PAN-OS 11.2.7 Addressed Issues
Table of Contents
Expand All
|
Collapse All
Next-Generation Firewall Docs
-
-
-
-
-
-
-
- PAN-OS 12.1
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 11.0 (EoL)
- PAN-OS 10.2
- PAN-OS 10.1
- PAN-OS 10.0 (EoL)
- PAN-OS 9.1 (EoL)
- PAN-OS 9.0 (EoL)
- PAN-OS 8.1 (EoL)
-
- PAN-OS 12.1
- PAN-OS 11.2
- PAN-OS 11.1
- PAN-OS 10.2
- PAN-OS 10.1
PAN-OS 11.2.7 Addressed Issues
PAN-OSĀ® 11.2.7 addressed issues.
Issue ID | Description |
---|---|
PAN-290803 | (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where firewall failed to bootstrap with a custom image, and VM-Series plugin information was not displayed in the system information.
|
PAN-290542
|
Fixed an issue where the all_task process stopped
responding when an additional header logging HTTP header was split
across 2 packets.
|
PAN-290239 | (PA-455 firewalls in active/passive high availability (HA) configurations only) Fixed an
issue where, after an upgrade, the TCP session for syslog forwarding
did not resume after the syslog server service was disabled and then
re-enabled, which caused logs to be dropped. This occurred when the
syslog server was down for more than 16 minutes.
|
PAN-289102 |
(PA-7500 Series, PA-5410, PA-5420, PA-5430, PA-5440, PA-5445,
PA-3400 Series, PA-1400 Series, PA-400 Series, VM-Series, and
CN-Series firewalls only) Fixed a race condition issue
related to predict processing, which resulted in a dataplane restart
and traffic loss.
|
PAN-288930 | Fixed an issue where traffic from cloud applications intermittently matched an incorrect cloud-apps policy rule when ACE (App-ID Cloud Engine) was enabled.
|
PAN-287818 | Fixed an issue where sessions timed out sooner than expected due to the pan_proxy_accumulation_restore_timeout not initiating when the accumulation session_init failed.
|
PAN-286897 | Fixed an issue where the pan_task process stopped responding when the firewall attempted to forward files to the WildFire public cloud, which caused the dataplane to experience heartbeat failures.
|
PAN-286857 | Fixed an issue where only failed Kerberos authentication events were logged in auth.log, and successful authentication events were not logged.
|
PAN-286848 | Fixed an issue where ECMP incorrectly balanced sessions across links based on the configured metric, which led to an imbalance in traffic distribution and resulted in traffic assignment shifting disproportionately to routes with lower metrics.
|
PAN-286825 | Fixed an issue where GlobalProtect User-ID mappings were lost after 5 minutes, which caused users to not match User-ID source-based policy rules. This occurred due to a mismatch between the GlobalProtect gateway connection settings and the device behavior and when the inactivity-logout setting was deleted and set to a different value.
|
PAN-285894 | Fixed an issue where the all_task process stopped responding, which caused the firewall to reboot unexpectedly, and traffic failures occurred.
|
PAN-285651 | (Panorama appliances in active/passive HA configurations on Microsoft Azure environments only) Fixed an issue on Panorama that caused firewalls to disconnect unexpectedly.
|
PAN-285597 | Fixed an issue where a routed process memory leak occurred when advanced routing was enabled.
|
PAN-285590 | (VM-Series firewalls on Amazon Web Services (AWS) GWLB environments only) Fixed an issue where the firewall CPU usage reached 100% after upgrading to PAN-OS 11.1.6-h1.
|
PAN-284117
|
(Panorama appliances in Log Collector mode only) Fixed an
issue where the vm_agent process restarted after an
upgrade.
|
PAN-284066 | Fixed an issue where, after an upgrade, the SNMP polled values for IF-MIB::ifInErrors displayed a high number of errors that did not match the values in the CLI show interface command.
|
PAN-283813 | Fixed an issue on Panorama where the web interface performance was slower than usual when retrieving read-only configurations from Panorama.
|
PAN-283789 | (Firewalls in HA configurations only) Fixed an issue where, after an upgrade, the mac receive error counter in receive incoming errors increased, which resulted in SNMP alerts.
|
PAN-283644 | (Prisma Access only) Fixed an issue where URL log ingestion decreased after an upgrade, and secondary connections were lost.
|
PAN-283331 | Fixed an issue where selective pushes to managed devices failed when the User ID Master Device was configured.
|
PAN-282697 | Fixed an issue where traffic was delayed significantly when it used No Authentication Explicit Proxy and matched a decryption policy rule.
|
PAN-282640 | Fixed an issue where custom reports showed incomplete data when exported in CSV format from Panorama.
|
PAN-282394 | Fixed an issue where a firewall was only able to display a maximum of 14 permitted IP addresses from a Panorama Template Variable.
|
PAN-282391 | (Panorama appliances and Log Collectors only) Fixed an issue where a VLD memory leak caused increased memory use, which resulted in OOM errors.
|
PAN-282359 | Fixed an issue where the Panorama web interface was slower than expected.
|
PAN-282240 | Fixed an issue where, when attempting to modify an Anti-Spyware profile via the web interface under a shared location, clicking the OK button displayed a console exception error.
|
PAN-281885 | Fixed an issue where, when exporting and importing CSV files, the hash values of pre-shared key variables set at template and template stack levels changed inconsistently, which resulted in both variables displaying the same hash value.
|
PAN-281882 | Fixed an issue where OSPF redistributed connected routes beyond the intended loopback IP address.
|
PAN-281649 | Fixed an issue where the index size limit was incorrectly calculated and indices rolled over earlier than expected, which resulted in high memory and OOM errors.
|
PAN-281540 | Fixed an issue where the logd process repeatedly restarted when the SD-WAN site name was over 31 characters and contained certain XML escape characters.
|
PAN-281509 | (Panorama appliances only) Fixed an issue where log exports were slower than expected or failed when filtering logs after an upgrade, which resulted in timeouts or delays in displaying logs on the web interface.
|
PAN-281269 | (PA-5420 firewalls) Fixed an issue where the firewall management server memory usage continuously increased.
|
PAN-281264 | Fixed an issue where the routed process memory usage continuously increased when Advanced Routing was enabled.
|
PAN-280942 | Fixed an issue where the logrcvr process stopped responding.
|
PAN-280698 | Fixed an issue where the firewall removed the TCP timestamp from client hello messages that did not fit in a single packet, which resulted in connection issues.
|
PAN-280532 | Fixed an issue where, after disabling and re-enabling the external syslog server, the TCP session was not resumed, which caused all logs that were forwarded to the syslog server to be dropped.
|
PAN-280505 | Fixed an issue where the web interface did not display a message to commit prior changes before attempting a partial configuration load.
|
PAN-280477 | Fixed an issue on the web interface were you were unable to scroll up or down to view source zones in a NAT policy rule.
|
PAN-280335 | Fixed an issue with an SNMPv3 EngineBoots value discrepancy that prevented to SNMP server from logging.
|
PAN-280243 | Fixed an issue where the firewall lost the pre-shared key configuration assigned from a PSK variable when an unrelated device group configuration was loaded.
|
PAN-279691 | (Firewalls in active/passive HA configurations only) Fixed an issue where the firewall didn't synchronize IPSec SAs (security associations) to the passive firewall if the tunnel was not initially established by the active firewall.
|
PAN-279500 | To use this fix, run the following CLI command: debug dataplane set ssl-decrypt accumulate-client-hello asym-disable yes.
|
PAN-279495 | Fixed an issue where accessing a URL from the browser returned the error message ERR_RESPONSE_HEADERS_TRUNCATED when the firewall was configured with TLS 1.3.
|
PAN-279400 | Fixed an issue where, when Restrict Certificate Extensions was enabled on decryption profiles, the basic constraints extension was overwritten incorrectly.
|
PAN-279336 | Fixed an issue where the CLI did not display a message to commit prior changes before loading a partial configuration.
|
PAN-279176 | Fixed an issue where the configuration audit displayed inaccurate information after partially loading the configuration via the CLI, which caused the audit to flag the configuration as deleted or changed.
|
PAN-279065 | Fixed an issue where the firewall sent logs with connection succeeded to the syslog server every time a connection was established, which resulted in excessive logs.
|
PAN-278981 | Fixed an issue where DNS domain resolutions experienced intermittent delays due to the firewall not connecting to the DNS Security cloud.
To use this fix, enable DNS monitoring on the dataplane via the CLI command debug dnsproxyd enable-rtsig-health-monitor yes.
To show the current setting, run the CLI command debug dnsproxyd enable-rtsig-health-monitor show. If the cfg.general.dns-rtsig-monitor-interval shows a non-zero value, DNS monitoring is enabled.
|
PAN-278812 | Fixed an issue where authentication to GlobalProtect failed with the error message User not in allowed list.
|
PAN-278461
|
(Firewalls deployed in Amazon Web Services (AWS) environments
only) Fixed an issue where DNS Security retransmit packets
were not re-encapsulated into Geneve, which caused DNS requests that
were initiated from the firewall to be returned to AWS GWLB.
|
PAN-278190 | Fixed an issue on Panorama where a scheduled report with SLS data had an invalid translated-query.
|
PAN-278150 | Fixed an issue where the firewall removed the Authentication Key Identifier (AKID) from the certificate during SSL decryption, which caused Python 3.13 to fail with a certificate verification error.
|
PAN-277808 | Fixed an issue where the eproxy. process stopped responding when running a long duration test using IXload with hybrid SWG SAML authentication bypass for HTTPS payloads, which caused the proxy to become unreachable.
|
PAN-277631 | Fixed an issue where the logrcvr process discarded logs due to a full queue.
|
PAN-277464 | Fixed an issue with intermittent access and slower than expected loading times when accessing
websites. This occurred when Anti-Spyware inline cloud analysis was
enabled and the SSL Command and Control
action was not either allow or
alert and server hello packets were out
of order.
|
PAN-277234 | Fixed an issue where a device group import resulted in a Security policy rule being created with Application set to none.
|
PAN-277147 | Fixed an issue where daily scheduled reports were not generated and emailed.
|
PAN-276920 | Fixed an issue where web-advertisement traffic was not immediately blocked which resulted in pages loading indefinitely.
|
PAN-276678 | Fixed an issue where Panorama became unresponsive while performing a dynamic address update without a lock.
|
PAN-276276 | (PA-450 firewalls only) Fixed an issue where, after an upgrade, data that was excluded using the query builder in a custom report was still visible in the report, and the logs displayed errors related to invalid threat names being queried.
|
PAN-276062 | Fixed an issue where importing a firewall with a large number of address objects into Panorama did not work and remained at 99% completion.
|
PAN-275754 | Added support for bootstrapping Panorama virtual appliances on ESXi.
|
PAN-275718 | Fixed an issue where Panorama stopped forwarding logs to a syslog server after upgrading to
PAN-OS 11.1.5-h1.
|
PAN-275713 | Fixed an issue where the dscd process stopped responding when Endpoint Serial Number was enabled, which resulted in the **Active Directory* returning a list of serial numbers for a specific firewall from the Cloud Identity Engine.
|
PAN-275133 | Fixed an issue where HTTP 503 server errors occurred while browsing websites due to slow Secure Web Gateway (SWG) bypass rule lookup.
|
PAN-275077 | Fixed an issue where DNS Security intermittently logs malicious domain URLs as Alert instead of taking a Sinkhole action, even when configured to Sinkhole malicious DNS domains.
|
PAN-275047 | (VM-Series firewalls only) Fixed an issue where, after an upgrade, the firewall was unable to send logs to the Strata Logging Service (SLS) when using a specific proxy server, and the SSL connection status displayed as failed when attempting to forward logs through the web proxy.
|
PAN-274806 | (PA-5250 firewalls only) Fixed an issue where IPv6 pings experienced a high number of dropped packets when forwarded to another dataplane, which resulted in ping failures. This occurred when initiating a ping to the link local address of the firewall and the packet drop percentage depended on the number of dataplanes.
|
PAN-274797 | Fixed an issue where a DPC on slot 3 failed intermittently due to the pktlog_forwarding process restarting, which resulted in an unexpected HA failover.
|
PAN-274750 | Fixed an issue where the detailed log view in Panorama did not display all packet details for traffic logs received from the cloud.
|
PAN-274726 | Fixed an issue where Wildfire signature generation was enabled on all nodes in a cluster instead of only the active node.
|
PAN-274697 | Fixed an issue where push operations from Panorama failed on passive firewalls when an application was removed from a Security policy rule and the policy rule was referenced in a device group.
|
PAN-274671 | Fixed an issue where empty traffic logdb folders were generated for each day even when trafcfic logs were not received by the logrcvr process.
|
PAN-274569 | Fixed an issue where the QSPF transceiver interface displayed an incorrect range figure on the temperature alarm.
|
PAN-274496 | Fixed an issue where the root partition reached 100% which caused the system to become non-functional and failover even when aggressive cleaning was enabled.
|
PAN-274146 | Fixed an issue where the firewall rebooted continuously after upgrading to PAN-OS 11.1.5-h1 when a tunnel session was established in a Gateway Load Balancing (GWLB) scenario and no data packet was associated with the packet.
|
PAN-273964 | Fixed an issue where SNMP scans to a firewall timed out after upgrading to a PAN-OS 10.2 release.
|
PAN-273694 | Fixed an issue where the firewall rebooted due to an out-of-bounds memory access that occurred as a result of the SIP content length value being split across packets.
|
PAN-273614 | Fixed an issue where packets were dropped initially when a SYN cookie with activation threshold 0 was enabled.
|
PAN-273597 | Fixed an issue where logs in the cloud database displayed in the Not-Resolved category but not in the local database.
|
PAN-273453 | Fixed an issue where restarting the firewall did not initiate an autocommit job, which caused the firewall to stop responding and the HA interface to go down.
|
PAN-273277 | Fixed an issue where GlobalProtect clients on macOS devices were prompted to enter their username and password for Kerberos SSO authentication.
|
PAN-273153 | Fixed an issue where the Panorama web interface was slower than expected due to excessive polling of the MonitorDirect.getTasks API by the Task Manager.
|
PAN-273141 | Fixed an issue where GlobalProtect clients experienced slow file transfer download throughput when passing through an IPSec tunnel.
|
PAN-272812 | Fixed an issue where SNMP monitoring of tunnel interfaces displayed zero values for received bytes and packets.
|
PAN-272746 | (PA-440 firewalls only) Fixed an issue where the firewall entered an unstable state after committing changes or onboarding to Panorama.
|
PAN-272605 | Fixed an issue where the firewall did not display VPC endpoints when there was a large amount of VPC endpoints to interface mappings.
|
PAN-272539 | (Panorama appliances on Microsoft Azure environments only) Fixed an issue where user to IP address mapping was missing for some users connected to specific Prisma Access gateways, which caused the collection layer Azure firewall to not form the mapping.
|
PAN-272395 | Fixed an issue where informational logs caused the distributord process log file to be frequently overwritten.
|
PAN-272175 | Fixed an issue where session rematch caused ACE cloud application traffic to match the wrong policy.
|
PAN-271700 | Fixed an issue where User-ID connections were lost after an HA failover.
|
PAN-271560 | Fixed an issue where DNS requests to malware sites were not blocked as expected, and the dns-security-categories log-level and action displayed default values instead of unavailable.
|
PAN-271498 | (PA-7000 Series firewalls, PA-5200 firewalls, and PA-5400f firewalls in FIPS mode only) Fixed an issue where decrypted traffic repeatedly failed and frequent reboots were required.
|
PAN-271425 | (Firewalls in active/active HA configurations only) Fixed an issue with SSL inbound decryption on firewalls on a vwire setup with asymmetric routing.
To use this fix, enter the CLI command set system setting ssl-decrypt ha-vwire-mac-learn global yes on both firewalls in an HA pair.
|
PAN-271184 | Fixed an issue where Device Telemetry failed due to an issue with the encoding of characters in the log file path.
|
PAN-271175 | Fixed an issue where the all_task process stopped responding with a SIGABRT.
|
PAN-271151 | Fixed an issue where the GlobalProtect client did not automatically initiate a Kerberos SSO connection after logging in to Windows.
|
PAN-270849 | Fixed a memory leak issue related to the configd process that occurred when running consecutive commits for multiple days.
|
PAN-270744 | Fixed an issue where API calls to Panorama failed with the error Server error : Timed out while getting config lock. Please try again.
|
PAN-270379 | Fixed an issue where socket files created in the /tmp directory were not cleared.
|
PAN-270193 | Fixed an issue where the Panorama management server changed its certificate authority (CA) unexpectedly, which caused managed firewalls to disconnect.
|
PAN-270192 | Fixed an issue where Panorama did not display the management IP address of devices onboarded via ZTP.
|
PAN-269700 | Fixed an issue where commits to service connection firewalls from Panorama failed.
|
PAN-269677 | Fixed an issue where Panorama did not check for a NULL pointer when querying logs, which caused logs to not display on the web interface.
|
PAN-269624 | Fixed an issue where GlobalProtect clients failed to connect with the error message The device or feature requires a GlobalProtect subscription license.
|
PAN-269193 | Fixed an issue where the firewall redirected the user to the first application instead of the portal page with a list of applications when multiple applications were configured for GlobalProtect clientless VPN along with any user match.
|
PAN-269139 | (Firewalls with DPDK enabled in Azure, GCP, AWS, and KVM environments only) Fixed an issue where, after an upgrade to PAN-OS 11.1.4, the mac receive error counter increased without an error even though traffic was not impacted.
|
PAN-268708 | Fixed an issue where PDF summary and email reports displayed IPv6 addresses instead of IPv4 addresses.
|
PAN-268614 | Fixed an issue on the web interface where, when all rules were highlighted when a read-only admin user clicked the Highlight Unused Rules checkbox.
|
PAN-268489 | Fixed a Threat log PCAP ID overwrapping issue.
|
PAN-268465 | Fixed an issue with firewalls in active/passive HA configurations where the total user count in the registered users was different between the active and passive firewall.
|
PAN-268279 | Fixed an issue where autocommits failed if the management IPv6 gateway was the same as the dataplane interface IP address.
|
PAN-267759 | Fixed an issue where Prisma Access gateway downloads were slower than expected.
|
PAN-267518 | Fixed an issue where WildFire submission logs incorrectly reported allowed malicious samples even when they were blocked by threat prevention profiles.
|
PAN-266427 | Fixed an issue on the firewall where, when a high number of SD-WAN branch sites or interfaces were not connected, SD-WAN processes and tund processes stopped responding due to a high probing rate.
|
PAN-266116 | Fixed an issue where URLs did not work due to certificate revocation list (CRL) requests failing.
|
PAN-265900 | Fixed an issue where the firewall stopped responding due to a tund process or SD-WAN process restart.
|
PAN-265791 | Fixed an issue where the all_task process stopped responding, which caused the dataplane to go down.
|
PAN-264982 | (VM-Series firewalls on Kernel-based Virtual Machine (KVM) only) Fixed an issue where the firewall entered maintenance mode after an auto-commit when sending an ARP packet through the loopback interface using an IPv6 address.
|
PAN-264708 | Fixed an issue where a selective push was blocked when a configuration load was done.
|
PAN-262729 | (Panorama appliances only) Fixed an issue where the configd process experienced continuous high CPU utilization and repeatedly restarted.
|
PAN-262373 | Fixed an issue where the error message Failed to reload config files displayed in the system logs even when device telemetry was not enabled.
|
PAN-262372 | Fixed an issue where the firewall generated the error message Successfully generating a new set of config files in the system logs even when device telemetry was not enabled.
|
PAN-262063 | Fixed an issue where the firewall did not display the converted configurations before a commit and reboot, and the commit failed when attempting to migrate from MS to FRR mode.
|
PAN-261597 | Fixed an issue where the all_pktproc process stopped responding, which caused the firewall to become unavailable.
|
PAN-261312 | Fixed an issue where a commit for a policy and configuration dump overlapped, which resulted in a null pointer exception.
|
PAN-261074 | Fixed an issue where the firewall delayed video file transfers over SMB when Exclude Video Traffic from the Tunnel feature was enabled and no applications were added to the list.
|
PAN-260229 | Fixed an issue where HA path monitoring using VWire did not work as expected after a reboot.
|
PAN-259727 | (Panorama appliances in HA configurations only) Fixed an issue where Panorama became unresponsive and displayed a 504 gateway timeout error when accessing the web interface or the CLI.
|
PAN-259610 | Fixed an issue where Wildfire content installation failed for WF-500B clusters when deployed from Panorama using the deployment schedule.
|
PAN-258743 | Fixed an issue where, when you attempted to select a redistribution profile when creating a BGP Redistribute policy rule, the firewall displayed an empty dropdown.
|
PAN-258166 | (PA-220 firewalls only) Fixed an issue where the root partition frequently reached 100%.
|
PAN-258162 | (Panorama appliances on AWS environments only Fixed an issue where IP addresses were not retrieved in Dynamic Address Groups when multiple AND operators were configured.
|
PAN-257183 | Fixed an issue where the firewall dropped DNS traffic when using DNS Security.
|
PAN-256904 | Fixed an issue where the firewall inconsistently blocked URLs due to intermittent URL category misidentification.
|
PAN-256867 | Fixed an issue where the logrcvr process stopped responding while processing session logs for forwarding to the LFC.
|
PAN-255759 | Fixed an issue where the firewall was unable to match HIP data with the correct anti-malware object for Windows Defender.
|
PAN-254904 | Fixed an issue on Panorama where a core file was generated by /usr/local/bin/logd during a restart.
|
PAN-254524 | Fixed an issue on Panorama where, when the Commit and Push button was clicked during a selective Commit and Push operation, the window stopped responding, which caused the operation to be delayed.
|
PAN-253127 | Fixed an issue where, after upgrading to PAN-OS 11.0.2-h3, the hardware pool DFLT became highly utilized, and the packet buffer gradually increased.
|
PAN-251715 | Fixed an issue where the firewall closed the SSL connection to the user ID agent.
|
PAN-243235 | Fixed an issue where Panorama stopped responding and rebooted repeatedly after an upgrade.
|
PAN-193285 | Fixed an issue where the policy optimizer feature did not add entries back to the mongodb database after removing them during an upgrade or downgrade.
|