Addressed Issues in Prisma SD-WAN ION Releases
Focus
Focus
Prisma SD-WAN

Addressed Issues in Prisma SD-WAN ION Releases

Table of Contents
Learn about the issues addressed in Prisma SD-WAN ION releases.
This table lists addressed issues across Prisma SD-WAN ION releases. Starting with 6.5.0 release, a separate Addressed Issues document will no longer be published. Refer to this document for 6.5.0 and any supported release.
Releases marked with an asterisk (*) have reached End-of-Life (EoL). Review the hardware and software End-of-Life (EoL) information for products and releases that have reached End-of-Life (EoL) status.
Issue IDDescriptionAddressed in Release/(s)Found in Release
CGSDW-30125Resolved an issue where a value of zero entered for Cache Size in the DNS profile from the web interface was not being pushed to the ION device.6.5.26.1.9
CGSDW-29556Resolved an issue where remote login and service link connections were failing in FIPS mode on a device software upgrade to software version 6.3 or higher.6.5.2, 6.5.1, 6.4.2, 6.3.56.3.5
CGSDW-29207Resolved an issue for WAN to WAN flow failures in Branch Gateway sites, where the app probe entries were being created with the flow's source port as the probe destination port.6.4.2, 6.5.1, 6.5.26.4.1, 6.5.1
CGSDW-29116Resolved an issue of the fp-rte process restart, when the max number of VPNs for FEC were exceeded.6.3.56.3.4
CGSDW-29042Resolved an issue wherein the LAN sub-interface/virtual interface on a standby ION device in an HA configuration was sending ARPs causing LAN disruption.6.3.56.3.5
CGSDW-28712Resolved an issue where IP addresses were missing on interfaces.6.3.56.3.4
CGSDW-28697Resolved an issue where two flows were being created for a VPN tunnel with global VRF configured.6.5.16.4.1, 6.5.1
CGSDW-28458Resolved an issue where the ION Device was not passing traffic after the DEVICESW_CONCURRENT_FLOWLIMIT_EXCEEDED alarm was generated.6.5.16.4.1
CGSDW-28329Resolved an issue where a backup DC ION device continued to advertise branch prefixes after a BGP reset.6.5.1, 6.1.9, 6.1.11, 6.3.56.1.9
CGSDW-28214Resolved an issue wherein a stand-alone interface of the backup ION device connected via a bypass configuration to the active ION went down, when the active ION device was powered down.6.5.1, 6.4.2, 6.3.4, 6.1.106.1.10
CGSDW-28187Resolved an issue where BGP was not being reestablished after a device reboot.6.1.11, 6.5.16.1.9
CGSDW-28049Resolved an issue where the dump-support output and dump-support all commands did not capture the syslogs in the ION 9000 platform, if there was a soft link.6.5.16.3.3
CGSDW-28036Resolved an issue where the VPN Object Identifiers were changing for every polling request.6.5.1, 6.1.11, 6.3.56.3.4
CGSDW-27827Resolved an issue where event logs and SNMP alerts were triggered opposite to the action on the web interface.6.1.11, 6.5.16.1.10
CGSDW-27805Resolved an issue of the SNMP agent not responding for a higher number of VPN tunnels.6.1.11, 6.5.2, 6.3.56.1.1
CGSDW-27728Resolved an issue where the fp-rte process was crashing on an upgrade to software version 6.3.4.6.5.16.3.4, 6.5.1
CGSDW-27697Resolved an issue where statistics were not displayed due to memory issues.6.5.16.4.2, 6.5.1
CGSDW-27588Resolved an issue where the WAN Interface was displaying the ID instead of the name on the web interface.6.5.16.4.2
CGSDW-27542Resolved an issue where the BGP was going down on the active ION device after an HA switchover after upgrading the software version to 6.3.4. 6.3.5, 6.5.16.3.3
CGSDW-27498Resolved an issue where the default route was missing on sub-interfaces after a device reboot.6.5.16.4.1
CGSDW-27462Resolved an issue where application flow was being dropped after the application was detected on upgrading the device software to version 6.3.3.6.3.56.3.3
CGSDW-27387Resolved an issue where traffic from a Standard VPN tunnel was not being routed to the branch over the fabric through the transit DC on the ION 9000 platform.6.3.56.3.3, 6.4.2
CGSDW-27359Resolved an issue of missing application statistics, when a higher number of application performance SLA thresholds were configured.6.1.11, 6.3.5, 6.5.16.1.9
CGSDW-27241After enabling logs for the flow controller, the logs are not rolling over correctly, thus using up all the space in the log directory.6.5.16.4.2
CGSDW-26901Resolved an issue where the remote access session for the device toolkit was timing out and closing after logging in from the web interface.6.4.1, 6.4.26.4.1
CGSDW-26686Resolved an issue where maximum segment size (MSS) clamping was not happening for a PPPoE interface with DPDK after upgrading from software version 5.6.9.6.1.11, 6.3.55.6.9
CGSDW-26247Resolved an issue where the FC control thread was taking a lot of time to populate fib-leak entries in FIB scale.6.3.4-
CGSDW-26226Resolved an issue in which the BGP on a DC ION device did not advertise the /25 route to the core router after multiple VPN flaps (due to switchover in the branch).6.4.2, 6.3.4, 6.2.4, 6.1.106.4.1
CGSDW-25838Expedited the OSPF process reset to ensure a quick re-establishment of neighborships.6.4.26.4.1
CGSDW-25738Resolved an issue for IPFIX, wherein the socket connect was always binding to the device instead of the IP address for non-used-for-controller interfaces.6.4.2, 6.3.4-
CGSDW-25658Resolved an issue of the fp-rte process restarting which was leading to HA fail-over and instability of the device.6.5.16.3.2
CGSDW-25586Resolved an issue where the GRE tunnel was not being established when in FIPS mode.6.4.2, 6.3.4, 6.1.106.4.1
CGSDW-25179Resolved an issue wherein the LAN interface on a standby ION device in an HA configuration was sending ARPs causing LAN disruption.6.4.1
CGSDW-25152Resolved an issue where custom L3/L4 applications were not being detected properly for UDP traffic after an HA switchover.6.5.1, 6.4.2, 6.3.4, 6.1.106.3.2
CGSDW-24973Some advertised prefixes are not displayed for a DC ION device after changing the site mode from Control to Disabled and then back to Control.6.4.1-
CGSDW-24875Fixed an issue where the LQM service was crashing.6.4.16.3.1
CGSDW-24528Enhanced device logging to capture kernel activity in the event of a device restart.6.4.2-
CGSDW-24501Resolved issues of higher switchover periods in an HA setup.6.4.1-
CGSDW-24485Resolved an issue of FC crashing for flows with path type LAN_TO_PRIVATE_DIRECT.6.1.106.1.6
CGSDW-24482Resolved an issue where HMAC integrity check was failing for the controller_ca_chain.pem.6.4.1, 6.2.4, 6.3.4
CGSDW-24400Resolved an issue where the User ID agent was crashing when there were IPv6 entries in NGFW.6.4.1, 6.3.46.4.1
CGSDW-24273Resolved an issue where the v6 default routes for Internet and Private WAN were not being removed from the FIB entries even after powering down the interface.6.4.2, 6.3.4-
CGSDW-24269Resolved an issue where the APPLICATION_CUSTOM_RULE_CONFLICT incident was being raised for system applications.6.4.2, 6.3.4, 6.1.106.1.8
CGSDW-24262Resolved an issue where a route, which was not necessarily the best route, was getting selected as the reachable route.6.4.1, 6.2.4, 6.3.4, 6.1.106.1.6
CGSDW-24246Resolved an issue where the device shell bypass pair on the ION 9200 device was not being configured successfully.6.4.26.4.1
CGSDW-24112Resolved an issue where some packages were being skipped for HMAC integrity check during boot up.6.4.1, 6.3.4-
CGSDW-24099Increased the VRF scale for device interfaces.6.4.2, 6.3.46.4.1
CGSDW-24071Set the concurrent flow limit to 20K.6.4.1, 6.3.46.3.1
CGSDW-23928Resolved an issue where the snmpwalk command was returning incorrect information.6.4.2, 6.3.4, 6.1.106.1.7
CGSDW-23926Resolved an issue where SNMP walk was showing inconsistent interface operation status for switched ports.6.4.2, 6.1.106.1.7
CGSDW-23921Resolved an issue where BGP sessions were not being re-established after a LAN switch reset for the ION 1200-S platform.6.4.1, 6.3.4, 6.1.106.3.2
CGSDW-23881Resolved an issue for a potential DDoS vulnerability wherein the flows now time out correctly.6.5.1, 6.4.2, 6.3.4, 6.1.106.4.1
CGSDW-23705Resolved an issue where stale entries for VPN paths were being retained in the lqm_results.state database.6.4.1, 6.3.4-
CGSDW-23608Optimized security policies to prevent the generation of core files for fp-rte.6.3.46.2.3
CGSDW-23534Resolved an issue where the Ingress displayed a zero value for Bandwidth Utilization.6.4.2, 6.3.4, 6.1.106.1.5
CGSDW-23508Resolved an issue where the app detection did not work as expected after upgrading to software version 6.1.6.6.1.96.1.6
CGSDW-23493Added CPLD reset reasons to the device reboot reasons for better troubleshooting.6.4.1, 6.3.4, 6.1.10-
CGSDW-23429Resolved an issue where the remote terminal connection was failing with the used_for_controller interface.6.3.46.3.2
CGSDW-23414Resolved an issue where the clear dhcp lease command was not deleting the DHCP leases.6.1.96.1.4
CGSDW-23398Resolved an issue where extra interfaces were seen on SNMPv3 polling.6.4.2, 6.1.106.4.1
CGSDW-23397Resolved an issue where the snmp_network_discovery service was restarting every hour on a device which had an attached SNMP discovery profile with an SNMPv3 configuration.6.3.46.3.1
CGSDW-23395After upgrading to device software version 6.3.2-b5, the backup ION device continues to attempt to establish a connection with the controller. If controller port of the device next hop is pointing to ION device LAN interface then use the following workaround for this issue:
  • On the active device, add a static arp entry on the LAN interface which points to the controller interface IP address of the backup device.
  • On the backup device, add a static arp entry on the LAN interface which points to the controller interface IP address of the active device.
6.4.1, 6.3.46.3.2
CGSDW-23390Added the latest ADEM package to device software version 6.1.9.6.1.9, 5.6.19-
CGSDW-23324Resolved an issue where the bypass pair Ethernet port configuration was reset after being assigned to a device shell.6.4.26.4.1
CGSDW-23221Resolved an issue where the ionhwd process was consuming a lot of memory.6.4.1, 6.3.46.2.3
CGSDW-23109Resolved an issue where newly allocated devices were not able to connect to the controller.6.4.1-
CGSDW-23098Resolved an issue where overlapping IP addresses were not working as expected in VRF.6.4.1, 6.3.4-
CGSDW-23049Resolved an issue where core files were being generated when the device was being upgraded.6.4.2, 6.3.4, 6.1.106.4.1
CGSDW-23031Resolved an issue of memory leak in the FC User App logic.6.4.1, 6.1.9, 6.3.4-
CGSDW-22700Resolved an issue where the branch ION device acting as a DHCP relay in a custom VRF configuration was not forwarding requests to the DHCP server at the DC ION device.6.4.1, 6.3.46.3.2
CGSDW-22659The system does not display the correct interface speed for interfaces where no link is detected, i.e. when the operational status is down.6.4.26.1.1
CGSDW-22633Fixed memory issues that were being caused due to security policy configuration.6.3.4, 6.1.106.1.9
CGSDW-22389Resolved an issue where the app probe remained operational after a firewall was removed from the active path.6.4.1, 6.3.46.3.2
CGSDW-22281Resolved an issue where the application reachability probes were crashing on a branch ION device.6.4.1, 6.3.3, 6.3.4-
CGSDW-22281Resolved an issue where the application reachability probes were crashing on a branch ION device.6.4.1, 6.3.3, 6.3.4-
CGSDW-22259Resolved an issue where SNMPv3 was not polling all the interfaces on the ION 9200 platform.6.2.4, 6.1.9, 6.3.46.1.7
CGSDW-22192Resolved an issue where core files were being generated and the device was losing connectivity with the controller when traffic on the client side was abruptly stopped and restarted.6.4.1, 6.3.3, 6.3.46.3.2
CGSDW-22072Resolved an issue where the rtr_mgr_api process was holding a lot of memory.6.4.1, 6.1.9, 6.3.46.1.6
CGSDW-22070Resolved an issue where the statistics server was taking too long to respond to requests for statistics from SCM.6.1.96.1.7
CGSDW-21868Resolved an issue where the outbound SSH6 was not working on the ION device.6.4.1, 6.3.26.3.1
CGSDW-21836Resolved an issue where the VRF creation was failing if the SVI name was longer than nine characters.6.4.16.3.1
CGSDW-21698Resolved an issue where the static ARP was not getting added on the new active device during an HA switchover.6.3.2-
CGSDW-21607Resolved a possible sequencing problem that could arise in the ION device if the VRF profile configuration was done after the interface configuration.6.4.1, 6.3.26.3.1
CGSDW-21580Resolved an issue where the backup ION device was unable to connect to the controller in an HA deployment.6.3.26.3.1
CGSDW-21512Enabled default behavior for the bypass pair latch only in the following scenarios:The device is a backup device in an HA group.The device is powered off.6.1.9, 6.3.46.1.1
CGSDW-21451After being assigned to a site, the ION device does not receive the VRF context in time. This causes incorrect mapping between interfaces and VRFs.6.4.16.3.1
CGSDW-21409FC crashes when many app-map entries are being created, modified, or deleted in parallel. Resolved an issue where the FC was crashing when many app-map entries were being created, modified, or deleted in parallel.6.4.1, 6.3.2, 6.1.96.1.6
CGSDW-21381Removed the unused memory which was allocated for the app-id-elem objects.6.3.26.3.1
CGSDW-21320Resolved an issue where the ION device did not respond to DHCP until it was rebooted or there was a change in configuration.6.4.1, 6.2.4, 6.1.9, 6.3.46.2.2
CGSDW-21300Resolved an issue where the DHCP server wasn't working with the controller and the LAN interface in the same subnet.6.3.26.3.1
CGSDW-21181Added support for AWS IMDSv2 for metadata.6.3.36.3.1
CGSDW-21176Resolved an issue where the SVI interface did not pass traffic.6.4.1, 6.2.4, 6.1.9, 6.3.46.1.5
CGSDW-21119Resolved an issue where the bypass pair ports of a device remained in the bypass pair mode even after the device was declaimed.6.3.1, 6.3.2, 6.2.4, 6.1.96.3.1
CGSDW-21116Resolved an issue where the outbound SSH was not supported on the used-for-controller interface.6.3.26.3.1
CGSDW-21115Resolved an issue where the FEC action was not being displayed in the Flow Browser for inbound (DC to branch) traffic.6.3.46.3.1
CGSDW-21088Resolved an issue where the static ARP entry was incorrectly added on the standby ION device.6.3.26.3.1
CGSDW-21025Resolved an issue where the VPN path was not correct in the performance policy path after detaching and reattaching the circuit on the parent interface.6.3.26.3.1
CGSDW-20864If the only prefix of a VRF at a branch site is deleted, then the entries leaked to the DC site for the specific VRF are also deleted. The workaround is to configure at least one dummy global prefix for the VRF at the branch site.6.3.26.3.1
CGSDW-20824Reduced the downtime in tunnel establishment, such that the ION device re-initiates a new SA with the peer as soon as three tunnel probes fail.6.4.1, 6.1.9, 6.3.46.1.6
CGSDW-20807Resolved an issue where the FIB VPN entries for global VRF were not seen on upgrading the device to software version 6.3.1.6.3.26.3.1
CGSDW-20671Resolved an issue where incidents related to RADIUS server were raised even when a RADIUS server was not configured.6.3.2, 6.1.76.1.6
CGSDW-20649Resolved an issue where the SNMP daemon process was slowly consuming the memory in the ION device suggesting a possible memory leak.6.3.2, 6.2.4, 6.1.76.3.1
CGSDW-20631Resolved an issue where the log-agent was not processing all the DHCP messages received from the log-collector-client.6.3.26.3.1
CGSDW-20382Assessed that the ION device is not impacted by OpenSSH:CVE-2023-51385 and CVE-2023-51767.6.3.2, 6.1.85.6.11
CGSDW-20241Resolved an issue of packet loss on ICMP traffic on the non-default VRF.6.3.26.2.2
CGSDW-20234Resolved an issue where a virtual interface with sub-interfaces was not passing traffic.6.4.1, 6.1.9, 6.3.46.1.6
CGSDW-20223Resolved an issue where the signal strength for the cellular network was displayed incorrectly on the web interface and CLI.6.4.1, 6.2.4, 6.1.76.1.5
CGSDW-19987Resolved an issue where the default signature file was packaged with an incorrect name causing the app-engine to restart.6.3.1, 6.1.96.1.6
CGSDW-19834Resolved an issue where the TCP connection was not being terminated by the controller during a device reboot.6.3.1, 6.3.2, 6.2.4, 6.1.7-
CGSDW-19833Disabled NR5G SA mode and enabled NR5G NSA mode for 5G IPv6 connectivity.6.4.1, 6.1.9, 6.3.46.3.1
CGSDW-19778Resolved an issue where the blobfish process kept on restarting during remote access of the ION device.6.3.1, 6.2.4, 6.1.7-
CGSDW-19707Resolved an issue where the Standard VPN path was not displayed in the list of paths when configured through easy onboarding.6.3.1, 6.1.76.1.1
CGSDW-19674Resolved an issue where the fc-monitor, fp-metrics, and fp-scm processes were crashing due to buffer overflow in DPDK.6.3.1, 6.1.76.1.5
CGSDW-19628Resolved an issue where return traffic was not seen from the DC ION to the branch ION device.6.4.1, 6.3.2, 6.2.4, 6.1.96.1.1
CGSDW-19582Resolved an issue of tunnel detection and ADEM operability during the easy onboarding process.6.3.1, 6.1.6, 6.1.76.1.6
CGSDW-19542Assessed that the ION device is not vulnerable to a Terrapin attack (CVE-2023-48795).6.3.2, 6.1.8, 5.6.19 5.3.1
CGSDW-19493Resolved an issue where the health events prefix shows the prefix in reverse order.6.1.6-
CGSDW-19485Resolved an issue where ADEM was not working after enabling easy onboarding.6.3.1, 6.4.1-
CGSDW-19473Resolved an issue of FC restarting after 3 days of running scan tests on interfaces.6.1.6-
CGSDW-19466Resolved an issue wherein the device to controller connection was taking a long time to establish after a reboot.6.3.1-
CGSDW-19427Resolved an issue where the FC was crashing if the clear user-app-session all CLI command was executed during interface scanning.6.4.1, 6.1.96.1.6
CGSDW-19357When a DC ION receives routes for a /32 prefix from both the underlay and overlay, the DC ION tries to split the route and thus the BGP route selection process fails.6.5.16.1.5
CGSDW-19353Resolved an issue where Path App Prefix Stats can be avoided for network scan.6.1.6-
CGSDW-19255Resolved an issue where the fp-rte process was crashing when the RTE memzone limits were exceeded.6.1.66.1.5
CGSDW-19237Resolved an issue where the FC was crashing due to stack corruption in ION 5200.6.1.76.1.4
CGSDW-19206Resolved an issue where the device interface was flapping with 1000/Full-Cisco switch and 100/10 Full config.6.3.1, 6.1.6, 6.2.46.1.6
CGSDW-19117Resolved an issue where the LQM session wasn't get reestablished after a vpnd process crash.6.5.16.1.2, 6.1.3
CGSDW-19102Resolved an issue where the FC crashed on ION 9200 due to large number of security rules.6.3.1, 6.1.6-
CGSDW-19044Resolved an issue where the ION device was blocking the flow for a custom application due to flow re-classification.6.1.66.1.5
CGSDW-19043Resolved an issue that was causing the fp-rte process to crash on using the clear user-app-session command multiple times.6.1.66.1.5
CGSDW-19015Resolved an issue where the ION device was not able to process large packets on the ION 1000, 2000, and 3000 platforms.6.1.66.0.1*
CGSDW-18982Resolved an issue where fp-rte process crashed due to an exception packet.6.1.6-
CGSDW-18954Resolved an issue where IPFIX was not working when the controller interface was configured as the source interface.6.3.26.3.1
CGSDW-18876Resolved an issue where the SNMP agent on the ION device was restarting with multiple error logs.6.1.66.1.4
CGSDW-18816Resolved an issue of interface flapping on the ION device after a device software upgrade.6.3.1, 6.1.66.1.5
CGSDW-18768Resolved an issue where FC crashed due to ingress QoS.6.1.66.1.5
CGSDW-18490Resolved an issue where the FC was crashing when the security policy rules list counter exceeded 256.6.1.66.1.4
CGSDW-18350Resolved an issue where the ION device was dropping LAN-to-LAN traffic due to security policy configuration.6.1.66.1.4
CGSDW-18252Resolved an issue where the cellular failover to another SIM degraded the performance until a device reboot, modem restart or radio restart was performed.6.1.6-
CGSDW-18164Resolved an issue where the FC was crashing due to a VPN interface being mapped to multiple VPN links.6.1.6-
CGSDW-18158Resolved an issue where dot1xmgr process was consuming high CPU in the ION 1200-S device.6.3.1, 6.1.66.1.5
CGSDW-18154Resolved an issue where ION 1200-C5G-exp didn't support ION 6.1.5-b1 version.6.1.66.1.5
CGSDW-17904Resolved an issue where the dump interface status command did not display the Supported Link modes and the Advertised Link modes.6.3.2-
CGSDW-17886Resolved an issue where a default route was missing in the route table for ION devices with VRF enabled.6.3.1-
CGSDW-17652Resolved an issue where the LAN to LAN traffic was not flowing.6.2.3-
CGSDW-17641Resolved an issue where the interface did not display the IPv6 DNS Server details although the interface was enabled to receive autoconf information.6.2.3-
CGSDW-17572Resolved an issue where the virtual interface couldn't be used for HA topology in the 6.1.x versions.6.1.66.1.4
CGSDW-17571Resolved an issue where incorrect WAN paths were accounted for in the flows.6.3.1, 6.1.6-
CGSDW-17461Resolved an issue with the programming of the VLAN on the trunk port that carries the HA control traffic.6.2.3-
CGSDW-17418Resolved an issue where the ION 5200 and 9200 devices were unable to handle oversize packets.6.2.3, 6.1.56.1.3
CGSDW-17361Implemented a change to handle BGP attributes.6.2.3-
CGSDW-17345Resolved an issue where the device in an unclaimed state was not sending software upgrade states to the controller.6.1.9-
CGSDW-17284Resolved an issue where the FC was crashing due to ADEM.6.2.3-
CGSDW-17214Resolved an issue where setting a custom value for fib_admin_distance displayed an error on the DC ION device.6.2.3 -
CGSDW-17138Fixed a BGP attribute that was seen as corrupted.6.1.5-
CGSDW-17125Resolved an issue where the controller ARP entry was missing on the ION device gateway.6.1.9-
CGSDW-17094Resolved an issue of traffic dropping on an ION 2000 device during the switchover back to the active device in an HA setup.6.1.5-
CGSDW-17031Resolved an issue where the fc-monitor process crashed on ION 2000 during port scanning and restart with an out of memory error.6.1.66.1.5
CGSDW-16971Resolved an issue of delay in VPN tunnel establishment when using same IP addresses for bypass pairs in branch HA.6.3.1-
CGSDW-16947Resolved an issue where fp-rte core files were being generated for traffic from a number of applications with WAN impairments.6.2.3-
CGSDW-16932Updated Zoom Phone application definition with additional prefixes.6.3.1-
CGSDW-16839Resolved an issue where the app-engine was consuming high memory during high traffic flows.6.1.5-
CGSDW-16836Resolved a memory leak caused by the stpstat process.6.2.3, 6.1.56.1.3
CGSDW-16717Resolved an issue where the fp-rte process was crashing if the packet size was larger than 16384.6.2.3, 6.1.5-
CGSDW-16681Resolved an issue where the emif process was crashing on VFF.6.2.3-
CGSDW-16647Optimized traffic loss that occurred during reboot of the device with hardware bypass pairs.6.2.3-
CGSDW-16391Resolved an issue where the FC monitor was crashing after upgrading from the device from software version 5.6.13 to 6.1.3-b1.6.2.3-
CGSDW-16280Resolved an issue wherein the DC ION device did not forward traffic to the mgmt-vlan prefix if the management port of the core switch went down.6.2.3, 6.1.5-
CGSDW-16269Resolved an issue where high payload traffic sent over Private WAN VPN with a high throughput was dropping.6.3.1, 6.2.3, 6.1.5-
CGSDW-16246Resolved an issue where (SACK) block truncated warnings were seen in the log messages.6.2.3-
CGSDW-16172Resolved an issue wherein the ION device with ZBFW was treating the first packet block differently for LAN-to-LAN and LAN-to-WAN traffic.6.3.1, 6.1.7-
CGSDW-16031There is a delay in bringing down the BGP peer of a data center ION device when the remote end of the interface is shut down.6.1.56.1.4
CGSDW-16005Resolved an issue where the app-engine was crashing on an ION 2000 device during continuous traffic flow.6.1.56.1.4
CGSDW-16003Resolved an issue where the FC was crashing due to the ADEM process.6.1.5-
CGSDW-15988On upgrading the device software, a parent interface with more than 20 subinterfaces flaps, resulting in flapping of the IP addresses of the subinterfaces.6.1.56.1.4
CGSDW-15970When rebooting the active device in an HA configuration on the 2000 platform, the bypass pair of the active device does not pass traffic during reload.6.1.56.1.4
CGSDW-15969Resolved an issue where the subinterface was operational in spite of shutting down the remote parent interface on the 1200-S/3200/5200/9200 platforms.6.2.3, 6.1.4-
CGSDW-15967High memory consumption by the ADEM process causes ION device reboot.6.3.2, 6.1.76.1.5
CGSDW-15868Resolved an issue wherein high memory consumption by the ADEM process was causing other processes to crash and device to reboot.6.2.3, 6.1.56.1.4
CGSDW-15828Resolved an issue where the alarm for Power Supply Unit (PSU) removal was not working for the ION 5200 and 9200 devices.6.2.3, 6.1.5-
CGSDW-15663Resolved an issue where the thmgr process did not start after upgrading the device software version.6.2.3, 6.1.5-
CGSDW-15661Resolved an issue where memory leak was observed in the VPN process.6.3.1, 6.2.3, 6.1.4-
CGSDW-15650Resolved an issue where the software version 6.2.x was not compatible with ADEM for the ION 2000 device.6.2.3-
CGSDW-15623Resolved an issue where the FC process was restarting on the ION device.6.1.5-
CGSDW-15529Resolved an issue where the per BGP peer statistics table did not have any data.6.2.3, 6.1.5-
CGSDW-15397Resolved an issue where explicit rule ordering was not taking precedence over implicit rule ordering for User ID based policies.6.2.3-
CGSDW-15393Addressed an issue where the Advertised auto-negotiation mode duplex setting was erroneously set to Yes following a reboot of the ION device through the web interface.6.2.3, 6.1.5-
CGSDW-15339Resolved an issue wherein FC crashes were occurring due to a high volume of subinterfaces.6.1.4-
CGSDW-15258Resolved an issue where the device went offline intermittently due to restart of the FC process.6.3.1, 6.2.3, 6.1.4-
CGSDW-15257Resolved an issue wherein previously reachable prefixes from a DC ION device became unreachable after upgrading the device software to version 6.1.2.6.1.56.1.4
CGSDW-15238Resolved an issue where the fp-metrics process was crashing on clearing flows on the ION device during traffic flow.6.1.5-
CGSDW-15212Resolved an issue where a subinterface on a virtual ION device with DPDK was not passing traffic.6.3.1, 6.1.6-
CGSDW-15201Resolved an issue where the ingress capacity bandwidth calculation was displaying as zero for some WAN links.6.3.1, 5.6.15, 6.2.3, 6.1.4-
CGSDW-15155Resolved an issue where the traffic would take more than 20 seconds to resume after rebooting the active ION device in an HA deployment.6.2.3-
CGSDW-15039Resolved an issue where the domain names were not displayed for Applications on the Flows tab.6.2.3, 6.1.5-
CGSDW-15028Resolved an issue where the Radius attribute Service-Type needed to be set to Callcheck for successful MAC authentication.6.2.26.2.1
CGSDW-15027Resolved an issue where the SNMP interface bandwidth was being reported incorrectly after upgrading the device software version from 5.6.x.6.4.1, 6.3.2, 6.1.76.1.6
CGSDW-14980Resolved an issue where custom applications with L3/L4 prefixes were not detected when used in security policies.6.2.3, 6.1.46.1.2
CGSDW-14766Resolved an issue wherein the configuration for a BGP peer wasn't removed on deleting the BGP peer.6.3.1, 6.1.4-
CGSDW-14737Resolved an issue where the Local AS # was not getting updated correctly in the BGP configuration.6.2.2, 6.1.4-
CGSDW-14698Provided the ability to shut down PoE operations when the device CPU temperature rose above 85 degrees C.6.2.3-
CGSDW-14509Resolved an issue where the interface MAC address configuration was out of sync if the address was configured when the interface was down.6.2.3, 6.1.6-
CGSDW-14432The fp-rte process crashes when fetching information on security policy counters and app stats.6.2.2, 6.1.66.1.1
CGSDW-14344Resolved an issue where the FC process was crashing when traffic was initiated on an idle ION device.6.3.1, 6.2.2, 6.1.3 -
CGSDW-14342Resolved an issue where branch to branch VPNs could not be created for the ION 1200-S device.6.2.3, 6.1.5-
CGSDW-14341Resolved an issue where the Flow Controller was crashing frequently due to a security policy on a branch ION device.6.1.3-
CGSDW-14208Resolved an issue where the data center ION device was forwarding traffic incorrectly.6.2.2, 6.1.3-
CGSDW-14164SNMP support extended for ION-1200-C-5G-EXP.6.2.3-
CGSDW-14120Resolved an issue where the Flow Controller kept on restarting.6.2.2, 6.1.3-
CGSDW-14009Resolved an issue where the HA LED did not light up.6.2.2, 6.1.3-
CGSDW-13982Provided an option to disable tunnel reoptimization based period tunnel latency checks.6.1.4-
CGSDW-13819Resolved an issue of fc-monitor crash wherein the time taken by fc-control thread to report to fc-monitor thread was being incorrectly evaluated.6.2.2, 6.1.3-
CGSDW-13805Resolved an issue wherein received BGP routes were getting filtered in case of uneven route lengths.6.2.3, 6.1.5-
CGSDW-13760Resolved an issue where the FC process would restart on ION device version 6.0.1-b70.6.1.3-
CGSDW-13720Resolved an issue where the IPv4 details for an interface obtained via DHCP changed, when Autoconf was used for IPv6 configuration of the interface.6.2.2-
CGSDW-13533Resolved an issue where the SNMP agent was crashing if the platform did not support certain LLDP MIBs.6.1.3-
CGSDW-13486Resolved an issue where the SNMP agent failed to start after upgrading the ION device.6.2.2, 6.1.3-
CGSDW-13424Resolved an issue where the flow controller was crashing due to incorrect source prefixes configured in the security policy rule.6.1.3-
CGSDW-13415Resolved an issue where the CPU utilization value on the front panel of the device differed from the value on the web interface.6.2.2, 6.1.3-
CGSDW-13412Resolved an issue where an FC process was crashing when trying to forward a flow which was marked for deletion.6.1.3-
CGSDW-13397Resolved an issue where the FC was crashing during a TCP SYN scan.6.2.3, 6.1.66.1.5
CGSDW-13297Resolved an issue where the DHCPv4 server did not start on an interface, if the interface was configured as a relay agent earlier.6.2.2-
CGSDW-13238Resolved an issue where the inspect flow internal command was not working.6.2.2-
CGSDW-13161Resolved an issue where the software bypass was not working after an FC restart for the ION 3200 device.6.2.3, 6.1.9-
CGSDW-12977Resolved an issue that was causing a missing ARP entry for the controller gateway on reload/upgrade to version 5.6.11.6.2.2, 6.1.3-
CGSDW-12960Resolved an issue where Prisma SD-WAN tunnel would not form when using a Virtual Interface on a Data Center ION device.6.2.1, 6.1.3-
CGSDW-12802Resolved an issue where a DHCP server configured on an SVI interface did not work.6.1.3-
CGSDW-12741Resolved an issue where the FC on the data center ION device was crashing after removing multicast profile on a branch site where no devices were assigned.6.1.3-
CGSDW-12733DPD with IKEv2 on Standard VPN does not bring the tunnel down based on the configuration on the DPD timer.6.4.16.1.3
CGSDW-12698Resolved an issue where the branch ION device wasn't passing ICMP traffic originating from a DC ION device to a non-CGNX prefix from WAN to LAN.6.1.56.1.3
CGSDW-12663Resolved an issue in which the HA switchover took place only after restarting the flow controller (FC).6.2.2-
CGSDW-12616Resolved an issue where custom roles could not perform edit actions.6.2.1-
CGSDW-12578Resolved an issue wherein the FC process was restarting frequently after upgrading the device.6.1.3-
CGSDW-12565Resolved an issue where the fp-metrics process was crashing on an ION device due to improper flow clean up.6.1.3-
CGSDW-12562Resolved an issue where ARP packets were not being received over the virtual VLAN interface for a branch ION device.6.2.1, 6.1.3-
CGSDW-12501Resolved an issue where an FC process was crashing on an ION 2000 device when trying to forward a flow which was marked for deletion.6.1.3-
CGSDW-12299Resolved an issue where the PDN selection for custom APN was not following the designated IP address type.6.1.7-
CGSDW-12204Resolved an issue where an FC process was crashing on an ION 3000 device due to insufficient memory.6.1.3-
CGSDW-12189Resolved an issue where the DHCP server could not configure the bootfile for devices without a PXEClient VCI.6.2.1-
CGSDW-12185Resolved an issue where packets were being dropped at the branch site when the TCP ports numbers were re-used between subsequent flows.6.2.1, 6.1.3-
CGSDW-12155Resolved an issue where some CLI dump commands were failing on virtual ION devices.6.1.3-
CGSDW-12127Resolved an issue that was causing intermittent packet drops for ICMP/PING flows in WAN to LAN traffic from Prisma Access mobile users to a Prisma SD-WAN remote branch LAN host.6.2.1, 6.1.35.6.1
CGSDW-11997Resolved an issue where UDP sessions were timing out causing packet drops.6.2.1, 6.1.2-
CGSDW-11976Resolved an issue in which the CPU utilization was reported incorrectly by the ION device.6.2.1, 6.1.36.0.1*
CGSDW-11581Increased the concurrent flow support of the ION-1200-S device to 40,000.6.2.1, 6.1.56.1.2
CGSDW-11579Resolved an issue which prevented deletion of unnecessary configuration on the ION 1000 device.6.2.1, 6.1.35.6.3
CGSDW-11472Resolved an issue where DC ION devices did not forward traffic to the management VLAN prefixes via the core peer router, if the management port on the core went down.6.1.35.5.1
CGSDW-11416Resolved an issue where application override could not be configured for some of the system applications.6.2.16.1.1
CGSDW-11384Resolved an issue where static route polling was failing after 18 hours.6.2.1, 6.1.55.6.5
CGSDW-11378Resolved an issue wherein multicast could not be enabled on the peer with network configured interfaces with a private WAN label attached for a data center ION device.6.1.26.1.1
CGSDW-11353Resolved an issue wherein the Zoom Meeting application traffic destined for 206.247.0.0/16 was not identified correctly.6.2.16.0.1*
CGSDW-11327Resolved an issue where old records in the ARP table were not being removed.6.1.75.6.9
CGSDW-11326Resolved an issue where the vION device interfaces did not display after upgrading the device from device version 5.6.5 to 6.0.1-b70.6.0.1*, 6.0.3*, 6.1.2, 6.2.15.6.5
CGSDW-11155Resolved an issue wherein the FC was crashing due to insufficient memory.6.0.1*, 6.0.3*, 6.1.1, 6.1.3-
CGSDW-11150Resolved an issue where there could be a possibility of malicious command injections through the ION device CLI.6.2.1, 5.6.11, 6.1.55.6.3
CGSDW-11086Resolved an issue where an incorrect DNS entry was being sent to the controller.6.2.1, 6.1.3, 5.6.156.1.1
CGSDW-11059Resolved an issue where the API call for a device bulk configuration query for a greenfield tenant would return an invalid Tenant API version error.6.1.2, 6.2.16.0.2*
CGSDW-10905Resolved an issue where a standard VPN tunnel may flap during the IKE rekey process.6.1.2, 6.2.1, 5.6.115.5.1
CGSDW-10897Resolved an issue where the state change events like LLDP flooding was handled that affected multiple processes.6.2.1, 6.1.66.0.2*
CGSDW-10819Resolved an issue in which LLDP packets were flooding out of the bypass pair for Prisma SD-WAN switching platforms.6.0.3*, 6.1.2, 6.1.16.0.2*
CGSDW-10641Resolved an issue wherein special characters were not allowed in the NTP template names.6.1.26.0.1*
CGSDW-10086Resolved an issue where the Rtr-mgr would leak memory and eventually run out of memory.6.0.1*, 6.1.1, 6.0.2*, 5.6.9, 5.6.135.4.1*
CGSDW-9947Resolved an issue where the 2.3 version of the API for monitoring metrics returned a 403 error.6.1.16.0.2*
CGSDW-9806Resolved an issue where the configuration was not getting pushed to the ION device from the controller, leading to a condition where the ION device ports were not displayed correctly when using CLI commands.6.1.15.6.5
CGSDW-9643Resolved an issue where the branch ION device was going offline or was being disconnected from the controller intermittently whenever IPv6 addresses were present in the DNS responses for ION device internal services.5.6.9, 6.2.2, 6.1.35.2.1*
CGSDW-9540Resolved an issue where the controller would try to alternately connect to the IPv4 address and then the IPv6 address of the VPN interface, when the VPN tunnel was down.6.1.26.0.1*
CGSDW-9421Resolved an issue where bandwidth statistics were occasionally not displayed correctly.6.0.2*, 6.2.1, 6.1.36.0.1*
CGSDW-9379Resolved an issue wherein remote login to the ION device for CLI access was failing.6.0.1*, 6.1.1, 6.0.2, 5.6.95.6.1
CGSDW-9369Resolved an issue wherein the Edit and Delete buttons were not visible on the DHCP Servers page on the Prisma SASE web interface.6.1.16.0.1*
CGSDW-9339Resolved an issue wherein Prisma SD-WAN widgets were not loading on the SASE web interface for a View Only Administrator MSP role.6.1.26.0.1*
CGSDW-9331Resolved an issue where the All Roles filter for Branch and Data Center sites on the ManageDevices page was not working.6.1.16.0.2*
CGSDW-8982Resolved an issue where the tcpdump command did not display the expected packets for sub-interfaces.6.1.16.0.1*
CGSDW-8754Resolved an issue in which the BGP status for a backup ION device displayed as unsynchronized on the web interface.6.1.2, 5.6.115.5.3*
CGSDW-8622Resolved an issue in which the rtr-manager process was constantly restarting.6.0.3*, 5.5.9*, 5.6.9, 6.2.3, 6.1.55.4.5*
CGSDW-8389Prisma Access tunnels configured manually will not support ADEM.6.1.15.6.1
CGSDW-8227Resolved an issue that caused the system routes to disappear during a switchover in a branch high availability (HA) deployment.6.2.1, 5.6.13, 6.1.35.5.5*
CGSDW-8179Added support for pagination for the NAT Zone and Interface Bindings pages.6.1.25.6.1
CGSDW-7844Resolved an issue where the site counter was missing for the Sites page under Manage>Sites.6.1.26.0.1*
CGSDW-7838Resolved an issue where the navigation through stack policies on the web interface was slow.6.2.16.0.1*
CGSDW-7806Resolved an issue where the DHCP Relay was choosing the secondary IP address instead of the primary IP address for sending a DHCP request.6.3.1, 6.1.95.6.1
CGSDW-5513Resolved an issue where domains were missing for applications on the Flow Browser page on the web interface.6.2.1, 6.1.36.0.1*
CGSDW-3861Resolved an issue wherein API calls to a branch ION device were returning inconsistent values when the vpn_to_vpn_forwarding value was set to true.6.2.15.6.1
CGSDW-3841Resolved an issue where a DC ION device was not advertising BGP prefixes learnt from the branch LAN peer to the core peer after an HA switchover.5.6.3, 6.2.3, 6.1.55.5.3