| CGSDW-33589 | Resolved an issue where BGP aggregated routes were not added to
the forwarding table, preventing traffic from reaching connected
subnets under the aggregated prefix. This occurred because the
prefix length validation incorrectly rejected connected route
supersets. |
| CGSDW-37535 | Resolved an issue where the traceroute command with the -I option
defaulted to UDP instead of using ICMP. This occurred because the
ICMP traceroute feature was disabled in the build
configuration. |
| CGSDW-37642 | Resolved an issue where Layer 7 system applications were randomly
identified as SSL even when application mapping cache was present.
This occurred because SSL detection from the application engine
overrode previously cached DNS-based application identification when
TLS 1.3 traffic lacked Server Name Indication (SNI). |
| CGSDW-38087 | Resolved an issue where device certificate renewal failed. This
occurred because TPM key creation failed during the renewal
process. |
| CGSDW-38388 | Resolved an issue where Data Center virtual ION devices stopped
advertising BGP prefixes to Branch Gateways, causing connectivity
loss. This occurred because BGP prefix advertisements were not
properly maintained during virtual ION operational state
changes. |
| CGSDW-38511 | Resolved an issue where the ION device became unresponsive after
unexpected power loss and reboot. This occurred because the
authentication daemon process terminated unexpectedly during system
recovery. |
| CGSDW-38747 | Resolved an issue where Data Center hub devices took over one
hour to process interface queues during VPN failover events at 6,000
VPN scale, receiving prefixes from only one site per minute. This
occurred because interface programming operations were processed
sequentially without batching optimization. |
| CGSDW-38824 | Resolved an issue where SSH authentication logs for successful
login sessions were missing the source IP address (rhost field).
This occurred because the authentication daemon did not properly log
remote host information for successful SSH sessions. |
| CGSDW-38944 | Resolved an issue where both active and standby ION devices in a
high availability pair responded to ARP requests after LACP
reconvergence, causing duplicate ARP responses. This occurred
because kernel ARP filter rules were removed during LAG interface
changes but not reapplied after LACP reconvergence
completed. |
| CGSDW-38947 | Resolved an issue where the ION device went offline and did not
reconnect to the controller. This occurred because internal
management processes entered an unrecoverable state requiring a
manual reboot. |
| CGSDW-38948 | Resolved an issue where the system application twitter-base was
not detected for new sessions after deleting a custom application
with the same domain name. This occurred because the application
mapping cache was not properly invalidated when custom applications
were deleted. |
| CGSDW-39293 | Resolved an issue where the ASE process repeatedly restarted on
active ION devices after replacing ION 3000 devices with ION 3200
devices using the RMA wizard. This occurred because the deprecated
ASE process was not properly decommissioned on upgraded
devices. |
| CGSDW-39585 | Resolved an issue where Layer 2 mode VLAN interfaces became
operationally down even though they were configured as
administratively up. This occurred because interface state
synchronization failed during device initialization, requiring
manual interface state changes to restore connectivity. |
| CGSDW-39695 | Resolved an issue where DHCP relay stopped working after device
upgrade or reboot in deployments with 10 or more sub-interfaces
configured. This occurred because DHCP relay service initialization
did not properly restore relay configurations for all VLAN
interfaces. |