PAN-OS 11.2.4-h12 Addressed Issues
Table of Contents
                    
          Expand All
          |
          Collapse All
        
        Next-Generation Firewall Docs
- 
                  
                  
- 
                  
                  
- 
                  
                  
- 
                  
                  
- 
                  
                  
- 
                  
                  
- 
                  
                  - PAN-OS 12.1
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 11.0 (EoL)
- PAN-OS 10.2
- PAN-OS 10.1
- PAN-OS 10.0 (EoL)
- PAN-OS 9.1 (EoL)
- PAN-OS 9.0 (EoL)
- PAN-OS 8.1 (EoL)
 
- 
                  
                  - PAN-OS 12.1
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 10.2
- PAN-OS 10.1
 
PAN-OS 11.2.4-h12 Addressed Issues
PAN-OSĀ® 11.2.4-h12 addressed issues.
    
  | Issue ID | Description | 
|---|---|
| PAN-296519 | Fixed an issue where a stream receiving a reconnect signal with an
                                associated error in Wifclient caused the entire pool to
                                close, which resulted in a complete disconnection.  | 
| PAN-295560 | Fixed an issue where, after upgrading Panorama and Log Collectors,
                                tunnel logs were not visible in Panorama or Splunk even though
                                traffic and threat logs were received.  | 
| PAN-293673 | Fixed an issue where the firewall stopped all tasks due to an OOM
                                condition caused by a scheduled log export using FTP to an external
                                FTP server. | 
| PAN-292229 | Fixed an issue where Panorama was unable to retrieve
                                    userid logs from the firewall for subscribed
                                user-ip-mappings after Panorama was rebooted.  | 
| PAN-292202 | Fixed an issue where the system logs repeatedly displayed the alert
                                    Clearing snmpd.log due to log
                                    overflow due to the SNMP counters rolling
                                over. | 
| PAN-291716 | Fixed an issue where PA-460 firewalls experienced out-of-memory (OOM)
                                conditions, leading to device crashes and reboots.  | 
| PAN-291631 | (VM-Series firewalls only) Fixed an issue where the firewall
                                frequently rebooted.  | 
| PAN-291288 | Fixed an issue where the firewall rebooted unexpectedly due to a
                                    pan_task process restart related to page allocation
                                failures. | 
| PAN-291094 | Fixed an issue the firewall experienced packet descriptor on chip and
                                buffer spikes, which led to dropped traffic due to an unidentified
                                traffic pattern.  | 
| PAN-291067 | Fixed an issue where the devsrvr process periodically
                                exceeded its virtual memory limit and restarted, which led to
                                intermittent outages.  | 
| PAN-290542 | Fixed an issue where the all_task process stopped
                                responding when an additional header logging HTTP header was split
                                across 2 packets.  | 
| PAN-290449 | Fixed an issue where, when multiple scheduled vulnerability reports
                                were sent in the same email, only the first attached report was
                                displayed.  | 
| PAN-287818 | Fixed an issue where sessions timed out sooner than expected due to
                                the
                                    pan_proxy_accumulation_restore_timeout
                                not initiating when the accumulation
                                    session_init failed.  | 
| PAN-287803 | Fixed an issue where, after upgrading firewalls to PAN-OS 11.1.6-h1,
                                certain websites weren't accessible when the accumulation proxy was
                                enabled. The proxy did not use the same DF bit state as the original
                                traffic, causing it to be fragmented and dropped elsewhere in the
                                network.  | 
| PAN-287782 | Fixed an issue where firewalls configured in vwire mode modified DSCP
                                values from AF11 to CS0 on traffic passing through the firewall,
                                even when QoS policy rules and DSCP rewrite settings were not
                                configured.  | 
| PAN-287622 | Fixed an issue where IPv6 traffic was affected after upgrading the
                                firewall to PAN-OS 11.1.6-h4 and later versions. With SSL decryption
                                enabled and a decryption policy configured for the traffic, the
                                firewall dropped packets due to receiving a Packet Too
                                    Big ICMP message. This occurred because the
                                PathMTU information update was incorrect for the TCB (pan-server)
                                when the firewall was acting as a server. Additionally, the flow
                                label under the IPv6 header was set to zero while the packet was
                                being transmitted out of the firewall.  | 
| PAN-287601 | Fixed an issue on Panorama where commits took longer than expected.
                             | 
|  PAN-287423 | Fixed an issue where content loading issues occurred on IPv6 websites
                                due to the firewall incorrectly setting the IPv6 header flow label
                                to 0.  | 
| PAN-286299 | Fixed an issue on firewalls running PAN-OS 11.1 releases where, after
                                being offboarded from Panorama, the firewall XML configuration file
                                retained template information from the previous Panorama
                                configuration. As a result, when the firewall and its configuration
                                were imported to another Panorama appliance, all configurations in
                                the Network and Device
                                tabs became read-only.  | 
| PAN-285285 | Fixed an issue where commits remained at 98% completion when static
                                route configuration cleanup was in progress.  | 
|  PAN-286231 | Fixed an issue where a simultaneous selective push from Panorama to
                                multiple firewalls with different base configurations resulted in
                                configuration corruption, which caused the firewall to go down.  | 
| PAN-280698 | Fixed an issue where the firewall removed the TCP timestamp from
                                client hello messages that did not fit in a single packet, which
                                resulted in connection issues.  | 
| PAN-279706 | (M-600 appliances only) Fixed an issue where Panorama did
                                not update all panreplay database entries after
                                performing a commit and full push to all devices.  | 
| PAN-276484 | Fixed an issue where Panorama did not display license information for
                                Cloud NGFW firewalls under (Device Deployment >
                                    Licenses) due to the inability to perform
                                batch-license refreshes.  | 
| PAN-273453 | Fixed an issue where restarting the firewall did not initiate an
                                autocommit job, which caused the firewall to stop responding and the
                                HA interface to go down.  | 
| PAN-273300 | Fixed an issue on Panorama where upgrading to PAN-OS 11.0.4-h2 failed
                                with a validation error.  | 
| PAN-265044 | Fixed an issue where the default software packet buffer size for the
                                Advanced Header Learning (AHL) feature was excessively large, which
                                led to inefficient use of software packet buffers.  | 
| PAN-260015 | Fixed an issue on the firewall where enabling Inline Cloud Analysis
                                features might cause the firewall to unexpectedly reboot, due to an
                                issue related to loopback data handling.  | 
