8.0.10 Release Notes

Release Date: 11 August 2025

Release Notes Last Updated: 22 December 2025

Corrected Issues in Aviatrix Release 8.0.10

Issue Description

AVX-60731

Fixed an issue where BGP gateways could crash when receiving route updates containing AS-SET information in the AS-PATH attribute. The system now rejects AS-SET and AS_CONFED_SET using default configuration, improving BGP stability and aligning with industry standards.

AVX-63016

Fixed an issue where OpenVPN gateways in split tunnel mode did not propagate newly added Additional CIDRs to clients. The problem occurred because the OpenVPN service was not automatically restarted after CIDR updates, requiring manual restarts. The fix ensures that route and DNS configuration changes now properly trigger service restarts, so Additional CIDRs and DNS settings are pushed to clients without manual intervention.

AVX-63522

Fixed an issue where GCP gateways with FireNet or BGPoLAN enabled were incorrectly configured with subnet-based netmasks instead of the required /32 prefix. This caused routing failures and connectivity issues with firewall appliances.

AVX-63608

Fixed an issue where gateway resize operations could fail with a KeyError: 'src' during validation. This occurred when resizing gateways, including attempts to resize to the same instance size for recovery. The fix improves peer data handling to ensure resize operations complete successfully.

AVX-64741

Fixed an issue where transit peering status was shown as UNKNOWN in the Controller even though tunnels were established. The problem was caused by Edge gateways sending invalid peer values (“<nil>”), which blocked route exchange. The fix adds proper validation of peer IP values so that transit status is reported correctly and routes are exchanged as expected.

AVX-64447

Site2Cloud High Availability (HA) tunnels may not behave correctly when toggling between Active/Active and Active/Standby modes.

Problem 1: When disabling Active/Active HA, the HA Gateway (HAGW) may retain metric 100 routes pointing to tunnel interfaces in the Gateway Route table, even though they should be removed.

Problem 2: When enabling Active/Active HA from Active/Standby, the HA Gateway tunnel may not be properly enabled. This can result in missing routes despite the UI showing Active/Active status.

Impact:

  • Inconsistent routes on the gateway while switching the s2c HA Mode.

  • Potential routing gaps on the gateway lead to incorrect traffic distribution.

Workaround:

If you encounter this issue, contact Aviatrix Support for assistance.

AVX-64774

Fixed an issue where backup restoration failed on GCP controllers when restoring from earlier versions (such as 7.2.5090) to 8.0.0 and later. The issue was caused by a Google Cloud Storage API error during the upload phase. The fix includes a library update and improved error handling to ensure successful restoration.

AVX-65016

In some environments, the Firewall state may not recover from Unaccessible after the first vendor integration failure. This issue has been observed when integrating with third-party firewall vendors, leaving the gateway firewall state stuck even after the environment stabilizes.

Impact:

  • Firewall integration appears stuck in Unaccessible state

  • Recovery does not occur automatically after initial failure

  • May require manual intervention to restore proper firewall state reporting

Workaround:

Contact Aviatrix Support for manual correction.

AVX-65050

Fixed an issue where DCF policies failed to apply to Azure gateways due to Cloud Asset Inventory (CAI) not resolving Azure subnets correctly. This was caused by missing Azure VNET GUID metadata during upgrades, resulting in Smart Group resolution failures and incorrect policy rule enforcement. The fix improves Azure metadata handling and ensures consistent DCF policy application.

AVX-65213

Fixed an issue where system diagnostics could fail with an AttributeError during Controller operations. The error occurred when collecting CloudXD process data that unexpectedly returned None. The fix adds proper null checks to ensure the diagnostic collection completes successfully.

AVX-65565

Fixed an issue where Distributed Cloud Firewall (DCF) eBPF programs were not fully cleaned up from gateway interfaces when DCF features were disabled. The cleanup logic has been improved to ensure all interfaces are properly cleared, preventing residual eBPF programs from remaining after disabling Site-to-Cloud DCF or other DCF features.

AVX-65698

Fixed a memory leak in the DCF Traffic Server (TS_MAIN process) that could cause gateway reboots during high-volume threat IP traffic processing. The issue occurred when multiple DCF rules with ThreatIQ external groups were triggered by continuous probing to inactive threat IPs. Memory usage now stabilizes under sustained load.

AVX-66162

Fixed an issue where DNAT and SNAT configuration updates failed on gateways with policy-based Site2Cloud tunnels. The NAT validation logic has been corrected to properly resolve interfaces, ensuring DNAT and SNAT rules can now be created, modified, or deleted through the Controller UI without errors.

AVX-66961

Fixed a memory leak in the DCF Traffic Server (TS_MAIN process) that could cause gateway memory exhaustion and potential traffic impact. The issue occurred on gateways running Distributed Cloud Firewall (DCF) with WebGroups enabled.

AVX-67128

Fixed an issue where user-uploaded SSL certificates were not automatically restored during Controller migration to version 8.0.0. This caused FQDN-based secure access to the Controller UI to fail post-migration. The fix ensures that existing certificates are now retained and restored during the migration process.

AVX-68308

Fixed an issue in UserConnect 7.2 where gateway resize operations could fail with a KeyError: 'src' exception. This occurred in deployments upgraded from version 6.6 with non-HPE peering configurations and prevented users from resizing gateways once they entered a config_fail state.

Known Issues in Aviatrix Release 8.0.10

Issue Description

AVX-58696

TCP MSS clamping is not supported on Standalone Gateways in Release 7.1 and later.

AVX-59376

When using Controller High Availability (HA) with Controllers version 8.0 and later, the standby Controller will fail to launch correctly. This is because the HA mechanism relies on a fixed software version specified in the Auto Scaling Group (ASG) launch template, but with Controllers version 8.0 and later now require the version to be passed dynamically through cloud-init during instance creation.

This issue occurs only in environments that use:

  • Controller HA for with Controllers version 8.0 and later

  • AWS Auto Scaling Group (ASG) launch templates

  • The default CloudFormation HA deployment method

Workaround:

Use the new CloudFormation template to enable AWS Controller High Availability. This template supports dynamic version injection and restores compatibility with Controllers version 8.0 and later in supported regions. For versions 7.x and earlier, use the existing CloudFormation script (without the v3 suffix).

Note: This solution is not available in AWS regions that do not support Lambda Function URLs.

AVX-61355

Azure Standard_B1ms SNAT-enabled Egress Spoke Gateways may experience significant throughput drops under high connection loads. This limitation is caused by the Azure Standard_B1ms instance type, which has limited compute and network resources.

Affected Scenario:

  • SNAT-enabled Egress Spoke Gateways using Azure Standard_B1ms under high connection loads.

Workaround:

Upsize the Spoke Gateway to a larger Azure instance type for workloads that require more than 10K concurrent connections or consistent network throughput.

AVX-62003

Azure gateway image upgrades may fail when the Controller does not have the required Azure image subscription access. During the upgrade, the system deletes the existing gateway before validating subscription availability, which can result in gateway deletion without a replacement being created. This leaves dangling gateways in the Controller and can cause potential service outages.

Impact:

  • Existing gateways may be deleted during image upgrade

  • Replacement gateway creation fails due to missing subscription

  • Customers may experience connectivity loss and dangling gateway entries in the Controller

  • Manual intervention required, leading to support escalations

Workaround:

None. To avoid outages, ensure the Controller subscription includes access to the required Azure image before attempting upgrades.

AVX-62011

Auto migration will not work from 7.2 to 8.0 when proxy is enabled. You must use a manual backup and restore process to perform the upgrade. Follow the steps below to back up and restore during the upgrade:

  1. If your Controller software version is 7.2.5012 or older, upgrade both the Controller and Gateways to the latest 7.2 build.

  2. Delete the proxy configuration from Controller UI > Settings > Advanced > Proxy.

  3. Back up the Controller from Controller UI > Settings > Maintenance > Backup & Restore > Backup.

  4. Shut down the old Controller.

  5. Launch the new 8.0 Controller and transfer the EIP.

  6. Once the 8.0 Controller is up, restore the Controller using the backup config from Controller UI > Settings > Maintenance > Backup & Restore > Restore.

  7. Add back the proxy configuration from Controller UI > Settings > Advanced > Proxy.

  8. Software upgrade the Gateways from version 7.2 to 8.0.

AVX-62147

The Controller auto-migration and Gateway upgrade features do not function properly when the Aviatrix Controller has proxy settings enabled. In such environments, migration may fail, and you must follow a manual backup and restore process instead of using the standard auto-migration workflow. This limitation is due to current backend behavior that does not support migration through proxy-enabled setups.

Affected Scenario:

  • Controller and Gateway upgrades using auto-migration in environments where proxy settings are enabled on the Aviatrix Controller

Check Whether You Are Affected:

  • In Controller UI: Go to Settings > Advanced > Proxy

  • In CoPilot UI: Go to Settings > Configuration > Private Mode > Proxy Servers

If proxy configurations are present in either location, your deployment is affected.

Workaround:

Follow the manual backup and restore steps below to upgrade the Aviatrix Controller and Gateways:

  1. If the Controller is running version 7.2.5012 or earlier, upgrade to the latest 7.2 build first.

  2. Delete the proxy configuration in the Controller UI.

  3. Back up the Controller from Settings > Maintenance > Backup & Restore > Backup in the CoPilot UI.

  4. Shut down the old Controller.

  5. Launch a new Controller with version 8.0 and reassign the EIP.

  6. Restore the backup in the new Controller.

  7. Reconfigure the proxy settings.

  8. Upgrade the Gateways from version 7.2 to 8.0.

    A maintenance window is recommended for this manual upgrade, as it involves Controller downtime and multiple steps.

AVX-62299

When upgrading from Controller version 7.1 to 7.2 or 8.0, Spoke Gateways with routing through a Public Subnet Filtering (PSF) Gateway may fail to upgrade and become unreachable if the PSF Gateway has not been upgraded first. This issue affects AWS environments where Spoke Gateway route tables are configured to point to a PSF Gateway.

To avoid this issue, follow the correct upgrade sequence:

  1. Upgrade the PSF Gateway first.

  2. Wait for the PSF Gateway upgrade to complete successfully.

  3. Then upgrade the dependent Spoke Gateways.

AVX-62506

During a gateway software upgrade, traffic matching DCF WebGroup rules may be briefly dropped during the upgrade. This impacts both Layer 7 (HTTP/HTTPS) and Layer 4 traffic and occurs across all supported cloud providers (AWS, Azure, and GCP). The disruption typically lasts a few seconds but may vary depending on gateway load and policy complexity.

Workaround:

None

Recommendations:

  • Schedule gateway upgrades during maintenance windows or low-traffic periods.

  • Use HA deployments and upgrade gateways one at a time in HA pairs.

  • Monitor logs for “Failed to load policy” messages to confirm when policies are reloaded.

AVX-62542

In environments where Distributed Cloud Firewall (DCF) and customized SNAT are used together, DCF rules may fail to match traffic correctly when the same SmartGroups are specified in both the source and destination fields. This is because the system does not account for the translated source address during rule evaluation.

As a result, traffic may be unintentionally blocked by the DefaultDenyAll rule, and policies may not apply as expected—particularly in cross-cloud or cross-region scenarios.

Affected Configurations:

  • Customized SNAT (not Single IP SNAT) configured on gateways

  • DCF rules with overlapping SmartGroups in source and destination

  • Environments involving SNAT-translated traffic

Workaround:

In earlier versions, avoid using 0.0.0.0/0 as the destination in SNAT rules. Instead, specify only the required destination CIDRs.

AVX-62712

When recreating a policy-based Site-to-Cloud (S2C) VPN connection after deleting a previous one with the same remote CIDR, the system may incorrectly report a CIDR overlap error, even though the original connection has been removed. This occurs because the system does not fully clean up the remote CIDR information, causing it to believe the CIDR is still in use.

Affected Scenario:

  • Recreating a policy-based Site-to-Cloud VPN connection using the same remote CIDR after deletion, in either of the following cases:

    • The deleted connection was a route-based S2C connection on a gateway that still has other S2C connections.

    • The deleted connection was a policy-based S2C connection.

Workaround:

Contact Aviatrix Support to manually clear the cached CIDR information.

AVX-63175

In Aviatrix Controller version 8.0, Edge Gateway version numbers may be incorrectly updated in the Controller UI after the gateway comes back online from a down state. This occurs even when no new software installation has taken place.

Instead of preserving the actual version running on the Edge Gateway, the Controller may incorrectly overwrite it with its own version. This can lead to confusion during troubleshooting, upgrade planning, or compliance checks.

Affected Environments:

  • All Edge Gateway platforms, including Equinix Network Edge, AEP appliances, and other supported Edge deployments

  • The issue occurs whenever an Edge Gateway transitions from a "down" to "up" state for any reason other than initial installation (for example, reboot, network disruption, or manual restart)

Workaround:

  • Maintain a separate record of installed Gateway versions outside the Controller

  • Use the Edge Gateway’s local console or logs to verify the current version when planning upgrades or diagnosing issues

Note:

This issue only affects Edge Gateways. Cloud provider (CSP) Gateways in AWS, Azure, GCP, or OCI are not affected.

AVX-63846

In the CoPilot UI, Groups > SmartGroups and Groups > ExternalGroups with multiple filters may not appear as originally configured after being saved. This issue occurs when creating groups with multiple sets of any resource type. While policy enforcement is correct, the UI may display missing or merged filter sets, leading to ambiguity and confusion during review or editing.

Affected Scenario:

  • Creating or editing SmartGroups or ExternalGroups with multiple filters applied

Workaround:

There is no workaround at this time. If possible, avoid using multiple filter sets in a single group until the issue is resolved.

AVX-63883

In Aviatrix Controller version 8.0.0, you may encounter a problem when creating or modifying Distributed Cloud Firewall (DCF) rules using either the CoPilot UI or Terraform. In the CoPilot UI, the ruleset may not display correctly and the "Commit" button may be non-functional. When using Terraform, an error may occur indicating that the DCF policy API is unavailable.

This issue prevents you from applying new or updated DCF rules, impacting network security policy management.

Affected Scenario:

  • Creating or modifying DCF rules using the CoPilot UI or Terraform

  • DCF-enabled environments where no rules are currently visible or editable

Workaround:

Contact Aviatrix Support. They can run a script to restore the missing policy list without requiring a full upgrade.

AVX-64015

Jumbo Frame support cannot be enabled on BGPoLAN (BGP over LAN) connections for AWS HPE gateways. Attempts to enable this feature may result in an error indicating that Jumbo Frames are not supported.

This affects environments where high-throughput performance is critical, such as large-scale or latency-sensitive deployments.

Affected Scenario:

  • BGPoLAN connections on AWS HPE gateways

  • Use cases that rely on Jumbo Frame support for performance optimization

Limitation:

In version 8.0.0, Jumbo Frame support can only be enabled when creating a new BGPoLAN connection on AWS HPE gateways. Editing an existing connection to enable Jumbo Frames is not supported.

Workaround:

None.

To enable Jumbo Frame support, delete the existing connection and recreate it with the setting enabled.

AVX-64136

In OCI environments, new CIDRs added to a VCN via the OCI console may not be reflected in the Controller after the initial spoke-transit attachment. As a result, users cannot create gateways in the newly added CIDRs, and the CIDR will not appear in the subnet selection dropdown.

Impact:

  • Controller fails to recognize new OCI CIDRs

  • Gateway creation fails in new CIDR ranges

  • Manual intervention required to refresh CIDR information

Workaround:

  • Add both the original and newly added CIDRs to the Customized Spoke Advertised VPC CIDRs field in the Controller.

AVX-64339

AWS t3.small and t3.medium instances used for Egress Spoke Gateways have limited connection tracking capacity, which can affect performance in high-connection environments.

Impact:

  • t3.medium supports around 25,000 concurrent connections

  • IDS-enabled DCF rules can reduce this to about 2,000

  • When limits are exceeded, traffic may drop and SSH access to the gateway may fail

Workaround:

  • Use larger instance types such as c5.xlarge or c6in.large for applications requiring high concurrent connections

  • Avoid or remove IDS-enabled DCF rules if high connection capacity is needed

  • Monitor conntrack usage using platform tools or gateway diagnostics

Resolution:

This is a documented platform limitation. No product fix is required. Refer to Aviatrix Best Practices for gateway sizing guidance.

AVX-64502

Resolved an issue where, under certain conditions, the eth0 interface on an HPE-enabled Azure gateway could go down, causing the DHCP-assigned primary IP address to be released and a static IP to be promoted as the primary address, which causes traffic disruption.

With this fix, the primary IP address is retained even if the interface temporarily goes down, preventing traffic disruption and gateway connectivity issues.

AVX-64868

In some scenarios involving rapid VRRP state transitions, the keepalived VRRP state may not be reported accurately to the Controller. This can result in temporary discrepancies between the actual VRRP status and what is displayed in the Controller UI, leading to confusion and difficulties during troubleshooting.

Impact:

  • Controller UI may show incorrect VRRP status such as both peers reporting Primary or Initializing

  • No impact on actual VRRP traffic handling or failover behavior.

Workaround:

  • Use diagnostic logs to verify actual VRRP state

AVX-66190

When using Threat Intelligence (ThreatIQ) external groups in Distributed Cloud Firewall (DCF), gateways may log field threat_severity not found errors if unsupported selectors (such as threat_severity) are used.

These configurations are currently accepted by the Controller without validation, but the unsupported selectors are ignored during policy enforcement, and repeated error messages are logged.

Impact:

  • DCF policies continue to function as expected, but administrators may be unaware that some threat selectors are not being applied.

  • The repeated log entries may also affect log analysis and monitoring.

Workaround:

  • Remove unsupported selectors (e.g., threat_severity) from threat group configurations

  • Use only supported fields when defining ThreatIQ external groups

  • Monitor DCF gateway logs for error messages to identify invalid selectors

Resolution:

Future enhancements will add validation during configuration and UI notifications when unsupported selectors are used.

AVX-66324

When using Distributed Cloud Firewall (DCF) Layer 7 rules with Smart Groups that contain tagged resources, no bell notifications appear when configuration issues potentially block traffic. This affects deployments where Smart Groups match resources by tags (such as AWS instance tags) rather than static IPs or CIDRs. Although traffic is enforced correctly, administrators may not be alerted to the problematic configuration.

Affected Scenario:

  • DCF Layer 7 rules configured between Smart Groups based on resource tags (for example, Kubernetes pods and VMs)

  • Both VPCs use RFC1918 IP addresses

  • Gateways are deployed in High Availability (HA) mode

Impact:

Only affects notifications. Traffic enforcement continues to function as expected.

Workaround:

  • Monitor traffic flow manually

  • Use Smart Groups with static IPs or CIDRs if alerting is critical

AVX-66630

Uploading SSL certificates from some providers (such as GoDaddy) could fail if the PEM file included a Unicode Byte Order Mark (BOM). The certificate might appear to upload successfully but would not take effect, and could cause the Controller’s application server to crash with a "missing private key" error.

Impact:

  • SSL certificate installation may silently fail

  • In some cases, the Controller application server could crash

  • Affects wildcard and other SSL certificates from providers like GoDaddy

Workaround:

  • Open the certificate file in a text editor that supports encoding and remove the BOM before uploading

  • Use certificates saved in standard UTF-8 format without BOM

AVX-70123

When upgrading from Controller 8.0.x to 8.1.x, the upgrade may fail to complete due to incorrect database schema type definitions.

As a result, the controller remains on version 8.0.x and the upgrade process does not finish successfully.

Impact: Controller upgrade from 8.0.x to 8.1.x fails.

Workaround: Contact Aviatrix Support for a manual fix to complete the upgrade.

AVX-70253

FireNet deployment with bootstrap enabled may fail in Google Cloud due to changes in how GCP credentials are handled.

The system no longer reads GCP credentials from local files during bootstrap. Instead, credentials are retrieved as encoded data from the database, which causes bootstrap operations to fail in certain FireNet deployment workflows.

Impact: FireNet deployment with bootstrap fails in the Google Cloud environment.

Affected Scenario: FireNet deployments with bootstrap enabled in Google Cloud.

Workaround: Do not use bootstrap when deploying FireNet in Google Cloud. Alternatively, perform the bootstrap process directly from the GCP cloud.

AVX-71087

When upgrading to Controller versions 8.0 or 8.1, ICMP traffic may be blocked by default due to updated access control rules that do not include allowances for ICMP-based debugging.

Affected Scenario: Environments where ICMP is used for network troubleshooting and diagnostic workflows.

Impact:

  • ICMP-based debugging tools may stop functioning

  • Network troubleshooting capabilities may be limited

  • Existing workflows that depend on ICMP may be disrupted Workaround: Manually add access control rules to the Controller to explicitly allow ICMP traffic for debugging. Contact Aviatrix Support for assistance if needed.

AVX-71820

When deploying a load balancer–enabled VPN gateway with an overlapping VPN CIDR on Controller versions 8.0, 8.1, or 8.2, the gateway creation fails.

Impact:

  • VPN gateway deployment fails

  • Error message does not clearly indicate the root cause

Affected Scenario: Load balancer–enabled VPN gateway deployments on Controller versions 8.0, 8.1, and 8.2.

Workaround:

Ensure that the VPN CIDR does not overlap with existing gateways behind the load balancer before deployment. Contact Aviatrix Support for assistance.

AVX-73061

The Cloud Asset Inventory (CAI) service has a memory leak in its L1 cache. When cloud instances such as VMs are removed from the cloud provider, the associated network interfaces remain cached and are never cleaned up.

Impact:

  • In environments that regularly cycle VMs (such as those using spot instances), the CAI service memory consumption grows over time and is never reclaimed.

  • This can lead to high memory usage by the CAI service, potentially affecting Controller performance.

Workaround:

Contact Aviatrix Support for assistance with periodic CAI service restarts to reclaim memory.