PAN-OS 11.1.13-h2 Addressed Issues
Table of Contents
Expand All
|
Collapse All
Next-Generation Firewall Docs
-
-
-
-
-
-
-
- PAN-OS 12.1
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 11.0 (EoL)
- PAN-OS 10.2
- PAN-OS 10.1
- PAN-OS 10.0 (EoL)
- PAN-OS 9.1 (EoL)
- PAN-OS 9.0 (EoL)
- PAN-OS 8.1 (EoL)
-
- PAN-OS 12.1
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 10.2
- PAN-OS 10.1
PAN-OS 11.1.13-h2 Addressed Issues
PAN-OSĀ® 11.1.13-h2 addressed issues.
Issue ID | Description |
|---|---|
|
PAN-314319
|
Fixed an issue where the firewall experienced increased packet drops
and slower performance after an upgrade due to high burst
traffic.
|
|
| |
|
PAN-313572
|
(VM-Series firewalls only) Fixed an issue where the
dataplane restarted due to a segmentation fault.
|
PAN-312706 | Fixed an issue where the firewalls restarted due to a function lacking a NULL-pointer sanity check.
|
|
PAN-311524
|
Fixed an issue where config-lock was not displayed on the web
interface.
|
PAN-311250 | (Panorama appliances and Log Collectors only) Fixed an issue where logs from multiple devices were not visible on Panorama even though the Elasticsearch health status on the dedicated Log Collectors appeared green.
|
|
PAN-311073
|
(Panorama managed firewalls in HA configurations only) Fixed
an issue where firewalls incorrectly updated the modified date and
MD5 hash of policy rules during an HA sync commit job or a
subsequent local commit, even when no changes were made to the
policy rules.
|
PAN-308786 | (Panorama appliances only) Fixed an issue where traffic log queries using the device_name filter returned no results, and, additionally complex log queries that included negation operators produced incorrect outputs.
|
|
PAN-308654
|
Fixed an issue where the Elasticsearch Close Indices process closed
more indices than expected and dropped the number of open shards
below the minimum of 800 per Elasticsearch instance. This occurred
because the process did not correctly account for the number of
Elasticsearch instances when calculating the maximum number of
allowed open shards.
|
PAN-307702 | (Firewalls in HA configurations only) Fixed an issue where traffic passing through AE layer 2 interfaces was interrupted during HA failovers.
|
PAN-307597 | Fixed an issue where BGP peering sessions between a hub firewall and a satellite firewall over GlobalProtect LSVPN failed to connect.
|
PAN-306555 | Fixed an issue where the firewall stopped responding, which led to service outages.
|
|
PAN-306451
|
(VM-Series firewalls on AWS environments only) Fixed an
issue where, after upgrading the firewall to an affected release,
GlobalProtect clients did not connect with IPSec and instead
connected using SSL due to traffic flow being disabled when checking
for health check packets.
|
PAN-305700 | Fixed an issue where a reboot loop occurred when OSPF interfaces were configued with a link type of point-to-point.
|
PAN-305552 | Fixed an issue where DLP logs displayed an incorrect file type when the firewall did not set the file type field.
|
|
PAN-304746
|
(Panorama appliances and Panorama virtual appliances only)
Fixed an issue where the configd process restarted when
committing and pushing configuration for a new WildFire cluster.
|
|
PAN-304718
|
Fixed an issue where OSPF and BGP outages occurred due to an
all_task process restart during clientless VPN
content rewrite processing.
|
|
PAN-304696
|
Fixed an issue where the Cloud User-ID connection timed out because
the firewall took too long to process the OCSP response.
|
|
PAN-304576
|
Fixed an issue where the firewall entered a non-functional state due
to segmentation fault within the all_pktproc process
that was caused by a session that involved http2 cleartext
traffic
|
|
PAN-303745
|
Fixed an issue where inter-dataplane forwarding did not work for
sessions ingressing on Slot 2, which resulted in intermittent ping
failures to interfaces on Network Card 2 when traffic was forwarded
to Slot 3. Note: With this fix, after a slot restart, the global
counter will still show dot1q errors for a short period.
|
PAN-303722 | Fixed an issue on the firewall where configuring spyware and vulnerability profiles in Security policy rules caused a memory leak in the devsrvr process with each configuration commit.
|
PAN-301731 | Fixed an issue where, when the firewall was unable to establish an SCM connection due to the discovery service returning a 404 error when the device was not yet known to the service, the firewall did not retry the attempt as expected.
|
PAN-300664 | Fixed an issue on the Panorama and firewall web interface where Applications pages became unresponsive after activating the SaaS Inline license.
|
PAN-299705 | Fixed an issue where API calls to commit changes on Panorama intermittently failed when using the XML API with refresh=no, which caused changes to not be applied to the partial-commit configuration.
|
PAN-299495 | Fixed an issue where the show system setting ssl-decrypt certificate CLI command did not display certificates when XML output was enabled.
|
PAN-298945 | Fixed an issue where OSCP HTTP POST requests were not formatted correctly, which caused failures with strict responders.
|
|
PAN-297540
|
(Panorama managed firewalls in HA configurations only) Fixed
an issue where the HA-Link-Monitor configuration pushed from
Panorama was converted to a local configuration on the peer device
after an HA sync, which caused subsequent Panorama pushes of link
monitor changes to be flagged as overwritten, and a forced template
push or manual clearing of the configuration on the firewall was
required.
|
PAN-296694 | Fixed an issue where the firewall rebooted due to the useridd process repeatedly restarting during an IP-port data type writes to the redis from multiple sources such as TSA or XML in a scale environment.
|
PAN-295803 | Addressed a memory leak issue under sc3 and automatic commit recovery (ACR) code path.
|
PAN-295802 | Fixed an issue where a memory leak related to the configd process occurred.
|
|
PAN-294379
|
Fixed an issue where, when SD-WAN SaaS Application path monitoring
failed for all interfaces, the firewall stopped forwarding traffic
even if the ISP links and default gateway probing were still
active.
|
PAN-292306 | Fixed an issue where the authd process stopped handling RADIUS authentication requests and required a restart.
|
PAN-290938 | Fixed an issue where multiple memory leaks occurred related to the configd process.
|
PAN-288175 | Addressed a stack buffer overflow memory leak under plugin management code path.
|
PAN-287159 | Fixed an issue where file uploads to Dropbox stalled when using a PA-CPT device with MLC2 and DLP Mirror mode enabled for HTTP2 traffic. This occurred because the proxy was unable to decrement packet counts properly when the queue was large, resulting in a receive window size of 0 for the parent session.
|
|
PAN-279364
|
(VM-Series firewalls with multiple NICs only) Fixed an issue
were the queue count in the task dump displayed an incorrect number
of queues for SR-IOV interfaces due to the queue mapping logic
incorrectly using a non-multi-NIC function.
|
|
PAN-278688
|
Fixed an issue where DNS Security threat logs were not displayed on
the firewall when packet capture was enabled and the domain name
length was 62 characters.
|
|
PAN-274742
|
(VM-Series firewalls only) Fixed an issue where the
task-queue dump CLI command
returned incorrect information in multi-nic mode.
|
PAN-259785 | Fixed an issue where the devsrvr process restarted and created a core dump because two threads did not terminate correctly.
|