Policy and Workloads
PCE Health no longer includes authentication failures in failure percentages (E-90325)
The Health page in the PCE web console and the PCE Health API included authentication failures in heartbeat and policy failure percentages. This led to unnecessary alarm, as these requests do not put a significant load on the PCE. This issue is resolved. The status codes 401 and 403 are now excluded from failure percentages.
Labels were incorrectly marked as unused and could be deleted (E-89189)
Labels could be incorrectly marked as not in use by the workload, based on the status of the VEN. As a result, it was possible to delete the label if the VEN had a status other than Active. This issue is resolved.
Rule Optimization for rules with IP lists (E-89091)
In this release, Illumio has optimized rules that have only IP lists on one side of the rule.
Container workloads could continuously sync policy with the PCE (E-88967)
Environments with high rates of container workload changes and container policy changes could experience a condition where all VENs were constantly syncing policy and PCE performance significantly degraded. This issue is resolved.
Unmanaged workload creation/deletion didn't always trigger policy changes (E-89874)
Under certain conditions, workload policy would not be updated in response to changes to unmanaged workloads, including unmanaged workload creation and deletion. Usage of containers or other workloads with a short lifespan increased the likelihood of encountering this issue. This issue is resolved.
Filtering enforcement boundaries returns the 500 error (E-88230)
Filtering enforcement boundaries by name and service (by HREF) was returning the 500 error. This issue is resolved.
Workload object limit for unmanaged workloads not respected (E-88160)
The PCE did not respect the workload object limit when using bulk APIs to create unmanaged workloads. This issue is resolved.
Workloads synchronizing banner not working properly (E-87593)
In rare cases when the PCE is under load or PCE services were restarting, the banner showing the number of Workloads synchronizing did not work. This issue is resolved.
Filtering Workloads and VENs by IPvb6 IP Address failed in some circumstances (E-87543)
In Workloads & VENs, attempting to filter workloads or VENs by IP Address by specifying part of an IPv6 address that included double colons "::" returned faulty matching results. This issue is resolved, and filtering in this way now works as expected.