PAN-OS 11.2.4-h12 Addressed Issues
Focus
Focus

PAN-OS 11.2.4-h12 Addressed Issues

Table of Contents

PAN-OS 11.2.4-h12 Addressed Issues

PAN-OSĀ® 11.2.4-h12 addressed issues.
Issue ID
Description
PAN-296519
Fixed an issue where a stream receiving a reconnect signal with an associated error in Wifclient caused the entire pool to close, which resulted in a complete disconnection.
PAN-295560
Fixed an issue where, after upgrading Panorama and Log Collectors, tunnel logs were not visible in Panorama or Splunk even though traffic and threat logs were received.
PAN-293673
Fixed an issue where the firewall stopped all tasks due to an OOM condition caused by a scheduled log export using FTP to an external FTP server.
PAN-292229
Fixed an issue where Panorama was unable to retrieve userid logs from the firewall for subscribed user-ip-mappings after Panorama was rebooted.
PAN-292202
Fixed an issue where the system logs repeatedly displayed the alert Clearing snmpd.log due to log overflow due to the SNMP counters rolling over.
PAN-291716
Fixed an issue where PA-460 firewalls experienced out-of-memory (OOM) conditions, leading to device crashes and reboots.
PAN-291631
(VM-Series firewalls only) Fixed an issue where the firewall frequently rebooted.
PAN-291288
Fixed an issue where the firewall rebooted unexpectedly due to a pan_task process restart related to page allocation failures.
PAN-291094
Fixed an issue the firewall experienced packet descriptor on chip and buffer spikes, which led to dropped traffic due to an unidentified traffic pattern.
PAN-291067
Fixed an issue where the devsrvr process periodically exceeded its virtual memory limit and restarted, which led to intermittent outages.
PAN-290542
Fixed an issue where the all_task process stopped responding when an additional header logging HTTP header was split across 2 packets.
PAN-290449
Fixed an issue where, when multiple scheduled vulnerability reports were sent in the same email, only the first attached report was displayed.
PAN-287818
Fixed an issue where sessions timed out sooner than expected due to the pan_proxy_accumulation_restore_timeout not initiating when the accumulation session_init failed.
PAN-287803
Fixed an issue where, after upgrading firewalls to PAN-OS 11.1.6-h1, certain websites weren't accessible when the accumulation proxy was enabled. The proxy did not use the same DF bit state as the original traffic, causing it to be fragmented and dropped elsewhere in the network.
PAN-287782
Fixed an issue where firewalls configured in vwire mode modified DSCP values from AF11 to CS0 on traffic passing through the firewall, even when QoS policy rules and DSCP rewrite settings were not configured.
PAN-287622
Fixed an issue where IPv6 traffic was affected after upgrading the firewall to PAN-OS 11.1.6-h4 and later versions. With SSL decryption enabled and a decryption policy configured for the traffic, the firewall dropped packets due to receiving a Packet Too Big ICMP message. This occurred because the PathMTU information update was incorrect for the TCB (pan-server) when the firewall was acting as a server. Additionally, the flow label under the IPv6 header was set to zero while the packet was being transmitted out of the firewall.
PAN-287601
Fixed an issue on Panorama where commits took longer than expected.
PAN-287423
Fixed an issue where content loading issues occurred on IPv6 websites due to the firewall incorrectly setting the IPv6 header flow label to 0.
PAN-286299
Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the Network and Device tabs became read-only.
PAN-285285
Fixed an issue where commits remained at 98% completion when static route configuration cleanup was in progress.
PAN-286231
Fixed an issue where a simultaneous selective push from Panorama to multiple firewalls with different base configurations resulted in configuration corruption, which caused the firewall to go down.
PAN-280698
Fixed an issue where the firewall removed the TCP timestamp from client hello messages that did not fit in a single packet, which resulted in connection issues.
PAN-279706
(M-600 appliances only) Fixed an issue where Panorama did not update all panreplay database entries after performing a commit and full push to all devices.
PAN-276484
Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (Device Deployment > Licenses) due to the inability to perform batch-license refreshes.
PAN-273453
Fixed an issue where restarting the firewall did not initiate an autocommit job, which caused the firewall to stop responding and the HA interface to go down.
PAN-273300
Fixed an issue on Panorama where upgrading to PAN-OS 11.0.4-h2 failed with a validation error.
PAN-265044
Fixed an issue where the default software packet buffer size for the Advanced Header Learning (AHL) feature was excessively large, which led to inefficient use of software packet buffers.
PAN-260015
Fixed an issue on the firewall where enabling Inline Cloud Analysis features might cause the firewall to unexpectedly reboot, due to an issue related to loopback data handling.