Palo Alto Networks Release Notes

Follow

223 release notes curated from 272 sources by the Releasebot Team. Last updated: Sep 12, 2026

Get this feed:
  • Sep 11, 2026
    • Date parsed from source:
      Sep 11, 2026
    • First seen by Releasebot:
      Sep 12, 2026
    Palo Alto Networks logo

    Palo Alto Networks

    AI Red Teaming

    Palo Alto Networks adds AI Red Teaming for security testing of AI systems.

    AI Red Teaming

    Original source
  • Sep 9, 2026
    • Date parsed from source:
      Sep 9, 2026
    • First seen by Releasebot:
      Sep 12, 2026
    Palo Alto Networks logo

    Palo Alto Networks

    Prisma Browser Dashboards

    Palo Alto Networks adds Prisma Browser dashboards in Strata Cloud Manager, bringing real-time insights for web security, data loss prevention, assets, policy, and user behavior. The dashboards support filtering, raw data drill-downs, and customizable layouts for deeper analysis.

    The Prisma Browser dashboards deliver real-time, relevant data, and metrics for various use cases, catering to the specific needs and interests of diverse user groups. Use the dashboards to derive meaningful insights from the analysis of user behavior and browsing data. There are a variety of dashboards for specific use cases you might want to monitor, such as user behavior, data leak prevention, web security, and policy. Each dashboard contains a collection of widgets and some of the widgets appear in multiple dashboards.

    To access the Prisma Browser dashboards:

    • From Strata Cloud Manager, select Command Center.
      By default, the Overview dashboard displays on the Home screen.
      You can also access the dashboards from Dashboards Prisma Browser. If the Prisma Browser dashboard is not showing, click More Dashboards and select it for display.

    • To add additional Prisma Browser dashboards to the display, click the + icon and select a dashboard to open in a new tab (up to a total of 12 tabs).
      In addition to the Overview dashboard that displays by default, the following dashboards are available:

      • Web security
      • Data leakage prevention
      • Assets
      • Policy
      • User behavior
        You can open a total of 12 dashboard tabs, including opening multiple instances of the same dashboard.
    • Use the following dashboard features to perform deep dives and analyze information, data patterns, and user behavior.

      • Filter by users or user groups —Sometimes, you may want to examine data for specific entities, such as Users or User groups to see how they compare to the overall user data shown in the widget. This can help identify if a specific group is skewing the displayed data.
      • Filter by time —Select a different Time frame, ranging from the last 24 hours up to the last 30 days. This allows you to investigate the behavior over time so that you can see trends in activity, fine-tune existing rules, and create new rules based on the information gleaned from the investigations. The default time frame for all dashboards except Web Security is 7 days; the default for the Web Security dashboard is 30 days.
      • Look at raw data —Many of the widgets provide links to the raw data for better data analysis and additional filtering options. Clicking the link takes you to the corresponding page in Strata Cloud Manager.
        Open multiple instances of the same dashboard and filter by a different set of users or time frames. You can tab between the dashboards to compare and analyze the different groupings.
    • (Optional) Adjust the widget layouts.
      The dashboard widgets have a flexible layout, allowing you to adjust the widget layout and order as needed. This is useful when the information you want to see isn't next to each other in the default tab layout. For example, if you want to examine the Top 10 most visited apps and websites and compare it to the Top 5 SaaS applications by user data volume. To move a widget:

      • Hover over the title bar on the widget you want to move until the drag tool appears.
      • Drag the widget to its desired location.

    Web Security Dashboard

    The Prisma Browser Web Security dashboard displays the occurrence of issues that are based on user access to web applications and websites and the related information to help you assess and troubleshoot the issues. This dashboard contains the following widgets:

    • Top 10 most visited apps and websites
    • Top 10 most visited web classifications, by events
    • Allowed and Blocked access activities —Correlation
    • Top 10 most active apps and websites (data focus)
    • Top 5 SaaS applications by data volume
    • Blocked access activities (Average and Median per user)

    This dashboard shows a filtered view of events based on time, users, and user groups. You can click directly from the dashboard to the corresponding Event log entry. For example, if you click into the Top 5 SaaS applications by user data volume widget, you can see a filtered view of the Events page.

    You can continue to drill-down from the Events page. For example, click on one of the apps or websites listed in the widget to go to the Applications directory. For example, if you click on Google Drive, you will see the following view:

    Data Leakage Prevention Dashboard

    This dashboard highlights events—primarily upload, download, cut, and copy events—that could potentially lead to a data leakage. This dashboard contains the following widgets:

    • Data leakage prevention overview
    • Top 10 most active apps and websites (data focus)
    • Top 5 SaaS applications by user data volume
    • File type distribution and data volume—File download by events
    • File type distribution and data volume—File upload by events

    Assets Dashboard

    The Assets dashboard provides details about the devices and their security posture, device groups, and device usage in your enterprise browser environment. This dashboard contains the following widgets:

    • OS platform distribution by devices
    • OS platform and violations correlation, by events
    • Extensions installation method, by extensions
    • Device type distribution, by devices
    • Screen lock status breakdown, by devices
    • Disk encryption status breakdown, by devices
    • Firewall status breakdown, by devices
    • EPP status breakdown by devices
    • Top 10 device group distribution, by devices

    Policy Dashboard

    The Policy dashboard displays information about the different policies and rules governing your Prisma Browser deployment. This dashboard contains the Top 5 most active user defined rules widget, which lists the most active rules and details the difference between active events and monitoring events.

    User Behavior Dashboard

    The User Behavior dashboard allows you to track and analyze the behavior of your users. This dashboard contains the following widgets:

    • Top 5 most active users
    • Top 5 most active users (data focus)
    • Top 5 users by data volume
    • Allowed and blocked activities volumes (data focus)—Relative analysis
    Original source
  • All of your release notes in one feed

    Join Releasebot and get updates from Palo Alto Networks and hundreds of other software products.

    Create account
  • Sep 9, 2026
    • Date parsed from source:
      Sep 9, 2026
    • First seen by Releasebot:
      Sep 10, 2026
    Palo Alto Networks logo

    Palo Alto Networks

    PAN-OS 11.2.10-h6 Addressed Issues

    Palo Alto Networks releases a security-focused update that requires GlobalProtect users to reauthenticate after upgrading and fixes multiple CVEs plus issues affecting firewalls, Panorama, telemetry, logging, HA stability, and process reliability.

    After upgrading to this release, all GlobalProtect users will be required to reauthenticate.

    ISSUE ID | DESCRIPTION

    • — | Fixes were made to address the following CVEs: CVE-2026-0265 CVE-2026-0264 CVE-2026-0263 CVE-2026-0262 CVE-2026-0261 CVE-2026-0258 CVE-2026-0256 CVE-2026-0259 CVE-2026-0300
    • PAN-317215 | (VM-Series firewalls on ESXi with Intel E810 NICs using PCI passthrough) Fixed an issue where the brdagent process became unresponsive during data port initialization, which resulted in system instability, interface outages, HA split-brain conditions, and unexpected reboots during failover.
    • PAN-315919 | Fixed an issue where GlobalProtect pre-logon tunnel session was not cleared even after the user was logged in. With this fix, the session is cleared after the session timeout expires.
    • PAN-313849 | Fixed an issue on Panorama where the logd process exited unexpectedly when handling syslog forwarding.
    • PAN-311192 | Fixed an issue where the device-telemetry collect-now process became unresponsive when the process was initiated multiple times with other processes running concurrently, which prevented subsequent telemetry collection.
    • PAN-308377 | (PA-7050 firewalls in HA configurations only) Fixed an issue where the firewall reached 100% disk utilization due to the logrcvr process repeatedly restarting and dumping core files due to a blocked hints processing thread, which caused a failover.
    • PAN-306356 | Fixed an issue where the logrcvr process on a firewall stopped responding due to a document node being unexpectedly freed.
    • PAN-303663 | Fixed an issue on the firewall where SolarWinds monitoring systems reported 100% usage for Slot1 Data Processor-0 Hardware Packet Buffers due to an inaccurate reported packet buffer.
    • PAN-295806 | Fixed an issue where memory leaks on the configd process occurred due to a hash insert operation failing during connection management and SSL connections.
    • PAN-288175 | Addressed a stack buffer overflow memory leak under plugin management code path.
    Original source
  • Sep 9, 2026
    • Date parsed from source:
      Sep 9, 2026
    • First seen by Releasebot:
      Sep 10, 2026
    Palo Alto Networks logo

    Palo Alto Networks

    PAN-OS 11.2.4-h4 Addressed Issues

    Palo Alto Networks fixes a wide range of firewall and Panorama issues, including IPsec and IKEv2 tunnel mismatches, SSL and TLS decryption problems, web interface glitches, logging gaps, and stability crashes, while also addressing several CVEs.

    PAN-276130: Fixed an issue where, when a new IKEv2 was created on Panorama on a PAN-OS 11.2 release using the default IKE version (IKEv2) and IPSec crypto profiles with no specific changes to the crypto profile parameters, and the configuration was pushed to a firewall on PAN-OS 11.2.0 to PAN-OS 11.2.4, the firewall interpreted the IKEv2 gateway as IKEv1.

    PAN-274029: Fixed an issue where upgrading Panorama and pushing configurations to the firewall caused an IKE version mismatch, which resulted in IPSec tunnel failure with the peer device.

    PAN-273994: A fix was made to address CVE-2025-0111.

    PAN-273971: A fix was made to address CVE-2025-0108.

    PAN-273278: A fix was made to address CVE-2025-0109.

    PAN-273197: Fixed an issue where the endpoint ID was not populated in logs when the least significant word of the Geneve header was 0.

    PAN-273165: Fixed an issue where HTTP/2 sessions failed on the firewall when Dynamic Memory Management was enabled.

    PAN-273085: Fixed an issue on the web interface where you were unable to edit or create policy rules.

    PAN-273019: Fixed an intermittent issue where SSL decryption failed.

    PAN-272021: (M-300 Appliances only) Fixed an issue where a split brain condition was not triggered during an inter-Log Collector disconnect between DLC firewalls in an Elasticsearch cluster, which resulted in missing logs.

    PAN-271926: Fixed an issue where TLS 1.3 decryption failed with a bad record MAC error when the firewall was configured to decrypt and inspect TLS traffic.

    PAN-271828: Fixed an issue where, after an accumulation proxy changed to no-decrypt or no proxy, only the Client Hello was sent to Content Threat Detection.

    PAN-270549: Fixed an issue where some TLS connections were not handled correctly, which led to instability in the dataplane.

    PAN-270248: Fixed an issue where the firewall failed to forward logs to a SNMP trap server if the SNMP manager IP address was unable to be resolved.

    PAN-268815: Fixed an issue where the firewall entered a non-functional state due to duplicate entries in the shared memory.

    PAN-268727: Fixed an issue where traffic was dropped when the accumulation proxy was enabled and header insertion modified packets.

    PAN-268229: Fixed an issue where the firewall stopped responding during session setup for ECMP hit-count updates.

    PAN-268215: (Panorama appliances in HA configurations only) Fixed an issue where, when Elasticsearch was forming a cluster and the port was disabled or disconnected and then reconnected, Elasticsearch did not reform the cluster.

    PAN-267781: Fixed an issue where Panorama did not display the Source Dynamic Address Group.

    PAN-267671: Fixed an issue where the firewall rebooted unexpectedly due to the all_task process restarting and repeated OOM conditions occurring on the pan_task process.

    PAN-265742: Fixed an issue on the Panorama web interface where the OK button on the GlobalProtect gateway configuration dialog box was not clickable.

    PAN-263987: Fixed an issue on the firewall where, when a NAT transversal IPSec tunnel was terminated, and the NAT rule that was applied to the NAT-T IPSec tunnel was on the same firewall, traffic flowing through the tunnel was not correctly translated.

    PAN-252036: Fixed an issue where, when the GlobalProtect portal was not configured, accessing the GlobalProtect gateway still loaded a portal malformed page.

    Original source
  • Sep 9, 2026
    • Date parsed from source:
      Sep 9, 2026
    • First seen by Releasebot:
      Sep 10, 2026
    Palo Alto Networks logo

    Palo Alto Networks

    PAN-OS 11.2.0-h1 Addressed Issues

    Palo Alto Networks fixes CVE-2024-0012 and CVE-2024-9474.

    ISSUE ID

    DESCRIPTION

    PAN-272809

    A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and CVE-2024-9474.

    Original source
  • Similar to Palo Alto Networks with recent updates:

  • Sep 9, 2026
    • Date parsed from source:
      Sep 9, 2026
    • First seen by Releasebot:
      Sep 10, 2026
    Palo Alto Networks logo

    Palo Alto Networks

    PAN-OS 11.2.3-h5 Addressed Issues

    Palo Alto Networks fixes several firewall and Panorama issues, improving upgrade stability, configuration pushes, log display, latency timer handling, Cloud NGFW policy updates, and WildFire Analysis report generation.

    Fixed Issues

    PAN-273215: Fixed an issue where a syntax error in the index generation script caused a high management plane CPU load after upgrading.

    PAN-271613: Fixed an issue where configuration pushes from Panorama to the firewall failed due to an OOXML commit error.

    PAN-269404: Fixed an issue where the firewall did not reset the maximum latency timer for hold mode.

    PAN-268823: Fixed an issue where Monitor > Log Display did not display all logs when you applied a filter.

    PAN-264549: Fixed an issue where, after modifying a policy rule on Panorama, pushes to the Cloud NGFW failed with the error saas-user-list unexpected here.

    PAN-259078: Fixed an issue where WildFire Analysis reports were not generated and the following error message was displayed: Error 500: Internal Server Error.

    Original source
  • Sep 9, 2026
    • Date parsed from source:
      Sep 9, 2026
    • First seen by Releasebot:
      Sep 10, 2026
    Palo Alto Networks logo

    Palo Alto Networks

    Mobile Infrastructure Security Features

    Palo Alto Networks adds GTP support for Intelligent Security in PAN-OS 11.2.0, expanding UEIP correlation options for mobile network traffic. The update helps enforce identity-based security policy with added visibility, protocol validity checks, and zero trust protection for 5G and 4G/LTE environments.

    GTP Support for Intelligent Security

    May 2024 Introduced in PAN-OS 11.2.0

    Intelligent Security, also known as User Equipment to IP Address Mapping or UEIP, helps to correlate mobile user equipment (UE) with IP addresses for security policy enforcement. By mapping the subscriber ID and equipment ID to the IP address associated with traffic from the user equipment (UE), Intelligent Security allows you to create security policy rules for mobile network traffic and helps to ensure consistent application of the security policy rules throughout all of the devices on your network. Configuring Intelligent Security for UEIP Correlation helps you to apply subscriber and equipment identity-based security policy in an enterprise 5G network and to provide advanced threat prevention service for your enterprise 5G customers.

    To enable even more deployment options when using Intelligent Security for your mobile infrastructure security policy, Intelligent Security now supports the GPRS tunneling protocol (GTP) traffic in addition to Packet Forwarding Control Protocol (PFCP) and Remote Authentication Dial-In Service (RADIUS) traffic. When you select GTP as the source for UEIP Correlation with Intelligent Security, you can also optionally apply a number of additional security measures, such as protocol validity checks, as well as gain important context through additional visibility for important information contained in GTP session logs.

    By providing a simple method to secure your mobile network traffic, whether it is for perimeter security, RAN security, core security, or roaming security, Intelligent Security helps you to establish a zero trust security policy for the traffic on your 5G and 4G/LTE mobile networks.

    Original source
  • Sep 9, 2026
    • Date parsed from source:
      Sep 9, 2026
    • First seen by Releasebot:
      Sep 10, 2026
    Palo Alto Networks logo

    Palo Alto Networks

    PAN-OS 11.2.13-h1 Addressed Issues

    Palo Alto Networks releases PAN-OS 11.2.13-h1 with stability and reliability fixes across Panorama, dataplane, logging, and policy workflows, including memory leak, unresponsive process, commit and push, and traffic handling improvements.

    The following table lists the addressed issues in PAN-OS 11.2.13-h1.

    ISSUE ID | DESCRIPTION

    ISSUE ID DESCRIPTION PAN-329834 Fixed an issue where a memory leak associated with some display CLI commands caused instability. PAN-329698 (OCTEON, MIPS, platforms only) Fixed an issue where the dataplane became unresponsive. With this fix, the dataplane operates stably. PAN-329180 Fixed an issue where Panorama did not automatically resume syslog forwarding over TCP after the syslog server became unavailable or was restarted. PAN-327460 Fixed an issue where a Commit and Push operation on Panorama did not successfully push configuration changes to Prisma Access endpoints. This occurred when the system reported that not all commit jobs were triggered. With this fix, Commit and Push operations now correctly apply configurations to Prisma Access. PAN-326705 Fixed an issue where high CPU utilization occurred on one of the CPU cores. PAN-325002 (Google Cloud NGFW Enterprise VM-Series firewalls only) Fixed an issue where the HTTP2 threat logs did not include VPC ID, Security_key, and Endpoint ID. PAN-323485 Fixed an issue where multicast radio RTP based traffic was dropped after an upgrade when the firewall performed Cloud Inline inspection, which led to an exceeded session queue for Cloud Threat Detection. PAN-317648 (PA-5450 firewalls and PA-7000 Series firewalls with 100G NPCs only) Fixed an issue where intermittent packet loss occurred when traversing the dataplane after upgrading the firewall. This occurred when a dataplane HA interface was configured in an environment where Slot 1 was unpopulated, which resulted in a wildcard entry being created within the QMAP table. PAN-317068 Fixed an issue on the Panorama web interface where you were able to enable IPv6 for IKE gateways and IPSec tunnels even when IPv6 WAN was disabled, which resulted in an invalid configuration. To utilize this fix, upgrade to the latest Panorama plugin. PAN-316721 Fixed an issue where multiple EDL fetches were queued and did not complete. PAN-314776 Fixed an issue where the configd process stopped responding after pushing configuration changes from Panorama to the firewall. PAN-314624 Fixed an issue where the useridd process became unresponsive and restarted when attempting to dump the Host Information Profile (HIP) database via CLI while the system was actively processing HIP reports. This was caused by a lock contention. With this fix, the process now operates as expected under these conditions. PAN-313827 Fixed an issue where a memory leak occurred related to the reportd process when custom reports were run via API. PAN-310736 Fixed an issue where importing a profile that included a source address would not correctly display the source address on the policy page. With this fix, the source address now displays as expected after profile import. Original source
  • Sep 9, 2026
    • Date parsed from source:
      Sep 9, 2026
    • First seen by Releasebot:
      Sep 10, 2026
    Palo Alto Networks logo

    Palo Alto Networks

    PAN-OS 11.2.1 Addressed Issues

    Palo Alto Networks fixes multiple firewall, Panorama, and endpoint issues, improving explicit proxy SAML handling, Advanced Routing, DHCP hostname behavior, SSL/TLS inspection, dynamic list updates, and commit reliability across supported platforms.

    PAN-257919

    Fixed an issue where, when using explicit proxy with SAML authentication, initiating SAML authentication with a non-GET request resulted in a 302 redirect response instead of the expected 200 ok response.

    PAN-256343

    Fixed an issue where, when Advanced Routing Engine was enabled and OSPFv3 was configured, the CLI command show advanced-routing ospf interface caused traffic to be disrupted, and the interface and area information did not display in CLI or the web interface.

    PAN-255868

    (PA-3400 Series firewalls only) Fixed an issue where the firewall entered maintenance mode after enabling kernel data collection during the silent reboot.

    PAN-252661

    Fixed an issue where changes to the gp-ip-mgmt service route did not take effect after a commit.

    PAN-255227

    Fixed an issue where the the MAC address was sent to the DHCP server instead of the hostname on macOS endpoints.

    PAN-254236

    Fixed an issue where Client Hello packets were dropped when SSL/TLS handshake inspection was enabled.

    PAN-249292

    (VM-Series firewalls on Microsoft Azure environments only) Fixed an issue where CPU usage was higher than expected after a hotplug event when Accelerated Networking was enabled for the management interface.

    PAN-247728

    Fixed an issue where IP multicast did not work when Advanced Routing was enabled.

    PAN-236909

    Fixed an issue where, when you committed the first configuration change after booting up the firewall, the external dynamic list file download failed until the list was refreshed. This occurred when the configuration was pushed with a certificate profile.

    PAN-164885

    Fixed an issue on Panorama where Commit and Push or Push to Devices operations failed when an external dynamic list was configured to check for updates every 5 minutes due to the commit and external dynamic fetch processes overlapping.

    Original source
  • Sep 9, 2026
    • Date parsed from source:
      Sep 9, 2026
    • First seen by Releasebot:
      Sep 10, 2026
    Palo Alto Networks logo

    Palo Alto Networks

    PAN-OS 11.2.8 Addressed Issues

    Palo Alto Networks fixes a wide range of PAN-OS, Panorama, and GlobalProtect issues, improving stability, reporting, logging, routing, decryption, and HA behavior across firewalls, VM-Series, and cloud deployments, while also adding a few helpful CLI commands and debug enhancements.

    Fixed an issue where attempting to generate reports in a WildFire FIPS Private Cloud or WF-500 deployment returned 401 errors.

    Fixed an issue where a 404 error occurred when attempting to download a sample file.

    Fixed an issue where the logrcvr process stopped responding due to memory allocation errors during Redis communication.

    Fixed an issue where certificate data was missing in decryption logs for No decrypt policy rules and TLS1.2 traffic after upgrading, and the Subject Common Name, Issuer Common Name, Certificate Start Date, Certificate End Date, Certificate Serial Number, and Certificate Fingerprint fields were blank in the decryption logs.

    Fixed an issue where polling failed for ethernet interfaces due to the physical port counters read from the MAC being 0.

    Fixed an issue where the mprelay process repeatedly restarted.

    Fixed an issue where the hybrid-SWG service proxy stopped working after upgrading to PAN-OS 11.1.6-h13 due to the firewall failing to establish the listening interface.

    Fixed an issue where the firewall stopped all tasks due to an OOM condition caused by a scheduled log export using FTP to an external FTP server.

    Fixed an issue where, after upgrading the firewall having an IKE gateway that uses an aggregate ethernet interface in DHCP client mode, the IPSec tunnels went down with the error failed to find a socket for retransmission.

    (Panorama virtual appliances in FIPS mode only) Fixed an issue where plugin installs failed with the error invalid image after manually uploading the plugin package from the Customer Support Portal (CSP).

    Fixed an issue on the firewall where the source and destination NAT IP addresses did not display in traffic and threat logs.

    Fixed an issue where the firewall rebooted multiple times after an upgrade if the config contained an EDL (External Dynamic List) that didn't have an associated certificate profile.

    Fixed an issue where the system logs repeatedly displayed the alert Clearing snmpd.log due to log overflow due to the SNMP counters rolling over.

    Fixed an issue where the Advanced Routing Engine stopped responding when a route-map was configured to match on a metric with a value of 0.

    (VM-Series firewalls on Amazon Web Services (AWS) only) Fixed an issue where the firewall frequently rebooted.

    (Firewalls in active/passive HA configurations only) Fixed an issue where, when the passive firewall was down and the idmr process was reset, the firewall generated the system log User-ID manager was reset. Commit is not required to reinitialize User-ID, even though the idmr process restart was not successful.

    ( VM-Series firewalls on Amazon Web Services (AWS) envirobments only) Fixed an issue where newly deployed firewalls were unable to connect to the Palo Alto Networks Software License Server (SLS) until after a reboot, license fetch, or management server restart.

    Fixed an issue where the custom completer for device groups and templates received the device group name and template name from the running configuration instead of the candidate configuration.

    Fixed an issue on the Panorama web interface where you were unable to override the primary or secondary DNS server address in the template stack.

    Fixed an issue where the firewall rebooted unexpectedly due to a pan_task process restart related to page allocation failures.

    Fixed an issue on Panorama where a memory leak associated with the configd process occurred during commits, which caused the configd process to restart and the commit to fail.

    Fixed an issue where a PA-VM-Flex firewall in an air-gapped environment failed to install the license when bootstrapping after a factory reset when the ISO image contained a PAN-OS image.

    (Firewalls with multi-vsys enabled only) Fixed an issue where an XML API call to get the running Security policy rules returned only the first Security policy rules.

    Fixed an issue the firewall experienced packet descriptor on chip and buffer spikes, which led to dropped traffic due to an unidentified traffic pattern.

    Fixed an issue where commits failed due to the configured connected gateway IPv6 address in the NAT64 policy exceeding the 31 character limit.

    (Firewalls on Microsoft Azure environments only) Fixed an issue where management plane CPU usage was unexpectedly high for netsec firewall.

    Fixed an issue where SNMP walks returned a value of 0 for the CPS (Connections Per Second) per vsys on firewalls after upgrading to PAN-OS 11.1.6-h3, even when active connections were present.

    (Panorama virtual appliances only) Fixed an issue on the web interface where you were unable to export the Threat Map.

    Fixed an issue where Panorama in FIPS-CC mode failed to push IKEv2 Post-Quantum Pre-Shared Key (PQ PPK) configurations to firewalls that were not in FIPS-CC mode.

    Fixed an issue where Log Quotas incorrectly displayed a value that was higher than possible.

    Fixed an issue on the Panorama web interface where you were unable to push shared objects to devices if an HA failover occurred during a configuration push.

    Added the CLI command set system setting ctd h323_rtp_predict timeout to increase the maximum timeout limit from 3600 seconds to 65535 seconds.

    Fixed an issue where, when multiple scheduled vulnerability reports were were sent in the same email, only the first attached report was displayed.

    Fixed an issue where the useridd process became unresponsive, which caused User ID CLI commands to time out.

    Fixed an issue where BGP learned routes were not advertised when Legacy Routing was used and an export policy rule was configured to match the next hop of the learned route.

    Fixed an issue on Panorama where the configd process stopped responding when filtering in the Config Audit window, which caused Panorama to restart unexpectedly.

    Fixed an issue where a memory leak occurred related to the configd process when pushing configurations from Panorama to a firewall. This occurred when the configurations contained shared policy rules.

    Fixed an issue where IPv6 URLs were incorrectly categorized as private-ip-addresses even if the URL had a valid category. This occurred because the firewall did not check for IPv6 addresses when determining if an IP address was private.

    Fixed an issue where, when SSL decryption was enabled, traffic matching a deny rule was incorrectly allowed until the SSL handshake was complete.

    (Panorama virtual appliances only) Fixed an issue where Panorama failed to mount logging disks larger than 2TB due to a partitioning error.

    Fixed an issue on Panorama where a selective push of policy rule changes to a firewall caused the firewall to lose its Security policy rules.

    Fixed an issue on the firewall where AIPOs and ADEM licenses failed when SD-WAN or GlobalProtect licenses were not present.

    (PA-5400f firewalls only) Fixed an issue where SD-WAN SaaS monitoring did not work with URL monitoring.

    (Prisma Access only) Fixed an issue where persistent commit failures occurred due to a missing transformation script when downgrading from PAN-OS 10.2.0 to PAN-OS 10.1.0.

    Fixed an issue related to external URL lists where pushing configuration changes from Panorama failed.

    Fixed an issue on Panorama where the web interface became unresponsive when attempting to edit the Allow traffic to specified FQDN when Enforce GlobalProtect Connection for Network Access setting in a GlobalProtect portal configuration after adding 40 or more FQDN entries.

    Fixed an issue where, when the Advanced Routing Engine was enabled, PIM (Protocol Independent Multicast) neighborship was not established concurrently on multiple interfaces.

    Fixed an issue where, when redistributing User-ID information between firewalls, the receiving firewall incorrectly received and stored duplicate Host Information Profile (HIP) profiles. This occurred when a GlobalProtect gateway redistributed User-ID and HIP information through an intermediate firewall.

    (VM-Series firewalls only) Added the CLI command no-refresh-discard-session to address an issue where the discarded session time to live (TTL) did not refresh at the default value.

    Fixed an issue where the MPLS interface eth1/6 went down and remained down, even after replacing the SFP with a supported one and adjusting duplex and speed settings.

    Fixed an issue where External Dynamic List (EDL) entries for predefined lists were not visible in Panorama when logged in with a SuperUser Read-Only role.

    (PA-7500 firewalls only) Fixed an issue where SNMP polling failed due to the snmpd process becoming unresponsive to incoming requests, which resulted in high CPU usage.

    Fixed an issue on the Panorama web interface where a template name or device group name displayed invalid text.

    Fixed an issue where internet access through Secure Web Gateway (SWG) proxy nodes did not work when the default internet access policy rule source user was not known-user.

    Fixed an issue on Panorama where a new virtual system (vsys) was automatically created with the name of a device group.

    (Firewalls in HA active/passive configurations only) Fixed an issue where the firewalls experienced high dataplane CPU use when NAT64 was enabled. This occurred due to NAT64 traffic not being offloaded and unnecessary HA session updates being sent for every NAT64 packet.

    Fixed an issue where the Panorama web interface was slower than expected during configuration operations and a configuration lock time out occurred during a commit.

    Fixed an issue on Panorama where, after logging in to the web interface as the ZTP installer administrator, the web interface was blank.

    Fixed an issue where the logrcvr process stopped responding due to an invalid SSL context being used for socket communication, which caused commits to fail.

    (Firewalls in multi-vsys configurations only) Fixed an issue where HTTP/2 traffic failed due when one virtual system (vsys) had a decryption policy rule enabled and another vsys had a no-decrypt policy rule for the same session.

    Fixed an issue where the firewall incorrectly allowed traffic for certain applications when no decryption policy rule was configured.

    Fixed an issue where the useridd process stopped responding due to a Security policy rule ID being set to 0, which caused the last configuration retrieval to fail.

    Fixed an issue where importing a device configuration into Panorama failed with a validation error if the configuration included a shared gateway with shared address objects.

    Fixed an issue where the firewall attempted to connect to wildfire.paloaltonetworks.com when a user downloaded a WildFire PDF report from the CSP/WF portal even if the user was not behind the firewall.

    Fixed an issue where the firewall failed to forward critical system logs to Strata Logging Service due to a reboot.

    Fixed an issue where, when Advanced Routing Engine was enabled firewalls configured with multiple logical routers, static routes were preferred over eBGP routes even though the static routes had a higher administrative distance.

    Fixed an issue on Panorama where commit jobs were not queued and the system reported that the useridd was not connected.

    (M-600 Panorama appliances in Log Collector mode in a Log Collector group only) Fixed an issue where the reportd and logd processes stopped responding, which resulted in the Panorama server not receiving logs from firewalls configured under the Log Collector group.

    (VM-Series firewalls only) Fixed an issue where the firewall became inaccessible via the web interface and SSH and remained in an initializing state.

    Fixed an issue where the debug dataplane sync ippool CLI command output incorrectly included reserved ports.

    (Firewalls in HA configurations only) Fixed an issue where on the firewall where the routed process stopped responding after changing the MTU or any link state parameters when OSPF and PIM were enabled on the same interface.

    Fixed an issue where a directly connected interface or aggregate interface did not appear in the routing table, which caused ping failures to the directly connected interface.

    (VM-Series firewalls only) Fixed an issue where the maximum registered IP address for was incorrectly set to 100,000 instead of the expected 500,000.

    Fixed an issue where the comm process stopped responding due to missing heartbeats, which resulted in a system alert and HA communication loss on slot1.

    (Panorama appliances only) Fixed an issue on the web interface where resetting the rule hit counter for multiple policy rules failed with the error message Failed to reset rule-hit job.

    Fixed an issue where SAML authentication failed, which caused the GlobalProtect client to repeatedly attempted to reconnect.

    Fixed an issue where the error message Scan ERR: Internal Err 1002 was generated unexpectedly when WIF shared memory use was high.

    Fixed an issue where the firewall failed to connect to the Palo Alto Networks update server when using a customized service route with the source interface as MGT.

    Added debug logs for an issue where a slow IP address pool NAT leak occurred when persistent NAT was enabled, which led to NAT IP pool exhaustion.

    Fixed an issue where, after upgrading, the firewall incorrectly calculated the UDP checksum for RTP traffic after NAT and Security policy application, which led to dropped packets and silent calls in applications.

    Fixed an issue on Panorama where commits took longer than expected.

    Fixed an issue on the web interface where the address object pop up window only displayed a maximum of four address objects in the policy rule even after expanding the window.

    Fixed an issue on the firewall where the QSFP-40G-SR-BD transceiver was incorrectly flagged as an unsupported SFP.

    Fixed an issue where Security policy rules that had the same parameters were not detected as shadow rules on commit.

    Fixed an issue where content loading issues occurred on IPv6 websites due to the firewall incorrectly setting the IPv6 header flow label to 0.

    (CN-Series firewalls only) Fixed an issue where the firewall generated critical system log alerts every 3 minutes.

    Fixed an issue with firewalls in active/passive HA configurations where an OOM condition occurred and caused a failover due to a memory leak associated with the logrcvr process.

    Fixed an issue on the firewall were fan alarms were incorrectly generated constantly.

    Fixed an issue on the firewall where the show advanced-routing bgp loc-rib-detail CLI command incorrectly displayed no BGP route when multiple BGP peers were enabled. With this fix, the CLI command requires a peer name to be specified to display local RIB details.

    Fixed an issue on the Panorama web interface where assigning a policy rule to a group at the top or bottom of the list changed the order of other policy rules.

    Fixed an issue where BGP export policy rules with next-hop matching failed to block the advertisement of static routes, and the firewall incorrectly matched the egress interface IP address instead of the original next-hop IP address of the static route, which caused the deny rule to fail.

    Fixed an issue where, when an application stopped responding, a large file was created in the /opt/panlogs directory, which caused the partition to fill up.

    Fixed an issue where a large number of logs caused the logrcvr process to stop responding.

    Fixed an issue where syslog forwarding in PAN-OS 11.1 and later releases did not support service routes when performing certificate validation over TLS.

    Fixed an issue where user-to-IP address mappings were not available on the dataplane for User-ID, which prevented the enforcement of user-based Security policy rules. This was due to the firewall not validating the timestamp of mappings received from certain User Identification Agent (UIA) agents before adding them to the dataplane.

    Fixed an issue where the device-group-tags CLI command used an unnecessary configuration read lock.

    (VM-Series firewalls only AWS environments only) Fixed an issue where the firewall did not send ICMP unreachable - Fragmentation Needed message when it received packets larger than the MTU.

    Fixed an issue where closing an SSH session to a Panorama using Ctrl+D did not generate a log message in the system logs, and the session remained in an idle state for 60 minutes before being automatically terminated.

    (Panorama virtual appliances in HA configurations on Microsoft Azure environments only) Fixed an issue where plugin versions displayed when hovering over the Green Match icon were inconsistent even though the web interface reported the versions as matching.

    (PA-5450 firewalls only) Added uplink counters to enhance debug capability for traffic drops.

    (Panorama appliances only) Fixed an issue where the Require SSL/TLS secured connection in the LDAP profile within the template stack did not take effect after overriding the configuration. This occurred even when the setting was enabled multiple times.

    (PA-5410 and PA-5430 firewalls only) Fixed an issue where SFP28 25G ports using S28-25G-LR transceivers did not come up after an upgrade when Forward Error Connection (FEC) was disabled on the ports.

    Fixed an issue where the all_pktproc process restarted, which caused heartbeat failures to occur and a slot to go down due to path monitor failure.

    Fixed an issue where a multi-vsys firewall was unable to retrieve address groups and address objects pushed from Panorama as shared objects when using the REST API.

    Fixed an issue on Panorama where logs were not forwarded to syslog servers due to missing CLI options to configure the syslog queue size and threads.

    Fixed an issue where the option to sort sequence numbers was missing from Filters prefix list in the advanced routing filters.

    Fixed an issue where, after an upgrade, the firewall was unable to be managed via HTTPS or SSH.

    Fixed an issue where, when getting transceiver information from ESCC for SFP 25G modules, the transceiver code was incorrectly updated with Unknown instead of 25GBase-SR.

    Fixed an issue on firewalls running PAN-OS 11.1 releases where, after being offboarded from Panorama, the firewall XML configuration file retained template information from the previous Panorama configuration. As a result, when the firewall and its configuration were imported to another Panorama appliance, all configurations in the Network and Device tab became read-only.

    Fixed an issue where a simultaneous selective push from Panorama to multiple firewalls with different base configurations resulted in configuration corruption, which caused the firewall to go down.

    (Firewalls in HA configurations only) Fixed an issue where, after a failover, an SSH decryption caused a mismatch in the host key, which resulted in a warning message. This issue occurred because the SSH tunnel keys were not synchronized between the active and passive firewalls.

    Fixed an issue where the firewall stopped processing traffic.

    Fixed an issue where the XML API returned an error when attempting to view debug log receiver statistics.

    Fixed an issue on Panorama where Policy recommendation displayed Unable to read data for certain profiles due to a large response size.

    Fixed an issue where a tool was needed to display leaked NAT port numbers without requiring a forced synchronization.

    Fixed an issue where the configd process stopped responding during a selective push after a move and rename operation when the configuration was performed via the CLI.

    Fixed an issue where firewalls entered a boot loop after receiving a HSM configuration template push from Panorama.

    Fixed an issue where the configd process restarted and generated a core file during an HA sync commit job. This occurred when the firewall was in the HA passive state.

    Fixed an issue where, when the firewall acted as an IKEv2 responder with fragmentation enabled, the firewall did not send the Notify message type 16430 “IKEV2_FRAGMENTATION_SUPPORTED” in the IKE_SA_INIT exchange. This prevented the remote peer from fragmenting subsequent IKEv2 messages.

    Fixed an issue where the Panorama web interface did not display a warning message when a collector group was configured with a 2 node cluster.

    Fixed an issue where a selective push from Panorama caused the firewall Security policy rules to be removed on firewalls associated with the device group. This occurred when the base configuration version chosen for the selective push preceded the device config import operation, which caused the imported configuration to not be included in the pushed configuration.

    Fixed an issue on Panorama where tags were not automatically populated in the Security policy rule when searching by name in the tag field.

    Fixed an issue where the firewall became unresponsive when the show user user-ids user all CLI command was executed repeatedly on large scale LDAP group mappings, and you were unable to connect to the gateways with the error message The network connection is unreachable or the gateway is unresponsive. Check the network connection and reconnect.

    Fixed an issue where commits remained at 98% completion when static route configuration cleanup was in progress.

    Fixed an issue where the Panorama web interface displayed No Data when viewing configuration logs to see changes before and after a configuration change.

    (Firewalls in active/passive HA configurations only) Fixed an issue where commits failed due the useridd process restarting.

    Fixed an issue where the LFC failed to validate Certificate Revocation Lists (CRL) for SSL syslog connections, which caused a failure to forward logs to external syslog servers.

    (PA-5220 firewalls only) Fixed an issue where custom reports were delayed when sent via email instead of being sent at the scheduled time.

    Fixed an issue where a PBF (Policy Based Forwarding) policy rule using an AE (Aggregate Ethernet) interface configured with DHCP as the egress interface incorrectly transitioned to an active state after a commit operation, even when the DHCP lease had expired and the interface had no assigned IP address.

    Fixed an issue where, when a firewall had more than 4,400 logical interfaces, commits failed with the error message Error pre-installing config failed to handle CONFIG_COMMIT.

    Fixed an issue where, after upgrading the firewall, GlobalProtect connections failed with the error message Network Connection is unreachable.

    Fixed an issue where committing a custom report in Panorama incorrectly generated a pending push to devices.

    Fixed an issue on Palo Alto Networks firewalls running PAN-OS 11.1.6 where the CLI command traceroute ipv4 yes host failed with a missing argument error message.

    (VM-Series firewalls with Advanced Routing Engine enabled only) Fixed an issue where the frr_ns2_bgpd process repeatedly restarted after committing a configuration that included the same route-map in both the exist and non-exist clauses of a conditional advertisement or when the same route-map was used in both the Advertise-out and conditional exist out map configurations.

    Fixed an issue where QoS throughput limits were not enforced correctly on aggregate ethernet interfaces. As a result, when QoS was enabled on aggregate interfaces, the subnet index was not handled correctly, which caused traffic shaping to be misdirected.

    Fixed an issue where GlobalProtect (GP) portal authentication for satellites using RADIUS authentication failed due to the authentication timeout value being set to 0.

    Fixed an issue where, after an upgrade, the total number of logout records in the HIP database incorrectly displayed as zero.

    Fixed a cumulative memory leak in the devsrvr process that occurred whenever the CLI command show running application statistics was issued. This memory leak would gradually consume system memory and produce an out-of-memory (OOM) condition, causing the firewall to reboot.

    Fixed an issue where clients did not receive a valid response when searching a website due to a compression error.

    Fixed an issue where the firewall became non-functional due to high root partition use.

    Fixed an issue where the configd process stopped responding due to a circular reference between address groups.

    (Panorama appliances only) Fixed an issue where the configd process intermittently restarted, which caused Panorama to be temporarily unavailable.

    Fixed an issue where DNS Security Category exceptions created with DNS category UTID were not ignored.

    Fixed an issue where HTTP/2 child streams were blocked by strict-ip-check zone protection when traffic passed through a transparent proxy.

    Fixed an issue on the web interface where the IP Tag Quota(%) value displayed as 2 even when changed.

    Fixed an issue where iPerf file transfers between a client and server were slower than expected when the firewall was involved in the traffic flow due to cfg.uplink-buffer-resize not being enabled by default.

    Fixed an issue where the GlobalProtect gateway firewall intermittently failed to assign an IP address to GlobalProtect clients from the DHCP server, even after successfully receiving a DHCP offer. This occurred when the DHCP retry and timeout settings were overwritten due to parsing results being stored in the same variable, which caused the last gateway configuration to take effect.

    Fixed an issue where a failover event caused packet loss due to a delay in the child error indication.

    Fixed an issue where the firewall used an unnecessary configuration lock when running operational commands.

    Fixed an issue where changes made to the management interface permitted IP address list in a global template were not pushed to the template stack or firewalls.

    Fixed an issue on Panorama where Device Health displayed the device memory as 0%.

    Fixed an issue where, after an upgrade, GlobalProtect attempted to use the embedded browser instead of the default browser for gateway authentication even when it was configured to use the default browser.

    (Firewalls in HA configurations only) Fixed an issue where the configd process restarted during a configuration push from Panorama, which caused the active firewall to lose management access for 20-30 minutes.

    Fixed an issue where the OCSP Signing purpose was not included in the Extended Key Usage field when a certificate was generated on the firewall with the OCSP responder called in the certificate. This caused the GlobalProtect connection to fail with the error Missing OCSP signing purpose in the ExtendedKeyUsage.

    Fixed an issue where a stack overflow occurred when the DNS domain name length exceeded 255 characters.

    Fixed an issue where IPv6 BGP peering established between virtual routers even without dataplane connectivity. This occurred because the firewall used the kernel for lookups instead of the dataplane.

    Fixed an issue on Panorama where custom reports displayed an incorrect log count with critical severity when the report filter was built with and without explicitly specifying severity as critical.

    Fixed an issue where the number of registered IP Tags on Panorama did not match the number of registered IP Tags on the managed firewalls due to a change in file format between PAN-OS releases.

    (VM-Series firewalls in AWS environments only) Fixed an issue where HA failover mode incorrectly changed from interface move to secondary IP move after a reboot.

    Fixed an issue where Panorama failed to upgrade due to duplicate path-monitor names configured across different static routes within the same virtual router or logical router.

    Fixed an issue that caused the request system private-data-reset CLI command to fail.

    Fixed an issue where moving an address object from a device group to shared and renaming it did not reflect in the address group, which caused commits to fail.

    Fixed an issue where deleting the NTP server address caused a commit validation error. This occurred when the configuration included both primary and secondary NTP servers and the secondary server was removed.

    Fixed an issue where the XML API and REST API failed to run commands with an error.

    Fixed an issue where random characters were added to the proxy_authorization in HTTP messages when the firewall accessed certain services through a configured proxy server. This caused proxy server authentication to intermittently fail.

    Fixed an issue where WildFire reports were not fully displayed and were not downloadable due to static resources not being found.

    Fixed an issue where FTP data connections did not work for EPRT with Source IP + Port translation enabled on the firewall.

    Fixed an issue where the firewall stopped responding after upgrading to PAN-OS 11.0.2 with lockless-qos enabled.

    Fixed an issue where adding an SD-WAN interface profile to an overridden interface on a template stack failed with an sdwan-interface-profile is invalid error.

    Fixed an issue where the CLI command syntax was incorrect when configuring the deviceconfig values from the Template Stack.

    Fixed an issue on Panorama where the logd process stopped responding unexpectedly.

    Fixed an issue where the GlobalProtect client displayed an error message when you clicked Check Now and Preferred Releases and Base Releases were unchecked (Device > Software).

    Fixed an issue where the firewall unexpectedly rebooted when the show dns-proxy ddns interface name all CLI command was executed with the error Server error: op command for client dnsproxyd timed out as client is not available.

    Fixed an issue on the firewall where half-duplex settings on Ethernet were not visible.

    Fixed an issue where the password expiry prompt was not visible when logging in via the web interface.

    (Panorama virtual appliances only) Fixed an issue where Panorama stopped responding when running reports.

    Fixed an issue where Panorama did not display license information for Cloud NGFW firewalls under (Device Deployment > Licenses) due to the inability to perform batch-license refreshes.

    Fixed an issue where you were unable to download XML files from Panorama > Summary > Backups.

    Fixed an issue where multicast flows were dropped due to a missing sysd variable for maximum multicast routes.

    Fixed an issue where User-ID mappings were not correctly redistributed from Panorama to firewalls, causing some users to be identified as unknown, which prevented access to resources based on AD group membership.

    Fixed an issue on the web interface where the Response Page action column was not accessible.

    Fixed an issue on Panorama managed firewalls where SAML identity provider and Clientless Apps objects did not have override or revert options.

    (Firewalls in HA configurations only) Fixed an issue where the confgid process and mgmtsrvr process restarted daily when processing a show rule-hit-count CLI command when retrieving Security policy rules for vsys1.

    Fixed an issue where the Log Collector service did not start on a new Log Collector appliance added to a Log Collector group. As a result, the new Log Collector appliance did not appear in the cluster and the number of nodes in the cluster was incorrect.

    Fixed an issue where, when Panorama was not internet connected and you attempted to upload images to managed firewalls using the Validate option, the upload failed with the error Failed to create multi-upload job. No valid software deploy targets found.

    (Panorama appliances only) Fixed an issue where sequence numbers were lost when forwarded from Panorama, which resulted in missing or lost logs.

    Fixed an issue where a dataplane restart was not triggered as expected when internal packet path monitoring failure occurred.

    Fixed an issue where a devsrvr process restart caused commits to fail due to cloud app validation, which resulted in WildFire installs failing.

    Fixed an issue where the Japanese translation for the URL filtering option to add a trailing slash to entries and the device license status error was incorrect.

    Fixed an issue where you were unable to to adjust the frequency of the Advanced Cloud Explorer (ACE) cloud fetch via the CLI.

    Fixed an issue on Panorama where Config Audit Commit Date displayed the timestamp of the configuration edit instead of the commit time.

    Fixed an issue where the firewall did not perform certificate expiry validation during a commit, which resulted in successful authentication even when an intermediate certificate had expired.

    Fixed an issue on the Panorama web interface where GlobalProtect client images were not exported via SCP.

    Fixed an issue where the Logging Service License Status displayed as red even though a valid license was installed on the firewall.

    (M-600 Appliances only) Fixed an issue where the web interface was slow when logging in and filtering for policies due to deep search operations taking longer than expected.

    Fixed an issue where the firewall did not properly update incremental update data maintained at the management plane when an IP address was part of both a Dynamic Address Group and an External Dynamic List (EDL). This resulted in the firewall not matching the expected Security policy rule and threat signature.

    Fixed an issue where Global Search did not redirect correctly to routing profiles when searching for their names.

    Fixed an issue where the firewall incorrectly assembled SIP NOTIFY and REFER messages when processing SIP TCP packets that contained a partial content-body from a previous SIP message and a complete header and content-body from the next SIP message.

    Fixed an issue on Panorama where the request batch license info CLI command displayed entries for devices that were no longer attached to Panorama.

    Fixed an issue where you were unable to use the s_encrypted field in custom reports for the Panorama threat log database.

    Fixed an issue where the transmit power for a cable that was used on port 44 displayed as N/A.

    Fixed an issue where the Panorama interface template did not include the Forward Error Correction (FEC) setting.

    Fixed an issue where GlobalProtect health information (HIP) did not display the certificate key usage.

    Fixed an issue where the displayed group name differed depending on whether the group was configured locally on the firewall or through Panorama.

    Fixed an issue where SAML authentication for GlobalProtect failed when the GlobalProtect portal was accessed externally on a non-standard port.

    Fixed an issue where firewalls configured with a VPN tunnel stopped responding when a configuration update was applied.

    Fixed an issue where the configuration version did not increment in the Audit Comment Archive after making changes to the Security policy rule with an audit comment and performing a commit. As a result, all subsequent changes were grouped under the same configuration version, which prevented the comparison of changes in the Rule Changes field of the Security policy rule.

    (PA-5400 firewalls only) Fixed an issue where frequent BGP/BFD flaps occurred and HA2 keep-alives went down.

    Fixed an issue where commits from Panorama to VM-Series firewalls on Microsoft Azure environments failed.

    Fixed an issue where you were unable to export the GlobalProtect client software version to the SCP server.

    Fixed an issue on the Panorama web interface where administrators were unable to export GlobalProtect client images and received an scp export failed error. This was due to the system attempting to retrieve the file from an incorrect directory.

    Fixed an issue where non-captive portal traffic was not visible under Traffic Logs when the traffic was denied by an authentication rule and the session was discarded.

    Fixed an issue on the web interface where the URL Filtering change category feature did not work.

    Fixed an issue where GlobalProtect cookie authentication failed with the error User is not in allow list.

    Fixed an issue where the DNS exception displayed 0 instead of no result in the anti-spyware profile when no threat ID was available for a DNS Security category.

    (PA-1420 firewalls only) Fixed an issue where the firewall reported unsupported SFPs when PAN-SFPPLUS10GBASE-T SFPs were used on ports Ethernet 1/21 and 1/22.

    Fixed an issue where the firewall displayed packet buffers between 18 and 19 even when there was little or no traffic.

    Fixed an issue where plugin_api_server could experience a memory leak when using OpenConfig for telemetry.

    Fixed an issue where auto-negotiation advertised and negotiated 10/100 half and full duplex.

    Fixed an issue where the firewall did not increase the metric of the default route when redistributed into OSPF when the firewall was configured as an NSSA ABR.

    (PA-1400 and PA-3400 Series firewalls only) Fixed an issue where the firewall displayed the error message Failed to parse pbf policy when you committed a configuration that included more than 8 Policy Based Forwarding (PBF) rules with symmetric return enabled.

    Fixed an issue on the firewall that caused the following error message to be displayed: frr_ns0: failed to stop child frr_ns0_ospf6d.

    Fixed an issue where PublicCloud Server certificate validation failed. Dest Addr: (null), Reason: self signed certificate in certificate chain generated as a high alert in the system log every 5 minutes.

    Fixed an issue where the firewall calculated available memory incorrectly on CENTOS devices, which caused the firewall to display high memory usage alerts even when sufficient memory was available.

    A CLI counter was added to indicate a full suppression queue.

    Fixed an issue where the character ( + ) in the authentication message prompt displayed incorrectly as #43; on the GlobalProtect client after upgrading to a PAN-OS 10.2 release.

    (VM-Series firewalls on Amazon Web Services (AWS) environments with GWLB integrated only) Fixed an issue where DNS queries timed out when overlay routing was enabled.

    Fixed an issue where performing a factory reset caused the firewall to enter a continuous boot loop due to a failure in generating the global.xml configuration file.

    Fixed an issue where the firewall displayed an incorrect maximum translated IP capacity when using DIPP NAT policy rules.

    Fixed an issue on the web interface where you were unable to add Threat IDs to Signature Exceptions.

    Fixed an issue where the show system statistics application CLI command failed.

    Fixed an issue where the GlobalProtect client (UWP) or metered hotspot connections triggered TLS resumption fo GlobalProtect portal authentication, which caused the portal authentication to fail with a valid cert required error.

    Fixed an issue where the Low free buffer limit output was not available.

    Fixed an issue where the firewall allowed cleartext web-browsing traffic on port 443 when the Security policy rule was configured to allow application: web-browsing with service: application-default.

    Fixed an issue threat reports were empty when generated from Panorama, but displayed correctly when generated from the firewall.

    Fixed an issue where the firewall dropped non-SYN TCP packets even when the Reject non-SYN TCP option was set to No when a session rematch was triggered.

    Fixed an issue where half-closed TCP sessions did not refresh the session timeout when continuously receiving data after setting the cfg.session.tcp-no-refresh-fin-rst option toTrue.

    Fixed an issue on the firewall where you were unable to configure more than 500 DHCP relay servers even though the supported limit was 4096.

    Fixed an issue where the mib ID returned an incorrect value via SNMP.

    Fixed an issue where the show user ip-user-mapping all option detail XML API command did not show the complete output.

    Fixed an issue where BGP aggregate routes with the AS-SET option enabled had incorrect AS paths.

    Fixed an issue where the CSV export of disabled applications included duplicate entries, which caused the count of disabled applications to be higher in the CSV export than on the web interface.

    Fixed an issue where the firewall did not query for an AAAA record when only IPv6 was enabled for the management interface.

    Fixed an issue where the all_task process stopped responding, which caused a split brain condition.

    (VM-Series firewalls only) Fixed an issue where the aggressive clean-up threshold for disk space was set to 95% in system monitor.

    Fixed an issue where the domain-edl column was empty in the threat log even when a threat was detected as a DNS alert.

    Fixed an issue where an OOM condition occurred, which caused processes to stop responding.

    Fixed an issue where the routed process stopped responding due to accessing freed memory from a hash table when the route vectors were resized. This occurred when a large number of static routes were configured.

    Fixed an issue where, when using WildFire Private Cloud, the system log displayed the error message tls-X509-validation.

    (PA-3220 firewalls in HA configurations only) Fixed an intermittent issue where the firewalls went out of sync after a configuration push from Panorama.

    Fixed an issue where users were unable to log in to Panorama and the following error message was displayed: Timed out while getting config lock. Please try again. This occurred when pushing configurations to a large number of devices.

    Fixed an issue where the configd process stopped responding when a configuration merge operation changed.

    Fixed an issue where GlobalProtect users with client certificates received an authentication failure message without entering a password and clicking connect or login.

    Fixed an issue where the firewall displayed 0 bytes received for GlobalProtect SSL sessions in the traffic logs.

    Fixed an issue where the web interface was slower than expected when logging in and filtering for policies.

    Fixed an issue where the firewall failed to connect to the update server with a customized service route when the source interface was set to MGT and the source address was set as IPv4.

    Fixed an issue where the firewall was unable to connect to a syslog server that used a TLS certificate without a subject key identifier.

    Fixed an issue where the execute show transceiver-detail all XML API command returned an incorrect value for the low temperature alarm threshold.

    Fixed an issue where the Priority Code Point (PCP) bits in the VLAN header were not reset to 0 when a packet was received from one Layer 3 tagged interface and forwarded to another, which resulted in dropped packets. To use this fix, run the CLI command set force-vlan-pcp-reset yes and reboot the firewall.

    Fixed an issue where importing a device configuration into Panorama failed with a validation error if the configuration included a shared gateways containing NAT/PBF rules. To use this fix: Enable the configuration. Commit failures may occur if the device is not able to support the number of objects. Export and push the device group only. Push the template. Note: This fix is supported on PAN-OS 10.2 and later releases.

    Fixed an issue where commits failed with a validation error when you changed the encryption level and re-encryption option on a Panorama managed firewall.

    Fixed an issue on the Panorama web interface where Application and Category was not able to be selected under Test Policy Match.

    Fixed an issue where the snmpd.log.old file continuously increased, which caused the root partition to become full.

    Fixed an issue where the Panorama web interface was slower than expected due to high CPU utilization on the mongodb process.

    (Firewalls in HA configuration only) Fixed an issue where the Network pre-negotiation enabled page did not display on the firewall dashboard.

    Fixed an issue where the firewall failed to upload a macOSX file if the file had a MIME boundary.

    Fixed an issue where the firewall dropped inbount RTP traffic after using Webex Screen Sharing due to the firewall removing the NAT cache when the predict timed out, which caused a new NAT to be established that conflicted with existing sessions. To use this fix, run the CLI command set system setting ctd h323_rtp_predict timeout <120-3600> to increase the timeout limit.

    Fixed an issue where the all_task process stopped responding, which caused the firewall to stop processing traffic.

    (VM-Series firewalls only) Fixed an issue where BGP route refreshes occurred when a commit was performed if AS Set was enabled for BGP aggregate routes.

    Fixed an issue on the firewall where ICMP ping loss occurred after installing a Network Processing Card (NPC) in slot 7.

    Fixed an issue where the firewall generated AAAA DNS queries when IPv6 firewalling was disabled.

    Fixed an issue where sessions ended with the message decrypt error in the logs for traffic that matched a no-decrypt policy.

    Fixed an issue where an email was able to be transferred to the destination MTA even when the firewall detected a suspicious file with a reset-bot action when it was encrypted by STARTTLS.

    Fixed an issue on the firewall where traffic matched a custom signature even if the custom signature was removed from the configuration.

    Fixed an issue where the firewall was unable to generate a tech support file when management server debug was disabled.

    Fixed an issue where OSPFv3 Link State (LS) update packets (type 9) were not fragmented properly, which caused the OSPF header to have an incorrect checksum when sent from the firewall. This occurred when the update packet size exceeded 1514 byte, which resulted in the peer device rejecting the packet and the neighbor relationship going down.

    (PA-3400 Series firewalls only) Fixed an issue where the all_task process stopped responding, which caused the firewall to reboot.

    Fixed an issue where double-clicking the login button returned the error message Login session expired.

    Fixed an issue on Panorama where, after you enabled multihop in a BFD profile, you were unable to disable it via the web interface.

    Fixed an issue where the GlobalProtect portal logged passwords in cleartext.

    Fixed an issue where the firewall did not shut down completely.

    Fixed an issue on Panorama where the dynamic address group IP addresses of the Kubernetes plugin or Prisma Cloud plugin for Secure Developer Environment were not displayed.

    Fixed an issue where the configd process restarted when pushing configurations to multiple device groups via XML API, which caused the push to fail.

    Fixed an issue where the maximum session limit for a vsys was 4,194,290.

    (VM-Series firewalls only) Fixed an issue where the all_task process stopped responding and a reboot was required.

    Fixed an issue where the routed process core failed the automation run.

    Fixed an issue where AAAA DNS queries went out even when IPv6 firewalling was disabled.

    PA-440 firewalls only) Fixed an issue where the firewall was unable to create more than 6 GlobalProtect gateways.

    (VM-Series firewalls in HA configurations only) Fixed an issue where the firewall rebooted due to multiple HA failovers.

    Fixed an issue where management plane CPU usage increased after upgrading when there was a full-mesh User-ID redistribution configuration between multiple firewalls.

    Fixed an issue where exporting managed device information from Panorama in CSV format included extraneous characters.

    Fixed an issue where, after a commit was performed from Strata Cloud Manager, the SD-WAN configuration containing BGP routes did not display on the hub firewall.

    Fixed an issue where the request logdb migrate-to-panorama start end-time CLI command did not work as expected, and you were unable to resend logs from a firewall to Panorama or a log collector.

    Fixed an issue where the firewall displayed incorrect policy cache usage and configuration memory usage during a commit, which caused the configuration commit to fail with a CONFIG_UPDATE_START error. This occurred when a large number of External Dynamic Lists (EDLs), shared addresses, and policy rules were configured.

    Fixed an issue where imported certificates were not visible on firewalls with multi-vsys disabled.

    Fixed an issue where the service route setting for HTTP was not applied when the source interface IP address was set via an address object, which caused HTTP traffic to be sent from the management interface.

    Fixed an issue where Voice over WiFi (VoWiFi) stopped working after switching from a PA-5200 Series firewall to a PA-7500 Series firewall in NGFW clustering mode with NATT IPSec Passthrough and NAT policy enabled. To use this fix, enter the CLI command show tunnel-acceleration, disable tunnel acceleration, and reboot the PA-7500 Series firewall.

    Fixed an issue where WildFire submission logs were not displayed when filtered by Sender Address.

    Fixed an issue where GlobalProtect Decryption logs were not forwarded to Panorama.

    Fixed an issue where the Panorama port 28270 did not adhere to the restricted TLS version and ciphers set in the Secure Communication Settings.

    Fixed an issue where the bytes transmitted and packet transmitted counters for hardware interfaces incorrectly displayed as 0 after a restart of slot-1.

    Fixed an issue where the firewall did not support TLSv1.3 in the Clientless VPN, which caused the portal page to not load.

    Fixed an issue where daily email reports generated from the custom report did not display the report details in PDF or CSV files.

    Fixed an issue where Panorama template changes to the zone and virtual router were not pushed to managed firewalls when the template stack default virtual system was set to None.

    Fixed an issue where task-debug logs remained on the debug level even after running the debug dataplane packet-diag set log off CLI command, which caused high dataplane CPU utilization.

    Fixed an issue where Panorama was unable to generate PDF reports when the footer contained a GIF image.

    (M-600 Appliances only) Fixed an issue where log collectors in a cluster stopped responding when running high load tests.

    Fixed an issue where the firewall dropped GRE keepalive packets that were encapsulated under another GRE tunnel.

    Fixed an issue on the Panorama web interface where the Configuration tab did not accurately display changes made to URL filtering profiles.

    Fixed an issue where IPv4 BGP routes were not included in the routing table or FIB of a virtual router when ECMP was configured with more than two next hops.

    Fixed an issue where the CLI command show user ip-user-mapping-mp all displayed the total timeout value instead of

    Original source
  • Sep 9, 2026
    • Date parsed from source:
      Sep 9, 2026
    • First seen by Releasebot:
      Sep 10, 2026
    Palo Alto Networks logo

    Palo Alto Networks

    PAN-OS 11.2.7-h19 Addressed Issues

    Palo Alto Networks fixes multiple PAN-OS 11.2.7-h19 issues, improving CPU stability, GlobalProtect addressing, logging, commit behavior, traffic handling, and Azure Cloud NGFW reliability. The update also addresses cloud log flooding and session timer edge cases.

    The following table lists the addressed issues in PAN-OS 11.2.7-h19.

    ISSUE ID | DESCRIPTION

    • PAN-326705 | Fixed an issue where high CPU utilization occurred on one of the CPU cores.
    • PAN-318619 | Fixed an issue where Geneve ingress traffic did not use the correct public IP address for return traffic.
    • PAN-316937 | Fixed an issue where GlobalProtect users intermittently received incorrect private IP addresses after connecting to a gateway behind a Network Load Balancer (NLB).
    • PAN-312725 | Fixed an issue where no warning message was displayed during commits for improperly formatted FQDN or IP address values in the GlobalProtect Enforcer configuration. This fix requires a compatible content version on the firewall.
    • PAN-304840 | Fixed an issue where multiple firewalls experienced high management CPU utilization after upgrading to an affected release due to repeated index regeneration occurring every 15 minutes, which caused periodic CPU spikes above 90%.
    • PAN-303156 | Fixed an issue where the session timer for a custom application did not transition from the initial 3-way handshake timer to the application timeout when out-of-order 3-way handshake packets were detected.
    • PAN-298788 | Fixed an issue where the /pancfg partition on the Azure Cloud NGFW reached 100% utilization, which caused commit failures.
    • PAN-292242 | Fixed an intermittent issue where traffic logs were truncated when they were forwarded using a TCP syslog configuration due to the forwarding queue capacity being exceeded.
    • PAN-266843 | Fixed an issue on airgapped firewalls where cloud connection errors flooded the system logs.
    Original source
  • Sep 9, 2026
    • Date parsed from source:
      Sep 9, 2026
    • First seen by Releasebot:
      Sep 10, 2026
    Palo Alto Networks logo

    Palo Alto Networks

    PAN-OS 11.2.3-h3 Addressed Issues

    Palo Alto Networks fixes security and upgrade issues in PAN-OS, including CVE-2024-0012, CVE-2024-9474, and syslog forwarding.

    ISSUE ID DESCRIPTION

    PAN-272809 A fix was made to address CVE-2024-0012 (PAN-SA-2024-0015) and CVE-2024-9474.

    PAN-247230 Fixed an issue where the syslog forwarding configuration did not include the full path for Security policy rules.

    PAN-259997 (PA-3410, PA-3420, and PA-3430 firewalls only) Fixed an issue where the install failed when upgrading from PAN-OS 10.2.3-h3 and later 10.2 releases to PAN-OS 10.2.10 due to the number of configured vsys zones exceeding the zone limit in PAN-OS 10.2.10.

    Original source
  • Sep 9, 2026
    • Date parsed from source:
      Sep 9, 2026
    • First seen by Releasebot:
      Sep 10, 2026
    Palo Alto Networks logo

    Palo Alto Networks

    PAN-OS 11.2.7-h12 Addressed Issues

    Palo Alto Networks fixes a broad set of firewall and Panorama issues, improving SD-WAN traffic handling, logging, certificate renewal, DNS stability, memory use, and overall system reliability across VM-Series, AWS, HA, and Prisma Access related deployments.

    PAN-316911

    (VM-Series firewalls on Amazon Web Services (AWS) environments only) Fixed an issue where a newly bootstrapped firewall required a management server restart, relicensing, or license push from Panorama to invoke the device certificate.

    PAN-315912

    Fixed an issue where the Maximum Segment Size (MSS) rewrite functionality for packets ingressing through SD-WAN interfaces on firewalls was not optimized.

    PAN-314147

    Fixed an issue where SSL traffic was dropped on SD-WAN DIA interfaces with member having different MTU.

    PAN-313623

    Fixed an issue where the /opt/pancfg/mgmt/ssl/private/ directory on Palo Alto Networks devices with TPM support became 100% utilized due to an accumulation of undeleted .pub_pem files. This occurred because executing the show device-certificate status CLI command initiated a process that generated these files but failed to remove them, which prevented the fetching of new device certificates.

    PAN-313216

    Fixed an issue where firewalls with Prisma Access incorrectly displayed some traffic as unsanctioned in traffic logs for cloud applications that were tagged as sanctioned.

    PAN-312706

    Fixed an issue where the firewalls restarted due to a function lacking a NULL-pointer sanity check.

    PAN-311512

    Fixed an issue where HIP (Host Information Profile) reports were blocked on GlobalProtect when Authentication Cookie Usage Restrictions was enabled and the Prisma Access Agent protocol was in use. This occurred because the system failed to correctly process HIP messages that were relayed via IPSec tunnels with a Virtual IP as the source, leading to their rejection.

    PAN-309300

    Fixed an issue where management plane system resources configuration size exceeded 28 MB for over 4 hours, and the following error message was displayed: Configuration size reaching device capacity limit.

    PAN-308786

    (Panorama appliances only) Fixed an issue where traffic log queries using the device_name filter returned no results, and complex log queries that included negation operators produced incorrect outputs.

    PAN-308564

    Fixed an issue where packets were dropped on SD-WAN interfaces when a proxy was enabled due to an MTU inconsistency where the firewall failed to rewrite the maximum segment size in SYN/ACK packets based on the SD-WAN virtual interface MTU. Note: This fix does not apply when the traffic egress interface is SD-WAN Direct Internet Access (DIA) interface and proxy is enabled.

    PAN-308507

    (Panorama managed firewalls only) Fixed an issue where the firewall intermittently failed to maintain active log forwarding streams to Strata Logging Service (SLS) even when duplicate logging and enhanced application logging were enabled.

    PAN-308418

    Fixed an issue where, when Advanced DNS Security was enabled and experienced unusually high loads, DNS resolution failures occurred with the error resources-unavailable.

    PAN-306555

    Fixed an issue where the firewall stopped responding, which led to service outages.

    PAN-304019

    (VM-Series firewalls only) Fixed an issue where the firewall did not send traffic to SCM or SLS via a configured explicit proxy IP address when the proxy username was not configured.

    PAN-303745

    Fixed an issue where inter-dataplane forwarding did not work for sessions ingressing on Slot 2, which resulted in intermittent ping failures to interfaces on Network Card 2 when traffic was forwarded to Slot 3. Note: With this fix, after a slot restart, the global counter will still show dot1q errors for a short period.

    PAN-302983

    Fixed an issue where, after committing changes on Panorama, a shared post-rule moved to the end of the post shared rulebase on the managed device instead of remaining at the top.

    PAN-302564

    Fixed an issue on the firewall where a path monitoring failure occurred and caused the dataplane to restart.

    PAN-301653

    Fixed an issue where DNS traffic sessions prematurely terminated with the message resources-unavailable. This occurred due to IPv4 fragmented DNS responses causing the Advanced DNS Security module to incorrectly pack the DNS payload multiple times when forwarding to the cloud for inspection.

    PAN-300837

    Fixed an issue where firewalls experienced multiple reboots due to the pan_task process restarting with a SIGSEGV signal. This occurred because the client-to-firewall side assumed TLS 1.3 for the firewall-server side.

    PAN-300671

    Fixed an issue where traffic reports that were generated with destination/source and destination/source hostnames were not displayed in IPv4 format.

    PAN-300423

    Fixed an issue where Data Processing Cards (DPCs) installed in slots 5 and 6 remained stuck in a starting state with the error Signal detected for port xeS5-DP0 but Link Down alerts, which resulted in device instability.

    PAN-299242

    Fixed an issue where the firewall's SSL proxy sent an empty HTTP2 SETTINGS message to the client before confirming server support, which caused some clients to incorrectly assume HTTP/2 support and not fall back to HTTP/1.1. Additionally, the firewall dropped HTTP1.1 400 Bad Request frames from the server, which prevented the client from correctly detecting the lack of HTTP/2 support.

    PAN-298617

    Optimized the commit workflow to reduce the size of the effective configuration, resulting in lower memory consumption.

    PAN-297708

    Fixed an issue where a long-lived session with many Machine Learning (ML) model triggers caused a memory leak of feature states associated with the ML model runs. This resulted in Spyware_State failure increases, allocation max outs, and impaired policy matching.

    PAN-295802

    Fixed an issue where a memory leak related to the configd process occurred.

    PAN-295309

    Fixed an issue where OSPF session using MD5 authentication experienced intermittent flapping due to out-of-order packet processing.

    PAN-293644

    (Firewalls in HA configurations only) Fixed an issue where the configd process stopped responding during an External Dynamic List (EDL) refresh.

    PAN-290938

    Fixed an issue where multiple memory leaks occurred related to the configd process.

    PAN-264762

    Fixed an issue where the firewall showed the status of SFP+ interfaces as not up, or up but not configured, when a PAN-SFP-PLUS-SR cable was connected.

    PAN-263691

    Fixed an issue where the firewall rebooted unexpectedly due to a memory leak in the all_task process.

    PAN-248913

    Fixed an issue where the Elasticsearch client certificate was not auto renewed, which caused it to enter a Red state, and logs were not displayed in Panorama.

    Original source
  • Sep 9, 2026
    • Date parsed from source:
      Sep 9, 2026
    • First seen by Releasebot:
      Sep 10, 2026
    Palo Alto Networks logo

    Palo Alto Networks

    PAN-OS 11.2.4-h6 Addressed Issues

    Palo Alto Networks fixes a broad set of firewall and Panorama issues, improving stability, logging, performance, packet handling, and HA behavior while also addressing device-specific thermal, reboot, and interface problems across multiple platforms.

    PAN-284036: (PA-450R and PA-450R-5G firewalls only) Fixed an issue where the maximum temperature threshold and shutdown threshold were not set correctly.

    PAN-282236: Fixed an issue where large IPv6 packets were reassembled incorrectly on the firewall when the packets arrived fragmented over an IPv4 tunnel.

    PAN-282206: Fixed an issue where configuring Secure Web Gateway (SWG) in no-auth mode led to latency when no decryption policy rules or No-decrypt policy rules were present.

    PAN-282022: Fixed the support limitation for the Panorama M-600 and M-700 appliances.

    PAN-280471: Fixed an issue where navigating Panorama > Monitor > Logs was slower than expected.

    PAN-279746: Fixed an issue where SMTP packets were not sent out when the Client Hello arrived at the firewall in multiple out-of-order segments and the traffic was not subject to SSL decryption.

    PAN-279197: (PA-450R-5G firewalls only) Fixed an issue where the firewall stopped responding and displayed the error message Thermal temperature exceeds system threshold! Shutting down NOW even when the firewall was within the threshold.

    PAN-278684: (PA-445 firewalls only) Fixed an issue where the firewall did not properly power cycle during a reboot.

    PAN-278296: Fixed an issue where the system MAC address of the aggregate interface was the same on the active firewall and the passive firewall after an upgrade.

    PAN-276546: Fixed an issue where a session lost the PBF rule mapping after a configuration change or commit.

    PAN-275905: Fixed an issue where the Panorama web interface was slower than expected and Elasticsearch CPU usage was high.

    PAN-273949: Fixed an issue where the firewall generated the following error message in the snmpd logs: pan_get_keystr_from_cryptod(pan_snmpinterface.c:181): Key X2F1dGhfa2V5 import from cryptod failed.

    PAN-273026: Fixed an issue where traffic logs did not display correctly when filters were applied.

    PAN-273021: Fixed an issue where 25G port links did not come up due to a change in the handling of 25G DAC modules.

    PAN-272849: Fixed an issue where log forwarding to a UDP syslog server stopped when an unreachable TCP syslog server was configured and applied.

    PAN-272538: Fixed an issue where the configd process stopped responding during a commit-all validation when there were uncommitted changes and share-unused-objects-with-devices was set to off.

    PAN-272085: Fixed an issue where the firewall might crash and reboot when DoH is enabled for DNS Security and multiple DoH transactions are sent in a single HTTP/1 connection.

    PAN-271912: Fixed an issue on Panorama where the configd process stopped responding when filtering in the configuration audit window after upgrading to PAN-OS 11.1.3.

    PAN-271351: A fix was made to address CVE-2025-0116.

    PAN-270224: Fixed an issue where indices were not opened after a query.

    PAN-269956: Fixed an issue where the all_pktproc process stopped responding, which caused internal path monitor failures.

    PAN-269291: Fixed an issue where the scheduled report generation script did not return debug information.

    PAN-269106: Fixed an issue where the wifclient stopped responding during server certificate verification for MICA gRPC connections and caused the dataplane to restart when using a cloud-based ML detection engine (MICA). On certain platforms, this caused the firewall to reboot periodically.

    PAN-269091: Fixed an issue where the varrcvr process stopped responding.

    PAN-268501: Fixed an issue where the firewall was unable to generate a TSF file due to a full root partition.

    PAN-267430: Fixed an issue where Panorama was unable to return logs for queries that were longer than 64,000 characters.

    PAN-265179: Fixed an issue where a kernel race condition caused the firewall to reboot with a kernel panic.

    PAN-263208: (PA-5440 and PA-5445 firewalls only) Fixed an issue where interrupts were generated at a certain packet rate, and dataplane processes missed heartbeats, which caused the dataplane to go down.

    PAN-262383: Fixed an issue where the firewall was unable to decompress the HTTP2 header, which caused the session to be classified as unknown-tcp instead of web-browsing.

    PAN-261739: (VM-Series firewalls in Microsoft Azure environments only) Fixed an issue where the firewall displayed 0 for the physical port counters read from MAC.

    PAN-261484: Fixed an issue on the firewall where DPDK allocated twice the amount of memory as requested for pre-allocation.

    PAN-258736: Fixed an issue where policy rule configurations pushed from Panorama were not reflected on the firewall if the rule had 63 characters.

    PAN-258570: Fixed an issue where the firewall might reboot unexpectedly due to the varrcvr process progressively using more memory when WildFire file forwarding is handling PE files.

    PAN-257619: Fixed an issue on Panorama where the Task Manager took longer than expected to display managed firewall report tasks.

    PAN-257028: (Firewalls in active/passive HA configurations only) Fixed an issue where firewalls entered a non-functional state and displayed the error message Dataplane down: path monitor failure during the fail-over.

    PAN-255323: (PA-7050 firewalls only) Fixed an issue where the Network Processing Card (NPC), Data Processing Card (DPC), and Log forwarding Card (LFC) remained in a starting state after an unexpected power cycle.

    Original source
  • Sep 9, 2026
    • Date parsed from source:
      Sep 9, 2026
    • First seen by Releasebot:
      Sep 10, 2026
    Palo Alto Networks logo

    Palo Alto Networks

    Changes to Default Behavior in PAN-OS 11.2

    Palo Alto Networks updates PAN-OS 11.2 default behaviors for upgrades, including stronger DoS blocking timing and a shift to IKEv2 as the default VPN protocol. It also notes a Panorama-managed IKEv2 gateway issue that may require an explicit CLI setting.

    The following table details the changes in default behavior upon upgrade to PAN-OS® 11.2. You may also want to review the Upgrade/Downgrade Considerations before upgrading to this release.

    FEATURE

    FEATURE CHANGE Preventing DoS Attacks with Enhanced DoS and PBP configurations In PAN-OS 11.2.2 and previous versions, the default value of the hardware-acl-blocking duration is one second. In PAN-OS 11.2.3 and later 11.2 versions, the default value for the hardware-acl-blocking duration has been increased to 30 seconds. IKE protocol version support (PAN-OS 11.2 and later releases) We have changed the default IKE protocol version support from IKEv1 to IKEv2. If you have not configured the IKE protocol version in the IKE gateway configuration, then PAN-OS supports the IKEv2 protocol version by default. For VPN clusters, PAN-OS supports IKEv2 only mode by default and the support for IKEv1 only mode and IKEv2 preferred mode configuration are removed. IKEv2 Gateway configuration Requires Explicit CLI Setting (For firewalls running versions between 11.2.0 and 11.2.4 managed by Panorama running 11.2 or later versions) A configuration interpretation error occurs on the Panorama managed firewalls when establishing IKEv2 gateways through Panorama's default configuration settings. When you configure a new IKEv2 gateway on Panorama using the default settings, specifically the default IKE version (IKEv2) and default IKE and IPSec Crypto profiles without making any specific modifications to the crypto profile parameters and subsequently push this configuration to a managed firewall, the receiving firewall incorrectly interprets the new IKEv2 gateway as an IKEv1 gateway instead. To prevent this misinterpretation, you need to manually specify the IKE version as "IKEv2" through Panorama's CLI before committing and deploying the configuration on the firewalls. This issue specifically impacts firewalls running versions between 11.2.0 and 11.2.4 when they receive configurations from Panorama running version 11.2 or later versions. Original source
Releasebot

Curated by the Releasebot team

Releasebot is an aggregator of official release notes from hundreds of software vendors and thousands of sources.

Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.