8.0.10 Release Notes
Release Date: 11 August 2025
Corrected Issues in Aviatrix Release 8.0.10
Issue |
Description |
AVX-60731 |
Fixed an issue where BGP gateways could crash when receiving route updates containing AS-SET information in the AS-PATH attribute. The system now rejects AS-SET and AS_CONFED_SET using default configuration, improving BGP stability and aligning with industry standards. |
AVX-63608 |
Fixed an issue where gateway resize operations could fail with a KeyError: 'src' during validation. This occurred when resizing gateways, including attempts to resize to the same instance size for recovery. The fix improves peer data handling to ensure resize operations complete successfully. |
AVX-64774 |
Fixed an issue where backup restoration failed on GCP controllers when restoring from earlier versions (such as 7.2.5090) to 8.0.0 and later. The issue was caused by a Google Cloud Storage API error during the upload phase. The fix includes a library update and improved error handling to ensure successful restoration. Affected Versions: 8.0.10, 8.1.0 Affected Versions: Prior to the latest 8.1.x and 8.0.x builds |
AVX-65050 |
Fixed an issue where DCF policies failed to apply to Azure gateways due to Cloud Asset Inventory (CAI) not resolving Azure subnets correctly. This was caused by missing Azure VNET GUID metadata during upgrades, resulting in Smart Group resolution failures and incorrect policy rule enforcement. The fix improves Azure metadata handling and ensures consistent DCF policy application. Affected Versions: 8.0.10, 8.1.0, and 8.1.10 |
AVX-65213 |
Fixed an issue where system diagnostics could fail with an AttributeError during Controller operations. The error occurred when collecting CloudXD process data that unexpectedly returned |
AVX-65565 |
Fixed an issue where Distributed Cloud Firewall (DCF) eBPF programs were not fully cleaned up from gateway interfaces when DCF features were disabled. The cleanup logic has been improved to ensure all interfaces are properly cleared, preventing residual eBPF programs from remaining after disabling Site-to-Cloud DCF or other DCF features. Affected Versions: 8.0.10, 8.1.0 |
AVX-65698 |
Fixed a memory leak in the DCF Traffic Server (TS_MAIN process) that could cause gateway reboots during high-volume threat IP traffic processing.
The issue occurred when multiple DCF rules with ThreatIQ external groups were triggered by continuous probing to inactive threat IPs. Memory usage now stabilizes under |
AVX-67128 |
Fixed an issue where user-uploaded SSL certificates were not automatically restored during Controller migration to version 8.0.0. This caused FQDN-based secure access to the Controller UI to fail post-migration. The fix ensures that existing certificates are now retained and restored during the migration process. |
Known Issues in Aviatrix Release 8.0.10
Issue |
Description |
||
AVX-58696 |
TCP MSS clamping is not supported on Standalone Gateways in Release 7.1 and later. |
||
AVX-59376 |
When using Controller High Availability (HA) with Controllers version 8.0 and later, the standby Controller will fail to launch correctly. This is because the HA mechanism relies on a fixed software version specified in the Auto Scaling Group (ASG) launch template, but with Controllers version 8.0 and later now require the version to be passed dynamically through This issue occurs only in environments that use:
Workaround: Use the new CloudFormation template to enable AWS Controller High Availability. This template supports dynamic version injection and restores compatibility with Controllers version 8.0 and later in supported regions. For versions 7.x and earlier, use the existing CloudFormation script (without the v3 suffix). Note: This solution is not available in AWS regions that do not support Lambda Function URLs. |
||
AVX-61355 |
Azure Affected Scenario:
Workaround: Upsize the Spoke Gateway to a larger Azure instance type for workloads that require more than 10K concurrent connections or consistent network throughput. |
||
AVX-62011 |
Auto migration will not work from 7.2 to 8.0 when proxy is enabled. You must use a manual backup and restore process to perform the upgrade. Follow the steps below to back up and restore during the upgrade:
|
||
AVX-62147 |
The Controller auto-migration and Gateway upgrade features do not function properly when the Aviatrix Controller has proxy settings enabled. In such environments, migration may fail, and you must follow a manual backup and restore process instead of using the standard auto-migration workflow. This limitation is due to current backend behavior that does not support migration through proxy-enabled setups. Affected Scenario:
Check Whether You Are Affected:
If proxy configurations are present in either location, your deployment is affected. Workaround: Follow the manual backup and restore steps below to upgrade the Aviatrix Controller and Gateways:
|
||
AVX-62299 |
When upgrading from Controller version 7.1 to 7.2 or 8.0, Spoke Gateways with routing through a Public Subnet Filtering (PSF) Gateway may fail to upgrade and become unreachable if the PSF Gateway has not been upgraded first. This issue affects AWS environments where Spoke Gateway route tables are configured to point to a PSF Gateway. To avoid this issue, follow the correct upgrade sequence:
|
||
AVX-62506 |
During a gateway software upgrade, traffic matching DCF WebGroup rules may be briefly dropped during the upgrade. This impacts both Layer 7 (HTTP/HTTPS) and Layer 4 traffic and occurs across all supported cloud providers (AWS, Azure, and GCP). The disruption typically lasts a few seconds but may vary depending on gateway load and policy complexity. Workaround: None Recommendations:
|
||
AVX-62542 |
In environments where Distributed Cloud Firewall (DCF) and customized SNAT are used together, DCF rules may fail to match traffic correctly when the same SmartGroups are specified in both the source and destination fields. This is because the system does not account for the translated source address during rule evaluation. As a result, traffic may be unintentionally blocked by the DefaultDenyAll rule, and policies may not apply as expected—particularly in cross-cloud or cross-region scenarios. Affected Configurations:
Workaround: In earlier versions, avoid using |
||
AVX-62712 |
When recreating a policy-based Site-to-Cloud (S2C) VPN connection after deleting a previous one with the same remote CIDR, the system may incorrectly report a CIDR overlap error, even though the original connection has been removed. This occurs because the system does not fully clean up the remote CIDR information, causing it to believe the CIDR is still in use. Affected Scenario:
Workaround: Contact Aviatrix Support to manually clear the cached CIDR information. |
||
AVX-63175 |
In Aviatrix Controller version 8.0, Edge Gateway version numbers may be incorrectly updated in the Controller UI after the gateway comes back online from a down state. This occurs even when no new software installation has taken place. Instead of preserving the actual version running on the Edge Gateway, the Controller may incorrectly overwrite it with its own version. This can lead to confusion during troubleshooting, upgrade planning, or compliance checks. Affected Environments:
Workaround:
Note: This issue only affects Edge Gateways. Cloud provider (CSP) Gateways in AWS, Azure, GCP, or OCI are not affected. |
||
AVX-63846 |
In the CoPilot UI, Groups > SmartGroups and Groups > ExternalGroups with multiple filters may not appear as originally configured after being saved. This issue occurs when creating groups with multiple sets of any resource type. While policy enforcement is correct, the UI may display missing or merged filter sets, leading to ambiguity and confusion during review or editing. Affected Scenario:
Workaround: There is no workaround at this time. If possible, avoid using multiple filter sets in a single group until the issue is resolved. |
||
AVX-63883 |
In Aviatrix Controller version 8.0.0, you may encounter a problem when creating or modifying Distributed Cloud Firewall (DCF) rules using either the CoPilot UI or Terraform. In the CoPilot UI, the ruleset may not display correctly and the "Commit" button may be non-functional. When using Terraform, an error may occur indicating that the DCF policy API is unavailable. This issue prevents you from applying new or updated DCF rules, impacting network security policy management. Affected Scenario:
Workaround: Contact Aviatrix Support. They can run a script to restore the missing policy list without requiring a full upgrade. |
||
AVX-64015 |
Jumbo Frame support cannot be enabled on BGPoLAN (BGP over LAN) connections for AWS HPE gateways. Attempts to enable this feature may result in an error indicating that Jumbo Frames are not supported. This affects environments where high-throughput performance is critical, such as large-scale or latency-sensitive deployments. Affected Scenario:
Limitation: In version 8.0.0, Jumbo Frame support can only be enabled when creating a new BGPoLAN connection on AWS HPE gateways. Editing an existing connection to enable Jumbo Frames is not supported. Workaround: None. To enable Jumbo Frame support, delete the existing connection and recreate it with the setting enabled. |
||
AVX-66190 |
When using Threat Intelligence (ThreatIQ) external groups in Distributed Cloud Firewall (DCF), gateways may log These configurations are currently accepted by the Controller without validation, but the unsupported selectors are ignored during policy enforcement, and repeated error messages are logged. Affected Versions: 8.0.10, 8.1.0 Workaround:
Impact:
Resolution: Future enhancements will add validation during configuration and UI notifications when unsupported selectors are used. |
||
AVX-66324 |
When using Distributed Cloud Firewall (DCF) Layer 7 rules with Smart Groups that contain tagged resources, no bell notifications appear when configuration issues potentially block traffic. This affects deployments where Smart Groups match resources by tags (such as AWS instance tags) rather than static IPs or CIDRs. Although traffic is enforced correctly, administrators may not be alerted to the problematic configuration. Affected Scenario:
Workaround:
Impact: Only affects notifications. Traffic enforcement continues to function as expected. |
||
AVX-66630 |
Uploading SSL certificates from some providers (such as GoDaddy) could fail if the PEM file included a Unicode Byte Order Mark (BOM). The certificate might appear to upload successfully but would not take effect, and could cause the Controller’s application server to crash with a “missing private key” error. Workaround:
Impact:
|
||
AVX-71630 |
On Azure Aviatrix gateways with accelerated networking enabled and using Distributed Cloud Firewall (DCF) features, intermittent traffic drops may occur after upgrading from a version earlier than 7.2.2994 to 7.2.2994 or later. This issue is caused by incorrect eBPF filters being applied to the slave Affected Scenario:
Impact:
Workaround: Contact Aviatrix Support for assistance. |
||
AVX-73061 |
The Cloud Asset Inventory (CAI) service has a memory leak in its L1 cache. When cloud instances such as VMs are removed from the cloud provider, the associated network interfaces remain cached and are never cleaned up. Impact:
Workaround: Contact Aviatrix Support for assistance with periodic CAI service restarts to reclaim memory. |