PAN-OS 11.1.16-h2 Addressed Issues
Focus
Focus

PAN-OS 11.1.16-h2 Addressed Issues

Table of Contents


PAN-OS 11.1.16-h2 Addressed Issues

Lists the addressed issues in PAN-OS 11.1.16-h2.
The following table lists the addressed issues in PAN-OS 11.1.16-h2.
Issue ID
Description
PAN-332608
Fixed an issue where firewalls intermittently disconnected from SLS. With this fix, firewalls maintained a stable connection to SLS.
PAN-332247
Fixed an issue where the proxy generated HTTP 503 errors for multiple URLs, which prevented users from connecting to servers. With this fix, the proxy now functions as expected.
PAN-332095
Fixed an issue where a commit to add a new tunnel interface to an existing Virtual Router caused BGP routes to be temporarily withdrawn, which led to active traffic sessions being routed over incorrect paths during the commit window. With this fix, adding a tunnel interface to an existing Virtual Router no longer disrupts BGP route availability.
PAN-331387
Fixed an issue where IPsec tunnels frequently went down due to high process memory utilization. With this fix, the system process now manages memory correctly, preventing tunnel instability.
PAN-330196
Fixed an issue where the firewall unexpectedly terminated operations and rebooted due to an internal software error.
PAN-329637
Fixed an issue where the push scope window did not display the target devices when attempting to push configurations from Panorama, which required manual selection of templates or device groups. With this fix, the push scope window now correctly populates with the intended push scope.
PAN-329612
Fixed an issue where multicast routing entries for certain IPTV streams were not correctly installed or populated with necessary interface information, which prevented the proper forwarding of multicast traffic. With this fix, multicast traffic now forwards as expected.
PAN-328770
Fixed an issue where BGP Graceful Restart (GR) capability continued to be advertised to BGP peers after GR was disabled on a Logical Router configured with the Advanced Routing Engine, which caused peers to incorrectly believe the firewall supported GR. With this fix, disabling BGP GR on a Logical Router correctly removes the capability from BGP Open messages.
PAN-325151
Fixed an issue where a system log was not generated when the proxy reached its session limit.
PAN-325057
Fixed an issue where TCP sessions were dropped due to an ACK-out-of-window condition during TCP reassembly when SYN cookies were enabled in a Zone Protection Profile. With this fix, TCP session establishment with SYN cookies enabled correctly tracks sequence numbers and no longer drops valid ACK packets from the Server.
PAN-324336
Fixed an issue where GlobalProtect iOS users were unable to connect due to the firewall incorrectly reporting that the maximum number of users was exceeded, even when the actual number of active users was below the configured limit.
PAN-321204
Fixed an issue where FTP-DATA sessions did not match the installed predict session, which led to session termination in HA configurations.
PAN-316979
Fixed an issue where the firewall rebooted unexpectedly when packet-diag logging was enabled. With this fix, the firewall maintains stability when this logging is active.
PAN-316869
Fixed an issue where previously committed Security policy rules were removed when a full commit was performed by a different administrator, which led to the inadvertent loss of configuration changes. With this fix, Security policy rules are retained as expected after a full commit.
PAN-315683
Fixed an issue where certain permitted IP addresses, when pushed from a Panorama template, remained editable on the firewall web interface. With this fix, these template-managed IP addresses are no longer editable on the firewall.
PAN-314873
Fixed an issue where the firewall intermittently stopped forwarding traffic to the internet.
PAN-312844
Fixed an issue where a TLSv1.3 handshake did not complete when SSL Forward Proxy was enabled. This occurred when a large ClientHello message was split across multiple TCP segments and the final segment contained only one byte.
PAN-311988
(Firewalls in FIPS mode only) Fixed decryption issues that occurred after an upgrade to an affected release.
To enable this fix, run the CLI command debug dataplane set ssl-decrypt low-memory-throttle enable.
PAN-310699
Fixed an issue where the firewall stripped the Authentication Key Identifier (AKID) from certificates using SSL decryption, which prevented clients from authenticating server certificates and resulted in decryption failures.
PAN-307933
(Panorama appliances in Log Collector mode only) Fixed an issue where the log collectors became unstable for an extended period of time when receiving large amounts of traffic.
PAN-301756
Fixed an issue where ACC logs displayed a discrepancy in SSL traffic information between Panorama and the firewall. With this fix, the SSL traffic information in ACC logs now aligns correctly.
PAN-297880
Fixed an issue where WildFire Analysis reports failed to load, displaying a 500 Internal Server Error when the system attempted to retrieve reports for certain files. With this fix, WildFire Analysis reports load as expected.
PAN-291706
Fixed an issue where the software tag descriptor was always at 100, which led to resource unavailability errors and prevented users from obtaining DHCP IP addresses.
PAN-283774
Fixed an issue where the firewall placed UDP sessions into a Discard state when a DNS Sinkhole/Block action occurred, which prevented subsequent DNS requests from reusing the same session and caused DNS-related outages.
PAN-264508
Fixed an issue where Cloud Identity Engine did not fetch user-mapping details for XML API users. This occurred when the firewall learned the same IP-user mapping multiple times within a short period. With this fix, the Cloud Identity Engine now accurately fetches these user-mapping details.