshake to CTD was enabled, and traffic hit a decryption policy rule configured with the no-decrypt action.
|
|
PAN-304636
|
Fixed an issue where BGP aggregate routes were not created and
discard routes were not installed in the routing table.
|
|
PAN-306226
|
Fixed an issue where the TLS handshake did not complete and the
session did not go through. This occurred if the HTTP header
insertion applied to an HTTP CONNECT request passing through the
firewall, the scan-handshake feature was enabled, the session
matched a decryption policy rule with the decrypt action, and if the
TLS client hello was in a single packet and TLS 1.2 or below.
|
PAN-304496 | Fixed an issue where, after unregistering an IP tag and registering a different IP tag for the same IP address via XML API, the dynamic address group membership was not updated on the dataplane, which resulted in Security policy rules being enforced incorrectly.
|
|
PAN-303954
|
Fixed an issue where, when configuring Safenet HSMs in HA and
authentication HSM manually, the second HSM server failed to
authenticate due to the firewall overwriting the first HSM server's
certificate with the second HSM server's certificate.
|
|
PAN-303051
|
Fixed an issue on Panorama where a memory leak occurred related to
the reportd process due to retaining memory that was
temporarily used for report generation instead of releasing the
memory for reuse, which resulted in continuous accumulation and
memory exhaustion.
|
PAN-301801 | Fixed an issue on Log Collectors where the Elasticsearch process fluctuated intermittently between green and red states, which led to interruptions in log collection. This issue occurred when the number of shards exceeded the cluster's maximum supported threshold of greater than 1000 shards per Elasticsearch instance.
|
PAN-300637 | (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where the firewall unexpectedly rebooted due to repeated varrcvr process restarts.
|
|
PAN-300548
|
Fixed an issue where using the IKEv2 multiplier setting for VPN
re-authentication resulted in the firewall not re-authenticating at
the expected intervals when both sides initiated rekeying. The
internal re-authentication counter incremented when the local side
triggered the rekey, but not when the peer side triggered it.
|
PAN-297975 | Fixed an issue where Panorama was unable to push the Trusted Root CA configuration to Log Collectors via a Collector Group push due to the Log Collector not supporting the trusted-root-CA configuration.
|
PAN-297708 | Fixed an issue where a long-lived session with many Machine Learning (ML) model triggers caused a memory leak of feature states associated with the ML model runs. This resulted in Spyware_State failure increases, allocation max outs, and impaired policy matching.
|
|
PAN-297610
|
Fixed an issue where the firewall became unresponsive after an
upgrade due to the fsck command scanning drive
partitions in parallel with the root partition, which caused the
process to take an extended amount of time.
|
PAN-297295 | (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the firewall repeatedly restarted due to high packet rates on the synthetic path in DPDK mode.
|
|
PAN-288158
|
(VM-Series firewalls only) Fixed an issue where the firewall
became inaccessible via the web interface and SSH and remained in an
initializing state.
|
PAN-287611 | Fixed an issue where, after upgrading, the firewall incorrectly calculated the UDP checksum for RTP traffic after NAT and Security policy application, which led to dropped packets and silent calls in applications.
|
|
PAN-284866
|
Fixed an issue where the LFC failed to validate Certificate
Revocation Lists (CRL) for SSL syslog connections, which caused a
failure to forward logs to external syslog servers.
|
|
PAN-278126
|
Fixed an issue where the number of registered IP Tags on Panorama did
not match the number of registered IP Tags on the managed firewalls
due to a change in file format between PAN-OS releases.
|
PAN-274742 | (VM-Series firewalls only) Fixed an issue where the task-queue dump CLI command returned incorrect information in multi-nic mode.
|
|
PAN-274697
|
Fixed an issue where push operations from Panorama failed on passive
firewalls when an application was removed from a Security policy
rule and the policy rule was referenced in a device group.
|
|
PAN-270554
|
Fixed an issue where the GlobalProtect client (UWP) or metered
hotspot connections triggered TLS resumption for GlobalProtect
portal authentication, which caused the portal authentication to
fail with a valid cert required error.
|
|
PAN-260090
|
Fixed an issue where commit all operations failed when the
application openair-psa was used as a
keyword on a remote network instance that was upgraded to an
affected release.
|
PAN-257616 | Fixed an issue where selective push operations from Panorama to managed firewalls failed with the error message Failed to generate selective push configuration. Schema validation failed. Please try a full push.
|
PAN-257362 | Fixed an issue where GlobalProtect traffic destined for the internet did not follow the path-based forwarding (PBF) rule and was sent out the wrong interface.
|
PAN-255253 | Fixed an issue where the firewall did not establish a syslog connection to the probe VM syslog server in ADEM Regressions.
|
|
PAN-242602
|
Fixed an issue where GlobalProtect clients experienced slow SMB-V3
download throughput when passing through a Prisma IPSec tunnel and
the firewall and the SMB-V3 session owner dataplane was the same as
the IPSec-ESP tunnel on the multi-dataplane firewall.
|
PAN-241694 | Fixed an issue where memory leaks related to the devsrvr process occurred when downloading and pushing updates from the App-ID Cloud Engine to the dataplane.
|