Features Introduced in Prisma SD-WAN ION Release 6.8
Focus
Focus
Prisma SD-WAN

Features Introduced in Prisma SD-WAN ION Release 6.8

Table of Contents

Features Introduced in Prisma SD-WAN ION Release 6.8

Learn about the new features released in the Prisma SD-WAN ION release 6.8.
Learn about the new features introduced in Prisma SD-WAN ION Release 6.8.

Features Introduced in Prisma SD-WAN Release 6.8.1

Support for Coffeeshop Policies in the Prisma SASE branch

Prisma SD-WAN now supports Coffeeshop deployment to automatically route Prisma Access Mobile User and Explicit Proxy traffic directly to the internet at branch sites, eliminating the need to manually configure and maintain path policies and static routes as gateway IP addresses change. Prisma SD-WAN now automatically learns Mobile User and Explicit Proxy gateway IP addresses from the Prisma Access infrastructure and maintains read-only, dynamically updated prefix lists. For tenants with Remote Network High Performance enabled, Prisma SD-WAN creates a Default Path Coffeeshop Simple Stack Policy Set with two protected rules that route this traffic directly to the internet. The rules automatically synchronize backup and L3 failure paths with your default rule configuration.
You can activate this feature by attaching the auto-created policy set to your active path policy stack and enabling the rules.

Support for Post-Quantum Cryptography

You can now protect Standard VPN connections against future quantum computer attacks using Post-Quantum Cryptography (PQC) on ION devices running release 6.8.1 and above. This release addresses "Harvest Now, Decrypt Later" threats where attackers collect encrypted data today to decrypt it when quantum computers become available.
This release includes:
  • RFC 8784 support for Post-Quantum Pre-shared Keys (PPK) with Mandatory and Preferred negotiation modes
  • RFC 9370/9242 support for up to seven additional key exchange rounds combining NIST-approved ML-KEM algorithms (ML-KEM-512, ML-KEM-768, ML-KEM-1024) with classical algorithms (ECDH, Diffie-Hellman)
  • TLS 1.3 with quantum-resistant hybrid key exchange groups (X25519MLKEM768, SecP256r1MLKEM768, SecP384r1MLKEM1024) for secure ION-to-controller communication
You configure PQC features when creating IPsec profiles for Standard VPN connections. The Prisma SD-WAN fabric tunnels continue to be PQC-compliant as they are based on symmetric key cryptographic ciphers.

Hop Count-Based Forwarding for Branch Gateway Mode

Branch Gateways (BGWs) now account for hop count when making forwarding decisions in BGW mode, consistent with the existing behavior in DC mode introduced in 6.5.1.
In full-mesh BGW deployments a BGW can learn the same prefix from multiple peer BGWs. Without hop count awareness, traffic could be forwarded sub-optimally, bouncing between BGWs before reaching its final destination. With this enhancement, BGWs prefer the lowest hop-count path, ensuring traffic takes the most direct route to its destination. This improvement benefits customers running full-mesh BGW topologies who prefer not to configure explicit prefix-based path policies, or those operating in dynamic environments where prefixes change frequently.

Support for New Indonesia Controller

Prisma SD-WAN now includes a cloud controller hosted in Indonesia, expanding regional coverage to host control plane data, ensuring both data plane and control plane data reside in Indonesia. The Indonesia controller addresses Indonesia's infrastructure demands, enabling lower-latency, locally compliant SD-WAN management for enterprise customers across the region. It is designed to support large-scale branch deployments in key verticals including Banking & Financial Services (BFSI), Telecommunications, and more.
Customers can now onboard SD-WAN tenants with data residency in Indonesia, meeting local regulatory and data sovereignty requirements critical for financial institutions and government-linked organizations operating in the country.

Prisma SD-WAN Fabric Routing and Interface Enhancements

Prisma® SD-WAN supports configurable fabric default route advertisement toward OSPF LAN peers and offers Layer 3 loopback interfaces with Custom VRFs. These enhancements give network administrators fine-grained control over default route distribution, route preference, and routing architecture flexibility across the SD-WAN fabric.
This release applies to ION devices running release 6.8.1 and later.
  • OSPF Default Route Advertisement Toward LAN — Enable or disable the advertisement of the fabric default route into OSPF on the LAN side. You can set a custom metric for the advertised route to control route preference in OSPF topologies.
  • Custom VRF Support for Layer 3 Loopbacks — Associate Layer 3 loopback interfaces with Custom VRFs. LAN-side loopbacks support both Default and Custom VRFs, while WAN-side loopbacks remain supported in the Default VRF only.
  • Expanded Loopback Services — Leverage loopback interfaces for SNMP services, BGP peering as the update source, and OSPF Router-ID assignment.

Enhanced Branch Security

Prisma SD-WAN supports CDSS (Cloud Delivered Security Services) Branch Security to extend on-box protection at the branch, complementing our SASE platform with capabilities such as intra-branch policy enforcement and local guest URL filtering. Note that the branch security feature requires a subscription license and is supported starting with the release 6.5.3-I. Logging to SLS also requires a valid SLS license for your tenant/devices. For more information, refer to the release notes.