Skip to main content

Illumio Core What's New and Release Notes for Release 24.2

Resolved Issues in Release 24.2.30-PCE

These release notes describe the resolved and known issues for this release.

Resolved Issues

Issue

Fix Description

E-127745

Editing the scope now possible when adding a policy

Users were unable to edit the scope when adding a policy from the "Inbound Admin Access" template. This occurred when the PCE didn't have the necessary scope labels. Normally, these labels and other dependencies are auto-generated when the template is created and saved.

The issue is resolved. Users can now successfully access, edit, and save the scope as expected when applying the template.

E-127078

Override Deny and Deny rules now counted toward the rule object limit

Before this issue was fixed, the deny and override deny rules weren't added to rules counts, and thus, rule limits didn't apply to them. After the fix, deny and override deny rules are counted together with allow rules.

E-126022

Count of VS IDs in the source_rule_ids is now correct

When multiple virtual services (VS) were assigned to a single workload, part of the policies had only one VS ID in the source_rule_ids instead of all of them. This resulted in some VS rules not having any hits at all. This is now fixed.

E-124261

CVEN Convergence Issue

These two problems have been resolved:

  • Out-of-sync problem: The customer fixed the problem with the Load Balancer.

  • Higher CPU utilization

    • Part of the policy Kubelink receives from the PCE for disconnected C-VENs was not acknowledged by the PCE, causing unnecessary policy calculations and a high PCE load. This issue is addressed in EYE-122830, Kubelink: Skipping the ACK of an unknown workload causes repeated policy calculations and sets ACKs. This issue is covered in the release notes for containers.

    • Kubelink was unable to process the PCE policy due to the incorrect format of the policy used for the selected agents. This issue is covered in EYE-117311, Unpair existing CVEN if a new one calls 'activate' with the same machine_id. This issue was not added to the release notes.

E-123013

Services on the standby cluster following the upgrade

Redis job services on the standby PCE didn't stay in the running state.

E-121874

Core services data creation

The Core Services page incorrectly displayed no data. This issue is resolved.

E-120467

Supercluster replication after upgrade to 23.5.x PCE

In rare cases where VENs were previously moved among PCEs in a Supercluster, replication failed after upgrading the PCE to 23.5. x. This issue is resolved.

E-108511

PCE "Upgrading" Status now Cleared

The PCE "Upgrading" Status was not cleared when the VEN was upgraded. This issue is resolved.