PAN-OS 11.2.10-h2 Addressed Issues
Table of Contents
Expand All
|
Collapse All
Next-Generation Firewall Docs
-
-
-
-
-
-
-
- PAN-OS 12.1
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 11.0 (EoL)
- PAN-OS 10.2
- PAN-OS 10.1
- PAN-OS 10.0 (EoL)
- PAN-OS 9.1 (EoL)
- PAN-OS 9.0 (EoL)
- PAN-OS 8.1 (EoL)
-
- PAN-OS 12.1
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 10.2
- PAN-OS 10.1
PAN-OS 11.2.10-h2 Addressed Issues
PAN-OSĀ® 11.2.10-h2 addressed issues.
Issue ID | Description |
|---|---|
|
PAN-306306
|
(Panorama appliances in FIPS-CC mode only) Fixed interdevice
TLS communication failures that occurred with RSA and RSA-PSS
signature algorithms across multiple layer 7 application
services.
|
|
PAN-303051
|
Fixed an issue on Panorama where a memory leak occurred related to
the reportd process due to retaining memory that was
temporarily used for report generation instead of releasing the
memory for reuse, which resulted in continuous accumulation and
memory exhaustion.
|
|
PAN-302927
|
Fixed an issue where, after upgrading Panorama, the Push
to Devices option did not display selected devices,
and the OK and Cancel
buttons did not function as expected. Selecting
OK did not close the window, and
selecting Cancel returned to the main push
screen with the push selected devices displaying as empty. Despite
this, selecting Push or Validate
Device Group Push still pushed to the previously
canceled, non-displayed devices.
|
PAN-301801 | Fixed an issue on Log Collectors where the Elasticsearch process fluctuated intermittently between green and red states, which led to interruptions in log collection. This issue occurred when the number of shards exceeded the cluster's maximum supported threshold of greater than 1000 shards per Elasticsearch instance.
|
|
PAN-301691
|
Fixed an issue where BGP stopped responding with the error message
Too many open files when pushing
1000 eBGP (External BGP) neighbor configurations. With this fix, the
number of file descriptors for the BGP process is increased from
1024 to 8192.
|
PAN-301456 | Fixed an issue on Panorama where the debug system reset-ztp CLI command was unavailable.
|
PAN-300216 | Fixed an issue where, when SD-WAN Direct Internet Access was configured and traffic traversed the cellular interface without a NAT policy rule, intermittent cellular modem connectivity issues occurred, which caused the firewall to disconnect and reconnect to the cellular network.
To use this fix, run the CLI command set session teardown-upon-fwd-zonechange yes.
|
|
PAN-300138
|
Fixed an issue where DNS queries stalled or repeatedly time out due
to multiple DNS responses with different CNAME values causing
evasion false positive alerts.
|
PAN-299815 | Fixed an issue on multi-vsys firewalls where a host was not removed from the quarantine list after receiving a redistribution message from Panorama. This occurred when Panorama was configured to redistribute quarantine messages to a firewall cluster, and the GlobalProtect configuration and redistribution were built out in a vsys other than vsys1.
|
|
PAN-298387
|
Fixed an issue on the firewall where the source and destination NAT
IP addresses did not display in traffic and threat logs.
|
|
PAN-297610
|
Fixed an issue where the firewall became unresponsive after an
upgrade due to the fsck command scanning drive
partitions in parallel with the root partition, which caused the
process to take an extended amount of time.
|
PAN-297005 | Fixed an issue where exporting custom reports resulted in empty CSV files.
|
|
PAN-296977
|
Fixed an issue where the web interface became unresponsive when
attempting to view Ethernet interface details
after applying a filter in NetworkInterfaces
|
|
PAN-296694
|
Fixed an issue where the firewall rebooted due to the
useridd process repeatedly restarting during an
IP-port data type writes to the redis from multiple sources such as
TSA or XML in a scale environment.
|
PAN-296535 | Fixed an issue on the firewall where BGP peers disconnected when more than 500 BGP neighbors were configured in a single Logical Router
|
PAN-295899 | Fixed an issue where DNS resolution failed on Linux machines running GlobalProtect client version 6.2.6 when connected with DNS Security enabled. This occurred because the firewall incorrectly discarded DNS packets when processing multiple DNS requests or responses over the same session, even when no malicious verdict was received.
|
PAN-276525 | Resolved multiple issues affecting IPSec tunnels using NAT Traversal (NAT-T) when a Dynamic NAT policy was configured (including Dynamic NAT or DIPP). During rekey events, tunnels could go down or flap due to incorrect session handling. This issue impacted both cluster and standalone deployments.
|
PAN-209516 | Fixed an issue where, when creating an interface, an error occurred when you clicked OK without providing a value in the Tag field even though the field was not displayed as mandatory.
|
PAN-185731 | Fixed an issue where the firewall was unable to parse the URL path and host when the host header was located in a different packet, which resulted in the firewall not logging the URL path in the first packet.
The fix is disabled by default. The following CLI commands can be used to enable/disable the feature:
set system setting ctd url-crosspkt-host-path-caching enable
set system setting ctd url-crosspkt-host-path-caching disable
set system setting ctd url-crosspkt-host-path-caching default
|