PAN-OS 11.1.10 Addressed Issues
Focus
Focus

PAN-OS 11.1.10 Addressed Issues

Table of Contents

PAN-OS 11.1.10 Addressed Issues

PAN-OSĀ® 11.1.10 addressed issues.
Issue ID
Description
PAN-288693
Fixed an issue where importing a device configuration into Panorama failed with a validation error if the configuration included a shared gateway with shared address objects.
PAN-286897
Fixed an issue where the pan_task process stopped responding when the firewall attempted to forward files to the WildFire public cloud, which caused the dataplane to experience heartbeat failures.
PAN-286475
Fixed an issue where the option to sort sequence numbers was missing from Filters prefix list in the advanced routing filters.
PAN-285590
(VM-Series firewalls on Amazon Web Services (AWS) GWLB environments only) Fixed an issue where the firewall CPU usage reached 100% after upgrading to PAN-OS 11.1.6-h1.
PAN-284840
(PA-5220 firewalls only) Fixed an issue where custom reports were delayed when sent via email instead of being sent at the scheduled time.
PAN-284116
Fixed an issue where mTLS decryption bypass did not work when the decryption profile was configured with the maximum TLS version as TLS 1.3.
PAN-284066
Fixed an issue where, after an upgrade, the SNMP polled values for IF-MIB::ifInErrors displayed a high number of errors that did not match the values in the CLI show interface command.
PAN-283789
(Firewalls in high availability (HA) configurations only) Fixed an issue where, after an upgrade, the mac receive error counter in receive incoming errors increased, which resulted in SNMP alerts.
PAN-283467
(PA-3400 Series firewalls only) Fixed an issue where the firewall unexpectedly rebooted and entered maintenance mode due to a ctd-agent out-of-memory (OOM) condition. This occurred during advanced services load testing and a high volume of IoT EAL log forwarding.
PAN-283331
Fixed an issue where selective pushes to managed devices failed when the User ID Master Device was configured.
PAN-282640
Fixed an issue where custom reports showed incomplete data when exported in CSV format from Panorama.
PAN-281776
Fixed an issue on the Panorama web interface where the error message PPPoEv6 Client Interface cannot be enabled with DHCPv6 client was generated when overriding aggregate interfaces even when no DHCPv6 or PPPoE was configured.
PAN-280698
Fixed an issue where the firewall removed the TCP timestamp from client hello messages that did not fit in a single packet, which resulted in connection issues.
PAN-280532
Fixed an issue where, after disabling and re-enabling the external syslog server, the TCP session was not resumed, which caused all logs that were forwarded to the syslog server to be dropped.
PAN-280335
Fixed an issue with an SNMPv3 EngineBoots value discrepancy that prevented to SNMP server from logging.
PAN-278981
Fixed an issue where DNS domain resolutions experienced intermittent delays due to the firewall not connecting to the DNS Security cloud.
To use this fix, enable DNS monitoring on the dataplane via the CLI command debug dnsproxyd enable-rtsig-health-monitor yes.
To show the current setting, run the CLI command debug dnsproxyd enable-rtsig-health-monitor show. If the cfg.general.dns-rtsig-monitor-interval shows a non-zero value, DNS monitoring is enabled.
PAN-276276
(PA-450 firewalls only) Fixed an issue where, after an upgrade, data that was excluded using the query builder in a custom report was still visible in the report, and the logs displayed errors related to invalid threat names being queried.
PAN-275601
Fixed an issue where, when Panorama was not internet connected and you attempted to upload images to managed firewalls using the Validate option, the upload failed with the error Failed to create multi-upload job. No valid software deploy targets found.
PAN-274806
(PA-5250 firewalls only) Fixed an issue where IPv6 pings experienced a high number of dropped packets when forwarded to another dataplane, which resulted in ping failures. This occurred when initiating a ping to the link local address of the firewall and the packet drop percentage depended on the number of dataplanes.
PAN-274496
Fixed an issue where the root partition reached 100% which caused the system to become non-functional and fail over even when aggressive cleaning was enabled.
PAN-272812
Fixed an issue where SNMP monitoring of tunnel interfaces displayed zero values for received bytes and packets.
PAN-271560
Fixed an issue where DNS requests to malware sites were not blocked as expected, and the dns-security-categories log-level and action displayed default values instead of unavailable.
PAN-271215
A fix was made to address CVE-2025-4230.
PAN-270379
Fixed an issue where socket files created in the /tmp directory were not cleared.
PAN-269155
Fixed an issue where an OOM condition occurred, which caused processes to stop responding.
PAN-269139
(Firewalls with DPDK enabled in Azure, GCP, AWS, and KVM environments only) Fixed an issue where, after an upgrade to PAN-OS 11.1.4, the mac receive error counter increased without an error even though traffic was not impacted.
PAN-268922
(PA-3220 firewalls in HA configurations only) Fixed an intermittent issue where the firewalls went out of sync after a configuration push from Panorama.
PAN-268680
Fixed an issue where the configd process stopped responding when a configuration merge operation changed.
PAN-268032
Fixed an issue where importing a device configuration into Panorama failed with a validation error if the configuration included a shared gateways containing NAT/PBF rules.
To use this fix:
  1. Enable the configuration. Commit failures may occur if the device is not able to support the number of objects.
  2. Export and push the device group only.
  3. Push the template.
Note: This fix is supported on PAN-OS 10.2 and later releases.
PAN-264982
(VM-Series firewalls on Kernel-based Virtual Machine (KVM) only) Fixed an issue where the firewall entered maintenance mode after an auto-commit when sending an ARP packet through the loopback interface using an IPv6 address.
PAN-263504
Fixed an issue where exporting managed device information from Panorama in CSV format included extraneous characters.
PAN-260661
Fixed an issue where daily email reports generated from the custom report did not display the report details in PDF or CSV files.
PAN-209516
Fixed an issue where, when creating an interface, an error occurred when you clicked OK without providing a value in the Tag field even though the field was not displayed as mandatory.