Addressed Issues in Prisma SD-WAN ION Release 6.8
Focus
Focus
Prisma SD-WAN

Addressed Issues in Prisma SD-WAN ION Release 6.8

Table of Contents

Addressed Issues in Prisma SD-WAN ION Release 6.8

Learn about the addressed issues in Prisma SD-WAN ION release 6.8.
Learn about the issues addressed in Prisma SD-WAN ION device release 6.8.

Addressed Issues in Prisma SD-WAN ION Device Release 6.8.1

The following table lists the issues addressed in Prisma SD-WAN ION device release 6.8.1.
Issue IDDescription
CGSDW-33589Resolved an issue where BGP aggregated routes were not added to the forwarding table, preventing traffic from reaching connected subnets under the aggregated prefix. This occurred because the prefix length validation incorrectly rejected connected route supersets.
CGSDW-37535Resolved an issue where the traceroute command with the -I option defaulted to UDP instead of using ICMP. This occurred because the ICMP traceroute feature was disabled in the build configuration.
CGSDW-37642Resolved an issue where Layer 7 system applications were randomly identified as SSL even when application mapping cache was present. This occurred because SSL detection from the application engine overrode previously cached DNS-based application identification when TLS 1.3 traffic lacked Server Name Indication (SNI).
CGSDW-38087Resolved an issue where device certificate renewal failed. This occurred because TPM key creation failed during the renewal process.
CGSDW-38388Resolved an issue where Data Center virtual ION devices stopped advertising BGP prefixes to Branch Gateways, causing connectivity loss. This occurred because BGP prefix advertisements were not properly maintained during virtual ION operational state changes.
CGSDW-38511Resolved an issue where the ION device became unresponsive after unexpected power loss and reboot. This occurred because the authentication daemon process terminated unexpectedly during system recovery.
CGSDW-38747Resolved an issue where Data Center hub devices took over one hour to process interface queues during VPN failover events at 6,000 VPN scale, receiving prefixes from only one site per minute. This occurred because interface programming operations were processed sequentially without batching optimization.
CGSDW-38824Resolved an issue where SSH authentication logs for successful login sessions were missing the source IP address (rhost field). This occurred because the authentication daemon did not properly log remote host information for successful SSH sessions.
CGSDW-38944Resolved an issue where both active and standby ION devices in a high availability pair responded to ARP requests after LACP reconvergence, causing duplicate ARP responses. This occurred because kernel ARP filter rules were removed during LAG interface changes but not reapplied after LACP reconvergence completed.
CGSDW-38947Resolved an issue where the ION device went offline and did not reconnect to the controller. This occurred because internal management processes entered an unrecoverable state requiring a manual reboot.
CGSDW-38948Resolved an issue where the system application twitter-base was not detected for new sessions after deleting a custom application with the same domain name. This occurred because the application mapping cache was not properly invalidated when custom applications were deleted.
CGSDW-39293Resolved an issue where the ASE process repeatedly restarted on active ION devices after replacing ION 3000 devices with ION 3200 devices using the RMA wizard. This occurred because the deprecated ASE process was not properly decommissioned on upgraded devices.
CGSDW-39585Resolved an issue where Layer 2 mode VLAN interfaces became operationally down even though they were configured as administratively up. This occurred because interface state synchronization failed during device initialization, requiring manual interface state changes to restore connectivity.
CGSDW-39695Resolved an issue where DHCP relay stopped working after device upgrade or reboot in deployments with 10 or more sub-interfaces configured. This occurred because DHCP relay service initialization did not properly restore relay configurations for all VLAN interfaces.