PAN-OS 11.1.6-h25 Addressed Issues
Focus
Focus

PAN-OS 11.1.6-h25 Addressed Issues

Table of Contents

PAN-OS 11.1.6-h25 Addressed Issues

PAN-OSĀ® 11.1.6-h25 addressed issues.
Issue ID
Description
PAN-308060
(Firewalls in active/active HA configurations only) Fixed an issue where the BFD session went down and did not recover even though the BGP remained in an established state, which caused the firewall to cease route learning and advertisement with the peer, even though BGP keep-alives were exchanged correctly.
PAN-307795
Fixed an issue where Panorama incorrectly generated system logs indicating a lost connection to its peer after an upgrade even when High Availability was not configured.
PAN-305412
Fixed an issue where the Logging Service License Status displays a license failure when the license status transitions from valid to expired and then back to valid even when the connection to the Security Logging Service (SLS) was working.
PAN-305301
Fixed an issue where the timing of GlobalProtect lifetime expiry or inactivity logout notifications used for GlobalProtect SSL tunnels could cause the pan_task process to stop responding and the dataplane to restart.
PAN-303959
Fixed an issue where traffic is incorrectly identified as unknown-tcp/unknown-udp due to App-ID resource leak and eventually dropped.
PAN-302551
Fixed an issue where the firewall displayed as disconnected in the SLS due to the serial number not being retrieved
PAN-301975
(Firewalls in HA configurations only) Fixed an issue where the passive firewall incorrectly triggered PBP alerts even with low packet rates.
PAN-301912
Fixed an issue where Panorama stopped responding when deploying dynamic updates to managed devices.
PAN-301600
Fixed an issue on the firewall where, after upgrading Panorama, OSPF adjacencies remained in the exchange start state, which resulted in an incomplete routing table.
PAN-301456
Fixed an issue on Panorama where the debug system reset-ztp CLI command was unavailable.
PAN-301409
Fixed an issue where Panorama failed to perform a selective push to a managed device when device tags were added or modified on the policy rules. The selective push failed with the error message Failed to generate selective push configuration. Schema validation failed. Please try a full push.
PAN-300837
Fixed an issue where firewalls experienced multiple reboots due to the pan_task process restarting with a SIGSEGV signal. This occurred because the client-to-firewall side assumed TLS 1.3 for the firewall-server side.
PAN-299751
Fixed an issue where the firewall was unable to connect to the Subscription License Service (SLS) due to a public and private key pair mismatch with the device certificate.
PAN-298907
Fixed an issue on PA-VM in AWS where, in a two-arm deployment integrated with Gateway Load Balancer (GWLB), the firewall did not preserve the GENEVE source port for internet traffic, resulting in increased latency. The fix ensures the firewall preserves the outer UDP source port of GENEVE encapsulation when sending traffic back to GWLB.
PAN-298872
(PA-400 Series firewalls in HA configurations only) Fixed an issue where ports went down after an HA failover.
PAN-297263
(PA-5220 firewalls only) Fixed an issue where the ikemgr process crashed intermittently, causing IPSec tunnels to go down randomly. The fix ensures that the IKE security association data structures are accessed in a thread-safe manner. This prevents the ikemgr process from referencing an invalid memory pointer during teardown operations and provides stability.
PAN-296208
Fixed an issue where the firewall did not accept address groups in the filter condition of a Log Forwarding Match list.
PAN-290241
Fixed an issue where the useridd process became unresponsive, which caused User-ID CLI commands to time out.
PAN-289652
Fixed an issue related to external URL lists where pushing configuration changes from Panorama failed.
PAN-288427
Fixed an issue on Panorama where commit jobs were not queued and the system reported that the useridd was not connected.
PAN-287921
(VM-Series firewalls only) Fixed an issue where the maximum registered IP address for was incorrectly set to 100,000 instead of the expected 500,000.
PAN-285208
Fixed an issue where the firewall did not automatically recover after a machine check exception (MCE) occurred.
PAN-281588
Fixed an issue where packet buffer depletion occurred due to the a high number of tcp_pkt_queued packets when Jumbo was enabled.
PAN-272731
Fixed an issue on Panorama where commits took longer than expected due to the show object dynamic-address-group all CLI command holding the devicetable lock for an extended period.
PAN-263691
Fixed an issue where the firewall rebooted unexpectedly due to a memory leak in the all_task process.
PAN-253921
Fixed an issue where the firewall displayed the following error message: critical userid registe 0 fail to integrate the update of registered ip addresses since 2 seconds ago; critical system log alerts observed.
PAN-185731
Fixed an issue where the firewall was unable to parse the URL path and host when the host header was located in a different packet, which resulted in the firewall not logging the URL path in the first packet. The fix is disabled by default. The following CLI commands can be used to enable/disable the feature:
  • set system setting ctd url-crosspkt-host-path-caching enable
  • set system setting ctd url-crosspkt-host-path-caching disable
  • set system setting ctd url-crosspkt-host-path-caching default