Loading...
Loading...
Hotfix versions were inferred because the vendor did not list them explicitly: 11.2.4-h1, 11.2.4-h2, 11.2.4-h3, 11.2.4-h4, 11.2.4-h5, 11.2.4-h6, 11.2.4-h7, 11.2.4-h8 Known affected versions were inferred from fixed-version data and were not explicitly confirmed by the vendor: 10.2.13-h21, 11.1.4-h33
The earliest recollection of this bug is traced back to PAN-OS 10.2.14 - July 08, 2026. This bug is fixed in PAN-OS versions 11.2.5, 10.2.14, 11.2.4-h9, 11.1.5. Fixed an issue where GlobalProtect user-to-IP address mapping was removed even though the tunnel for the specific user was up and traffic was being passed. If the GlobalProtect license is not installed or is invalid on the device, GlobalProtect user-to-IP address mapping is unexpectedly removed, despite the fact that the tunnel for a specific user is active and traffic is successfully passing through it. Due to the user-to-IP mapping being removed, the traffic matches the wrong policy. For more information: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-release-notes/pan-os-10-2-14-known-and-addressed-issues/pan-os-10-2-14-addressed-issues https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/pan-os-11-1-5-known-and-addressed-issues/pan-os-11-1-5-addressed-issues https://docs.paloaltonetworks.com/pan-os/11-2/pan-os-release-notes/pan-os-11-2-4-known-and-addressed-issues/pan-os-11-2-4-h9-addressed-issues https://docs.paloaltonetworks.com/pan-os/11-2/pan-os-release-notes/pan-os-11-2-4-known-and-addressed-issues/pan-os-11-2-4-known-issues https://docs.paloaltonetworks.com/pan-os/11-2/pan-os-release-notes/pan-os-11-2-5-known-and-addressed-issues/pan-os-11-2-5-addressed-issues
Palo Alto Networks Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.