PAN-OS 11.2.7-h4 Addressed Issues
Table of Contents
                    
          Expand All
          |
          Collapse All
        
        Next-Generation Firewall Docs
- 
                  
                  
- 
                  
                  
- 
                  
                  
- 
                  
                  
- 
                  
                  
- 
                  
                  
- 
                  
                  - PAN-OS 12.1
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 11.0 (EoL)
- PAN-OS 10.2
- PAN-OS 10.1
- PAN-OS 10.0 (EoL)
- PAN-OS 9.1 (EoL)
- PAN-OS 9.0 (EoL)
- PAN-OS 8.1 (EoL)
 
- 
                  
                  - PAN-OS 12.1
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 10.2
- PAN-OS 10.1
 
PAN-OS 11.2.7-h4 Addressed Issues
PAN-OSĀ® 11.2.7-h4 addressed issues.
    
  | Issue ID | Description | 
|---|---|
| PAN-304088 | Fixed an issue where TCP traffic stopped working from Prisma Access
                                clients to TCP services behind the Service Connection (SC) after a
                                dataplane upgrade to an affected release.  | 
| PAN-303559 | Fixed an issue where, after manually creating a device telemetry
                                bundle, the hour_cli_output.txt file within the bundle had a file
                                size of 0 bytes. This occurred when checking the bundle content
                                after enabling device telemetry and setting the device telemetry
                                upload endpoint.  | 
| PAN-301828 | Fixed an issue where, when a firewall was managed by Strata Cloud
                                Manager and configured to use a proxy server for external
                                connections, the management server did not use the configured
                                settings to connect to the Cloud Management service.  | 
| PAN-300906 | Fixed an issue where XML API commands failed with a
                                    Method not found (policy_xml) error
                                in dagger.log. The issue was due to missing XML-related functions
                                for inline-cloud-proxy.  | 
| PAN-298505 | Fixed an issue where, after upgrading an HA pair of PA-7050
                                firewalls, the vsys ID changed in sequence, causing autocommit
                                failures with validation errors. This occurred when the multi-vsys
                                firewall had virtual systems created and pushed from Panorama, and
                                the vsys ID was not in a correct sequence because the unused vsys
                                was deleted from Panorama and pushed to devices.  | 
| PAN-298387 | Fixed an issue on the firewall where the source and destination NAT
                                IP addresses did not display in traffic and threat logs.  | 
| PAN-297972 | Fixed an issue where a dataplane crash occurred when traffic matched
                                Inline Cloud Analysis prefiltering signatures, even when Inline
                                Cloud Analysis features were not enabled.  | 
| PAN-297775 | Fixed an issue where, after upgrading, the Visible Virtual
                                    Systems field started to reference the vsys name
                                instead of the vsys ID, which caused inter-vsys routing to fail.
                                This occurred when a vsys display name matched one of the vsys IDs.
                             | 
| PAN-297240 | Fixed an issue where attempting to generate reports in a WildFire
                                FIPS Private Cloud or WF-500 deployment returned 401 errors. | 
| PAN-295560 | Fixed an issue where, after upgrading Panorama and Log Collectors,
                                tunnel logs were not visible in Panorama or Splunk even though
                                traffic and threat logs were received.  | 
|  PAN-295385 | Fixed an issue where syslog forwarding dropped due to FQDN resolution
                                failures. | 
| PAN-295257 | Fixed an issue where, after onboarding a firewall to Panorama, IPsec
                                tunnels displayed IKEv2 in Panorama, even though the tunnels were
                                configured with IKEv1 locally on the firewall.  | 
| PAN-295221 | Fixed an issue where, after upgrading Panorama and Log Collectors,
                                Traffic and Threat logs were not forwarded to a Splunk server over
                                UDP.  | 
| PAN-294893 | Fixed an issue where firewalls with the Send handshake
                                    messages to CTD for inspection setting enabled
                                caused incorrect security policy rules to be matched. Specifically,
                                traffic not identified as openai-base or openai-chatgpt applications
                                was incorrectly matched by the ALLOW-OPEN-AI-FULL-ACCESS-URLS-ALERTS
                                rule. Additionally, the expected response page for blocked URLs was
                                not displayed.  | 
| PAN-294524 | Fixed an issue where firewalls and Panorama management servers were
                                unable to view or download WildFire reports from a WF-500 appliance,
                                resulting in a 401 error in the report tab. | 
| PAN-294320 | Fixed an issue where the mprelay process repeatedly
                                restarted.  | 
| PAN-292447 | Fixed an issue where Panorama did not display data in the
                                    Feature Adoption tab in Strata Cloud
                                Manager due to the system creating and deleting a CLI user for each
                                interval instead of reusing a permanent CLI user for telemetry.  | 
|  PAN-291940 | Fixed an issue where the firewall established multiple TCP
                                connections to a syslog server, which caused logs to be dropped.
                                This occurred because the firewall established a new TCP session for
                                each transfer and the sessions were not closed, which resulted in a
                                continuous increase in connections over time.  | 
| PAN-291716 | Fixed an issue where during a commit, the firewall experienced an
                                out-of-memory (OOM) condition due to a memory leak and displayed an
                                error message. This issue caused the device to crash and reboot
                                unexpectedly.  | 
| PAN-291653 | Fixed an issue where the GlobalProtect host ID field was
                                intermittently blank in traffic logs on Prisma Access, even when the
                                user was connected and had the correct host ID information. This
                                occurred when the IP address to host ID entry expired and the entry
                                was re-insterted without the dataplane flag being set.  | 
| PAN-291635 | Fixed an issue where cookie surrogate cache entries remained
                                unresolved after an idmgr process reset due to the
                                request not being retransmitted. This occurred because the timestamp
                                in the cache entry was refreshed even when the UID was 0, which
                                prevented the retransmission of the request if the initial response
                                was not received.  | 
| PAN-291067 | Fixed an issue where the devsrvr process periodically
                                exceeded its virtual memory limit and restarted, which led to
                                intermittent outages.  | 
| PAN-289859 | (Panorama virtual appliances only) Fixed an issue where
                                Panorama failed to mount logging disks larger than 2TB due to a
                                partitioning error.  | 
| PAN-289405 | (VM-Series firewalls only) Added the CLI command
                                    no-refresh-discard-session to
                                address an issue where the discarded session time to live (TTL) did
                                not refresh at the default value.  | 
| PAN-289383 | Fixed an issue where the MPLS interface eth1/6 went down and remained
                                down, even after replacing the SFP with a supported one and
                                adjusting duplex and speed settings.  | 
| PAN-289249 | Fixed an issue where a memory leak occurred on the
                                    reportd process when a WildFire update was
                                initiated while device telemetry data collection was in progress.
                                This resulted in an OOM condition.  | 
| PAN-289109 | Fixed an issue where the Panorama web interface was slower than
                                expected during configuration operations and a configuration lock
                                time out occurred during a commit.  | 
| PAN-288097 | Fixed an issue where on the firewall where the routed
                                process stopped responding after changing the MTU or any link state
                                parameters when OSPF and PIM were enabled on the same interface.
                             | 
| PAN-287803 | Fixed an issue where, after upgrading, certain websites weren't
                                accessible when the accumulation proxy was enabled. The proxy did
                                not use the same DF bit state as the original traffic, causing it to
                                be fragmented and dropped elsewhere in the network.  | 
| PAN-287782 | Fixed an issue where firewalls configured in vwire mode modified DSCP
                                values from AF11 to CS0 on traffic passing through the firewall,
                                even when QoS policy rules and DSCP rewrite settings were not
                                configured.  | 
| PAN-287622 | Fixed an issue where IPv6 traffic was affected after upgrading the
                                firewall. With SSL decryption enabled and a decryption policy
                                configured for the traffic, the firewall dropped packets due to
                                receiving a Packet Too Big ICMP
                                message. This occurred because the PathMTU information update was
                                incorrect for the TCB (pan-server) when the firewall was acting as a
                                server. Additionally, the flow label under the IPv6 header was set
                                to zero while the packet was being transmitted out of the firewall.
                             | 
| PAN-287601 | Fixed an issue on Panorama where commits took longer than expected.
                             | 
| PAN-287387 | Fixed an issue on Panorama where API jobs failed with the error
                                message Server error: Timed out while getting config
                                    lock. This occurred due to slow set request
                                performance when setting a large number of address objects in a
                                single set call.  | 
|  PAN-283053 | Fixed an issue where the firewall experienced high disk space
                                utilization, which caused the firewall to become non-functional.
                             | 
| PAN-282277 | Fixed an issue where an OOM condition on the logrcvr
                                process caused interface flapping, and the interface unexpectedly
                                went down and then recovered without intervention.  | 
| PAN-281776 | Fixed an issue on the Panorama web interface where the error message
                                    PPPoEv6 Client Interface cannot be enabled with
                                    DHCPv6 client was generated when overriding
                                aggregate interfaces even when no DHCPv6 or PPPoE was configured.
                             | 
| PAN-278836 | Fixed an issue where, after an upgrade, GlobalProtect attempted to
                                use the embedded browser instead of the default browser for gateway
                                authentication even when it was configured to use the default
                                browser.  | 
| PAN-272245 | Fixed an issue where the dnsproxy process stopped
                                responding due to memory corruption caused by a race condition when
                                the allow list downloading was impacted by a configuration
                                change. | 
| PAN-267450 | Fixed an issue where the reportd process stopped
                                responding with a SIGSEGV at
                                    schedule_report_es_response.  | 
