PAN-OS 11.2.7 Addressed Issues
Focus
Focus

PAN-OS 11.2.7 Addressed Issues

Table of Contents

PAN-OS 11.2.7 Addressed Issues

PAN-OSĀ® 11.2.7 addressed issues.
Issue ID
Description
PAN-290803
(VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where firewall failed to bootstrap with a custom image, and VM-Series plugin information was not displayed in the system information.
PAN-290542
Fixed an issue where the all_task process stopped responding when an additional header logging HTTP header was split across 2 packets.
PAN-290239
(PA-455 firewalls in active/passive high availability (HA) configurations only) Fixed an issue where, after an upgrade, the TCP session for syslog forwarding did not resume after the syslog server service was disabled and then re-enabled, which caused logs to be dropped. This occurred when the syslog server was down for more than 16 minutes.
PAN-289102
(PA-7500 Series, PA-5410, PA-5420, PA-5430, PA-5440, PA-5445, PA-3400 Series, PA-1400 Series, PA-400 Series, VM-Series, and CN-Series firewalls only) Fixed a race condition issue related to predict processing, which resulted in a dataplane restart and traffic loss.
PAN-288930
Fixed an issue where traffic from cloud applications intermittently matched an incorrect cloud-apps policy rule when ACE (App-ID Cloud Engine) was enabled.
PAN-287818
Fixed an issue where sessions timed out sooner than expected due to the pan_proxy_accumulation_restore_timeout not initiating when the accumulation session_init failed.
PAN-286897
Fixed an issue where the pan_task process stopped responding when the firewall attempted to forward files to the WildFire public cloud, which caused the dataplane to experience heartbeat failures.
PAN-286857
Fixed an issue where only failed Kerberos authentication events were logged in auth.log, and successful authentication events were not logged.
PAN-286848
Fixed an issue where ECMP incorrectly balanced sessions across links based on the configured metric, which led to an imbalance in traffic distribution and resulted in traffic assignment shifting disproportionately to routes with lower metrics.
PAN-286825
Fixed an issue where GlobalProtect User-ID mappings were lost after 5 minutes, which caused users to not match User-ID source-based policy rules. This occurred due to a mismatch between the GlobalProtect gateway connection settings and the device behavior and when the inactivity-logout setting was deleted and set to a different value.
PAN-285894
Fixed an issue where the all_task process stopped responding, which caused the firewall to reboot unexpectedly, and traffic failures occurred.
PAN-285651
(Panorama appliances in active/passive HA configurations on Microsoft Azure environments only) Fixed an issue on Panorama that caused firewalls to disconnect unexpectedly.
PAN-285597
Fixed an issue where a routed process memory leak occurred when advanced routing was enabled.
PAN-285590
(VM-Series firewalls on Amazon Web Services (AWS) GWLB environments only) Fixed an issue where the firewall CPU usage reached 100% after upgrading to PAN-OS 11.1.6-h1.
PAN-284117
(Panorama appliances in Log Collector mode only) Fixed an issue where the vm_agent process restarted after an upgrade.
PAN-284066
Fixed an issue where, after an upgrade, the SNMP polled values for IF-MIB::ifInErrors displayed a high number of errors that did not match the values in the CLI show interface command.
PAN-283813
Fixed an issue on Panorama where the web interface performance was slower than usual when retrieving read-only configurations from Panorama.
PAN-283789
(Firewalls in HA configurations only) Fixed an issue where, after an upgrade, the mac receive error counter in receive incoming errors increased, which resulted in SNMP alerts.
PAN-283644
(Prisma Access only) Fixed an issue where URL log ingestion decreased after an upgrade, and secondary connections were lost.
PAN-283331
Fixed an issue where selective pushes to managed devices failed when the User ID Master Device was configured.
PAN-282697
Fixed an issue where traffic was delayed significantly when it used No Authentication Explicit Proxy and matched a decryption policy rule.
PAN-282640
Fixed an issue where custom reports showed incomplete data when exported in CSV format from Panorama.
PAN-282394
Fixed an issue where a firewall was only able to display a maximum of 14 permitted IP addresses from a Panorama Template Variable.
PAN-282391
(Panorama appliances and Log Collectors only) Fixed an issue where a VLD memory leak caused increased memory use, which resulted in OOM errors.
PAN-282359
Fixed an issue where the Panorama web interface was slower than expected.
PAN-282240
Fixed an issue where, when attempting to modify an Anti-Spyware profile via the web interface under a shared location, clicking the OK button displayed a console exception error.
PAN-281885
Fixed an issue where, when exporting and importing CSV files, the hash values of pre-shared key variables set at template and template stack levels changed inconsistently, which resulted in both variables displaying the same hash value.
PAN-281882
Fixed an issue where OSPF redistributed connected routes beyond the intended loopback IP address.
PAN-281649
Fixed an issue where the index size limit was incorrectly calculated and indices rolled over earlier than expected, which resulted in high memory and OOM errors.
PAN-281540
Fixed an issue where the logd process repeatedly restarted when the SD-WAN site name was over 31 characters and contained certain XML escape characters.
PAN-281509
(Panorama appliances only) Fixed an issue where log exports were slower than expected or failed when filtering logs after an upgrade, which resulted in timeouts or delays in displaying logs on the web interface.
PAN-281269
(PA-5420 firewalls) Fixed an issue where the firewall management server memory usage continuously increased.
PAN-281264
Fixed an issue where the routed process memory usage continuously increased when Advanced Routing was enabled.
PAN-280942
Fixed an issue where the logrcvr process stopped responding.
PAN-280698
Fixed an issue where the firewall removed the TCP timestamp from client hello messages that did not fit in a single packet, which resulted in connection issues.
PAN-280532
Fixed an issue where, after disabling and re-enabling the external syslog server, the TCP session was not resumed, which caused all logs that were forwarded to the syslog server to be dropped.
PAN-280505
Fixed an issue where the web interface did not display a message to commit prior changes before attempting a partial configuration load.
PAN-280477
Fixed an issue on the web interface were you were unable to scroll up or down to view source zones in a NAT policy rule.
PAN-280335
Fixed an issue with an SNMPv3 EngineBoots value discrepancy that prevented to SNMP server from logging.
PAN-280243
Fixed an issue where the firewall lost the pre-shared key configuration assigned from a PSK variable when an unrelated device group configuration was loaded.
PAN-279691
(Firewalls in active/passive HA configurations only) Fixed an issue where the firewall didn't synchronize IPSec SAs (security associations) to the passive firewall if the tunnel was not initially established by the active firewall.
PAN-279500
To use this fix, run the following CLI command: debug dataplane set ssl-decrypt accumulate-client-hello asym-disable yes.
PAN-279495
Fixed an issue where accessing a URL from the browser returned the error message ERR_RESPONSE_HEADERS_TRUNCATED when the firewall was configured with TLS 1.3.
PAN-279400
Fixed an issue where, when Restrict Certificate Extensions was enabled on decryption profiles, the basic constraints extension was overwritten incorrectly.
PAN-279336
Fixed an issue where the CLI did not display a message to commit prior changes before loading a partial configuration.
PAN-279176
Fixed an issue where the configuration audit displayed inaccurate information after partially loading the configuration via the CLI, which caused the audit to flag the configuration as deleted or changed.
PAN-279065
Fixed an issue where the firewall sent logs with connection succeeded to the syslog server every time a connection was established, which resulted in excessive logs.
PAN-278981
Fixed an issue where DNS domain resolutions experienced intermittent delays due to the firewall not connecting to the DNS Security cloud.
To use this fix, enable DNS monitoring on the dataplane via the CLI command debug dnsproxyd enable-rtsig-health-monitor yes.
To show the current setting, run the CLI command debug dnsproxyd enable-rtsig-health-monitor show. If the cfg.general.dns-rtsig-monitor-interval shows a non-zero value, DNS monitoring is enabled.
PAN-278812
Fixed an issue where authentication to GlobalProtect failed with the error message User not in allowed list.
PAN-278461
(Firewalls deployed in Amazon Web Services (AWS) environments only) Fixed an issue where DNS Security retransmit packets were not re-encapsulated into Geneve, which caused DNS requests that were initiated from the firewall to be returned to AWS GWLB.
PAN-278190
Fixed an issue on Panorama where a scheduled report with SLS data had an invalid translated-query.
PAN-278150
Fixed an issue where the firewall removed the Authentication Key Identifier (AKID) from the certificate during SSL decryption, which caused Python 3.13 to fail with a certificate verification error.
PAN-277808
Fixed an issue where the eproxy. process stopped responding when running a long duration test using IXload with hybrid SWG SAML authentication bypass for HTTPS payloads, which caused the proxy to become unreachable.
PAN-277631
Fixed an issue where the logrcvr process discarded logs due to a full queue.
PAN-277464
Fixed an issue with intermittent access and slower than expected loading times when accessing websites. This occurred when Anti-Spyware inline cloud analysis was enabled and the SSL Command and Control action was not either allow or alert and server hello packets were out of order.
PAN-277234
Fixed an issue where a device group import resulted in a Security policy rule being created with Application set to none.
PAN-277147
Fixed an issue where daily scheduled reports were not generated and emailed.
PAN-276920
Fixed an issue where web-advertisement traffic was not immediately blocked which resulted in pages loading indefinitely.
PAN-276678
Fixed an issue where Panorama became unresponsive while performing a dynamic address update without a lock.
PAN-276276
(PA-450 firewalls only) Fixed an issue where, after an upgrade, data that was excluded using the query builder in a custom report was still visible in the report, and the logs displayed errors related to invalid threat names being queried.
PAN-276062
Fixed an issue where importing a firewall with a large number of address objects into Panorama did not work and remained at 99% completion.
PAN-275754
Added support for bootstrapping Panorama virtual appliances on ESXi.
PAN-275718
Fixed an issue where Panorama stopped forwarding logs to a syslog server after upgrading to PAN-OS 11.1.5-h1.
PAN-275713
Fixed an issue where the dscd process stopped responding when Endpoint Serial Number was enabled, which resulted in the **Active Directory* returning a list of serial numbers for a specific firewall from the Cloud Identity Engine.
PAN-275133
Fixed an issue where HTTP 503 server errors occurred while browsing websites due to slow Secure Web Gateway (SWG) bypass rule lookup.
PAN-275077
Fixed an issue where DNS Security intermittently logs malicious domain URLs as Alert instead of taking a Sinkhole action, even when configured to Sinkhole malicious DNS domains.
PAN-275047
(VM-Series firewalls only) Fixed an issue where, after an upgrade, the firewall was unable to send logs to the Strata Logging Service (SLS) when using a specific proxy server, and the SSL connection status displayed as failed when attempting to forward logs through the web proxy.
PAN-274806
(PA-5250 firewalls only) Fixed an issue where IPv6 pings experienced a high number of dropped packets when forwarded to another dataplane, which resulted in ping failures. This occurred when initiating a ping to the link local address of the firewall and the packet drop percentage depended on the number of dataplanes.
PAN-274797
Fixed an issue where a DPC on slot 3 failed intermittently due to the pktlog_forwarding process restarting, which resulted in an unexpected HA failover.
PAN-274750
Fixed an issue where the detailed log view in Panorama did not display all packet details for traffic logs received from the cloud.
PAN-274726
Fixed an issue where Wildfire signature generation was enabled on all nodes in a cluster instead of only the active node.
PAN-274697
Fixed an issue where push operations from Panorama failed on passive firewalls when an application was removed from a Security policy rule and the policy rule was referenced in a device group.
PAN-274671
Fixed an issue where empty traffic logdb folders were generated for each day even when trafcfic logs were not received by the logrcvr process.
PAN-274569
Fixed an issue where the QSPF transceiver interface displayed an incorrect range figure on the temperature alarm.
PAN-274496
Fixed an issue where the root partition reached 100% which caused the system to become non-functional and failover even when aggressive cleaning was enabled.
PAN-274146
Fixed an issue where the firewall rebooted continuously after upgrading to PAN-OS 11.1.5-h1 when a tunnel session was established in a Gateway Load Balancing (GWLB) scenario and no data packet was associated with the packet.
PAN-273964
Fixed an issue where SNMP scans to a firewall timed out after upgrading to a PAN-OS 10.2 release.
PAN-273694
Fixed an issue where the firewall rebooted due to an out-of-bounds memory access that occurred as a result of the SIP content length value being split across packets.
PAN-273614
Fixed an issue where packets were dropped initially when a SYN cookie with activation threshold 0 was enabled.
PAN-273597
Fixed an issue where logs in the cloud database displayed in the Not-Resolved category but not in the local database.
PAN-273453
Fixed an issue where restarting the firewall did not initiate an autocommit job, which caused the firewall to stop responding and the HA interface to go down.
PAN-273277
Fixed an issue where GlobalProtect clients on macOS devices were prompted to enter their username and password for Kerberos SSO authentication.
PAN-273153
Fixed an issue where the Panorama web interface was slower than expected due to excessive polling of the MonitorDirect.getTasks API by the Task Manager.
PAN-273141
Fixed an issue where GlobalProtect clients experienced slow file transfer download throughput when passing through an IPSec tunnel.
PAN-272812
Fixed an issue where SNMP monitoring of tunnel interfaces displayed zero values for received bytes and packets.
PAN-272746
(PA-440 firewalls only) Fixed an issue where the firewall entered an unstable state after committing changes or onboarding to Panorama.
PAN-272605
Fixed an issue where the firewall did not display VPC endpoints when there was a large amount of VPC endpoints to interface mappings.
PAN-272539
(Panorama appliances on Microsoft Azure environments only) Fixed an issue where user to IP address mapping was missing for some users connected to specific Prisma Access gateways, which caused the collection layer Azure firewall to not form the mapping.
PAN-272395
Fixed an issue where informational logs caused the distributord process log file to be frequently overwritten.
PAN-272175
Fixed an issue where session rematch caused ACE cloud application traffic to match the wrong policy.
PAN-271700
Fixed an issue where User-ID connections were lost after an HA failover.
PAN-271560
Fixed an issue where DNS requests to malware sites were not blocked as expected, and the dns-security-categories log-level and action displayed default values instead of unavailable.
PAN-271498
(PA-7000 Series firewalls, PA-5200 firewalls, and PA-5400f firewalls in FIPS mode only) Fixed an issue where decrypted traffic repeatedly failed and frequent reboots were required.
PAN-271425
(Firewalls in active/active HA configurations only) Fixed an issue with SSL inbound decryption on firewalls on a vwire setup with asymmetric routing.
To use this fix, enter the CLI command set system setting ssl-decrypt ha-vwire-mac-learn global yes on both firewalls in an HA pair.
PAN-271184
Fixed an issue where Device Telemetry failed due to an issue with the encoding of characters in the log file path.
PAN-271175
Fixed an issue where the all_task process stopped responding with a SIGABRT.
PAN-271151
Fixed an issue where the GlobalProtect client did not automatically initiate a Kerberos SSO connection after logging in to Windows.
PAN-270849
Fixed a memory leak issue related to the configd process that occurred when running consecutive commits for multiple days.
PAN-270744
Fixed an issue where API calls to Panorama failed with the error Server error : Timed out while getting config lock. Please try again.
PAN-270379
Fixed an issue where socket files created in the /tmp directory were not cleared.
PAN-270193
Fixed an issue where the Panorama management server changed its certificate authority (CA) unexpectedly, which caused managed firewalls to disconnect.
PAN-270192
Fixed an issue where Panorama did not display the management IP address of devices onboarded via ZTP.
PAN-269700
Fixed an issue where commits to service connection firewalls from Panorama failed.
PAN-269677
Fixed an issue where Panorama did not check for a NULL pointer when querying logs, which caused logs to not display on the web interface.
PAN-269624
Fixed an issue where GlobalProtect clients failed to connect with the error message The device or feature requires a GlobalProtect subscription license.
PAN-269193
Fixed an issue where the firewall redirected the user to the first application instead of the portal page with a list of applications when multiple applications were configured for GlobalProtect clientless VPN along with any user match.
PAN-269139
(Firewalls with DPDK enabled in Azure, GCP, AWS, and KVM environments only) Fixed an issue where, after an upgrade to PAN-OS 11.1.4, the mac receive error counter increased without an error even though traffic was not impacted.
PAN-268708
Fixed an issue where PDF summary and email reports displayed IPv6 addresses instead of IPv4 addresses.
PAN-268614
Fixed an issue on the web interface where, when all rules were highlighted when a read-only admin user clicked the Highlight Unused Rules checkbox.
PAN-268489
Fixed a Threat log PCAP ID overwrapping issue.
PAN-268465
Fixed an issue with firewalls in active/passive HA configurations where the total user count in the registered users was different between the active and passive firewall.
PAN-268279
Fixed an issue where autocommits failed if the management IPv6 gateway was the same as the dataplane interface IP address.
PAN-267759
Fixed an issue where Prisma Access gateway downloads were slower than expected.
PAN-267518
Fixed an issue where WildFire submission logs incorrectly reported allowed malicious samples even when they were blocked by threat prevention profiles.
PAN-266427
Fixed an issue on the firewall where, when a high number of SD-WAN branch sites or interfaces were not connected, SD-WAN processes and tund processes stopped responding due to a high probing rate.
PAN-266116
Fixed an issue where URLs did not work due to certificate revocation list (CRL) requests failing.
PAN-265900
Fixed an issue where the firewall stopped responding due to a tund process or SD-WAN process restart.
PAN-265791
Fixed an issue where the all_task process stopped responding, which caused the dataplane to go down.
PAN-264982
(VM-Series firewalls on Kernel-based Virtual Machine (KVM) only) Fixed an issue where the firewall entered maintenance mode after an auto-commit when sending an ARP packet through the loopback interface using an IPv6 address.
PAN-264708
Fixed an issue where a selective push was blocked when a configuration load was done.
PAN-262729
(Panorama appliances only) Fixed an issue where the configd process experienced continuous high CPU utilization and repeatedly restarted.
PAN-262373
Fixed an issue where the error message Failed to reload config files displayed in the system logs even when device telemetry was not enabled.
PAN-262372
Fixed an issue where the firewall generated the error message Successfully generating a new set of config files in the system logs even when device telemetry was not enabled.
PAN-262063
Fixed an issue where the firewall did not display the converted configurations before a commit and reboot, and the commit failed when attempting to migrate from MS to FRR mode.
PAN-261597
Fixed an issue where the all_pktproc process stopped responding, which caused the firewall to become unavailable.
PAN-261312
Fixed an issue where a commit for a policy and configuration dump overlapped, which resulted in a null pointer exception.
PAN-261074
Fixed an issue where the firewall delayed video file transfers over SMB when Exclude Video Traffic from the Tunnel feature was enabled and no applications were added to the list.
PAN-260229
Fixed an issue where HA path monitoring using VWire did not work as expected after a reboot.
PAN-259727
(Panorama appliances in HA configurations only) Fixed an issue where Panorama became unresponsive and displayed a 504 gateway timeout error when accessing the web interface or the CLI.
PAN-259610
Fixed an issue where Wildfire content installation failed for WF-500B clusters when deployed from Panorama using the deployment schedule.
PAN-258743
Fixed an issue where, when you attempted to select a redistribution profile when creating a BGP Redistribute policy rule, the firewall displayed an empty dropdown.
PAN-258166
(PA-220 firewalls only) Fixed an issue where the root partition frequently reached 100%.
PAN-258162
(Panorama appliances on AWS environments only Fixed an issue where IP addresses were not retrieved in Dynamic Address Groups when multiple AND operators were configured.
PAN-257183
Fixed an issue where the firewall dropped DNS traffic when using DNS Security.
PAN-256904
Fixed an issue where the firewall inconsistently blocked URLs due to intermittent URL category misidentification.
PAN-256867
Fixed an issue where the logrcvr process stopped responding while processing session logs for forwarding to the LFC.
PAN-255759
Fixed an issue where the firewall was unable to match HIP data with the correct anti-malware object for Windows Defender.
PAN-254904
Fixed an issue on Panorama where a core file was generated by /usr/local/bin/logd during a restart.
PAN-254524
Fixed an issue on Panorama where, when the Commit and Push button was clicked during a selective Commit and Push operation, the window stopped responding, which caused the operation to be delayed.
PAN-253127
Fixed an issue where, after upgrading to PAN-OS 11.0.2-h3, the hardware pool DFLT became highly utilized, and the packet buffer gradually increased.
PAN-251715
Fixed an issue where the firewall closed the SSL connection to the user ID agent.
PAN-243235
Fixed an issue where Panorama stopped responding and rebooted repeatedly after an upgrade.
PAN-193285
Fixed an issue where the policy optimizer feature did not add entries back to the mongodb database after removing them during an upgrade or downgrade.