
OPERATIONAL DEFECT DATABASE
...


...

The earliest recollection of this bug is traced back to PAN-OS 11.2.10 - October 30, 2025. This bug is fixed in PAN-OS versions 11.2.10. ( Firewalls in active/active HA configurations only ) Fixed an issue where return packets from a phone gateway looped between the HA pair instead of being encapsulated into the GlobalProtect tunnel. This occurred when the inner session and the outer IPSec tunnel terminated on different nodes, which led to excessive retries and packet drops. For more information: https://docs.paloaltonetworks.com/pan-os/11-2/pan-os-release-notes/pan-os-11-2-10-known-and-addressed-issues/pan-os-11-2-10-addressed-issues
Click on a version to see all relevant bugs
Palo Alto Networks Integration
Learn more about where this data comes from
Bug Scrub Advisor
Streamline upgrades with automated vendor bug scrubs
BugZero Enterprise
Wish you caught this bug sooner? Get proactive today.