PAN-OS 11.2.15 Addressed Issues
Focus
Focus

PAN-OS 11.2.15 Addressed Issues

Table of Contents

PAN-OS 11.2.15 Addressed Issues

Lists the addressed issues in PAN-OS 11.2.15.
The following table lists the addressed issues in PAN-OS 11.2.15.
Issue ID
Description
Fixes were made to address the following CVEs:
PAN-336162
Fixed an issue where commits involving routing related network configuration changes experienced slower than usual completion times or remaining at 20% completion.
PAN-333488
Fixed an issue where a selective push operation from Panorama removed active configurations from a firewall when the push payload excluded changes committed by other administrators that had not yet been pushed. This resulted in the affected device group entering an out-of-sync state. With this fix, selective push operations correctly preserve all active configurations on the firewall.
PAN-332608
Fixed an issue where firewalls intermittently disconnected from SLS. With this fix, firewalls maintained a stable connection to SLS.
PAN-332258
Fixed an issue where the mprelay process stopped responding unexpectedly, which led to the pan_task process becoming unresponsive and subsequently caused path monitoring issues.
PAN-332247
Fixed an issue where the proxy generated HTTP 503 errors for multiple URLs, which prevented users from connecting to servers. With this fix, the proxy now functions as expected.
PAN-331856
Fixed an issue where the firewall unexpectedly terminated the DNS proxy process when it received TCP/53 DNS queries on an interface configured for DNS proxy, which led to repeated firewall reboots and temporary unavailability of the web interface. With this fix, the firewall processes TCP/53 DNS queries without interruption.
PAN-331840
(VM-Series firewalls in Azure environments only) Fixed an issue where a hotplug event caused a system process to unexpectedly stop responding, which led to a firewall reboot.
PAN-331387
Fixed an issue where IPsec tunnels frequently went down due to high process memory utilization. With this fix, the system process now manages memory correctly, preventing tunnel instability.
PAN-331386
Fixed an issue where the firewall incorrectly routed DNS traffic from the management interface instead of the configured service route interface when an address object was set as the source address. With this fix, DNS traffic now correctly uses the designated service route interface.
PAN-330196
Fixed an issue where the firewall unexpectedly terminated operations and rebooted due to an internal software error.
PAN-330124
(VM-Series firewalls in Microsoft Azure environments integrated with Azure Gateway Load Balancer (GWLB)) Fixed an issue where SSL decryption did not function correctly for connections when the accumulation proxy was enabled, which caused the firewall to send an ACK packet through an incorrect tunnel. With this fix, SSL decryption operates as expected.
PAN-330095
(VM-Series firewalls in AWS Cloud Mode with Geneve-based service chaining) Fixed an issue where the firewall experienced unexpected reboots and a temporary loss of connectivity. This occurred when the mprelay process attempted to process system object modifications involving Geneve service chain metadata, which led to repeated process interruptions and a system reboot. With this fix, the firewall now handles these operations without interruption.
PAN-330016
Fixed an issue where enabling App Acceleration resulted in connectivity disruption for GlobalProtect users and branches connected through ION devices, which prevented access to applications. With this fix, App Acceleration functions as expected without causing connectivity issues.
PAN-329965
Fixed an issue where commit operations failed due to redis idmgr connection leaks. With this fix, commit operations complete as expected.
PAN-329834
Fixed an issue where a memory leak associated with some display CLI commands caused instability.
PAN-329809
Fixed an issue where testing an SCP server connection from the Panorama web interface returned an error instead of prompting to allow the host key, which prevented the successful establishment of the connection. With this fix, the system now correctly prompts to allow the host key.
PAN-329793
Fixed an issue where the characters in PDF Summary Reports did not display correctly when the Locale was set as Japanese, Korean, Simplified Chinese, or Traditional Chinese.
PAN-329698
(OCTEON, MIPS, platforms only) Fixed an issue where the dataplane became unresponsive. With this fix, the dataplane operates stably.
PAN-329675
Fixed an issue where a Strata Logging Service license showed as failing to install even though it was successfully fetched.
PAN-329637
Fixed an issue where the push scope window did not display the target devices when attempting to push configurations from Panorama, which required manual selection of templates or device groups. With this fix, the push scope window now correctly populates with the intended push scope.
PAN-329550
Fixed an issue where the firewall experienced unexpected process terminations, which resulted in an HA failover and led to the dataplane becoming unresponsive.
PAN-329182
(Panorama virtual appliances in management only mode deployed in AWS only) Fixed an issue where Panorama failed to mount panlogs.
PAN-329180
Fixed an issue where Panorama did not automatically resume syslog forwarding over TCP after the syslog server became unavailable or was restarted.
PAN-329034
Fixed an intermittent issue where firewall restarted unexpectedly while processing zip files.
PAN-328837
Fixed an issue where firewalls did not generate system logs when an administrator cleared logs, which impacted auditing capabilities. With this fix, firewalls now generate system logs for log clearing events.
PAN-328770
Fixed an issue where BGP Graceful Restart (GR) capability continued to be advertised to BGP peers after GR was disabled on a Logical Router configured with the Advanced Routing Engine, which caused peers to incorrectly believe the firewall supported GR. With this fix, disabling BGP GR on a Logical Router correctly removes the capability from BGP Open messages.
PAN-328742
Fixed an issue where the dataplane silently dropped HTTP POST payloads, which disrupted application integrations. This occurred due to an internal error when processing XFF headers within the CTD engine.
PAN-328712
Fixed an issue on the web interface where HA related filter options (HA Cluster ID, HA Cluster State, and HA Pair Status) disappeared from the Commit > Push to Devices > Edit Selection) window in Panorama when the window was reopened within the same login session. With this fix, these options remain visible as expected.
PAN-328654
Fixed an issue on the web interface where some threats were incorrectly displayed as Threat ID instead of Threat Name.
PAN-328625
(Firewalls in active/passive HA configurations only) Fixed an issue where Genetec camera streaming experienced lag and dropped video feeds due to the exhaustion of private RTP ports, which led to their accumulation over time. With this fix, the firewall now properly releases private RTP ports, preventing their exhaustion.
PAN-328145
Fixed an issue where a firewall functioning as an Area Border Router did not correctly translate NSSA Type-7 LSAs to Type-5 LSAs when OSPF neighbors set the Nt bit in the NSSA Area, and routes were not advertised to upstream OSPF neighbors in the backbone area, which resulted in traffic being silently discarded.
PAN-327960
Fixed an issue where firewalls experienced continuous unexpected restarts and entered a suspended state due to improper processing of certain URLs. With this fix, firewalls maintain stable operation in HA configurations.
PAN-327858
Fixed an issue where access to websites was interrupted or pages rendered incompletely when SSL/TLS decryption was enabled due to the firewall prematurely terminating sessions upon receiving a TLS Close Notify alert. With this fix, the firewall properly handls TLS Close Notify alerts, allowing complete page rendering.
PAN-327812
Fixed an issue where a process remained in a recursive loop when processing queued packets after hold mode was disengaged, particularly when handling ADNS traffic with failed wif-forward responses, which led to system instability. With this fix, the process properly continues packet processing.
PAN-327603
Fixed an issue where user-ID mappings for a user were incorrectly cleared during a user group synchronization event when the user was removed from one group before being added to another. With this fix, user-ID mappings are correctly updated during group changes.
PAN-327460
Fixed an issue where a Commit and Push operation on Panorama did not successfully push configuration changes to Prisma Access endpoints. This occurred when the system reported that not all commit jobs were triggered. With this fix, Commit and Push operations now correctly apply configurations to Prisma Access.
PAN-327443
Fixed an issue where log forwarding stopped. With this fix, log forwarding resumes normal operation.
PAN-327295
Fixed an issue where critical alerts related to registered IP address updates appeared in system logs even when User-ID was not configured due to a conflict during simultaneous updates of IP tags and EDLs.
To enable this fix, run the CLI command debug user-id regip-max-update-retry rate <value> with a value between 30 and 300.
PAN-327266
Fixed an issue where IP addresses configured for Source Address Exclusions in a Zone Protection Profile within a template stack did not save correctly. With this fix, the IP addresses save as expected.
PAN-327011
Fixed an issue where the firewall was unable to revert locally overridden configurations for permitted IP addresses on the management interface after an upgrade. With this fix, the configuration could be reverted as expected.
PAN-327009
Fixed an issue where the all_task process stopped responding.
PAN-326933
(PA-440 firewalls only) Fixed an issue where Management Plane (MP) CPU utilization frequently spiked to 100%, which triggered critical alerts. With this fix, the Management Plane CPU utilization remained stable under normal operating conditions.
PAN-326734
Fixed an issue where a Security policy rule configured in the Shared device group on Panorama was not displayed in the web interface for a child device group, which caused a discrepancy between the displayed configuration and the actual deployed configuration on the associated device. With this fix, the user interface accurately reflects the deployed security policy rules.
PAN-326705
Fixed an issue where high CPU utilization occurred on one of the CPU cores.
PAN-326694
Fixed an issue where enabling multi-vsys on a firewall with shared override nodes created duplicate configuration nodes, which caused commit operations to fail. With this fix, enabling multi-vsys no longer duplicates configuration nodes.
PAN-326677
Fixed an issue where a selective push from Panorama to the firewall was successful even when applying rename operation failed in selective push, which resulted in configurations on the firewall being deleted. With this fix, the selective push will fail when applying rename operation fails.
PAN-326354
Fixed an issue where the sslmgr process stopped responding when attempting to display the OSCP host cache.
PAN-326056
Fixed an issue where ACE applications did not match the correct Security policy rules when the service was not set to Application Default after an upgrade, which caused traffic to be incorrectly denied.
PAN-326054
Fixed an issue where Zone Protection dropped legitimate TCP scan traffic despite the source IP address being configured in the Source Address Exclusion list, which resulted in the blocked IP address not appearing in the dos-block table. With this fix, Zone Protection correctly applies source address exclusions and displays blocked IP addresses in the dos-block table.
PAN-325936
Fixed an issue where the log purging process on the Panorama log collector would not complete successfully, which prevented logs from being automatically removed after their configured retention period. With this fix, logs are purged as expected according to their retention settings.
PAN-325904
Fixed an issue where Panorama continued to display a message prompting a device reboot to activate changes, even after the managed device had been rebooted. This occurred after certain configuration changes, such as enabling jumbo frames, which caused the message to persist incorrectly. With this fix, the message now clears as expected after the device reboots.
PAN-325903
Fixed an issue where, after upgrading Panorama, a custom admin role with Object Level Changes disabled did not automatically populate out-of-sync firewalls in the push scope.
PAN-325890
Fixed an issue where licenses were not installed after bootstrapping a VM-Series firewall in an air-gapped environment.
PAN-325724
Fixed an issue where importing PKCS12 certificates failed with the error Import of certificate and private-key failed. Failed to extract certificate.
PAN-325496
(KVM VM-Series firewalls only) Fixed an issue where ARP entries were incomplete after an upgrade to an affected release.
PAN-325151
Fixed an issue where a system log was not generated when the proxy reached its session limit.
PAN-325120
Fixed an issue on PA-415, PA-415-5G, PA-445, PA-455, and PA-455-5G platforms where certain PAN-OS versions caused intermittent connectivity failures on the Eth1/1 data port and loss of power on PoE ports.
PAN-325105
Fixed an issue where a GlobalProtect gateway would not request a Host Information Profile (HIP) report from a client even when the client generated a new MD5 sum, which resulted in the firewall incorrectly determining that a new HIP report was not required and led to outdated information in the HIP match logs. With this fix, the gateway properly requests updated HIP reports when a new MD5 sum is detected.
PAN-325057
Fixed an issue where TCP sessions were dropped due to an ACK-out-of-window condition during TCP reassembly when SYN cookies were enabled in a Zone Protection Profile. With this fix, TCP session establishment with SYN cookies enabled correctly tracks sequence numbers and no longer drops valid ACK packets from the Server.
PAN-325002
(Google Cloud NGFW Enterprise VM-Series firewalls only) Fixed an issue where the HTTP2 threat logs did not include VPC ID, Security_key, and Endpoint ID.
PAN-324966
Fixed an issue on the web interface where you were unable to view new or modified App-IDs under Review Policy or Review Apps.
PAN-324902
Fixed an issue where exporting Custom Reports to CSV failed with a UnicodeEncodeError message when report entries contained multibyte characters.
PAN-324734
(Panorama only) Fixed an issue where the log daemon (logd) would restart periodically, which resulted in commit operations failing with a "Client logd not connected" error. This issue occurred when SD-WAN site names contained special characters or exceeded a specific length. With this fix, the log daemon remains stable and commit operations complete successfully.
PAN-324652
Fixed an issue where selective configuration pushes from Panorama failed after an upgrade, which caused shared policy rules to go out of sync. With this fix, selective configuration pushes complete successfully and policies remain in sync.
PAN-324370
Fixed an issue where IDE traffic did not function as expected when both HTTP head insertion and DLP inspection were enabled.
PAN-324336
Fixed an issue where GlobalProtect iOS users were unable to connect due to the firewall incorrectly reporting that the maximum number of users was exceeded, even when the actual number of active users was below the configured limit.
PAN-324275
Fixed an issue where requesting logging service forwarding certification information via the CLI did not work.
PAN-324136
Fixed an issue where the CRL download failed because it followed the Service Route Setting instead of the CRL's own setting. The fix allows CRL to follow its own setting, enabling the download to succeed.
PAN-324128
Fixed an issue where Panorama pushed an incorrect configuration to a firewall during a selective push, which occurred when the system would incorrectly select an older base configuration version after a successful push with large configuration lines. With this fix, Panorama now correctly handles selective pushes, ensuring the latest configuration is applied or the push fails as expected.
PAN-323842
Fixed an issue where commits intermittently failed on some Prisma Access nodes with the error message client pppoed phase 1 failure.
PAN-323798
Fixed an issue where firewalls experienced frequent, unexpected reboots, which occurred when internal processes became unresponsive and exceeded their restart limits. With this fix, firewalls no longer experience these unexpected reboots.
PAN-323501
Fixed an issue where SWG Explicit Proxy Kerberos authentication bypass did not occur for some URLs that matched a configured URL category.
PAN-323485
Fixed an issue where multicast radio RTP based traffic was dropped after an upgrade when the firewall performed Cloud Inline inspection, which led to an exceeded session queue for Cloud Threat Detection.
PAN-323249
(M-700 appliances only) Fixed an issue where the Elasticsearch processes repeatedly restarted and log collectors showed the Elasticsearch health status as red.
PAN-323243
Fixed an issue where the configd process stopped responding occurred when a Security policy rule was updated or refreshed in the web interface.
PAN-323219
Fixed an issue where an error message was displayed that an IoT Security license was required even when the firewall had a valid Enterprise IoT license, which resulted in devices not appearing under Objects > Devices but correctly appearing in SCM.
PAN-323154
Fixed an issue where Real-time Transport Protocol (RTP) packets were dropped after an upgrade, which occurred due to a predict session conversion failure and resulted in delayed or absent video streams. With this fix, RTP packets are processed correctly, and video streams display without delay.
PAN-323141
Fixed an issue where SD-WAN SaaS monitoring for HTTPS URLs continuously flapped, which caused frequent traffic shifting between ISPs. This occurred due to the firewall unexpectedly hitting resource limits for monitoring.
PAN-322815
(VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where the firewall entered maintenance mode after enabling FIPS-CC mode and rebooted.
PAN-322804
Fixed an issue where OSPF learned routes were not advertised to other OSPF peers, even when OSPF adjacencies were in a full state. This occurred when OSPF packets fragmented internally before transmission.
PAN-322402
Fixed an issue where ACC reports for a duration of seven or more days did not fully load or displayed partial information.
PAN-322390
Fixed an issue where the Enhanced Application Logging status in the Logging Service Status dashboard displayed as gray and indicated 0/0 connections, even though EAL logs were successfully forwarded to Cortex XDR.
PAN-322325
(PA-3400, PA-5400, PA-5500, and PA-5500l platforms with dedicated log interfaces only) Fixed an issue where email forwarding failed silently when the SMTP gateway was reachable only via the log-interface, even when test emails were forwarded successfully.
PAN-322159
This issue was addressed in this release.
PAN-322137
Fixed an issue where log retention policies prematurely purged Infrastructure and Audit logs, which occurred because the system removed entire log indices instead of only logs older than the configured retention period. With this fix, log retention policies correctly preserve logs for the specified duration.
PAN-321937
Fixed an issue where an expired SD-WAN license caused SD-WAN tunnels to become unavailable, which resulted in traffic interruptions. With this fix, the device provides logs and commit messages about expired licenses.
PAN-321816
Fixed an issue where processes stopped responding unexpectedly.
PAN-321699
Fixed an issue where device telemetry intermittently failed to send files, which resulted in critical alerts in system files.
PAN-321516
Fixed an issue where the dataplane restarted due to a race condition in the dataplane cache infrastructure.
PAN-321465
Fixed an issue where the IP-MIB (Management Information Base) reported an incorrect value for IPv6 address prefixes. With this fix, the correct IPv6 address prefix values are now reported.
PAN-321340
(Firewalls in FIPS mode only) Fixed an issue where GlobalProtect unexpectedly prompted for RADIUS authentication instead of client certificate authentication due to an OSCP validation error and subsequent CRL verification failure, which led to certificates being marked as invalid.
PAN-321282
Fix an issue where the AI Security profile was referenced in the Security profile group, which caused the device group to remain out of sync after a selective push to devices for device groups.
PAN-321222
Fixed an issue where you were unable to create an HTTP server profile an API key certificate was configured. This occurred because the generated API key exceeded the maximum character limit.
PAN-321204
Fixed an issue where FTP-DATA sessions did not match the installed predict session, which led to session termination in HA configurations.
PAN-321150
Fixed an issue where the interface remained down after an upgrade.
PAN-321084
(VM-Series firewalls on ESXi platforms only) Fixed an issue where enabling link monitoring caused the brdagent process to stop responding, which caused system instability, interface outages, split-brain conditions in HA pairs, and a reboot during failover.
PAN-321081
Fixed an issue where Log Quotas incorrectly displayed a value that was higher than possible.
PAN-321060
Fixed an issue where an ethernet interface remained in a down state after repeated automated enable/disable cycles and required manual intervention, which resulted in backup outages.
PAN-320966
Fixed an issue where the Panorama web interface incorrectly displayed pending template changes and outdated configurations for managed firewalls, which caused the firewalls to be flagged as out of sync even after successful configuration pushes. With this fix, Panorama accurately reflects the configuration state of managed firewalls.
PAN-320643
Fixed an issue where a system process terminated unexpectedly, which caused the device to restart and resulted in an extended service interruption. With this fix, the device maintains stable operation.
PAN-320598
Fixed an issue where internal and external DNS names did not resolve when connected to a GlobalProtect gateway.
PAN-320420
Fixed an issue where the show running resource-monitor ingress-backlogs API call returned an unexpected error instead of the expected resource monitoring information.
PAN-320370
Fixed an issue where your firewall, configured as a Dynamic Host Configuration Protocol (DHCP) client, unexpectedly changed its DHCP server IP address. This resulted in the firewall receiving negative acknowledgments (NAKs) during lease renewals and using an unintended DHCP server. This occurred when the DHCP client received a second DHCP Offer from a different server after completing its initial lease acquisition process. With this fix, your firewall maintains the correct DHCP server IP address, ensuring stable lease renewals.
PAN-320345
Fixed an issue where the firewall repeatedly restarted when the monitored User-ID server became unreachable during Kerberos authentication connection attempts, which caused the authentication process to stop responding. On firewalls in HA configurations, both peer firewalls entered maintenance mode.
PAN-320324
Fixed an issue where incorrect source region information appeared in GlobalProtect logs, which occurred because the location service lookup did not consistently return region information for public IP addresses. With this fix, accurate source region information is consistently displayed.
PAN-320290
Fixed an issue where ACC reports did not display data under the Area and Column graphs. This occurred when the report included dates prior to March 8.
PAN-320062
Fixed an issue where changing a firewall's master key caused template configuration, previously pushed by Panorama, to be incorrectly copied to the firewall's local running configuration, which resulted in the configuration persisting on the firewall even after it was removed from the Panorama template. With this fix, the template configuration is correctly managed.
PAN-319940
Fixed an issue where the set system setting target-vsys command output displayed the virtual system (vsys) ID in both columns. With this fix, the command output now correctly displayed the vsys ID and the corresponding vsys name.
PAN-319889
Fixed an issue where a firewall became non-functional when dataplane and control plane monitoring processes exited due to missed heartbeats, which occurred after a dataplane crash. With this fix, the firewall maintained operational stability.
PAN-319798
(Panorama virtual appliances in AWS environments only) Fixed an issue where logging disks failed to mount or reported an unknown file system type.
PAN-319793
Fixed an issue where, after upgrading to PAN-OS 12.1.5, GlobalProtect Clientless VPN failed to access JavaScripts.
PAN-319656
Fixed an issue where security policies intermittently did not apply as expected to users, which resulted in inconsistent access. This occurred because the User-ID Agent learned user identities in multiple formats, such as User Principal Name (UPN) and Security Account Manager (SAM) account names, which led to inconsistent group mapping and unreliable policy enforcement. With this fix, security policies apply consistently based on user group memberships.
PAN-319570
Fixed an issue where shadow rule and duplicate rule warnings did not appear during the validation stage of a configuration commit operation, which prevented administrators from addressing these issues before the final commit to the device. With this fix, these warnings now appear during the validation stage.
PAN-319557
Fixed an issue where graphical counters did not display correctly in the control plane or dataplane monitor logs.
PAN-319504
Fixed an issue where telemetry data was not sent to the cloud due to the firewall being unable to resolve the destination server's FQDN even when a proxy server was configured. With this fix, the firewall properly sends telemetry data through the configured proxy server without requiring direct public DNS resolution for the telemetry server's FQDN.
PAN-319481
Fixed an issue on Panorama where system logs did not display the firewall serial numbers when Panorama retrieved logs from the SLS.
PAN-319419
(Firewalls in active/passive HA configurations only) Fixed an issue where active firewalls were unable to send device telemetry data to CDL.
PAN-319415
(Firewalls in active/passive HA configurations only) Fixed an issue where the passive firewall's device certificate failed to automatically renew when the custom service route through data interface configured only for paloalto-networks-services but not for dns service. This occurred due to a logic error that caused the passive device to attempt a direct renewal through its own inactive data interface instead of properly tunneling the renewal through the active device via the HA1 interface. Because data ports cannot forward traffic on a passive firewall, the connection timed out, preventing automatic renewal.
PAN-319352
Fixed an issue where the firewall rebooted unexpectedly without any configuration or power changes.
PAN-319343
(Prisma Access Gateways only) Fixed an issue where the global management plane stopped responding, which caused SSH and HTML disconnections, HIP database lookup failures, and significantly slower SCM commits. This occurred when egress IP allow listing was enabled in SCM and changes were made to EDLs.
PAN-319342
Fixed an issue where, after upgrading Panorama, HA firewalls did not consistently group together in the Panorama interface even though HA was enabled on both peers.
PAN-319335
Fixed an issue where the firewall did not follow configured management proxy settings for OCSP and CRL queries, and instead reverted to default configurations after a process restart.
PAN-319288
Fixed an issue where a DPC in Slot 4 restarted repeatedly, which caused internal path monitoring failures and a failover event.
PAN-319266
(Cloud IPS only) Increased scale limit for zone mappings.
PAN-319228
Fixed an issue where External Dynamic List (EDL) refresh and commit operations remained in a pending state, which prevented any subsequent operations from completing.
PAN-319136
Fixed an issue where the firewall generated high-severity system log alerts due to a certificate trust issue during SSL handshakes.
PAN-319029
(Firewalls in an Active/Active HA configuration only) Fixed an issue where a discrepancy occurred between the total number of allocated sessions and the sum of active sessions on the secondary Active node. With this fix, the session counts now accurately reflect the active sessions.
PAN-318991
(PA-440 and PA-220 firewalls only) Fixed an issue where SNMP-reported ingress traffic statistics for tunnel interfaces were approximately doubled after a PAN-OS upgrade, which led to inaccurate monitoring data. With this fix, SNMP traffic statistics for tunnel interfaces now report accurate ingress traffic.
PAN-318990
(GlobalProtect dual-profile MacOS/Windows deployments only) Fixed an issue where GlobalProtect commit warnings incorrectly flagged SAML default browser mismatches between authentication profiles and agent configurations.
PAN-318949
Fixed an issue where irrelevant error messages related to IoT devices filled the logrcvr logs.
PAN-318784
Fixed an issue where the firewall stopped processing traffic and all VPN tunnels went down even when the firewall remained in an active state, and the CLI became unresponsive.
PAN-318619
Fixed an issue where Geneve ingress traffic did not use the correct public IP address for return traffic.
PAN-318614
(PA-7080 firewalls only) Fixed an issue where the Strata Logging Service (SLS/CDL) status displayed a device connectivity error erroneously.
PAN-318580
Fixed an issue where processes restarted and the firewall unexpectedly rebooted when you configured a Security policy rule with Source Device > quarantine.
PAN-318567
Fixed an issue where the OpenConfig plugin stopped working after a configuration update.
PAN-318472
Fixed an issue where traffic to multiple websites intermittently encountered a block page, which occurred because traffic was incorrectly matched to a default security policy instead of the intended allow policy. With this fix, traffic is processed according to the configured security policies.
PAN-318412
(On Panorama in management-only mode) Fixed an issue where the ACC SSL Activity tab did not display the statistics table. With this fix, the ACC SSL Activity tab now properly shows the statistics table.
PAN-318382
(Firewalls in HA configurations only) Fixed an issue where the secondary firewall remained at an Initial state after an upgrade.
PAN-318275
(VM-Series firewalls only) Fixed an issue where the firewall became unresponsive and did not automatically reboot, which led to prolonged outages. With this fix, the Linux kernel configuration will trigger a system panic and reboot.
PAN-318205
(Firewalls in active/passive HA configuration) Fixed an issue where the dnsproxy process would unexpectedly terminate, which led to an out-of-memory condition and affected network connectivity. With this fix, the dnsproxy process now maintains stable operation.
PAN-318186
Fixed an issue where Selective Push operations failed after a partial revert was performed for deleted objects in a Panorama device group, which led to invalid object references.
PAN-318120
Fixed an issue where SSL traffic was silently dropped when traffic was processed by a Security policy with an Anti-Spyware profile that had Inline cloud Analysis enabled for SSL C2 Detector with an action other than allow or alert.
PAN-318106
Fixed an issue where SCM did not update device telemetry for the firewall after upgrading to an affected release.
PAN-318033
Fixed an issue where IP mappings would remain with future timestamps, which prevented them from being visible through the command-line interface and from being cleared using standard commands. This behavior was caused by an NTP issue, which resulted in IP mappings not functioning as expected. With this fix, IP mappings are correctly managed and cleared.
PAN-318030
VM-Series firewalls in Hyper-V only) Fixed an issue where the throughput was reported to be twice as high as the actual traffic rate.
PAN-317904
Fixed an issue where you were unable to retrieve WildFire private content updates with when custom certificates were configured for authentication between the firewall and WildFire appliance.
PAN-317858
Added a CLI command to address an issue where ethernet trailer padding was not removed during IPv4-to-IPv6 packet translation. This occurred when the original packet contained ethernet trailers and the translated packet exceeded the minimum MTU.
PAN-317772
Added a fix to improve performance in lossy network conditions.
PAN-317755
Fixed an issue on Panorama where selective push operations failed when plugin configurations included access-domain or log-collector references.
PAN-317749
Fixed an issue where the commit scope preview for a vsys incorrectly displayed configuration changes made in other vsys, even when the commit only applied changes to the intended vsys.
PAN-317648
(PA-5450 firewalls and PA-7000 Series firewalls with 100G NPCs only) Fixed an issue where intermittent packet loss occurred when traversing the dataplane after upgrading the firewall. This occurred when a dataplane HA interface was configured in an environment where Slot 1 was unpopulated , which resulted in a wildcard entry being created within the QMAP table.
PAN-317614
Fixed an issue where high throughput and increased packet rates caused high dataplane CPU usage.
PAN-317600
(Firewalls in HA configurations only) Fixed an issue where autocommit operations took longer than expected to complete when the firewalls were configured with multiple vsys and EDLs. This occurred because the firewalls were unable to reach the DNS server during the autocommit process.
PAN-317598
(Firewalls in active/active HA configurations only) Fixed an issue where NAT failures occurred due to the IP pool not releasing unused resources in the Active Secondary firewall. This occurred because the secondary firewall attempts to release a Persistent DIPP NATed port that was originally allocated by the NAT policy from first firewall, leading to a ownership mismatch during the session teardown process.
PAN-317583
Fixed an issue with intermittent ICMP ping drops and packet loss in traffic flows between a hub and branch after upgrading to an affected PAN-OS release due to incorrect SD-WAN path monitor state.
PAN-317466
Fixed an issue where SIP sessions stopped progressing after the firewall received fragmented packets, fragmented at header field.
PAN-317372
Fixed an issue where custom administrators received an access denied error when attempting to view specific policy rule details from the Rule Shadow tab after a push from Panorama, even when the administrator had permissions to view Security policy rules.
PAN-317215
(VM-Series firewalls on ESXi with Intel E810 NICs using PCI passthrough) Fixed an issue where the brdagent process became unresponsive during data port initialization. This issue caused system instability, interface outages, HA split-brain conditions (which occur when nodes in a cluster lose communication with each other, remain operational, and independently assume they are the primary active unit), and unexpected reboots during failover.
PAN-317214
Fixed an issue where SNMP queries for TCP connections per second (CPS) metrics on single vsys firewalls returned inconsistent values.
PAN-317177
Fixed an issue on firewalls in DHCP Client mode where, after upgrading to an affected release, the SNMP process unexpectedly restarted after a commit, which led to false interface flap notifications on SNMP managers.
PAN-317068
Fixed an issue on the Panorama web interface where you were able to enable IPv6 for IKE gateways and IPSec tunnels even when IPv6 WAN was disabled, which resulted in an invalid configuration. To utilize this fix, upgrade to the latest Panorama plugin.
PAN-316979
Fixed an issue where the firewall rebooted unexpectedly when packet-diag logging was enabled. With this fix, the firewall maintains stability when this logging is active.
PAN-316978
Fixed an issue where system log error messages were displayed after every firewall reboot, even when the firewall functioned correctly after the reboot.
PAN-316937
Fixed an issue where GlobalProtect users intermittently received incorrect private IP addresses after connecting to a gateway behind a Network Load Balancer (NLB).
PAN-316922
Fixed an issue where BGP Conditional Router Advertisement did not function as expected after a change was made to the BGP configuration. With this fix, BGP Conditional Router Advertisement now behaves as intended.
PAN-316911
(VM-Series firewalls on Amazon Web Services (AWS) environments only) Fixed an issue where a newly bootstrapped firewall required a management server restart, relicensing, or license push from Panorama to invoke the device certificate.
PAN-316869
Fixed an issue where previously committed Security policy rules were removed when a full commit was performed by a different administrator, which led to the inadvertent loss of configuration changes. With this fix, Security policy rules are retained as expected after a full commit.
PAN-316856
Fixed an issue where an error message displayed when attempting to delete the Logging Service certificate or view the Logging Service customer information.
PAN-316761
Fixed an issue where reportd process timeout errors occurred during a manual management server restart.
PAN-316721
Fixed an issue where multiple EDL fetches were queued and did not complete.
PAN-316720
Fixed an issue on log collectors where Verify Update Server Identity was not consistently enabled and visible in the XML configuration after a configuration push from Panorama.
PAN-316718
Fixed an issue where the firewall stopped forwarding logs or generating system and configuration logs to Panorama after restarting the mgmtsrvr process.
PAN-316631
Fixed an issue BGP sessions experienced short disruptions across all peers, interfaces, and slots when a multicast event persisted longer than the NGP negotiated hold timers.
PAN-316605
Fixed an issue where HIP redistribution to remote network nodes from external gateways resulted in a large amount of error messages in User-ID logs.
PAN-316556
Fixed an issue where a race condition between the session ager and packet processing resulted in memory corruption and caused the pan_task process to stop responding, which resulted in the firewall becoming unresponsive
PAN-316435
Fixed an issue where the firewall restarted unexpectedly due to an OOM condition after upgrading to an affected release.
PAN-316433
Fixed an issue on the web interface where the last digit of entries in policy rule descriptions were truncated.
PAN-316263
Fixed an issue where an incorrect validation error was displayed, falsely indicating that IKE Gateway and IPSec tunnel names can begin with a numeral
PAN-316120
Fixed an issue where, after Advanced Routing was enabled, the firewall advertised routes to internal BGP neighbors with the original external BGP next-hop address.
PAN-316106
(Panorama appliances in Log Collector mode only) Fixed an issue where commit validation failed after an upgrade when the previous configuration included a shared-optimization setting.
PAN-316070
Fixed an issue where a BGP peer automatically established a BGP connection after manually adding it via the CLI when Advanced Routing was enabled.
PAN-315965
Fixed an issue to address TCP proxy fast recovery behavior to follow RFC 5681.
PAN-315964
Fixed an issue on the web interface where you were unable to sort an AS path list by its sequencing number (**Network > Routing > Routing Profiles > Filters > Filters AS Path Access List*).
PAN-315959
(M-700 appliances only) Fixed an issue where Panorama displayed an incorrect maximum recommended configuration size when performing a commit.
PAN-315958
(PA-1410 firewalls only) Fixed an issue where the SaaS Quality Profile HTTP/HTTPS monitoring feature failed to send probes due to the firewall being unable to determine the correct egress interface and source IP address for the monitoring probes.
PAN-315919
Fixed an issue where GlobalProtect pre-logon tunnel session was not cleared even after the user was logged in. With this fix, the session is cleared after the session timeout expires.
PAN-315913
Fixed an issue where, after a User-ID restart on a redistribution firewall, some expiring IP tag entries became permanent instead of aging out as intended, which affected Dynamic Address Group policy rule enforcement.
PAN-315912
Fixed an issue where the Maximum Segment Size (MSS) rewrite functionality for packets ingressing through SD-WAN interfaces on firewalls was not optimized.
PAN-315820
Fixed an issue where User-ID XML API requests took longer than expected to return a response, which caused the web interface and captive portal pages to respond slowly or fail to load. this occurred when sending XML API requests for IP address-to-user mapping.
PAN-315683
Fixed an issue where certain permitted IP addresses, when pushed from a Panorama template, remained editable on the firewall web interface. With this fix, these template-managed IP addresses are no longer editable on the firewall.
PAN-315661
Fixed an issue where exporting policies to PDF or CSV files from Panorama did not include all policies or resulted in out-of-order entries when using a read-only (RO) or read/write (RW) access account. With this fix, policy exports now include all policies and maintain the correct order.
PAN-315630
Fixed an issue where firewalls dropped new connections due to session allocation failures, which resulted in service disruption. With this fix, firewalls no longer dropped new connections due to session allocation failures.
PAN-315619
Fixed an issue on the web interface where the Logging and Reporting settings remained loading indefinitely after an upgrade.
PAN-315424
Fixed an issue where the BGP peer filter match condition incorrectly identified neighbors in the Advanced routing Engine, which led to incorrect Logical Preference assignments and illogical path selections. This occurred when a BGP Inbound Route Map was configured to prioritize a path from a specific peer by setting its Local Reference.
PAN-315337
Fixed an issue where GlobalProtect throughput was reduced after an upgrade.
PAN-315314
Fixed an issue where, when a push operation from Panorama to the firewall failed, accounting logs stopped forwarding.
PAN-315176
Added an enable and disable CLI command to address an issue where the firewall experienced increased packet drops and slower performance after an upgrade due to high burst traffic.
PAN-315069
Fixed an issue where, after an upgrade, Panorama displayed 0% (N/A) for Environmental and Device memory metrics under the Health tab, preventing you from viewing the expected health status of your managed devices. With this fix, Panorama now accurately displays the Environmental and Device memory health metrics for your managed firewalls.
PAN-315005
Fixed an issue where configured RIPv2 timer parameters were not applied when the profile was configured with custom update, expire, and delete values, and the system continued to use the default timer settings, which caused unexpected route removal and network disconnections.
PAN-315000
Fixed an issue where the "Block Repeated Characters" setting in Minimum Password Complexity did not prevent the use of certain repeated special characters. With this fix, the system now correctly blocks repeated special characters as configured.
PAN-314873
Fixed an issue where the firewall intermittently stopped forwarding traffic to the internet.
PAN-314868
Fixed an issue where a commit operation would fail after a PAN-OS upgrade, which occurred when the virtual system (VSYS) configuration allocator usage reached 100%. With this fix, the virtual system configuration allocator usage is managed correctly, allowing commit operations to complete successfully.
PAN-314818
Fixed an issue where the firewall dropped IPv6 packets after enabling Strict IP Check under Zone Protection in an SD-WAN configuration.
PAN-314776
Fixed an issue where the configd process stopped responding after pushing configuration changes from Panorama to the firewall.
PAN-314752
Fixed an issue on Panorama where, after removing a scheduled configuration push, Panorama still initiated the push at its previously scheduled time.
PAN-314712
(PA-7500 Series firewalls only) Fixed an issue where the source IP Dynamic Address Group mappings were intermittently not displayed under Monitor > Traffic logs. This occurred even when dynamic address groups were updated via XML API without an expiry time and no unregister requests were observed.
PAN-314635
(Firewalls in active/passive HA configurations only) Fixed an issue where both firewalls stopped responding and initiated multiple failovers when internal processes became unresponsive.
PAN-314630
Fixed an issue where the firewall repeatedly rebooted and entered maintenance mode, and a factory reset was required.
PAN-314624
Fixed an issue where the useridd process became unresponsive and restarted when attempting to dump the Host Information Profile (HIP) database via CLI while the system was actively processing HIP reports. This was caused by a lock contention. With this fix, the process now operates as expected under these conditions.
PAN-314623
(Firewalls in active/passive HA configurations only) Fixed an issue where, after a failover, routing information within OSPF protocol was not correctly translated or propagated, which affected network path convergence and FRR capabilities.
PAN-314512
Fixed an issue where the GlobalProtect portal became inaccessible when the dataplane was configured with a DHCP assigned IP address.
PAN-314499
(Firewalls with site-to-site IPSec VPN tunnels only) Fixed an issue where you were unable to access some websites over HTTPS when Accumulation Proxy was enabled. This occurred due to the external server's SYN-ACK packet not designating the MSS for HTTPS sessions traversing over IPSec VPN tunnel, which prevented Client Hello packets from forwarding correctly.
To use this fix, run the CLI command set deviceconfig setting tcp use-min-mss yes.
PAN-314477
Fixed an issue where committing configuration changes failed due to the routed process not responding.
PAN-314435
Fixed an issue on the Panorama web interface where custom application tags for cloud applications were not consistently displayed in the Application Filter or application details even though the tags were configured via CLI and successfully enforced traffic blocking policy rules.
PAN-314399
Fixed an issue where Layer 3 (L3) recovery did not activate on firewalls when a cellular interface was transmitting data but not receiving any, which prevented the firewall from re-establishing connectivity. With this fix, L3 recovery now properly initiates under these conditions.
PAN-314385
(Firewalls in active/passive HA clusters only) Fixed an issue where high dataplane CPU usage occurred and traffic offloading decreased when a failover occurred from the active firewall to the passive firewall, and then back to the active firewall.
PAN-314372
Fixed an issue where, when SSL Inbound Decryption was enabled, the inbound SMTP email delivery to an internal mail server failed due to the firewall silently dropping application packets containing SMTP commands after successful decryption.
PAN-314365
Fixed an issue where the logrcvr process stopped responding for traffic containing multiple XFF headers when URL XFF header logging was enabled along with additional XFF header logging, which caused subsequent commits to fail.
PAN-314319
Added a CLI command to enable and disable AHO software offload optimization.
PAN-314300
Fixed an issue where the firewall continued to send LLDP learned information via SNMP for an interface even after disabling LLDP on that interface. This occurred when a third-party tool polled SNMP and it received outdated topology information.
PAN-314223
Fixed an issue where the Panorama web interface did not display all Security policy rules when using a Chromium-based browser, and you were unable to scroll to the bottom of the page to view the complete list.
PAN-314147
Fixed an issue where SSL traffic was dropped on SD-WAN DIA interfaces with member having different MTU.
PAN-314142
Fixed an issue where establishing log forwarding connections to the Strata Logging Service (SLS) took longer than expected, which resulted in delayed log visibility on SLS.
PAN-314126
Fixed an issue where session rematch did not properly apply updated Security policy rules to existing traffic flows after committing changes, which caused traffic to still be allowed when a new Security policy was set to Deny.
PAN-314104
Fixed an issue where running BCM counter commands from the administrative shell did not consistently return output, and commands to modify queue sizes did not take effect.
PAN-314061
Fixed an issue where traffic was disrupted during IPSec rekey operations due to a 2 second delay in sending the DELETE message for the previous Security Association (SA) to the peer gateway after a new SA was negotiated.
PAN-314050
(Firewalls in a High Availability (HA) configuration) Fixed an issue where your Firewalls experienced HA split-brain, unexpected system restarts, and the routing process repeatedly stopped responding, leading to significant disruption of production traffic. This occurred when you enabled the Advanced Routing Engine, which also caused High Availability (HA) keep-alive connections to become unavailable and an out-of-memory condition. With this fix, your Firewalls maintain stable operation after you enable the Advanced Routing Engine.
PAN-314020
Fixed an issue where the firewall did not decapsulate GENEVE packets when DNS Security retransmitted a DNS query after receiving a verdict from the cloud.
PAN-314018
(VM-Series firewalls in AWS environments only) Fixed an issue where the decrypt mirror port did not function expected, which prevented decrypted traffic from reaching the intended destination collector.
PAN-313976
Fixed an issue on Panorama where traffic, URL, and unified log entries were duplicated, which led to inaccurate Security logging after applying a time filter for the previous 6 hours.
PAN-313915
Fixed an issue where GlobalProtect SAML metadata exported from the firewall displayed the gateway's IP address instead of the FQDN.
PAN-313850
(PA-1400 Series firewalls in HA configurations only) Fixed an issue where a split-brain condition occurred and HA1/HA2 links went down while upgrading when the HA configuration used dataplane interfaces for HA1 and a combination of HSCI and Ethernet interfaces for HA2.
PAN-313828
Fixed an issue where the firewall did not forward traffic due to memory issues on a forwarding component.
PAN-313827
Fixed an issue where a memory leak occurred related to the reportd process when custom reports were run via API.
PAN-313787
Fixed an issue where some system log filters with the eventid operator for a BGP event did not work.
PAN-313711
Fixed an issue where the show system environmentals power CLI command displayed duplicate slot names and associated voltage values.
PAN-313700
Fixed an issue where an unexpected reboot occurred when Inline Cloud Analysis was enabled in an Anti-Spyware and Vulnerability profile.
PAN-313623
Fixed an issue where the /opt/pancfg/mgmt/ssl/private/ directory on Palo Alto Networks devices with TPM support became 100% utilized due to an accumulation of undeleted .pub_pem files. This occurred because executing the show device-certificate status CLI command initiated a process that generated these files but failed to remove them, which prevented the fetching of new device certificates.
PAN-313606
Fixed an issue where Panorama pushed commits took longer than expected to complete without displaying an error message when committing due to slow cloud-app compilation.
PAN-313575
Fixed an issue where 10G connections on built-in RJ45 interfaces (ethernet1/1 through ethernet1/5) intermittently experienced interface flapping when connected to Cisco switchports.
PAN-313572
VM-Series firewalls only) Fixed an issue where the dataplane restarted due to a segmentation fault.
PAN-313523
Fixed an issue where generating a tech support file caused GlobalProtect users to be forcibly logged out.
PAN-313494
Fixed an issue where ARP entries remained in a complete state with a TTL of 0 on the active-secondary node, which prevented affected devices from reliably communicating when traffic routes routed through that node.
PAN-313481
Fixed an issue where, after configuring a PBF policy rule with return address in a multi-vsys configured device, commit operations failed due to the PBF return address exceeding the maximum capacity.
PAN-313443
Fixed an issue where firewalls acting as an accumulation proxy sent a server hello with an earlier TCP timestamp value than a preceding ACK packet, which prevented successful session establishment. This occurred when the client hello messages were split across multiple network segments.
To use this fix, run the CLI command debug dataplane set ssl-decrypt accumulate-client-hello ts-relay yes.
PAN-313393
Fixed an issue where, after you configured a proxy server, External Dynamic Lists (EDL) and system software checks did not function concurrently. This occurred when you configured service routes for Palo Alto Networks services, which caused either EDL updates or system software checks to fail, depending on the specific service route configuration. With this fix, both EDL updates and system software checks correctly utilize the configured proxy server.
PAN-313258
Fixed an issue where PIM multicast routing failed on appliances with advanced routing enabled.
PAN-313218
Added the following CLI commands to address QoS packet drops due to bursty traffic:
  • debug dataplane set qos-setting qos-param qlimit 300
  • debug dataplane set qos-setting qos-param red low 50 high 90
To utilize this fix, change the parameters, disable QoS, commit changes, enable QOS, and then re-commit changes.
PAN-313216
Fixed an issue where firewalls with Prisma Access incorrectly displayed some traffic as unsanctioned in traffic logs for cloud applications that were tagged as sanctioned.
PAN-313193
Firewalls in Layer 2 mode only) Fixed an issue where the new sessions were not able to be established due to the firewall intermittently dropping valid MAC address entries for specific VLANs when a manual switchover sent a high volume of traffic to the firewall.
PAN-313190
(VM-Series firewalls only) Fixed an issue where content updates and configuration commits failed with the error message client device phase 1 failure error.
PAN-313048
Fixed an issue where the BGP default route was lost from the forwarding table during a failover, which caused a temporary service interruption.
PAN-313036
Fixed an issue where the firewall dataplane continuously accumulated packets in the ctd_pkt_queue and packet buffers, which caused resource exhaustion and prematurely terminated sessions.
PAN-312870
Fixed an issue on Panorama where Apps Seen was not updated in Security policy rules even when the firewall correclty recorded the **Last App Seen* timestamp and Panorama received monitor logs.
PAN-312844
Fixed an issue where a TLSv1.3 handshake did not complete when SSL Forward Proxy was enabled. This occurred when a large ClientHello message was split across multiple TCP segments and the final segment contained only one byte.
PAN-312725
Fixed an issue where no warning message was displayed during commits for improperly formatted FQDN or IP address values in the GlobalProtect Enforcer configuration. This fix requires a compatible content version on the firewall.
PAN-312706
Fixed an issue where the firewalls restarted due to a function lacking a NULL-pointer sanity check.
PAN-312697
Fixed an issue where firewalls intermittently failed to send all logs to the SLS.
PAN-312685
Fixed an issue where committing a scheduled configuration push on Panorama caused the configd process to stop responding unexpectedly.
PAN-312618
(PA-3420, PA-3430, PA-3440 firewalls only) Fixed an issue where the firewall was unable to activate GlobalProtect client software and displayed SW LIMIT messages related to max-profiles and unsupported major and minor versions in the downgrade list, which prevented successful software installation.
PAN-312514
Fixed an issue where correlation logs were not forwarded via syslog or email.
PAN-312354
Fixed an issue where Captive Portal authentication redirects failed for HTTPS traffic when a user attempted to access internal HTTPS websites via URL, which led to ERR_CONNECTION_RESET error messages in the browser with SSL decryption and CTD handshake inspection enabled.
PAN-312330
(Firewalls in active/passive HA configurations only) Fixed an issue where the Clientless VPN applications failed to load due to the firewall dataplane incorrectly processing session information.
PAN-312277
Fixed an issue where, after manually restarting the mgmtsrvr process caused the firewall to stop generating or forwarding system and configuration logs to Panorama, and a reboot was required to restore logging functionality.
PAN-312267
Fixed an issue where the firewall lost its MAC entry which caused IPv6 traffic sessions to become unresponsive or drop. This occurred when PBF rules were configured with symmetric return and no-pbf.
PAN-312157
Fixed an issue where, during a commit, the firewall intermittently stopped sending SNMP messages, which caused interface counters to stop updating for brief periods of time.
PAN-312156
Fixed an issue where firewalls did not correctly apply SD-WAN policy rules, which caused traffic to be incorrectly routed via local breakout instead of VPN backhaul.
PAN-312021
Fixed an issue where API responses included an unexpected NUL character when retrieved using API clients, which interfered with the processing of the response.
PAN-311988
(Firewalls in FIPS mode only) Fixed decryption issues that occurred after an upgrade to an affected release.
To enable this fix, run the CLI command debug dataplane set ssl-decrypt low-memory-throttle enable.
PAN-311822
Fixed an issue where system processes would unexpectedly terminate on Prisma Access instances during a configuration commit operation when TLS 1.3 proxy settings were configured. With this fix, system processes remain stable during configuration commits.
PAN-311658
Fixed an issue where the reportd process stopped responding, which caused the firewall to reboot.
PAN-311624
Fixed an issue on Panorama where, when an Aggregate Ethernet interface was configured in override mode within a template stack, changing its management profile unexpectedly overrode other interface-specific variables.
PAN-311567
Fixed an issue where device-group and template admin sessions failed to time out, causing an accumulation of active sessions. With this fix, administrator sessions now terminate as expected.
PAN-311512
Fixed an issue where HIP (Host Information Profile) reports were blocked on GlobalProtect when Authentication Cookie Usage Restrictions was enabled and the Prisma Access Agent protocol was in use. This occurred because the system failed to correctly process HIP messages that were relayed via IPSec tunnels with a Virtual IP as the source, leading to their rejection.
PAN-311506
Fixed an issue on Panorama where scheduled Saas Application usage reports and on-demand reports generated using Run Now displayed different results.
PAN-311456
Enhanced the SCP-based export script by adding comprehensive logging to identify and diagnose the root cause for failed or incomplete traffic log exports.
PAN-311449
Fixed an issue where global search did not return comprehensive results after an upgrade and only displayed top-level objects.
PAN-311435
(VM-Series firewalls in Azure Public Cloud only) Fixed an issue where DHCP client IP addresses were unexpectedly cleared on interfaces after an upgrade and a subsequent configuration push from Panorama, particularly when committing certain configuration changes, which resulted in interface IP loss and service disruption. With this fix, DHCP client IP addresses are retained as expected after upgrades and configuration pushes.
PAN-311419
Fixed an issue where the recommended filter for identifying traffic from unidentified users in traffic logs reported an incorrectly low number of results.
PAN-311412
Fixed an issue where the show advanced-routing resource CLI command failed to execute successfully when invoked through the XML API and returned an error message.
PAN-311352
Fixed an issue in SD-WAN deployments where DIA traffic was disrupted when DIA AnyPath was enabled during path transitions from the SD-WAN VIF to the physical interface. With this fix, the drop the packet even on zone change configuration is not needed to prevent interrupted DIA traffic during path switching.
PAN-311285
Fixed an issue where a memory leak occurred related to the ospfd process, which caused RAM usage to continuously increase until the device stopped responding.
PAN-311261
Fixed an issue where the firewall generated duplicate URL Filtering logs due to an error condition when the new XFF feature was enabled.
PAN-311250
(Panorama appliances and Log Collectors only) Fixed an issue where logs from multiple devices were not visible on Panorama even though the Elasticsearch health status on the dedicated Log Collectors appeared green.
PAN-311248
Fixed an issue where the ABR failed to translate and advertise the default route (0.0.0.0/0) from an OSPF NSSA area into the OSPF backbone area as a Type-5 LSA.
PAN-311235
Fixed an issue where the management interface became temporarily disconnected after a commit.
PAN-311218
Fixed an issue on Panorama where a system health check Security policy rule was applied to any zones instead of Public or Private.
PAN-311205
Fixed an issue where XML queries failed when you attempted to compare configuration versions.
PAN-311192
Fixed an issue where the device-telemetry collect-now process became unresponsive when the process was initiated multiple times with other processes running concurrently, which prevented subsequent telemetry collection.
PAN-311166
Fixed an issue where the firewall rebooted unexpectedly to the all_task_1 process repeatedly restarting.
PAN-311113
Fixed an issue where the firewall was unable to clear sessions using the CLI command clear session all filter rule when the specified rule name exceeded 32 characters, even though the limit is 63 characters.
PAN-311098
Fixed an issue where firewalls entered a nonfunctional state due to L7 running out of resources due to a high volume of traffic.
PAN-311074
Fixed an issue where GRE tunnels took significantly longer to establish when the hold timer was configured to a value of 10 or higher, which resulted in a tunnel requiring more successful keepalive packets than expected to transition to an Up state.
PAN-311040
Fixed an issue where the all_task process stopped responding and caused the firewall to reboot unexpectedly.
PAN-310939
(Firewalls in HA active/active configurations only) Fixed an issue where the firewall experienced random reboots due to a memory leak in the ikemgr process triggered by configuration pushes. The leak occurred when an IKE Gateway was configured on a loopback interface using a floating IP address, leading to repeated socket bind failures on the secondary device.
PAN-310851
Fixed an issue where firewalls experienced snmpd log flooding with messages such as update_ifTable_utilization_rates(pan_interfacecache.c:1720): Last time is 0 for dedicated-ha2., which caused the snmpd log to overflow and be cleared every five minutes. This occurred because the snmpd process attempted to calculate interface utilization rates without first verifying if the interface had valid sysd configuration data, as the code incorrectly assumed all interfaces in the MIB would possess valid sysd data.
PAN-310743
Fixed an issue where you were unable to change an administrator's authentication profile to None.
PAN-310736
Fixed an issue where importing a profile that included a source address would not correctly display the source address on the policy page. With this fix, the source address now displays as expected after profile import.
PAN-310699
Fixed an issue where the firewall stripped the Authentication Key Identifier (AKID) from certificates using SSL decryption, which prevented clients from authenticating server certificates and resulted in decryption failures.
PAN-310627
Fixed an issue where Inline Cloud Analyzer (ICA) did not correctly apply custom URL categories configured as exceptions for traffic detection. With this fix, ICA correctly applies the configured custom URL category exceptions.
PAN-310622
Fixed an issue where customized destination pages displayed content improperly formatted. With this fix, customized destination pages display content correctly.
PAN-310618
Fixed an issue where you were unable to import the GlobalProtect app welcome page on Panorama using SCP or TFTP from the CLI.
PAN-310526
Fixed an issue where you were unable to download cellular firmware through Panorama.
PAN-310473
Fixed an issue where committing configuration changes to an Advanced Logical router caused a 20-30 second loss of management access in the firewall when IPv4 and IPv6 default static routes were configured with identical attributes including interface, next-hop, and metrics, which triggered an unnecessary routing table refresh.
PAN-310472
Fixed an issue on the web interface where checkboxes for default information originate and ABR in OSPF NSSA configurations were automatically enabled which resulted in unexpected configuration changes.
PAN-310362
Fixed an issue where IPv6 Routed HA did not function correctly when the HA1 (control link) was configured with an IPv6 routed connection.
PAN-310267
Fixed an issue where a process stopped responding during Go garbage collection (GC).
PAN-310263
(VM-Series firewalls only) Fixed an issue where enabling TLS1.3 in a decryption profile prevented access to websites.
PAN-310240
Fixed an issue where software packet buffers were completely utilized when performing a Data Loss Prevention longevity test.
PAN-310218
Fixed an issue where NFS hidden files accumulated in a log directory and led to high disk utilization, which prevented the system from automatically purging them. With this fix, the system properly manages and purges the files.
PAN-309960
Fixed an issue where a memory leak related to the useridd process on the passive device led to an OOM condition.
PAN-309944
Fixed an issue where an error message was incorrectly displayed instead of a debug message.
PAN-309927
Fixed an issue on Panorama where the multi-clone XML API operation reported a successful configuration change even when the specific device group did not exist.
PAN-309831
Fixed an issue where an AI Runtime Security Firewall rebooted when processing Cursor traffic.
PAN-309676
Fixed an issue on Panorama where a database component unexpectedly stopped when Panorama was deployed using an .ova file or upgraded/downgraded to an affected PAN-OS version. This occurred due to a required directory not being created during the initial provisioning workflow. With this fix, the necessary directory is created automatically during deployment.
PAN-309493
Fixed an issue where the URL cloud connection was impacted, which caused a traffic outage.
PAN-309306
Fixed a rare issue on Octeon Dataplane platforms where the firewall experienced an unexpected dataplane restart due to a race condition that occurred during session teardown for traffic undergoing software-based Content Threat detection.
PAN-309217
Fixed an issue on the Panorama web interface where refreshing or configuring settings in the Response Pages tab caused the web interface to respond more slowly when navigating to other tabs.
PAN-309014
Fixed an issue where an internal interface identifier became invalid following real-time threat analysis processing. This caused traffic to be misrouted or improperly handled. With this fix, the system correctly manages interface identifiers during threat analysis, ensuring consistent traffic flow.
PAN-308928
Fixed an issue where OSPF routes did not install correctly when you performed a traffic switch between firewalls with the Advanced Routing Engine enabled, which led to routing instability.
PAN-308876
Fixed an issue where upgrades to managed firewalls from Panorama failed.
PAN-308812
Fixed an issue where firewalls using the Real-Time update setting for WildFire intermittently generated system alerts indicating a failure to connect to the WildFire real-time cloud. With this fix, these alerts are no longer generated.
PAN-308775
(Firewalls in active/passive configurations only) Fixed an issue where NTP status intermittently showed as rejected on the active firewall, which prevented the firewalls from synchronizing time.
PAN-308769
Fixed an issue where BGP connections intermittently dropped and entered a Connect state, leading to service outages for traffic routed over Large Scale VPN (LSVPN) tunnels. This occurred because the firewall performed an incorrect route lookup for BGP traffic over an Internet Protocol Security (IPSec) tunnel. With this fix, BGP connections remain stable.
PAN-308732
(Multi-vsys firewalls only) Fixed an issue where GlobalProtect clients were unable to use custom source region objects for gateway selection criteria due to region objects defined in Panorama not being correctly recognized or displayed in the GlobalProtect Portal configuration.
PAN-308711
Fixed an issue where superusers with read-only privileges on Panorama were unable to execute show device-certificate CLI commands.
PAN-308710
Fixed an issue where Advanced DNS Security telemetry utilized only one processing stream even when multiple processing streams were available.
PAN-308651
Fixed an issue on the firewall web interface where the TLSv1.3_Default certificate setting and SSL/TLS profile were not displayed."
PAN-308564
Fixed an issue where packets were dropped on SD-WAN interfaces when a proxy was enabled due to an MTU inconsistency where the firewall failed to rewrite the maximum segment size in SYN/ACK packets based on the SD-WAN virtual interface MTU.
Note: This fix does not apply when the traffic egress interface is SD-WAN Direct Internet Access (DIA) interface and proxy is enabled.
PAN-308563
Fixed an issue where multiple pan_task processes attempted to clear the packet queue of the same session.
PAN-308509
(Panorama appliances on Google Cloud Platform only) Fixed an issue where administrators could not establish an SSH connection to Panorama using ed25519 keys. With this fix, ed25519 keys are now supported for SSH access.
PAN-308507
(Panorama managed firewalls only) Fixed an issue where the firewall intermittently failed to maintain active log forwarding streams to Strata Logging Service (SLS) even when duplicate logging and enhanced application logging were enabled.
PAN-308461
Fixed an issue where the CLI command request system software download to-version <version> failed to download multiple software images due with a Download terminated due to timeout error message.
PAN-308444
Fixed an issue where pushing multiple policy rules failed when the policy rules contained a large number of dynamic address object groups or user groups.
PAN-308418
Fixed an issue where, when Advanced DNS Security was enabled and experienced unusually high loads, DNS resolution failures occurred with the error resources-unavailable.
PAN-308377
(PA-7000 Series firewalls with an LFC in HA configurations only) Fixed an issue where the firewall reached 100% disk utilization due to the logrcvr process repeatedly restarting and dumping core files due to a blocked hints processing thread, which caused a failover.
PAN-308305
Fixed an issue where, when you selected a signature policy rule in the Anti-Spyware profile and clicked Find Matching Signatures, the automatically created filter was incorrect and prevented matching signatures from being displayed.
PAN-308261
Fixed an issue where the firewall failed to send SNMPv3 traps when the SNMP destination was configured with an FQDN that resolved to multiple IP address through DNS load balancing.
PAN-308188
Fixed an issue where, after a successful commit and push from Panorama, the management interface SSH profile configuration was missing or empty on Log Collectors.
PAN-307976
(Firewalls in active/active HA configurations only) Fixed an issue where tunnels failed to come up with the error message failed to find a socket for transmission.
PAN-307937
Fixed an issue on the web interface where the global filter set in ACC > Threat Activity did not apply when you navigated to the Network Activity tab.
PAN-307933
(Panorama appliances in Log Collector mode only) Fixed an issue where the log collectors became unstable for an extended period of time when receiving large amounts of traffic.
PAN-307717
Fixed an issue on Panorama where administrators were unable to override SNMP setup configurations within device groups due to the configured override not being retained.
PAN-307618
Added a debug CLI command to address where remote networks for Prisma Access tenants randomly dropped monitoring packets from peer devices, which caused tunnels to be marked as down. This occurred when a CPU core suddenly experienced high utilization.
To utilize this fix, run debug dataplane set ssl-decrypt use-new-peek-window yes.
PAN-307597
Fixed an issue where BGP peering sessions between a hub firewall and a satellite firewall over GlobalProtect LSVPN failed to connect.
PAN-307590
Fixed an issue where some FQDNs could not be resolved by the firewall. This occurred even when your configured Domain Name System (DNS) servers successfully returned valid IP addresses for the FQDNs. With this fix, the firewall correctly processes DNS responses and resolves FQDNs as expected.
PAN-307491
Fixed an issue where the firewall entered maintenance mode after a reboot when ZTP was enabled.
PAN-307481
Fixed a commit failure issue that occurred after migrating from Legacy to Advanced routing on firewalls where an OSPF authentication profile was configured to use a 16-character MD5 key with key-ID 10.
PAN-307470
Fixed an issue where an External Dynamic List (EDL) fetch with an invalid certificate was skipped on newly provisioned GlobalProtect gateway instances.
PAN-307190
Fixed an issue where LED indicators on combo ports remained off even when the network link was active.
PAN-306356
Fixed an issue where the logrcvr process on a firewall stopped responding due to a document node being unexpectedly freed.
PAN-306217
Fixed an issue on Panorama where scheduled reports with specific queries did not include any data.
PAN-305619
Fixed an issue where HTTP management access appeared to fail and incorrectly displayed the error message Error 503: Service Unavailable even though it functioned correctly as allowed. This occurred when an interface was configured with an address object.
PAN-305369
Fixed an issue where the firewall dropped packets due to an invalid interface when attempting to ping the next-hop gateway from a VLAN interface due to the firewall incorrectly resolving the ARP for the gateway on an unintended interface.
PAN-305327
Fixed an issue where SSL syslog forwarding did not work with CRL or OCSP check enabled with a management IPv6 address with a :: character.
PAN-305240
Fixed an issue where User-ID redistribution clients experienced delays in establishing initial communication with the redistribution server, which caused connection timeouts.
PAN-305105
Fixed an issue where commits involving routing related network configuration changes experienced slower than usual completion times or remaining at 20% completion.
PAN-304761
Fixed an issue on Panorama where the SD-WAN monitoring tab displayed incomplete names under Sites and VPN Cluster and displayed No Data when viewing status details.
PAN-304746
(Panorama appliances and Panorama virtual appliances only) Fixed an issue where the configd process restarted when committing and pushing configuration for a new WildFire cluster.
PAN-304718
Fixed an issue where OSPF and BGP outages occurred due to an all_task process restart during clientless VPN content rewrite processing.
PAN-304686
(AIRS firewalls on Google Cloud Platform (GCP) environments only) Fixed an issue where the firewall displayed a Kubernetes cluster ID of 0 in the traffic logs in SCM when traffic was denied for Kubernetes workloads, even though the traffic zone was correctly identified with the corresponding non-zero cluster ID.
PAN-304360
Fixed an issue where the firewall did not redistribute its application routes to BGP peers. This occurred in multi-mesh deployments with the multi-cloud networking feature enabled.
PAN-303662
Fixed an issue where PA-455 firewalls running PAN-OS 11.2.4-h7 intermittently failed to generate system logs and trigger an HA failover when a link-monitored interface was unplugged, despite the interface's status being reflected as down on the GUI.
PAN-303173
(Firewalls in Advanced Routing mode only) Fixed an issue where OSPF sessions using MD5 authentication experienced intermittent flapping due to out-of-order packets.
PAN-302790
Fixed an issue where, with Sender Side Loop Detection enabled, BGP WITHDRAWAL updates were not sent to peers after a route was removed, which caused stale routes to persist in the BGP table of neighboring firewalls.
PAN-302512
(Log Collectors in HA configurations only) Fixed an issue where log collectors displayed a disconnected inter-log collector status.
PAN-302175
Fixed an issue where, after upgrading an LSVPN portal/gateway to an affected release, the portal was unable to issue and transfer certificates to the satellite firewalls, which led to repeated certificate requests and prevented the satellite firewalls from authenticating to the gateway.
PAN-301756
Fixed an issue where ACC logs displayed a discrepancy in SSL traffic information between Panorama and the firewall. With this fix, the SSL traffic information in ACC logs now aligns correctly.
PAN-301513
Fixed an issue on Panorama managed multi-vsys firewalls where, when the shared-to-shared feature was enabled, shared objects reverted to an older configuration after a selective push to a vsys.
PAN-301430
Fixed an issue where the web server did not specify the content type in the header for font files, which could allow a browser to misinterpret the content and potentially lead to cross-site scripting (XSS) vulnerabilities.
PAN-300615
Fixed an issue where the pan_comm process stopped after multiple content versions were installed and the memory limits were reached.
PAN-300445
Fixed an issue where the firewall downloaded an Antivirus package but did not automatically install it.
PAN-300423
Fixed an issue where Data Processing Cards (DPCs) installed in slots 5 and 6 remained stuck in a starting state with the error Signal detected for port xeS5-DP0 but Link Down alerts, which resulted in device instability.
PAN-300055
Fixed an issue where the firewall experienced high disk utilization in the /opt/pancfg/mgmt/content-preview directory due to older content data not being automatically removed when an error occurred during the process.
PAN-299910
Fixed an issue where unintended ARP packets were sent out from the dataplane interface when the service route setting for DNS was configured to use that interface.
PAN-299623
(Panorama appliances in Management Only mode only) Fixed an issue where the firewall incorrectly allowed access to the web interface on a blocked port. Additionally, after configuring a custom certificate, Panorama continued to present the self-signed certificate on the blocked port.
PAN-298960
Fixed an issue where the firewall continuously rebooted when the useridd process repeatedly restarted.
PAN-297880
Fixed an issue where WildFire Analysis reports failed to load, displaying a 500 Internal Server Error when the system attempted to retrieve reports for certain files. With this fix, WildFire Analysis reports load as expected.
PAN-297782
Fixed an issue on Panorama where reassociating a vsys from one device group to another in a multi-vsys environment resulted in another vsys from the same firewall being removed from the original device group. This resulted in the device being moved into the no device groups attached group, a superuser was required to manually reattach the device.
PAN-297749
Fixed an issue where the redistribution agent status was blank on the web interface on both the firewall and Panorama, even though the CLI showed the agent as connected.
PAN-297245
(VM-Series firewalls in AWS environments configured with IMDSv2 only) Fixed an issue where Elastic Network Interface (ENI) IDs were not displayed by a diagnostic command, which occurred when Instance Metadata Service Version 2 (IMDSv2) was the only metadata service enabled for the instance. With this fix, the command now correctly displays ENI IDs.
PAN-296543
Fixed an issue where a memory leak related to the configd process occurred when committing configurations related to WildFire Cloud Services or WildFire appliance settings.
PAN-296246
Fixed an issue where policy cache corruption led to unexpected policy rule behavior or operational instability. This occurred when an internal system process restarted while a commit was in progress or when a commit operation failed.
PAN-295806
Fixed an issue where memory leaks on the configd process occurred due to a hash insert operation failing during connection management and SSL connections.
PAN-295309
Fixed an issue where OSPF session using MD5 authentication experienced intermittent flapping due to out-of-order packet processing.
PAN-295082
Fixed an issue on the Panorama web interface where you were unable to delete or change a logical router for tunnel, SD-WAN, VLAN, or loopback interfaces under a template.
PAN-295047
Fixed an issue where the staticd process stopped responding.
PAN-294998
Fixed an issue where the LogDB incorrectly reported that the database quota for extpcap logs was reached.
PAN-294434
Fixed an issue where memory leaks occurred. These leaks were caused by two distinct scenarios: the failure to deallocate memory for a nodeset when a new nodeset was assigned to the same variable, and the failure to free a UUID hash table during error conditions.
PAN-294001
Fixed an issue on Panorama managed firewalls generated Failed in get_pwchange_required error messages in the authd logs for local administators.
PAN-293586
(Panorama virtual appliances and M-600 appliances only) Extended IDMgr support to 3.5 million entries.
To utilize this feature, use the following commands. If you are in an HA deployment, execute these steps on both devices:
To enable the feature: debug user-id idmgr set-max-vsys-user-to-3600000 yes
To disable the feature: debug user-id idmgr set-max-vsys-user-to-3600000 no.
Note:
  • You must restart the useridd process after running these commands for the changes to take effect.
  • The system must meet the 64GB RAM minimum requirement for this fix.
PAN-292363
Fixed an issue where the built-in actions under Log Settings for GlobalProtect did not work when configured via the CLI, which prevented the use of tags on GlobalProtect logs for automated Security actions.
PAN-292191
Fixed an issue where the firewall dropped packets related to call recording and voice calls, which resulted in communication failures, retransmissions, and disconnected calls. This occurred when the firewall was positioned between a Private Branch Exchange and an AES server and users registered phones across different data centers.
PAN-291785
Fixed an issue where the all_task process stopped responding.
PAN-290712
(PA-7500 Firewalls in cluster mode only) Fixed an issue where the firewall incorrectly advertised BGP routes back to the external BGP peer, which resulted in routing inefficiency.
PAN-290663
(Panorama managed firewalls in HA configurations only) Fixed an issue where the firewall did not enforce serial number validation during HA deployment or replacement, which resulted in pairs being established even when the serial numbers configured on Panorama did not not match the serial number of the devices.
PAN-290117
(Firewalls in active/passive HA configurations only) Fixed an issue with high dataplane CPU utilization on both active and passive firewalls.
PAN-289822
Fixed an issue where the Policy Optimization feature did not display values correctly when the language was not set to English.
PAN-289460
Fixed an issue where the timestamp value in SNMPv3 trap headers was incorrect.
To use this fix, run the CLI command debug log-receiver enginetime-from-snmptime yes.
PAN-289413
Fixed an issue where dataplane interfaces went down and configurations were lost after a reboot.
PAN-286889
Fixed an issue where a website would intermittently fail to load in Mozilla Firefox after authentication when AURL inline cloud was active, which was caused by an interaction with the inline cloud analysis process. With this fix, websites now load consistently.
PAN-286492
Fixed an issue on Panorama where logs were not forwarded to syslog servers due to missing CLI options to configure the syslog queue size and threads.
PAN-286386
Fixed an issue where GlobalProtect users were unable to connect
PAN-285862
Fixed an issue where repeated unexpected terminations of a system component would cause the Data Plane to restart. With this fix, the Data Plane maintained stability.
PAN-285327
Fixed an issue where a memory leak occurred when processing device and vsys tags.
PAN-285213
Fixed an issue where proxy requests for certificate status (OCSP/CRL) from sslmgr contained incorrect values that caused unknown certificates to be blocked.
PAN-283774
Fixed an issue where the firewall placed UDP sessions into a Discard state when a DNS Sinkhole/Block action occurred, which prevented subsequent DNS requests from reusing the same session and caused DNS-related outages.
PAN-283429
Fixed an issue where Panorama presented default certificates during vulnerability scans even when Allow Custom Certificate Only was enabled.
PAN-282336
(Firewalls in Multi-Chassis Link Aggregation Group (MCLAG) configurations only) Fixed an issue where port counters for aggregated Ethernet member interfaces displayed incorrect received packet counts. With this fix, the counters now increment steadily and accurately.
PAN-282170
Fixed an issue on the web interface where the Managed Devices page took longer than expected to load. With this fix, the system now incorporates a global find usage-based search implementation, which improves page load performance.
PAN-279552
Fixed an issue where configuring a custom vulnerability object signature condition failed to commit when the negate option was disabled on the condition, and changes made to a custom vulnerability object were successfully committed to Panorama but not pushed to the firewall. This occurred when a vulnerability object contained two signatures.
PAN-278688
Fixed an issue where DNS Security threat logs were not displayed on the firewall when packet capture was enabled and the domain name length was 62 characters.
PAN-278561
Fixed an issue where TLSv1.3 session resumption continued to function even when Bypass Server Certificate Verification was enabled in the profile.
PAN-273487
Fixed an issue where the distributord process restarted on firewalls in multi-vsys environments with User-ID configured and Panorama as a redistribution client. This occurred when a large volume of IP address-to-user mappings were learned.
PAN-267067
Fixed an issue where VXLAN traffic failed and packet loss occurred in networks sensors after upgrading to an affected release.
PAN-264762
Fixed an issue where the firewall showed the status of SFP+ interfaces as not up, or up but not configured, when a PAN-SFP-PLUS-SR cable was connected.
PAN-264508
Fixed an issue where Cloud Identity Engine did not fetch user-mapping details for XML API users. This occurred when the firewall learned the same IP-user mapping multiple times within a short period. With this fix, the Cloud Identity Engine now accurately fetches these user-mapping details.
PAN-260303
Fixed an issue where internal memory profiling did not utilize specific allocation and in-use intervals. With this fix, internal memory profiling now operates with these defined parameters.
PAN-257879
Fixed an issue where, after a system event, selecting a configuration file from maintenance mode loaded the incorrect configuration.
PAN-250445
Fixed an issue where DLP logs accumulated in the logrcvr cache when using DLP in mirror mode.
PAN-250339
Added an improvement to automatically clean up idle HTTP connection pools to address an issue where idle connection pools accumulated when a circuit breaker limit was reached, which caused client requests to fail with a 503 no_healthy_upstream error.
PAN-246699
Fixed an issue on Panorama where Rule Usage and Apps Seen under Security policy rules stopped incrementing.
PAN-241887
Fixed an issue where log usernames were truncated, which caused users to be identified improperly on predefined SaaS reports.
PAN-240066
Fixed a duplicate MAC address issue where an ethernet interface sent out Gratuitous ARP (GARP) messages for an IP address that was not configured on it.
PAN-239917
Fixed an issue where the configd process experienced an OOM condition during extended operations with XML API calls.
PAN-234302
Fixed an issue where commit operations took longer than expected to complete due to EDL timeouts occurring on passive nodes when a service route was enabled.
PAN-233967
Fixed an issue where decryption logs for DNS over HTTPS (DoH) traffic were not consistently generated when a forward trust decryption profile was applied, resulting in incomplete visibility of web-browsing application traffic.