PAN-OS 11.1.13-h11 Addressed Issues
Focus
Focus

PAN-OS 11.1.13-h11 Addressed Issues

Table of Contents

PAN-OS 11.1.13-h11 Addressed Issues

Lists the addressed issues in PAN-OS 11.1.13-h11.
The following table lists the addressed issues in PAN-OS 11.1.13-h11.
Issue ID
Description
PAN-332095
Fixed an issue where a commit to add a new tunnel interface to an existing Virtual Router caused BGP routes to be temporarily withdrawn, which led to active traffic sessions being routed over incorrect paths during the commit window. With this fix, adding a tunnel interface to an existing Virtual Router no longer disrupts BGP route availability.
PAN-331387
Fixed an issue where IPsec tunnels frequently went down due to high process memory utilization. With this fix, the system process now manages memory correctly, preventing tunnel instability.
PAN-330196
Fixed an issue where the firewall unexpectedly terminated operations and rebooted due to an internal software error.
PAN-328770
Fixed an issue where BGP Graceful Restart (GR) capability continued to be advertised to BGP peers after GR was disabled on a Logical Router configured with the Advanced Routing Engine, which caused peers to incorrectly believe the firewall supported GR. With this fix, disabling BGP GR on a Logical Router correctly removes the capability from BGP Open messages.
PAN-326056
Fixed an issue where ACE applications did not match the correct Security policy rules when the service was not set to Application Default after an upgrade, which caused traffic to be incorrectly denied.
PAN-325496
(KVM VM-Series firewalls only) Fixed an issue where ARP entries were incomplete after an upgrade to an affected release.
PAN-325057
Fixed an issue where TCP sessions were dropped due to an ACK-out-of-window condition during TCP reassembly when SYN cookies were enabled in a Zone Protection Profile. With this fix, TCP session establishment with SYN cookies enabled correctly tracks sequence numbers and no longer drops valid ACK packets from the Server.
PAN-324336
Fixed an issue where GlobalProtect iOS users were unable to connect due to the firewall incorrectly reporting that the maximum number of users was exceeded, even when the actual number of active users was below the configured limit.
PAN-323974
Fixed an issue where you were unable to add logging drives to the firewall, and validation errors occurred when pushing configurations from Panorama.
PAN-329034
Fixed an intermittent issue where firewall restarted unexpectedly while processing zip files.
PAN-323501
Fixed an issue where SWG Explicit Proxy Kerberos authentication bypass did not occur for some URLs that matched a configured URL category.
PAN-323141
Fixed an issue where SD-WAN SaaS monitoring for HTTPS URLs continuously flapped, which caused frequent traffic shifting between ISPs. This occurred due to the firewall unexpectedly hitting resource limits for monitoring.
PAN-321937
Fixed an issue where an expired SD-WAN license caused SD-WAN tunnels to become unavailable, which resulted in traffic interruptions. With this fix, the device provides logs and commit messages about expired licenses.
PAN-321204
Fixed an issue where FTP-DATA sessions did not match the installed predict session, which led to session termination in HA configurations.
PAN-319343
(Prisma Access Gateways only) Fixed an issue where the global management plane stopped responding, which caused SSH and HTML disconnections, HIP database lookup failures, and significantly slower SCM commits. This occurred when egress IP allow listing was enabled in SCM and changes were made to EDLs.
PAN-317648
(PA-5450 firewalls and PA-7000 Series firewalls with 100G NPCs only) Fixed an issue where intermittent packet loss occurred when traversing the dataplane after upgrading the firewall. This occurred when a dataplane HA interface was configured in an environment where Slot 1 was unpopulated, which resulted in a wildcard entry being created within the QMAP table.
PAN-316721
Fixed an issue where multiple EDL fetches were queued and did not complete.
PAN-317614
Fixed an issue where high throughput and increased packet rates caused high dataplane CPU usage.
PAN-316979
Fixed an issue where the firewall rebooted unexpectedly when packet-diag logging was enabled. With this fix, the firewall maintains stability when this logging is active.
PAN-316869
Fixed an issue where previously committed Security policy rules were removed when a full commit was performed by a different administrator, which led to the inadvertent loss of configuration changes. With this fix, Security policy rules are retained as expected after a full commit.
PAN-314873
Fixed an issue where the firewall intermittently stopped forwarding traffic to the internet.
PAN-314776
Fixed an issue where the configd process stopped responding after pushing configuration changes from Panorama to the firewall.
PAN-314624
Fixed an issue where the useridd process became unresponsive and restarted when attempting to dump the Host Information Profile (HIP) database via CLI while the system was actively processing HIP reports. This was caused by a lock contention. With this fix, the process now operates as expected under these conditions.
PAN-312685
Fixed an issue where committing a scheduled configuration push on Panorama caused the configd process to stop responding unexpectedly.
PAN-312618
Fixed an issue where the firewall was unable to activate GlobalProtect client software and displayed SW LIMIT messages related to max-profiles and unsupported major and minor versions in the downgrade list, which prevented successful software installation.
PAN-312354
Fixed an issue where Captive Portal authentication redirects failed for HTTPS traffic when a user attempted to access internal HTTPS websites via URL, which led to ERR_CONNECTION_RESET error messages in the browser with SSL decryption and CTD handshake inspection enabled.
PAN-311988
(Firewalls in FIPS mode only) Fixed decryption issues that occurred after an upgrade to an affected release.
To enable this fix, run the CLI command debug dataplane set ssl-decrypt low-memory-throttle enable.
PAN-310699
Fixed an issue where the firewall stripped the Authentication Key Identifier (AKID) from certificates using SSL decryption, which prevented clients from authenticating server certificates and resulted in decryption failures.
PAN-310476
(Firewalls in active/passive HA configurations only) Fixed an issue where CPLD did not power cycle the firewall after internal packet path monitoring failures occurred, and both firewalls instead became simultaneously non-functional after a reboot.
PAN-310263
(VM-Series firewalls only) Fixed an issue where enabling TLS1.3 in a decryption profile prevented access to websites.
PAN-307933
(Panorama appliances in Log Collector mode only) Fixed an issue where the log collectors became unstable for an extended period of time when receiving large amounts of traffic.
PAN-306225
Fixed an issue on the firewall where the sslmgr process memory utilization continually increased due to memory fragmentation.
PAN-304840
Fixed an issue where multiple firewalls experienced high management CPU utilization after upgrading to an affected release due to repeated index regeneration occurring every 15 minutes, which caused periodic CPU spikes above 90%.
PAN-302983
Fixed an issue where, after committing changes on Panorama, a shared post-rule moved to the end of the post shared rulebase on the managed device instead of remaining at the top.
PAN-301756
Fixed an issue where ACC logs displayed a discrepancy in SSL traffic information between Panorama and the firewall. With this fix, the SSL traffic information in ACC logs now aligns correctly.
PAN-299027
(Panorama virtual appliances in Management Mode only) Fixed an issue where a maximum configuration size of 120 was incorrectly enforced instead of 150 MB.
PAN-297880
Fixed an issue where WildFire Analysis reports failed to load, displaying a 500 Internal Server Error when the system attempted to retrieve reports for certain files. With this fix, WildFire Analysis reports load as expected.
PAN-294001
Fixed an issue on Panorama managed firewalls generated Failed in get_pwchange_required error messages in the authd logs for local administators.
PAN-282335
Fixed an issue where firewalls in a cluster experienced approximately 50% packet loss on IPSec NATT tunnels when tunnel acceleration was enabled.