8.2.20 Release Notes
Release Date: 22 June 2026
|
Azure gateway customers: This release includes the MANA driver fix, which is a kernel-level change delivered only via an image upgrade. Performing a software-only upgrade to 8.2.20 does not install the new MANA driver. To pick up the fix, perform an image upgrade of all Azure gateways at this release. For details, see the MANA Field Notice. |
Corrected Issues in Aviatrix Release 8.2.20
| Issue | Description |
|---|---|
AVX-65016 |
Fixed an issue where the firewall state did not recover from the Unaccessible state after the first vendor integration failure. |
AVX-74719 |
Fixed an issue where performing a Controller backup restore could cause a temporary traffic outage of approximately 40 seconds due to all routes being deleted and re-added during the etcd route reconvergence process. Routes are now preserved during backup restore to prevent traffic disruption. |
AVX-74739 |
Fixed an issue where the database migration timeout during Controller upgrade was hard-coded at 15 minutes, causing upgrades to fail and roll back in large-scale deployments with thousands of gateways and tunnels. The migration timeout is now user-configurable. |
AVX-75117 |
Fixed a memory leak in the TrafficServer (ATS) process on gateways with DCF intrusion analysis and decryption enabled under high-concurrency traffic conditions that could cause the ATS process to crash and enter a restart loop. |
AVX-75135 |
Fixed an issue where tunnel status report processing on the Controller was slower after upgrading from version 8.0 to 8.1 due to increased database query overhead. The database queries have been optimized to restore processing performance. |
AVX-75256 |
Fixed an issue where FQDN gateway data was not correctly displayed after upgrading from version 7.2.x to 8.0 or later, causing the Egress FQDN Gateway View to appear empty. Gateways with FQDN tags now display correctly in the UI and are returned properly by the list_fqdn_gateways API. |
AVX-75414 |
Fixed an issue where a background service responsible for collecting network topology data experienced unbounded memory growth, which could eventually cause the process to be terminated due to excessive memory consumption. |
AVX-75496 |
Fixed an issue where a Controller upgrade could fail during a database migration step if a corrupted VPC record was present in the Controller database, causing the upgrade to fail and trigger a rollback. |
AVX-75582 |
Fixed an issue where the Aviatrix Controller retried Azure RequestDisallowedByPolicy errors unnecessarily, causing event handler congestion and delaying gateway deployments. |
AVX-76296 |
Fixed an issue in GCP global VPC environments where the Controller removed all gateway routes during routine gateway operations such as resize or image upgrade, causing extended traffic blackholing. |
AVX-76719 |
Fixed an issue where Controller restore operations could stall for approximately 30 minutes during the scheduler shutdown phase due to connectivity issues with AWS API endpoints or invalid/expired IAM credentials. |
AVX-76919 |
Fixed an issue where the gateway state synchronization service ( |
AVX-77088 |
Fixed an issue where editing legacy FQDN domain name filters on a gateway could cause all FQDN filtering processes to stop simultaneously, resulting in a brief filtering outage until the processes were automatically restarted. |
AVX-77419 |
Fixed an issue where importing a system-defined Distributed Cloud Firewall (DCF) ruleset, such as the V1 Policy List or the Kubernetes Policy List, into Terraform state as an |
AVX-77767 |
Fixed an issue where Azure transit gateways with very large numbers of IPsec tunnels (3000+) could lose all spoke peerings and enter a high-CPU charon state under sustained high tunnel activity. |
Known Issues in Aviatrix Release 8.2.20
| Issue | Description |
|---|---|
AVX-62003 |
Azure gateway image upgrades may fail when the Controller does not have the required Azure image subscription access. During the upgrade, the system deletes the existing gateway before validating subscription availability, which can result in gateway deletion without a replacement being created. This leaves dangling gateways in the Controller and can cause potential service outages. Impact:
Workaround: None. To avoid outages, ensure the Controller subscription includes access to the required Azure image before attempting upgrades. |
AVX-62299 |
When upgrading from Controller version 7.1 to 7.2 or 8.0, Spoke Gateways with routing through a Public Subnet Filtering (PSF) Gateway may fail to upgrade and become unreachable if the PSF Gateway has not been upgraded first. This issue affects AWS environments where Spoke Gateway route tables are configured to point to a PSF Gateway. To avoid this issue, follow the correct upgrade sequence:1. Upgrade the PSF Gateway first.
|
AVX-64868 |
In some scenarios involving rapid VRRP state transitions, the keepalived VRRP state may not be reported accurately to the Controller. This can result in temporary discrepancies between the actual VRRP status and what is displayed in the Controller UI, leading to confusion and difficulties during troubleshooting. Impact:
Workaround:
|
AVX-66631 |
Transit gateways with large-scale tunnel deployments (1300+ tunnels) may experience extended traffic loss during image upgrades. Although the image upgrade completes successfully, traffic may remain down for several minutes afterward due to delayed tunnel reconfiguration. Workaround:
Impact:
|
AVX-67126 |
Dry-run validation may fail when upgrading the Controller from version 8.0.10 to 8.1.0 due to a gateway version mismatch error. This occurs when the upgrade path starts from 8.0.0, progresses to 8.0.10 successfully, but encounters a dry-run failure when proceeding to 8.1.0. |
AVX-67180 |
In some environments running Aviatrix Controller version 8.1.x, the Controller UI may become inaccessible after the Controller is restarted. When this issue occurs, API requests fail with Impact: Users are unable to log in to the Controller UI or perform API operations. Workaround: Restart the VM where the Aviatrix Controller is running. |
AVX-68887 |
When attaching VPN users to profiles using the In some cases, users later reappear as active but still show no profile association in the UI. This results in a display inconsistency between the UI and the backend state. Impact: VPN user profile assignments may appear unsuccessful in the UI, which can cause confusion during profile management. There is no functional impact: the VPN profile is correctly assigned in the backend, and users can connect to the VPN as expected. Affected Scenario: OpenVPN profile management operations that use API-based user-to-profile attachment. Workaround: None. |
AVX-69649 |
The migration dry-run EIP accounting does not include public IPs that are not part of the Elastic IP quota, potentially producing inaccurate dry-run results. Impact:
Workaround: Manually verify EIP allocation and quotas before performing the migration. Contact Aviatrix Support for assistance. |
AVX-70543 |
When HA-enabled spoke gateways have DPI/IDS or Layer7 policies configured with "Destination: Anywhere" and the destination smart group contains private CIDRs, the policies become invalid and cause traffic drops. Affected Scenario: Spoke gateways with HA enabled using DPI/IDS or Layer7 policies where destination smart groups include private CIDR ranges. Impact:
Workaround: Modify the destination in DPI/IDS or Layer7 policies to use specific target addresses instead of "Anywhere" when the destination smart group contains private CIDRs on HA-enabled spoke gateways. |
AVX-70864 |
In Controller version 8.2.0, gateways may remain in a Configuration Not Up-to-Date state when applying Distributed Cloud Firewall (DCF) policies under certain conditions. This issue can occur when DCF policies with Web Groups and IDS or IPS enabled are pushed to gateways. The configuration update does not complete within the expected time, which may leave the gateway out of sync. Impact:
Affected Scenario: Gateways running Controller 8.2.0 with DCF policies that include IDS or IPS features, particularly on smaller gateway instance sizes. Workaround: Restart the affected gateway to clear the condition and allow the configuration to be applied successfully. If the issue persists, contact Aviatrix Support for assistance. |
AVX-70958 |
When clients use HTTP/2 connections, TrafficServer incorrectly reuses origin connections, potentially causing connection handling issues in MITM SNI verification scenarios. Impact:
Workaround: Use both IP address and SNI instead of IP alone to ensure proper connection isolation. |
AVX-71245 |
Additional Distributed Cloud Firewall (DCF) log support records end-session events for IDS and IPS signature matches. These logs include a reason field indicating the match type (IPS_POLICY_DENY or IDS_POLICY_ALERT) along with the Signature ID (SID) of the matched rule. Due to a bug, the end-session log is omitted when Decryption is not enabled for Intrusion Analysis. Impact:
Affected Version: 8.2.0 Workaround: Enable Decryption under Intrusion Analysis to ensure end-session logs are generated. |
AVX-71441 |
When upgrading gateways from version 8.1.20 to 8.2.0, in very rare cases, we have seen the gateway could enter an infinite retry loop attempting to download a non-existent configuration file from the Controller, causing the upgrade process to fail completely Impact:
Workaround: Retry the gateway upgrade operation from the Controller UI or Copilot UI. If the issue persists, perform an image upgrade of the impacted gateway. |
AVX-71559 |
When performing a batch gateway image upgrade in Azure, some gateways may fail during the upgrade process. Impact:
Workaround: Retry the gateway image upgrade for the failed gateways individually rather than as a batch operation. Contact Aviatrix Support for assistance. |
AVX-71820 |
When deploying a load balancer–enabled VPN gateway with an overlapping VPN CIDR on Controller versions 8.0, 8.1, or 8.2, the gateway creation fails. Impact:
Affected Scenario: Load balancer–enabled VPN gateway deployments on Controller versions 8.0, 8.1, and 8.2. Workaround: Ensure that the VPN CIDR does not overlap with existing gateways behind the load balancer before deployment. Contact Aviatrix Support for assistance. |
AVX-72940 |
Creating a new gateway with the same name as an existing gateway may cause local files of the existing gateway to be deleted when the creation fails. The existing gateway name disappears from the Controller CLI once we get into this issue. This can break SSH access (sshgw) for the existing gateway. Impact:
Affected Scenario:
Workaround:
|
AVX-73436 |
When using the update_spoke_vpc_route_table API to onboard an Azure route table, the default route (0.0.0.0/0) is not programmed in the spoke VNET route table if the Spoke Gateway has learned the default route from any of the following sources:
In all of the above cases, although the Spoke Gateway has successfully learned and installed the default route in its own routing table, the route is not re-programmed into the associated Azure VNET route table during the onboarding operation. Impact:
Workaround: Manually add the default route to the Azure route table. Contact Aviatrix Support for assistance. |
AVX-73589 |
In some high-traffic environments using FQDN filtering, the NFQ process may stall due to a deadlock. If the signal interrupts a thread that is already executing a non-reentrant function, the signal handler may attempt to acquire the same lock, causing a deadlock. Impact:
Workaround: Restart the instance to continue processing traffic. |
AVX-73836 |
In environments where Duo Authentication is enabled for Client VPN, Duo-authenticated users may intermittently fail to connect to the VPN Gateway. The gateway may log the following error message: Duo OpenVPN: Received 403 Client duo_openvpn version 2.4 is deprecated and no longer supportedThis occurs because the gateway uses an older Duo OpenVPN client library version that is no longer supported by the Duo service. Impact: Users configured with Duo authentication may fail to establish VPN connections. In some cases, bypass users may connect intermittently. Workaround: Update the Duo OpenVPN client version on the gateway by modifying the version in the |
AVX-74577 |
Users are unable to modify tags on third-party firewall instances when those tags contain values with multiple colons (for example, Impact:
Workaround: Avoid using multiple colons in tag values when modifying tags after deployment. Use alternative delimiters such as hyphens or underscores. |
AVX-75586 |
When using Terraform to create gateways and immediately attach them to transit gateways, a race condition can occur where the Terraform provider attempts to create the spoke-to-transit attachment before the gateway has fully transitioned to the "Up" state. The gateway creation API returns before the gateway is operationally ready, causing subsequent attachment operations to fail. Impact:
Workaround: Add a delay or polling mechanism in Terraform configurations between gateway creation and spoke-to-transit attachment resources. Use |
AVX-75607 |
Gateway launch may fail with a Impact:
Restart the avx-ctrl-appserver on the Controller to reset the registry state, then retry gateway creation. Contact Aviatrix Support for assistance. |
AVX-76132 |
Unable to configure more than one OpenVPN gateway behind a UDP Load Balancer. Only the first gateway is retained while additional gateways are incorrectly excluded. This issue affects versions 6.9, 7.x, 8.x, and 9.0.0. Impact:
Workaround: Contact Aviatrix Support for assistance in applying the workaround. |
AVX-76413 |
Description: When the Impact: A temporary dataplane disruption occurs while the controller has the gateways marked as down. The controller automatically detects the gateways are up and reprograms the network correctly immediately afterward. In a large-scale user deployment (~1,400 gateways), full recovery completed in approximately 6 minutes. The underlying behavior has existed for 4+ years and has been observed in a user environment only once. Workaround: Not applicable. The system recovers automatically, no user action required. Recovery typically completes within minutes (~6 min observed in a ~1,400-gateway deployment; smaller deployments recover faster). |
AVX-77135 |
When the Use SSL to connect option is enabled for LDAP configuration, VPN gateway configuration updates may not apply correctly. Impact:
Workaround: Contact Aviatrix Support for assistance. |
AVX-77419 |
Importing a system-defined Distributed Cloud Firewall (DCF) ruleset, such as the V1 Policy List or the Kubernetes Policy List, into Terraform state as an Impact:
There is no after-the-fact workaround. Do not use |
AVX-77618 |
Running Controller diagnostics may report NTP-related errors that do not reflect the actual NTP synchronization status of the Controller. Impact:
Workaround: Verify Controller time synchronization through other means before acting on NTP-related diagnostic errors. Contact Aviatrix Support for assistance. |
AVX-77958 |
When performing a gateway software rollback from version 8.2.20 to 8.1.40 on a Controller deployed in GCP, AWS and AWS GovCloud spoke gateways may fail to roll back successfully. The rollback may partially succeed, leaving affected gateways in an inconsistent state. Impact:
Workaround: Retry the rollback, as the issue is timing-related. If the issue persists, contact Aviatrix Support for further assistance. |