Friday, August 28, 2026
Follow on LinkedIn

Experiencing Unexpected Reboots/Restarts of Palo Alto Firewall? You’re Not Alone

Administrators using Palo Alto Networks firewalls running PAN-OS versions 11.1.4-h7 and 11.1.4-h9 are reporting widespread issues of unexpected reboots. 

The reboots appear to originate from a bug in the affected PAN-OS versions, with reports indicating that the problem is linked to specific network traffic patterns and SSL interception processes. 

Logs from affected devices often show errors such as:

This suggests that the issue may involve memory leaks or mismanagement of packet queues, particularly when SSL interception is enabled.

The ctd_pkt_queue misinterpreting a full state has been identified as a possible trigger for these crashes

The frustration among users is observable. Many have criticized Palo Alto Networks for the delayed response, as a fix is only expected by March 2025, leaving organizations vulnerable in the interim.

One user remarked, “This feels like a joke,” reflecting the sentiment that such a critical issue warrants a more immediate resolution.

Temporary Workarounds

Some administrators have shared temporary measures to mitigate the issue:

  • Manual Monitoring and Reboots: Rebooting passive HA units before they become active has been somewhat effective in minimizing downtime.
  • Disabling SSL Interception: Since the bug is linked to SSL processing, disabling this feature may reduce the likelihood of crashes, though it compromises security functionality.

Official Response and Fix

Palo Alto Networks has acknowledged the issue and released a limited hotfix (PAN-OS 11.1.4-h12) on January 31, 2025, for customers requiring immediate resolution. 

However, this hotfix is not yet widely available and must be requested through account teams. 

A broader release is expected by the end of February or early March. Additionally, future updates addressing this issue include versions 11.1.6-h1, 11.1.7, and beyond. 

While Palo Alto Networks works on a comprehensive fix, administrators must navigate this period with vigilance and temporary workarounds to ensure minimal disruption to their operations.

PCI DSS 4.0 & Supply Chain Attack Prevention – Free Webinar

Kaaviya
Kaaviyahttp://cybersecuritynews.com/
Kaaviya is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Cyber Security Guide

Latest Cyber News

Expert Talks