PAN-OS 11.2.4-h14 Addressed Issues
Table of Contents
Expand All
|
Collapse All
Next-Generation Firewall Docs
-
-
-
-
-
-
-
- PAN-OS 12.1
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 11.0 (EoL)
- PAN-OS 10.2
- PAN-OS 10.1
- PAN-OS 10.0 (EoL)
- PAN-OS 9.1 (EoL)
- PAN-OS 9.0 (EoL)
- PAN-OS 8.1 (EoL)
-
- PAN-OS 12.1
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 10.2
- PAN-OS 10.1
PAN-OS 11.2.4-h14 Addressed Issues
PAN-OSĀ® 11.2.4-h14 addressed issues.
Issue ID | Description |
|---|---|
|
PAN-303559
|
Fixed an issue where, after manually creating a device telemetry
bundle, the hour_cli_output.txt file
within the bundle had a file size of 0 bytes. This occurred when
checking the bundle content after enabling device telemetry and
setting the device telemetry upload endpoint.
|
|
PAN-301456
|
Fixed an issue on Panorama where the debug system
reset-ztp CLI command was unavailable.
|
|
PAN-300216
|
Fixed an issue where, when SD-WAN Direct Internet Access was
configured and traffic traversed the cellular interface without a
NAT policy rule, intermittent cellular modem connectivity issues
occurred, which caused the firewall to disconnect and reconnect to
the cellular network. To use this fix, run the CLI
command set session teardown-upon-fwd-zonechange
yes.
|
|
PAN-298462
|
Fixed an issue where the firewall experienced extended boot times
after a reboot due to the configd process needing to
rebuild the ACE catalog after detecting discrepancies that were
caused by duplicate application checking between the ACE catalog and
content.
|
PAN-297976 | Fixed an issue where the firewall experienced extended boot times after a reboot due to the configd process needing to rebuild the ACE catalog after detecting discrepancies that were caused by duplicate application checking between the ACE catalog and content.
|
PAN-297972 | Fixed an issue where a dataplane crash occurred when traffic matched Inline Cloud Analysis prefiltering signatures, even when Inline Cloud Analysis features were not enabled.
|
|
PAN-297775
|
Fixed an issue where, after upgrading to an affected PAN-OS release,
the Visible Virtual System field referenced the vsys name instead of
the vsys ID, which caused inter-vsys routing to fail. This occurred
when a vsys display name matched one of the vsys IDs. If you're
using a multivsys environment, you must upgrade your firewalls to a
fixed PAN-OS version. The best practice is to upgrade both the
firewalls and Panorama to a fixed PAN-OS version.
If you don't upgrade Panorama to a fixed version, you'll encounter
PAN-245064, where a commit on a multivsys firewall fails with the
message vsys name should end with a number vsys is
invalid after you Export or push
device config bundle from 11.1.1 Panorama.
After you upgrade Panorama to a fixed version, you'll encounter
PAN-214177, which causes an Export or Push device
config bundle from Panorama to the firewall to
fail. The workaround for PAN-214177 is to first push only the
template configuration and then push the device group
configurations.
|
|
PAN-296752
|
(PA-1410 Firewalls only) Fixed an issue where the firewall
experienced high management CPU usage and repeatedly rebooted when
attempting to retrieve SMART data.
|
|
PAN-296694
|
Fixed an issue where the firewall rebooted due to the
useridd process repeatedly restarting during an
IP-port data type writes to the redis from multiple sources such as
TSA or XML in a scale environment.
|
|
PAN-296535
|
Fixed an issue on the firewall where BGP peers disconnected due to
frr_ns1_bgpd restarting.
|
PAN-294436 | (PA-410, PA-440, PA-450, and PA-460 firewalls only) Fixed an issue where, after upgrading to PAN-OS 11.1.6-h6 the Eth1/2, Eth1/3, Eth1/8, and HA interfaces failed to display counters and statistics in the CLI and SNMP.
|
|
PAN-292447
|
Fixed an issue where Panorama did not display data in the
Feature Adoption tab in Strata Cloud
Manager due to the system creating and deleting a CLI user for each
interval instead of reusing a permanent CLI user for telemetry.
|
|
PAN-291940
|
Fixed an issue where the firewall established multiple TCP
connections to a syslog server, which caused logs to be dropped.
This occurred because the firewall established a new TCP session for
each transfer and the sessions were not closed, which resulted in a
continuous increase in connections over time.
|
|
PAN-291661
|
Fixed an issue on Panorama appliances and Log Collectors where, after
an upgrade, Elasticsearch intermittently entered into a Red state
before automatically recovering.
|
|
PAN-289249
|
Fixed an issue where a memory leak occurred on the
reportd process when a WildFire update was
initiated while device telemetry data collection was in progress.
This resulted in an OOM condition.
|
PAN-289109 | Fixed an issue where the Panorama web interface was slower than expected during configuration operations and a configuration lock time out occurred during a commit.
|
|
PAN-287387
|
Fixed an issue on Panorama where API jobs failed with the error
message Server error: Timed out while getting config
lock. This occurred due to slow set request
performance when setting a large number of address objects in a
single set call.
|
PAN-284279 | Fixed an issue where the policy destination always defaulted to any, even when specific IP addresses and FQDNs were specified during policy import.
|
PAN-284067 | Fixed a cumulative memory leak in the devsrvr process that occurred whenever the CLI
command show running application
statistics was issued. This memory leak would
gradually consume system memory and produce an OOM condition,
causing the firewall to reboot.
|
PAN-281776 | Fixed an issue on the Panorama web interface where the error message PPPoEv6 Client Interface cannot be enabled with DHCPv6 client was generated when overriding aggregate interfaces even when no DHCPv6 or PPPoE was configured.
|
|
PAN-279829
|
Fixed an issue where NAT pool leaks occurred during a test when RTSP
traffic hit NAT rules.
|
PAN-272746 | (PA-440 firewalls only) Fixed an issue where the firewall entered an unstable state after committing changes or onboarding to Panorama.
|
|
PAN-272605
|
Fixed an issue where the firewall did not display VPC endpoints when
there was a large amount of VPC endpoints to interface mappings.
|
PAN-272245 | Fixed an issue where the dnsproxy process stopped responding due to memory corruption caused by a race condition when the allow list downloading was impacted by a configuration change.
|
|
PAN-267450
|
Fixed an issue where the reportd process stopped
responding with a SIGSEGV at
schedule_report_es_response.
|
PAN-266312 | Fixed an issue where BFD sessions took longer than expected to establish after an HA failover due to BGP.
|
|
PAN-264131
|
Fixed an issue where the routed process core failed the
automation run.
|