PAN-OS 11.1.13-h2 Addressed Issues
Focus
Focus

PAN-OS 11.1.13-h2 Addressed Issues

Table of Contents

PAN-OS 11.1.13-h2 Addressed Issues

PAN-OSĀ® 11.1.13-h2 addressed issues.
Issue ID
Description
PAN-314319
Fixed an issue where the firewall experienced increased packet drops and slower performance after an upgrade due to high burst traffic.
PAN-313572
(VM-Series firewalls only) Fixed an issue where the dataplane restarted due to a segmentation fault.
PAN-312706
Fixed an issue where the firewalls restarted due to a function lacking a NULL-pointer sanity check.
PAN-311524
Fixed an issue where config-lock was not displayed on the web interface.
PAN-311250
(Panorama appliances and Log Collectors only) Fixed an issue where logs from multiple devices were not visible on Panorama even though the Elasticsearch health status on the dedicated Log Collectors appeared green.
PAN-311073
(Panorama managed firewalls in HA configurations only) Fixed an issue where firewalls incorrectly updated the modified date and MD5 hash of policy rules during an HA sync commit job or a subsequent local commit, even when no changes were made to the policy rules.
PAN-308786
(Panorama appliances only) Fixed an issue where traffic log queries using the device_name filter returned no results, and, additionally complex log queries that included negation operators produced incorrect outputs.
PAN-308654
Fixed an issue where the Elasticsearch Close Indices process closed more indices than expected and dropped the number of open shards below the minimum of 800 per Elasticsearch instance. This occurred because the process did not correctly account for the number of Elasticsearch instances when calculating the maximum number of allowed open shards.
PAN-307702
(Firewalls in HA configurations only) Fixed an issue where traffic passing through AE layer 2 interfaces was interrupted during HA failovers.
PAN-307597
Fixed an issue where BGP peering sessions between a hub firewall and a satellite firewall over GlobalProtect LSVPN failed to connect.
PAN-306555
Fixed an issue where the firewall stopped responding, which led to service outages.
PAN-306451
(VM-Series firewalls on AWS environments only) Fixed an issue where, after upgrading the firewall to an affected release, GlobalProtect clients did not connect with IPSec and instead connected using SSL due to traffic flow being disabled when checking for health check packets.
PAN-305700
Fixed an issue where a reboot loop occurred when OSPF interfaces were configued with a link type of point-to-point.
PAN-305552
Fixed an issue where DLP logs displayed an incorrect file type when the firewall did not set the file type field.
PAN-304746
(Panorama appliances and Panorama virtual appliances only) Fixed an issue where the configd process restarted when committing and pushing configuration for a new WildFire cluster.
PAN-304718
Fixed an issue where OSPF and BGP outages occurred due to an all_task process restart during clientless VPN content rewrite processing.
PAN-304696
Fixed an issue where the Cloud User-ID connection timed out because the firewall took too long to process the OCSP response.
PAN-304576
Fixed an issue where the firewall entered a non-functional state due to segmentation fault within the all_pktproc process that was caused by a session that involved http2 cleartext traffic
PAN-303745
Fixed an issue where inter-dataplane forwarding did not work for sessions ingressing on Slot 2, which resulted in intermittent ping failures to interfaces on Network Card 2 when traffic was forwarded to Slot 3. Note: With this fix, after a slot restart, the global counter will still show dot1q errors for a short period.
PAN-303722
Fixed an issue on the firewall where configuring spyware and vulnerability profiles in Security policy rules caused a memory leak in the devsrvr process with each configuration commit.
PAN-301731
Fixed an issue where, when the firewall was unable to establish an SCM connection due to the discovery service returning a 404 error when the device was not yet known to the service, the firewall did not retry the attempt as expected.
PAN-300664
Fixed an issue on the Panorama and firewall web interface where Applications pages became unresponsive after activating the SaaS Inline license.
PAN-299705
Fixed an issue where API calls to commit changes on Panorama intermittently failed when using the XML API with refresh=no, which caused changes to not be applied to the partial-commit configuration.
PAN-299495
Fixed an issue where the show system setting ssl-decrypt certificate CLI command did not display certificates when XML output was enabled.
PAN-298945
Fixed an issue where OSCP HTTP POST requests were not formatted correctly, which caused failures with strict responders.
PAN-297540
(Panorama managed firewalls in HA configurations only) Fixed an issue where the HA-Link-Monitor configuration pushed from Panorama was converted to a local configuration on the peer device after an HA sync, which caused subsequent Panorama pushes of link monitor changes to be flagged as overwritten, and a forced template push or manual clearing of the configuration on the firewall was required.
PAN-296694
Fixed an issue where the firewall rebooted due to the useridd process repeatedly restarting during an IP-port data type writes to the redis from multiple sources such as TSA or XML in a scale environment.
PAN-295803
Addressed a memory leak issue under sc3 and automatic commit recovery (ACR) code path.
PAN-295802
Fixed an issue where a memory leak related to the configd process occurred.
PAN-294379
Fixed an issue where, when SD-WAN SaaS Application path monitoring failed for all interfaces, the firewall stopped forwarding traffic even if the ISP links and default gateway probing were still active.
PAN-292306
Fixed an issue where the authd process stopped handling RADIUS authentication requests and required a restart.
PAN-290938
Fixed an issue where multiple memory leaks occurred related to the configd process.
PAN-288175
Addressed a stack buffer overflow memory leak under plugin management code path.
PAN-287159
Fixed an issue where file uploads to Dropbox stalled when using a PA-CPT device with MLC2 and DLP Mirror mode enabled for HTTP2 traffic. This occurred because the proxy was unable to decrement packet counts properly when the queue was large, resulting in a receive window size of 0 for the parent session.
PAN-279364
(VM-Series firewalls with multiple NICs only) Fixed an issue were the queue count in the task dump displayed an incorrect number of queues for SR-IOV interfaces due to the queue mapping logic incorrectly using a non-multi-NIC function.
PAN-278688
Fixed an issue where DNS Security threat logs were not displayed on the firewall when packet capture was enabled and the domain name length was 62 characters.
PAN-274742
(VM-Series firewalls only) Fixed an issue where the task-queue dump CLI command returned incorrect information in multi-nic mode.
PAN-259785
Fixed an issue where the devsrvr process restarted and created a core dump because two threads did not terminate correctly.