After PAN-OS upgrade to 11.1.5 or later, some s2c flows may not match the expected PBF rules

After PAN-OS upgrade to 11.1.5 or later, some s2c flows may not match the expected PBF rules

2203
Created On 02/21/25 13:48 PM - Last Modified 10/16/25 06:15 AM


Symptom


  • In CLI "show session all" output the impacted sessions will be listed with application "undecided".


  • In global counters <flow_fwd_zonechange> may increment:


  • Session details may show incorrect PBF match or no PBF at all.


  • Hit count on PBF rule will stop incrementing.
  • Packet capture may show dropped packets.
  • In traffic log the failing communication will show with application incomplete.



Environment




Cause


Software issue introduced in PAN-OS 11.1.5.

 



Resolution


  1. The issue is resolved in PAN-OS 11.1.8 under PAN-277751
  2. Upgrade to 11.1.8 or higher will resolve the issue.
  3. As a workaround till the upgrade is done, Update the service object used in the PBF rule with the source and destination ports matching the source and destination ports in s2c flow.

Note: For UDP the destination port will be set to ANY, while for TCP, the destination port range can be set to 1024-65535 or ANY.

 



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HF5bCAG&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail