Features Introduced in Prisma SD-WAN ION Release 6.8
Focus
Focus
Prisma SD-WAN

Features Introduced in Prisma SD-WAN ION Release 6.8

Table of Contents

Features Introduced in Prisma SD-WAN ION Release 6.8

Learn about the new features released in the Prisma SD-WAN ION release 6.8.
Learn about the new features introduced in Prisma SD-WAN ION Release 6.8.

Features Introduced in Prisma SD-WAN Release 6.8.1

Support for Coffeeshop Policies in the Prisma SASE branch

Prisma SD-WAN now supports Coffeeshop deployment to automatically route Prisma Access Mobile User and Explicit Proxy traffic directly to the internet at branch sites, eliminating the need to manually configure and maintain path policies and static routes as gateway IP addresses change. Prisma SD-WAN now automatically learns Mobile User and Explicit Proxy gateway IP addresses from the Prisma Access infrastructure and maintains read-only, dynamically updated prefix lists. For tenants with Remote Network High Performance enabled, Prisma SD-WAN creates a Default Path Coffeeshop Simple Stack Policy Set with two protected rules that route this traffic directly to the internet. The rules automatically synchronize backup and L3 failure paths with your default rule configuration.
You can activate this feature by attaching the auto-created policy set to your active path policy stack and enabling the rules.

Support for Post-Quantum Cryptography

You can now protect Standard VPN connections against future quantum computer attacks using Post-Quantum Cryptography (PQC) on ION devices running release 6.8.1 and above. This release addresses "Harvest Now, Decrypt Later" threats where attackers collect encrypted data today to decrypt it when quantum computers become available.
This release includes:
  • RFC 8784 support for Post-Quantum Pre-shared Keys (PPK) with Mandatory and Preferred negotiation modes
  • RFC 9370/9242 support for up to seven additional key exchange rounds combining NIST-approved ML-KEM algorithms (ML-KEM-512, ML-KEM-768, ML-KEM-1024) with classical algorithms (ECDH, Diffie-Hellman)
  • TLS 1.3 with quantum-resistant hybrid key exchange groups (X25519MLKEM768, SecP256r1MLKEM768, SecP384r1MLKEM1024) for secure ION-to-controller communication
You configure PQC features when creating IPsec profiles for Standard VPN connections.

Support for Branch Gateway across multiple DCs and Branch Gateways

You can now deploy Branch Gateways in full-mesh topologies across multiple data centers and regional hubs with intelligent routing that prevents asymmetry and suboptimal path selection. Prisma SD-WAN now uses hop-count-based path selection to automatically choose the optimal path when multiple Branch Gateways advertise the same prefix, preventing traffic looping and ensuring predictable routing across Branch Gateway nodes.
The system maintains symmetric routing across Branch–Branch Gateway–Data Center topologies, ensuring return traffic follows the same path as outbound flows without requiring manual routing overrides. You can now control prefix distribution using overlay prefix filters between Branch Gateway–Data Center and Branch Gateway–Branch Gateway connections, similar to the filtering capability available for Data Center Interconnect VPNs.

Support for New Indonesia Controller

Prisma SD-WAN now includes a cloud controller hosted in Indonesia, expanding regional coverage to host control plane data, ensuring both data plane and control plane data reside in Indonesia. The Indonesia controller addresses Indonesia's infrastructure demands, enabling lower-latency, locally compliant SD-WAN management for enterprise customers across the region. It is designed to support large-scale branch deployments in key verticals including Banking & Financial Services (BFSI), Telecommunications, and more.
Customers can now onboard SD-WAN tenants with data residency in Indonesia, meeting local regulatory and data sovereignty requirements critical for financial institutions and government-linked organizations operating in the country.

Custom VRF Support for Layer 3 Loopback Interfaces

You can now associate Layer 3 loopback interfaces with Custom VRFs on ION devices running release 6.8.1 and above. LAN-side loopbacks support both Default and Custom VRFs. WAN-side loopbacks continue to be supported in the Default VRF only. This release also adds SNMP as a supported service on loopback interfaces, BGP peering using a loopback as the update source, and OSPF Router-ID assignment from the loopback IP address.