8.2.20 Release Notes

Release Date: 22 June 2026

Azure gateway customers: This release includes the MANA driver fix, which is a kernel-level change delivered only via an image upgrade. Performing a software-only upgrade to 8.2.20 does not install the new MANA driver. To pick up the fix, perform an image upgrade of all Azure gateways at this release. For details, see the MANA Field Notice.

Corrected Issues in Aviatrix Release 8.2.20

Issue Description

AVX-65016

Fixed an issue where the firewall state did not recover from the Unaccessible state after the first vendor integration failure.

AVX-74719

Fixed an issue where performing a Controller backup restore could cause a temporary traffic outage of approximately 40 seconds due to all routes being deleted and re-added during the etcd route reconvergence process. Routes are now preserved during backup restore to prevent traffic disruption.

AVX-74739

Fixed an issue where the database migration timeout during Controller upgrade was hard-coded at 15 minutes, causing upgrades to fail and roll back in large-scale deployments with thousands of gateways and tunnels. The migration timeout is now user-configurable.

AVX-75117

Fixed a memory leak in the TrafficServer (ATS) process on gateways with DCF intrusion analysis and decryption enabled under high-concurrency traffic conditions that could cause the ATS process to crash and enter a restart loop.

AVX-75135

Fixed an issue where tunnel status report processing on the Controller was slower after upgrading from version 8.0 to 8.1 due to increased database query overhead. The database queries have been optimized to restore processing performance.

AVX-75256

Fixed an issue where FQDN gateway data was not correctly displayed after upgrading from version 7.2.x to 8.0 or later, causing the Egress FQDN Gateway View to appear empty. Gateways with FQDN tags now display correctly in the UI and are returned properly by the list_fqdn_gateways API.

AVX-75414

Fixed an issue where a background service responsible for collecting network topology data experienced unbounded memory growth, which could eventually cause the process to be terminated due to excessive memory consumption.

AVX-75496

Fixed an issue where a Controller upgrade could fail during a database migration step if a corrupted VPC record was present in the Controller database, causing the upgrade to fail and trigger a rollback.

AVX-75582

Fixed an issue where the Aviatrix Controller retried Azure RequestDisallowedByPolicy errors unnecessarily, causing event handler congestion and delaying gateway deployments.

AVX-76296

Fixed an issue in GCP global VPC environments where the Controller removed all gateway routes during routine gateway operations such as resize or image upgrade, causing extended traffic blackholing.

AVX-76719

Fixed an issue where Controller restore operations could stall for approximately 30 minutes during the scheduler shutdown phase due to connectivity issues with AWS API endpoints or invalid/expired IAM credentials.

AVX-76919

Fixed an issue where the gateway state synchronization service (avx-gw-state-sync) could crash if the gateway’s DNS configuration was not yet fully initialized, temporarily interrupting state synchronization between the Controller and gateways.

AVX-77088

Fixed an issue where editing legacy FQDN domain name filters on a gateway could cause all FQDN filtering processes to stop simultaneously, resulting in a brief filtering outage until the processes were automatically restarted.

AVX-77419

Fixed an issue where importing a system-defined Distributed Cloud Firewall (DCF) ruleset, such as the V1 Policy List or the Kubernetes Policy List, into Terraform state as an aviatrix_dcf_ruleset resource and then destroying the imported resource could delete the underlying system-defined ruleset on the Controller. Deletion of these system-defined rulesets is now prevented at the Controller.

AVX-77767

Fixed an issue where Azure transit gateways with very large numbers of IPsec tunnels (3000+) could lose all spoke peerings and enter a high-CPU charon state under sustained high tunnel activity.

Known Issues in Aviatrix Release 8.2.20

Issue Description

AVX-62003

Azure gateway image upgrades may fail when the Controller does not have the required Azure image subscription access. During the upgrade, the system deletes the existing gateway before validating subscription availability, which can result in gateway deletion without a replacement being created. This leaves dangling gateways in the Controller and can cause potential service outages.

Impact:

  • Existing gateways may be deleted during image upgrade

  • Replacement gateway creation fails due to missing subscription

  • Customers may experience connectivity loss and dangling gateway entries in the Controller

  • Manual intervention required, leading to support escalations

Workaround:

None. To avoid outages, ensure the Controller subscription includes access to the required Azure image before attempting upgrades.

AVX-62299

When upgrading from Controller version 7.1 to 7.2 or 8.0, Spoke Gateways with routing through a Public Subnet Filtering (PSF) Gateway may fail to upgrade and become unreachable if the PSF Gateway has not been upgraded first. This issue affects AWS environments where Spoke Gateway route tables are configured to point to a PSF Gateway.

To avoid this issue, follow the correct upgrade sequence:1. Upgrade the PSF Gateway first.

  1. Wait for the PSF Gateway upgrade to complete successfully.

  2. Then upgrade the dependent Spoke Gateways.

AVX-64868

In some scenarios involving rapid VRRP state transitions, the keepalived VRRP state may not be reported accurately to the Controller. This can result in temporary discrepancies between the actual VRRP status and what is displayed in the Controller UI, leading to confusion and difficulties during troubleshooting.

Impact:

  • Controller UI may show incorrect VRRP status such as both peers reporting Primary or Initializing

  • No impact on actual VRRP traffic handling or failover behavior.

Workaround:

  • Use diagnostic logs to verify actual VRRP state

AVX-66631

Transit gateways with large-scale tunnel deployments (1300+ tunnels) may experience extended traffic loss during image upgrades. Although the image upgrade completes successfully, traffic may remain down for several minutes afterward due to delayed tunnel reconfiguration.

Workaround:

  • Schedule maintenance windows to account for potential traffic loss beyond upgrade completion.

  • Consider staggering upgrades across transit gateways to reduce impact.

  • Monitor tunnel and route service status post-upgrade through CoPilot UI.

Impact:

  • Traffic loss may persist after image upgrade completes

  • Route service startup is blocked until all tunnels are sequentially reconfigured

  • Configuration push may time out with Context cancelled during Phase 1 Create error

AVX-67126

Dry-run validation may fail when upgrading the Controller from version 8.0.10 to 8.1.0 due to a gateway version mismatch error. This occurs when the upgrade path starts from 8.0.0, progresses to 8.0.10 successfully, but encounters a dry-run failure when proceeding to 8.1.0.

AVX-67180

In some environments running Aviatrix Controller version 8.1.x, the Controller UI may become inaccessible after the Controller is restarted. When this issue occurs, API requests fail with RequestRefused errors and the UI cannot be accessed, although SSH access to the Controller remains available.

Impact:

Users are unable to log in to the Controller UI or perform API operations.

Workaround:

Restart the VM where the Aviatrix Controller is running.

AVX-68887

When attaching VPN users to profiles using the attach_vpn_user_to_profile API, the CoPilot or Controller UI may continue to display the user profile as N/A even though the attachment operation completes successfully.

In some cases, users later reappear as active but still show no profile association in the UI. This results in a display inconsistency between the UI and the backend state.

Impact: VPN user profile assignments may appear unsuccessful in the UI, which can cause confusion during profile management. There is no functional impact: the VPN profile is correctly assigned in the backend, and users can connect to the VPN as expected.

Affected Scenario: OpenVPN profile management operations that use API-based user-to-profile attachment.

Workaround: None.

AVX-69649

The migration dry-run EIP accounting does not include public IPs that are not part of the Elastic IP quota, potentially producing inaccurate dry-run results.

Impact:

  • Dry-run migration reports may show incorrect EIP usage

  • Actual migration may encounter unexpected EIP limitations

Workaround:

Manually verify EIP allocation and quotas before performing the migration. Contact Aviatrix Support for assistance.

AVX-70543

When HA-enabled spoke gateways have DPI/IDS or Layer7 policies configured with "Destination: Anywhere" and the destination smart group contains private CIDRs, the policies become invalid and cause traffic drops.

Affected Scenario: Spoke gateways with HA enabled using DPI/IDS or Layer7 policies where destination smart groups include private CIDR ranges.

Impact:

  • All egress traffic matching the policy gets dropped

  • Network connectivity failures for affected traffic flows

  • Policy validation errors in gateway configuration

Workaround: Modify the destination in DPI/IDS or Layer7 policies to use specific target addresses instead of "Anywhere" when the destination smart group contains private CIDRs on HA-enabled spoke gateways.

AVX-70864

In Controller version 8.2.0, gateways may remain in a Configuration Not Up-to-Date state when applying Distributed Cloud Firewall (DCF) policies under certain conditions.

This issue can occur when DCF policies with Web Groups and IDS or IPS enabled are pushed to gateways. The configuration update does not complete within the expected time, which may leave the gateway out of sync.

Impact:

  • Gateway shows Configuration Not Up-to-Date status

  • DCF policies may not be fully applied

  • Traffic may be dropped unexpectedly

Affected Scenario:

Gateways running Controller 8.2.0 with DCF policies that include IDS or IPS features, particularly on smaller gateway instance sizes.

Workaround: Restart the affected gateway to clear the condition and allow the configuration to be applied successfully. If the issue persists, contact Aviatrix Support for assistance.

AVX-70958

When clients use HTTP/2 connections, TrafficServer incorrectly reuses origin connections, potentially causing connection handling issues in MITM SNI verification scenarios.

Impact:

  • Origin connections may be shared inappropriately between different client requests

  • MITM SNI verification may not function as expected

Workaround:

Use both IP address and SNI instead of IP alone to ensure proper connection isolation.

AVX-71245

Additional Distributed Cloud Firewall (DCF) log support records end-session events for IDS and IPS signature matches. These logs include a reason field indicating the match type (IPS_POLICY_DENY or IDS_POLICY_ALERT) along with the Signature ID (SID) of the matched rule.

Due to a bug, the end-session log is omitted when Decryption is not enabled for Intrusion Analysis.

Impact:

  • Missing end-session log entries for IDS/IPS signature matches when Decryption is disabled

  • No impact to DCF policy actions

  • No impact to existing Intrusion Analysis logs

Affected Version: 8.2.0

Workaround: Enable Decryption under Intrusion Analysis to ensure end-session logs are generated.

AVX-71441

When upgrading gateways from version 8.1.20 to 8.2.0, in very rare cases, we have seen the gateway could enter an infinite retry loop attempting to download a non-existent configuration file from the Controller, causing the upgrade process to fail completely

Impact:

  • Gateway upgrade fails and cannot be completed.

  • Gateway becomes stuck in upgrade state.

  • Network connectivity through the affected gateway will be disrupted.

Workaround: Retry the gateway upgrade operation from the Controller UI or Copilot UI. If the issue persists, perform an image upgrade of the impacted gateway.

AVX-71559

When performing a batch gateway image upgrade in Azure, some gateways may fail during the upgrade process.

Impact:

  • Gateway image upgrades in Azure environments may partially fail, with some gateways reporting errors during the replacement process.

  • Affected gateways may show an error indicating that gateway information cannot be retrieved in Azure ARM cloud.

Workaround:

Retry the gateway image upgrade for the failed gateways individually rather than as a batch operation. Contact Aviatrix Support for assistance.

AVX-71820

When deploying a load balancer–enabled VPN gateway with an overlapping VPN CIDR on Controller versions 8.0, 8.1, or 8.2, the gateway creation fails.

Impact:

  • VPN gateway deployment fails

  • Error message does not clearly indicate the root cause

Affected Scenario: Load balancer–enabled VPN gateway deployments on Controller versions 8.0, 8.1, and 8.2.

Workaround:

Ensure that the VPN CIDR does not overlap with existing gateways behind the load balancer before deployment. Contact Aviatrix Support for assistance.

AVX-72940

Creating a new gateway with the same name as an existing gateway may cause local files of the existing gateway to be deleted when the creation fails. The existing gateway name disappears from the Controller CLI once we get into this issue.

This can break SSH access (sshgw) for the existing gateway.

Impact:

  • SSH access to the existing gateway may stop working

  • Gateway recovery may require manual intervention

Affected Scenario:

  • Gateway creation using a name that already exists

Workaround:

AVX-73436

When using the update_spoke_vpc_route_table API to onboard an Azure route table, the default route (0.0.0.0/0) is not programmed in the spoke VNET route table if the Spoke Gateway has learned the default route from any of the following sources:

  • An attached Egress Transit Gateway (Transit with egress functionality enabled)

  • A Transit Gateway that learned the default route via an external Site-to-Cloud (S2C) connection (for example, from an on-premises network or third-party appliance advertising 0.0.0.0/0 over IPSec/BGP)

  • Another Spoke Gateway that is propagating the default route within the Aviatrix network

In all of the above cases, although the Spoke Gateway has successfully learned and installed the default route in its own routing table, the route is not re-programmed into the associated Azure VNET route table during the onboarding operation.

Impact:

  • Default route (0.0.0.0/0) is not installed in the onboarded Azure spoke VNET route table.

  • Traffic that depends on the default route — whether destined for the internet via an egress transit, for on-premises via an S2C-connected transit, or toward another spoke — may not be routed correctly from the Azure VNET.

Workaround:

Manually add the default route to the Azure route table. Contact Aviatrix Support for assistance.

AVX-73589

In some high-traffic environments using FQDN filtering, the NFQ process may stall due to a deadlock. If the signal interrupts a thread that is already executing a non-reentrant function, the signal handler may attempt to acquire the same lock, causing a deadlock.

Impact:

  • The avx-nfq process may stall and stop processing traffic until the service is restarted.

Workaround:

Restart the instance to continue processing traffic.

AVX-73836

In environments where Duo Authentication is enabled for Client VPN, Duo-authenticated users may intermittently fail to connect to the VPN Gateway.

The gateway may log the following error message:

Duo OpenVPN: Received 403 Client duo_openvpn version 2.4 is deprecated and no longer supportedThis occurs because the gateway uses an older Duo OpenVPN client library version that is no longer supported by the Duo service.

Impact:

Users configured with Duo authentication may fail to establish VPN connections. In some cases, bypass users may connect intermittently.

Workaround:

Update the Duo OpenVPN client version on the gateway by modifying the version in the duo_openvpn.py file from 2.4 to 3.0.

AVX-74577

Users are unable to modify tags on third-party firewall instances when those tags contain values with multiple colons (for example, team:iac:module.version:v1.5.3). Attempts to update tags after deployment fail with a too many values to unpack error. Initial deployment is unaffected because tags are passed via a different code path during creation.

Impact:

  • Third-party firewall instance tag updates fail when tag values contain multiple colons

  • Initial deployment with multi-colon tags is not affected

Workaround:

Avoid using multiple colons in tag values when modifying tags after deployment. Use alternative delimiters such as hyphens or underscores.

AVX-75586

When using Terraform to create gateways and immediately attach them to transit gateways, a race condition can occur where the Terraform provider attempts to create the spoke-to-transit attachment before the gateway has fully transitioned to the "Up" state. The gateway creation API returns before the gateway is operationally ready, causing subsequent attachment operations to fail.

Impact:

  • Terraform-driven spoke-to-transit gateway attachments may fail intermittently

  • Gateway creation appears successful but the gateway is not yet operationally ready

  • Terraform apply operations may require re-running to complete successfully

Workaround:

Add a delay or polling mechanism in Terraform configurations between gateway creation and spoke-to-transit attachment resources. Use depends_on with a time_sleep resource to allow the gateway to reach the "Up" state before attempting attachment.

AVX-75607

Gateway launch may fail with a tls: bad certificate error when pulling container images. The Controller’s registry TTL eviction (garbage collection) may fire while images are being downloaded to the gateway, corrupting in-flight blob transfers. The gateway’s container initialization cannot complete, and the apache-spiffe-helper service exits with code 125.

Impact:

  • Gateway creation fails with tls: bad certificate or unexpected EOF errors during container image pull

  • The apache-spiffe-helper service crash-loops with exit code 125

  • Manual intervention is required to recover Workaround:

Restart the avx-ctrl-appserver on the Controller to reset the registry state, then retry gateway creation. Contact Aviatrix Support for assistance.

AVX-76132

Unable to configure more than one OpenVPN gateway behind a UDP Load Balancer. Only the first gateway is retained while additional gateways are incorrectly excluded. This issue affects versions 6.9, 7.x, 8.x, and 9.0.0.

Impact:

  • Multi-gateway VPN deployments relying on UDP load balancing for redundancy or scale are affected.

  • No impact on single-gateway deployments or data plane traffic.

  • Existing multi-gateway configurations set up in 6.x continue to function after upgrading to 7.x or 8.x. Only new deployments or modifications to existing configurations are affected.

Workaround:

Contact Aviatrix Support for assistance in applying the workaround.

AVX-76413

Description: When the avx-ctrl-state-sync service starts up and finds gateways stored as "Down" in etcd, the controller reprograms the network as if those gateways are down, without allowing time for the gateways to connect and prove they are up. This can occur when the controller has previously lost connectivity to gateways (for example, during a transient network issue) and the service then restarts while the gateways themselves remain healthy and continue forwarding traffic.

Impact:

A temporary dataplane disruption occurs while the controller has the gateways marked as down. The controller automatically detects the gateways are up and reprograms the network correctly immediately afterward. In a large-scale user deployment (~1,400 gateways), full recovery completed in approximately 6 minutes. The underlying behavior has existed for 4+ years and has been observed in a user environment only once.

Workaround:

Not applicable. The system recovers automatically, no user action required. Recovery typically completes within minutes (~6 min observed in a ~1,400-gateway deployment; smaller deployments recover faster).

AVX-77135

When the Use SSL to connect option is enabled for LDAP configuration, VPN gateway configuration updates may not apply correctly.

Impact:

  • VPN gateway authentication using LDAP with TLS may not function as expected

  • Manual intervention may be required to ensure VPN authentication is properly configured

Workaround:

Contact Aviatrix Support for assistance.

AVX-77419

Importing a system-defined Distributed Cloud Firewall (DCF) ruleset, such as the V1 Policy List or the Kubernetes Policy List, into Terraform state as an aviatrix_dcf_ruleset resource is not supported. This can occur unintentionally when using the Controller’s Terraform export feature, which can include a system-defined ruleset in the exported state. If a user subsequently runs terraform destroy or removes the resource, the underlying system-defined ruleset is deleted from the Controller and cannot be restored, breaking DCF state on the Controller.

Impact:

  • Destroying an imported system-defined ruleset deletes the ruleset on the Controller; the deletion cannot be reversed.

  • After the V1 Policy List is deleted, customers cannot roll back to the V1 policy if issues are discovered with their DCF ruleset.

  • Note: Destroying the legacy aviatrix_distributed_firewalling_policy_list resource only deletes policies inside the list, not the list itself, and is not affected. Workaround:

There is no after-the-fact workaround. Do not use terraform import to bring system-defined rulesets into Terraform state. When using the Controller’s Terraform export feature on a dcf_ruleset resource, contact Aviatrix Support to review the exported state before running terraform apply or terraform destroy. From version 8.2.20 onwards, deletion of these system-defined rulesets is prevented at the Controller; on earlier versions, contact Aviatrix Support if a system-defined ruleset has already been deleted.

AVX-77618

Running Controller diagnostics may report NTP-related errors that do not reflect the actual NTP synchronization status of the Controller.

Impact:

  • Controller diagnostics output may show NTP errors even when time synchronization is functioning correctly.

  • These spurious diagnostic messages may cause unnecessary concern when reviewing Controller health output.

Workaround:

Verify Controller time synchronization through other means before acting on NTP-related diagnostic errors. Contact Aviatrix Support for assistance.

AVX-77958

When performing a gateway software rollback from version 8.2.20 to 8.1.40 on a Controller deployed in GCP, AWS and AWS GovCloud spoke gateways may fail to roll back successfully. The rollback may partially succeed, leaving affected gateways in an inconsistent state.

Impact:

  • Software rollback from 8.2.20 to 8.1.40 may fail for AWS and AWS GovCloud spoke gateways managed by a Controller deployed in GCP.

  • Affected gateways may be left in an inconsistent state and require manual recovery.

Workaround:

Retry the rollback, as the issue is timing-related. If the issue persists, contact Aviatrix Support for further assistance.